The rules are arriving in stages
India's Digital Personal Data Protection Act, 2023 (the DPDP Act) sets out how organizations must handle personal data in digital form. Its detailed rules, the DPDP Rules 2025, were notified in November 2025 with a staggered timetable: the Data Protection Board was set up straight away, provisions for consent managers follow after a year, and most of the core obligations on businesses apply around eighteen months after notification.
That sounds like plenty of time, but changing how an app collects, stores and deletes data takes longer than most teams expect. Building it into your next releases is far cheaper than retrofitting it under pressure.
This article is a practical guide for product and engineering teams, not legal advice. Confirm how the law applies to your business with a qualified adviser.
The words you'll hear
- Data principal: the person the data is about, such as your customer or user.
- Data fiduciary: the organization that decides why and how personal data is processed. If you run the app, that's usually you.
- Data processor: someone who processes data on your behalf, such as a hosting or messaging provider.
- Consent manager: a registered service that lets people give, manage and withdraw consent across organizations.
A checklist for your app
1. Know what you collect
You can't protect data you don't know you have. List every piece of personal data your app collects, where it's stored, who can see it, which providers receive it and why you need it. Include the easily forgotten places: logs, analytics, backups, exports and message histories.
2. Collect less
The simplest way to reduce risk is not to hold the data at all. For each item on your list, ask whether the feature truly needs it. A date of birth is often only needed as "over 18: yes or no".
3. Give a clear notice
When you ask for consent, people should be told in clear, plain language what data you collect and why, how to withdraw consent and how to complain. The notice should be available in English or in the Indian languages your users read. A wall of legal text that nobody reads doesn't meet the spirit of the law.
4. Ask for consent properly
Consent has to be free, specific and informed, given with a clear action. In practice, that means:
- No pre-ticked boxes, and no bundling unrelated purposes into one "I agree".
- Separate choices for separate purposes, such as order updates versus marketing.
- A record of what each person agreed to, when, and which version of the notice they saw.
- Withdrawing consent should be as easy as giving it.
5. Build the rights into the product
People have the right to access information about their data, to correct it, to have it erased and to have their grievances addressed. Make those requests easy to make and practical to fulfil: an account page that shows and edits data, a deletion flow that reaches every system, and a named contact for grievances.
6. Take extra care with children
Processing the personal data of children (under 18 under the Act) needs verifiable consent from a parent or guardian, and some kinds of tracking and targeted advertising aimed at children are not allowed. If children might use your product, design for it explicitly.
7. Protect what you keep
Reasonable security safeguards are a core obligation: encryption in transit and at rest, access by role, strong sign-in for staff, audit logs of who accessed what and regular updates. Make sure your providers' contracts commit them to the same standards.
8. Plan for a breach before it happens
If personal data is breached, the Board and the affected people must be informed. Decide now who investigates, who decides and who communicates, and make sure your logs would actually tell you what happened.
9. Delete on time
Data should not be kept once its purpose is served. Set retention periods for each kind of data, automate the deletion and remember backups and exports.
Where to start this quarter
- Make the data inventory. It's the foundation for everything else.
- Fix the notice and consent screens in your main sign-up and checkout flows.
- Add automatic deletion for the data you clearly no longer need.
- Write down your breach response plan.
Done well, data protection isn't only about avoiding penalties. People share more willingly with a business that's clear about what it does with their information.
Need help mapping your data or building consent and deletion into your product? See our quality and security service.