DPDP Act 2023: What Indian App and Website Owners Must Do

Key takeaways

  • The DPDP Act applies to almost every business collecting personal data online
  • You need clear notices, valid consent, user rights and security safeguards
  • Children’s data and breach notification carry strict obligations

If your website collects enquiry forms, your app has user accounts or your CRM stores customer phone numbers, India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you. This guide explains the key obligations in plain English and what to change in your product. It is general information, not legal advice — consult a qualified lawyer for your specific situation, especially as the DPDP Rules are implemented in phases.

Who the law applies to

The Act covers digital personal data processed in India, and data processed outside India if it relates to offering goods or services to people in India. In the law's terms, the business deciding why and how data is processed is a Data Fiduciary, and the person whose data it is is the Data Principal.

Key obligations for businesses

1. Lawful purpose and consent

Process personal data for a lawful purpose with the person's consent (or a legitimate use permitted by the Act). Consent should be free, specific, informed, unambiguous and given through a clear affirmative action — no pre-ticked boxes.

2. Clear notice

Tell users what data you collect, why, and how they can exercise their rights or complain.

3. Data minimisation and accuracy

Collect only what you need and keep it accurate.

4. Security safeguards

Take reasonable security measures to prevent personal data breaches — encryption, access control, logging and secure development practices.

5. Breach notification

Personal data breaches must be reported to the Data Protection Board of India and to affected users, as prescribed.

6. Retention limits

Delete personal data when it is no longer needed for the purpose, unless the law requires you to keep it.

7. Children's data

For users under 18, you need verifiable parental consent and must avoid tracking, behavioural monitoring or targeted advertising directed at children, subject to the Rules.

User rights you must support

  • Access a summary of their data and how it is processed
  • Correct, complete, update or erase their data
  • Withdraw consent as easily as they gave it
  • Grievance redressal
  • Nominate someone to exercise rights on their behalf

Penalties

The Act provides for significant financial penalties — up to ₹250 crore for certain failures such as not taking reasonable security safeguards. Compliance is far cheaper than a breach.

Practical checklist for your app or website

  • Add clear consent checkboxes to forms and sign-up flows
  • Publish an updated privacy notice
  • Build "download my data" and "delete my account" options
  • Encrypt data in transit (HTTPS) and at rest, and restrict admin access by role
  • Log access to sensitive data and review it
  • Set retention periods and automate deletion
  • Prepare an incident response and breach notification plan
  • Review third-party tools (analytics, CRMs, payment providers) that receive personal data

We build privacy into every project from day one — see our custom software development and web development services, or read how we handle sensitive data in healthcare apps.

Privacy by design: building it into your product

Compliance is easiest when privacy is part of the design, not a patch. Collect optional fields only when needed, separate marketing consent from service consent, mask sensitive data in admin screens, and give each team member access to only the data they need. Automated retention rules and audit logs turn policy into practice.

Vendors and third parties

Your obligations extend to the tools that process data on your behalf — hosting providers, CRMs, analytics, email and WhatsApp providers. Keep a list of these processors, understand what data each receives, and put appropriate contracts in place.

Frequently asked questions

Does the DPDP Act apply to small businesses?

Yes. It applies to businesses that process digital personal data, regardless of size, although some exemptions may be notified for certain entities.

Do I need consent for a website contact form?

You should clearly state why you are collecting the data and obtain consent, and use the data only for that purpose.

What happens if there is a data breach?

You must notify the Data Protection Board of India and affected users as prescribed, and you may face penalties if reasonable safeguards were not in place.

Is this legal advice?

No. This article is general information. Consult a qualified lawyer about your obligations.

Need help making your app or website privacy-ready? Get a free consultation — we reply within 24 hours.