Compliance · 6 min read
DPDP Act compliance for websites and apps: a checklist before May 2027
What India’s data protection rules mean for your forms, apps and databases, in plain English, with a checklist your developer can work through.

If your website has a contact form, your app has a login, or your store keeps customer addresses, India’s Digital Personal Data Protection Act applies to you. For a long time that felt theoretical. It won’t for much longer: the rules that give the Act its teeth take full effect in May 2027.
This guide translates the law into what it means for the websites and apps you run, and ends with a checklist your developer can actually work through. It’s written by developers, not lawyers, so treat it as a practical starting point and have your legal adviser review your specific situation.
The timeline, in brief
- August 2023: the Digital Personal Data Protection Act, 2023 was passed.
- 13 November 2025: the DPDP Rules, 2025 were notified. The Data Protection Board was set up immediately.
- November 2026: provisions for registering consent managers came into force, twelve months after notification.
- Mid-May 2027: eighteen months after notification, the main obligations apply: notices, consent, security safeguards, breach reporting, individuals’ rights and the Board’s power to impose penalties.
Eight months sounds like plenty of time. For a business with a website, an app, a CRM and a few marketing tools, it goes quickly.
Does it apply to your business?
Almost certainly. The Act applies to personal data collected in digital form in India, and to data collected offline and later digitised. It also reaches businesses outside India if they offer goods or services to people in India. There is no small-business exemption for the core obligations. A clinic in Porur with an appointment form is covered, just as a national retailer is.
The key terms, in plain English
- Data principal: the person the data is about, such as your customer, user, applicant or patient.
- Data fiduciary: you, the business that decides why and how the data is used.
- Data processor: anyone processing data on your behalf, like your hosting company, email tool, CRM or AI provider.
- Consent manager: a registered platform that lets people give, manage and withdraw consent across businesses.
What it means for a typical website
Contact and enquiry forms
Every form that collects a name, phone number or email needs a clear notice of what you collect and why, and consent where consent is the basis for using it. Collect only what you need. If a phone number is enough to call someone back, don’t also ask for their date of birth.
Newsletters and marketing
Consent for marketing must be separate from consent to answer an enquiry, and never pre-ticked. People must be able to withdraw it as easily as they gave it.
Analytics, pixels and tracking tools
Tracking that identifies individuals involves personal data. Audit which scripts run on your site, what they collect, and whether you need them. Fewer third-party scripts also makes a site faster and safer.
Chat widgets and AI assistants
People share personal details in chat. Make sure the provider has proper data-processing terms and doesn’t use your customers’ messages to train its models. We cover this in more depth in our guide to AI chatbots and their costs.
Careers pages
Résumés are full of personal data. Say how long you keep them and delete them when you no longer need them.
What it means for apps and customer portals
- Sign-up and onboarding need clear notices before data is collected, not a link to a 20-page policy.
- Permissions for location, contacts and camera should be requested only when needed, with a plain reason.
- Users under 18 need verifiable consent from a parent or guardian, and you can’t track them, monitor their behaviour or target ads at them. For education, gaming and social apps, this shapes the product itself.
- Account deletion should be available inside the app, and actually delete the data (subject to legal retention requirements).
- Admin panels need role-based access so staff see only the data their job requires.
The checklist
1. Know your data
- List every place personal data enters: forms, apps, WhatsApp, payment gateway, spreadsheets, CRM.
- Record what is collected, why, where it is stored, who can access it and which vendors process it.
2. Rewrite your notices
- Standalone, clear and in plain language, with an itemised list of the data collected and the purpose for each.
- Explain how to withdraw consent, exercise rights and complain to the Data Protection Board.
- Be ready to provide the notice in English or any language in the Eighth Schedule of the Constitution, which includes Tamil, if someone asks.
3. Fix consent
- No pre-ticked boxes. Separate consent for separate purposes, such as enquiries versus marketing.
- Keep a record of when and how each person consented.
- Make withdrawal as easy as giving consent, and make sure it actually stops the processing.
4. Secure it properly
- Encryption in transit and at rest, strong access control and two-factor login for admin accounts.
- Logs that let you detect and investigate misuse, kept for at least a year.
- Tested backups, and security updates applied promptly. Our website maintenance guide explains what that involves.
5. Prepare for a breach before one happens
- Inform affected people without delay, and send the Data Protection Board a detailed report within 72 hours of becoming aware of the breach.
- Write down who does what, who decides, and who contacts customers. Practise it once.
6. Delete what you no longer need
- Set retention periods for each type of data and delete it once the purpose is served, unless the law requires you to keep it.
- Very large ecommerce, gaming and social media platforms have specific rules to erase data after three years of user inactivity, with 48 hours’ notice first.
7. Honour people’s rights
- People can ask what data you hold, correct it, have it erased and nominate someone to act for them.
- Publish a contact for data questions and grievances, and respond within the timelines the rules set.
8. Tighten vendor contracts
- Hosting, email, CRM, analytics, payment and AI providers should be bound by contract to protect the data and use it only on your instructions.
What happens if you ignore it
The Act’s penalties are set per breach and are large: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to report a breach or meet the obligations around children’s data, and up to ₹50 crore for other failures. Small businesses are unlikely to face the maximum, but the reputational damage of a leaked customer list is immediate whatever your size.
What it costs to get compliant
For a typical business website, the technical work is modest: rewritten notices, better forms, consent records, a tidy-up of third-party scripts and security hardening. Apps and portals take more, because consent, deletion, access control and logging touch the product itself. Building these in during a redesign or a new build is far cheaper than retrofitting, which is one reason to plan them into your development process from the first week.
How we can help
We are not lawyers and won’t pretend to be. What we do is the technical side: auditing what your website or app collects, rebuilding forms and consent flows, securing data, setting up logging and breach procedures, and working alongside your legal adviser. See our custom software and website development pages, or get in touch for an audit.


