Navigating DPDP Act 2023 Compliance for SaaS Founders & Fintech Startups
India's Digital Personal Data Protection Act, 2023 (DPDP Act) received Presidential assent in August 2023, and after two years of drafting and public consultation, the DPDP Rules, 2025 were formally notified by MeitY(Ministry of Electronics and Information Technology of India) on 13 November 2025. The Data Protection Board of India (DPBI) is now operational and enforcement has already begun.
The first Data Protection Board enforcement actions were initiated in 2026 against app developers found processing data without valid consent or adequate retention policies. If your product has even a single Indian user, you are a Data Fiduciary under this law, and the obligations apply to you.
What Is the DPDP Act?
Think of it like this: India finally decided that your users' data belongs to them, not to you. You can borrow it (with permission), use it only for what you said you'd use it for, keep it only as long as needed, and return control to the user whenever they ask.
The DPDPA 2023 is India's answer to Europe's GDPR, but leaner and more practical. In force since November 2025, the DPDPA now has real enforcement power and startups are already being held accountable."
If you don't comply with this law, you could be fined up to ₹250 crore per violation, an amount that could shut down most startups overnight.

Key Definitions
Let's say you run a software company called ABC Tech. ABC Tech builds a project management app and collects user data to run the platform. We'll use this example throughout all 5 definitions.
The DPDP Act under Section 2 explains specific terms you'll hear constantly. Here's what they mean in the real world:
Data Principal: This term has been defined under Section 2(j) of the DPDP Act. In simple terms, Data Principal is the individual to whom the personal data relates i.e Your user. The person whose data you collect. They have rights, and this law is largely written to protect them.
Data Fiduciary: This term has been defined under Section 2(i) of the DPDP Act. In simple terms the company that decides why and how to collect and use that data is called the Data Fiduciary.If you decide why and how personal data is processed, you're the fiduciary.
In our example, ABC Tech is the Data Fiduciary. ABC Tech decided to collect user names, emails, and usage behaviour. ABC Tech decided what to do with it. So ABC Tech is responsible and accountable under this law.
Think of it like a bank. You deposit your money and trust them to keep it safe. The bank is your fiduciary. Similarly, your users deposit their data with you and trust you to protect it.
Data Processor: This term has been defined under Section 2(k) of the DPDP Act. The companies that handle data on your behalf, but don't decide what to do with it, are called Data Processors.
In our example, ABC Tech uses AWS to store user data and Mailchimp to send emails. AWS and Mailchimp are Data Processors. They follow ABC Tech's instructions. They don't decide anything on their own.
Even if AWS causes a breach, ABC Tech is still responsible. You cannot pass the blame to your vendor.
Consent Manager: This term has been defined under Section 2(g). In simple terms, a registered platform that allows users to manage all their data permissions in one place across multiple apps and services.
In our example, imagine a user who uses ABC Tech, a food delivery app, and a fintech app. Instead of managing privacy settings on three different apps, they can go to one Consent Manager platform and control everything from there.
Significant Data Fiduciary (SDF): This term has been defined under Section 2(t). In simple terms, a bigger, more regulated category of fiduciary. Some Data Fiduciaries handle so much sensitive data that the government puts them in a special higher-regulation category called Significant Data Fiduciary or SDF.
In our example, if ABC Tech grows and starts handling financial data, KYC documents, or data of 50 lakh+ users, the government may designate ABC Tech as an SDF. This brings extra obligations like appointing a Data Protection Officer, yearly audits, and algorithmic accountability.
Think of it like this, every restaurant needs a basic food licence. But a restaurant inside a hospital that serves patients needs extra certifications. SDF is that extra certification category.
Data Protection Board of India (DPBI): It is established under Section 18 of DPDP Act, 2023. The DPBI is the regulatory authority responsible for investigating complaints, adjudicating breaches, and imposing penalties under the DPDP Act.
Its key powers are spread across:
Section 19: Composition of the Board
Section 20: Qualifications of Chairperson and Members
Section 27: Powers of the Board during inquiry
Section 28: Powers of Civil Court given to the Board
Section 29: Penalties and directions the Board can issue
In our ABC Tech example, if a user complains that ABC Tech used their data without consent then they can approach the DPBI. The Board will investigate, call ABC Tech for hearing, and if found guilty can impose a fine.
Think of DPBI like a consumer court, but specifically for data violations. You file a complaint, they investigate, they decide.
Affected Users: Not defined as a standalone term in the DPDPA, but the obligation to notify them is clearly mentioned under Section 8(6) i.e. Every Data Fiduciary shall notify the Board and each affected Data Principal in the event of a personal data breach. Affected Users are the Data Principals whose personal data has been compromised, leaked, or misused, either due to a breach, unauthorized access, or accidental disclosure.
In our example, imagine ABC Tech suffers a cyberattack and the email addresses and phone numbers of 10,000 users get leaked. Those 10,000 users are the Affected Users.
Under the DPDPA, ABC Tech has two immediate obligations the moment this happens:
Notify the Data Protection Board of India: the regulator must know
Inform every Affected User: each person whose data was compromised must be told
You cannot stay silent, investigate quietly, and fix it without telling anyone. Notification is mandatory and immediate, no matter how embarrassing or damaging it is for your company.
Think of it like a water pipe bursting in an apartment building. You cannot just quietly mop your own floor. You have to knock on every affected flat's door and tell them water is coming.
Who is this Law applicable to?
Section 3 of DPDP Act, 2023 tells about the applicability of this law and explains who are covered and who are not covered under this Act.
Who is Covered?
1. Any business that collects digital personal data in India
If your platform collects even a single data point that is name, email, phone number, location from a person sitting in India, you are covered.
In our example, ABC Tech's app collects name, email, and usage data from users across India. ABC Tech is fully covered under this law and there are no exceptions.
2. Businesses outside India that serve Indian users
Even if your company is registered in Singapore, the US, or anywhere else and if your product is used by people in India, this law applies to you.
In our example, imagine ABC Tech expanded and is now incorporated in Singapore but still has 2 lakh Indian users. The DPDP Act still applies to ABC Tech because the data of Indian residents is being processed.
3. Companies that profile Indian users
If you track, analyse, or build profiles of Indian users, even without selling them anything then you are covered.
In our example, if ABC Tech runs an analytics engine that tracks how Indian users behave on the app, what features they use, how long they stay, what they click, that is profiling and falls under this law.
Who are not covered:
Under Section 3(2) of the DPDPA 2023, the following are excluded:
1. Publicly available data
If a user themselves made their data public like posting their phone number on a public website or social media and you use only that publicly available information, you are not covered for that specific data.
In our example, if ABC Tech only uses a user's LinkedIn profile information that the user themselves made public that data is outside the scope of DPDP Act.
2. Personal or domestic use
If you collect data purely for personal use, not for any business purpose then you are not covered.
In our example, if an ABC Tech employee maintains a personal spreadsheet of their friends' birthdays on their laptop then that is personal use and not covered under this law.
3. Non-digitised data that will never be digitised
If data exists only on paper and you never intend to put it into a digital system, it is outside the scope of this law.
In our example, if ABC Tech's office maintains a physical visitor register at the reception and never scans or enters that data into any system then that register is not covered under DPDP Act.
DPDP Compliance Checklist: The 7 Rules Every Startup Must Follow
Rule 1: Consent: Always Ask First
You cannot collect data without the user's clear, informed, and specific permission. No dark patterns, no pre-ticked boxes, no burying it in 40-page terms.
In our example, ABC Tech cannot simply start collecting a user's location data just because they signed up for the app. ABC Tech must show a clear popup saying, "We would like to access your location to show you nearby team members. Do you agree? Yes / No" and wait for the user to say yes.
If the user says no, ABC Tech cannot block them from using the app just because they refused location access. Consent must be free, not forced.
Rule 2: Purpose Limitation: Use It Only For What You Said
You can only use the data for the specific reason you told the user about. The moment you use it for something else, you are violating this rule.
In our example, ABC Tech collected a user's phone number for sending OTP during login. Now ABC Tech's marketing team wants to use that same phone number to send promotional messages about a new feature launch.
That is a violation. ABC Tech must go back to the user, explain the new purpose, and get fresh consent before sending any marketing messages on that number.
Rule 3: Data Minimisation: Collect Only What You Need
Do not collect data just because you can. Collect only what is genuinely required for your product to function.
In our example, ABC Tech's project management app asks users to fill in their date of birth, home address, and marital status during signup. None of these are needed to manage projects. This is over-collection and a direct violation.
ABC Tech should only ask for name, work email, and company name, the minimum needed to create an account and run the service.
Rule 4: Accuracy: Keep The Data Correct
You must ensure that the data you hold is accurate and up to date. Users have the right to correct wrong information and you must act on it.
In our example, a user tells ABC Tech that their email address has changed and asks them to update it. ABC Tech cannot ignore this request or delay it indefinitely. They must update it promptly and also update it with any vendor they have shared that email with, like their CRM or email marketing tool.
Rule 5: Storage Limitation: Don't Keep It Forever
Once the purpose for which you collected the data is done, delete it. You cannot hoard user data indefinitely just because it might be useful someday.
In our example, a user deletes their ABC Tech account in January 2026. ABC Tech cannot keep that user's name, email, usage history, and behavioural data sitting in their database forever. Once the account is closed and any legal retention period is over — the data must be permanently deleted.
Think of it like a hotel. Once the guest checks out, you return their key. You don't keep a copy.
Rule 6: Security Safeguards: Protect What You Have Collected
You must put appropriate technical and organisational measures in place to protect the data you hold. Encryption, access controls, audits, all of it.
In our example, ABC Tech stores user passwords in plain text in their database. A hacker breaks in and steals 50,000 passwords. This is not just a technical failure, it is a direct DPDPA violation because ABC Tech failed to implement basic security safeguards.
ABC Tech should have encrypted passwords, restricted database access to only essential team members, and conducted regular security audits.
Rule 7: Accountability: If Something Goes Wrong, It Is On You
You are responsible for everything that happens with your users' data, even if a vendor caused the problem. You cannot pass the blame.
In our example, ABC Tech uses a third-party email tool that suffers a breach and leaks 10,000 users' email addresses. ABC Tech cannot say "it was the email tool's fault, not ours."
Under DPDPA 2023, ABC Tech is the Data Fiduciary. They chose that vendor. They shared user data with them. They are accountable. ABC Tech must notify the Data Protection Board and inform all affected users, immediately.
The DPDP Compliance Checklist for Startups (2026 Edition)
Work through this systematically. This is your practical build list.
Step 1: Data Mapping (Do This First)
Before you can comply, you need to know what you have. Map every data point your product touches:
What personal data do you collect? (Name, phone, email, Aadhaar, PAN, bank details, location, device ID, behavioural data)
Where does it come from? (Direct input, third-party APIs, cookies, analytics tools)
Where does it live? (Your database, AWS S3, your CRM, your email tool)
Who has access to it? (Engineers, support staff, third-party vendors)
How long do you keep it? (Define retention periods for each category)
Where does it go? (Do you send it outside India? To vendors?)
This might feel boring, but do not skip it.
Most startups get into trouble not because of bad intentions, but simply because they never stopped to ask, "what data do we actually have and where is it sitting?"
Think of it like shifting houses. Before packing, you walk through every room and make a list. Without that list, you forget things, lose things, and carry unnecessary stuff to the new house.
A data map is exactly that list but for your users' data.
Once you know what you have, everything else follows. Your privacy policy, your vendor contracts, your breach response plan, all of it becomes straightforward.
Step 2: Fix Your Consent Flows
Your current "I agree to T&Cs" checkbox probably doesn't cut it anymore. Under the DPDP Act, consent must be:
Free: No coercion. Users shouldn't lose core functionality just because they said no to marketing.
Informed: Tell them exactly what you'll collect and why, in plain language.
Specific: One consent for one purpose. Separate consents for separate purposes.
Unconditional: You cannot bundle consent. "Agree to share data with partners OR don't use the app" is not valid.
Withdrawable: Users must be able to withdraw consent as easily as they gave it.
For Fintech specifically: KYC and regulatory compliance (RBI mandated AML/KYC) can rely on "legitimate use" without consent, you don't need user permission to fulfill a legal obligation. But marketing, cross-sell analytics, and partner data sharing all need explicit consent.
Step 3: Write a Proper Privacy Notice
You need a standalone privacy notice, separate from your Terms of Service and that tells users in plain language:
What data you collect and why
How they can exercise their rights (access, correct, delete, nominate)
Who your Data Protection Officer is (if applicable)
How to raise a grievance
Whether you share data outside India
The notice must be available in English or any language listed in the Eighth Schedule of the Indian Constitution. For regional apps, this matters. The DPDP Rules 2025 mandate that the privacy notice must be presented directly on your website or app, with direct communication links through which the user can withdraw consent, exercise their rights, and file a complaint with the Board. It must also include the contact details of your Data Protection Officer or authorised representative. In simple terms, it cannot be buried in your terms and conditions page that nobody reads. It must be front and accessible.
Step 4: Build User Rights Workflows
Under Section 11-14 of the DPDP Act, your users have four rights. You must build workflows to handle each:
Right to Access: If a user asks "what data do you have about me?", you must be able to tell them and send it within a prescribed period. Under Section 11, the Data Fiduciary must respond within 30 days of receiving the request, which can be extended to 60 days in complex cases. The first access request every year must be fulfilled free of charge, you cannot charge the user for it.
Right to Correction and Erasure: If they say "that data is wrong" or "delete my account," you must act on it. This includes cascading deletion to your data processors (your vendors).
Right to Grievance Redressal: You need a working, responsive grievance mechanism. A dead email address doesn't count.
Right to Nominate: Users can nominate someone to exercise their data rights in case of death or incapacity. You need a mechanism for this.
As a best practice, build a "Data & Privacy" section directly into your app settings, accessible in two taps, so users can view their data, manage consents, and raise grievances all in one place.
Step 5: Handle Children's Data Carefully
Anyone under 18 is a "child" under the DPDP Act. If your platform could have users under 18:
You must obtain verifiable parental consent before processing their data
You cannot track or behaviorally monitor children
You cannot run targeted advertising at children
You cannot allow content harmful to children's wellbeing
Age-gating on a signup form alone won't be enough. You need verifiable mechanisms. Fintech and edtech startups should pay special attention here.
Step 6: Secure Your Data Processors (Vendors)
You are accountable for what your vendors do with your users' data. Under Section 8(2) of the DPDP Act, you must have a valid data processing contract with every vendor that handles personal data on your behalf. This contract must require them to process data only as you instruct and maintain security standards.
Review your contracts with: cloud providers, email service providers, analytics platforms, payment gateways, CRM tools, customer support tools, marketing automation platforms, and any API integrations that receive user data.
Step 7: Build a Data Breach Response Plan
Under Section 8(6) of the DPDP Act, if you have a breach, you must notify both the Data Protection Board and the affected users. There's no grace period to "figure out what happened first", this is mandatory and immediate.
Your breach response plan should define: who declares a breach, who notifies the Board, what you tell users, and how you contain damage. Run a drill before you need it.
Step 8: Review Cross-Border Data Transfers
The DPDP Act permits data transfers outside India, but not to countries restricted by the Central Government (no restricted countries have been notified yet). If your SaaS sends data to US servers, EU data centers, or international vendors, you need to check whether those destinations are on the permitted list once the whitelist is notified by MeitY.
For Significant Data Fiduciaries specifically, transfers to non-whitelisted countries require a Transfer Impact Assessment.
Before sending user data to another country, a Significant Data Fiduciary must do a documented safety check, this is called a Transfer Impact Assessment.
It simply means answering three questions in writing:
What data are we sending and how sensitive is it?
Does the destination country have laws to protect it?
What could go wrong and what are we doing to prevent it?
If the answers raise red flags, the transfer should not happen until those risks are addressed.
What Is a Significant Data Fiduciary and Could That Be You?
This is the part most fintech founders need to read twice.
A Significant Data Fiduciary (SDF) is a Data Fiduciary that the Central Government designates as high-impact based on the following factors:
Volume of data: Processing data of a very large number of Indian residents (indicative threshold: 50 lakh+ users)
Sensitivity of data: Financial data, health data, biometric data, KYC data
Risk to users: Could a breach or misuse significantly harm people?
National security implications: Critical infrastructure, payment systems
Use in automated decision-making: Algorithms that determine credit scores, loan eligibility, insurance premiums
For fintech startups: If you process KYC data (Aadhaar, PAN), bank account details, credit bureau data, UPI transactions, or NBFC lending data, you are high on the SDF radar regardless of user volume. The law specifically calls out fintech, payments, and BFSI as being in "immediate focus" for SDF designation due to their integration with national infrastructure like UPI and Aadhaar.
Important nuance: SDF status is not self-declared. The Central Government formally notifies you. But you must prepare as if you will be designated, because once notified, obligations kick in and you're expected to comply quickly.
If You Are (or Might Be) an SDF, Your Additional Obligations Are:
1. Appoint a Data Protection Officer (DPO): Under Section 10(2) of DPDP Act, Data Fiduciary must appoint a DPO. It must be an individual residing in India and A background in law, information technology, or cybersecurity. He reports directly to your Board of Directors. Cannot be outsourced to a vendor. This is your regulatory interface with the DPBI and the point of contact for grievance redressal.
2. Conduct Annual Data Protection Impact Assessments (DPIAs) A documented review of: what data you process, for what purpose, the risks to users, and what you're doing to mitigate those risks. Must be done once every twelve months. Must include a review of any AI/algorithmic systems that use personal data.
3. Annual Independent Audit: Under Section 10(2)(b) of the Digital Personal Data Protection Act, 2023, the Significant Data Fiduciary itself appoints the independent data auditor and not the government or the Data Protection Board. An external auditor reviews your data practices and compliance. Significant findings must be reported to the Data Protection Board.
4. Algorithmic Accountability: If you use recommendation engines, credit scoring models, fraud detection algorithms, or any automated decision system that affects users, you must document that these systems don't pose a risk to user rights.
Key DPDP Act Compliance Deadlines
Milestone | Date | What it Means |
DPDP Rules Notified | 13 November 2025 | Enforcement Active |
Data Protection Board Operational | November 2025 (Phase 1) | Enforcement actions already initiated in 2026 |
Consent Manager Framework Live | 13 November 2026 | Users can manage consents centrally across services. |
SDF Designation Begins | November 2026 onwards | Government starts notifying which companies are SDF |
Full Compliance Deadline | 13 May 2027 | All operational obligations such as notice, consent, breach reporting, rights workflows, must be fully implemented |
2026 is not a planning year. It's a building year. The Consent Manager deadline and the start of SDF designations both land in November 2026. If you haven't built your compliance infrastructure by then, you'll be scrambling into live enforcement.
What Happens If You Don't Comply?
The penalty structure under the DPDPA Schedule is not hypothetical:
Violations | Maximum Penalty (Indian Rupees) |
Failure to implement security safeguards (Section 8(5)) | ₹250 crore |
Failure to notify users/Board of a data breach (Section 8(6)) | ₹200 crore |
Violations related to children's data processing | ₹200 crore |
Breach of SDF-specific obligations | ₹150 crore |
Any other provision violation | ₹50 crore |
Data Principal duty violations | ₹10,000 |
Beyond fines, the Data Protection Board can direct urgent mitigation measures, issue interim orders, and if you're an SDF, the consequences of non-compliance extend to your Board of Directors.
There are no criminal penalties under the DPDPA (unlike some other jurisdictions), which is a relief. But ₹250 crore in civil fines is plenty.
Fintech-Specific Obligations
Fintech startups face a tighter compliance environment because they sit at the intersection of the DPDPA and RBI regulations. Here's what's unique to you:
KYC Data: Collecting Aadhaar, PAN, selfies, and bank statements for KYC falls squarely within the DPDPA because you, the fintech, control the purpose and means of processing. You are unambiguously a Data Fiduciary.
Dual Compliance: RBI's guidelines (PA/PG guidelines, Account Aggregator framework) and the DPDP Act overlap significantly. RBI-mandated KYC and AML processing can proceed under "legitimate use",you don't need fresh consent for regulatory obligations. But everything beyond regulatory minimums such as marketing, cross-sell, analytics, credit profiling, requires explicit consent.
Credit Scoring Algorithms: If your platform generates or uses credit scores, loan eligibility decisions, or risk assessments, these are automated decision systems under the SDF framework. You'll need algorithmic impact documentation.
UPI and Payment Data: Processing millions of payment transactions daily puts most mature fintech platforms well within SDF territory. Start preparing DPO appointments and DPIA infrastructure now.
Data Minimisation in KYC: You cannot collect more KYC data than what your regulatory license requires. Over-collection is a direct violation of the DPDP Act violation.
How to start now and action list:
If you've never touched any of this, here's your immediate action list:
Assign an owner. Someone on your leadership team needs to own DPDP compliance. For most early-stage startups, this is the CTO or COO, not a lawyer you call once a year.
Do a 2-hour data audit. List every place you collect user data. Write it in a spreadsheet. What, from where, stored where, retained how long, shared with whom.
Read your current Privacy Policy. Does it say what data you collect, why, and how users can exercise rights? If not, it needs a rewrite.
Check your vendor contracts. Does your AWS agreement, your CRM contract, your email tool's MSA include a data processing clause? If not, get one.
Add a grievance mechanism. A dedicated privacy@yourdomain.com that is actually monitored, with a committed response time, is a good start.
If you're fintech, assess your SDF exposure. How many users do you have? What type of data are you handling? Get ahead of potential SDF designation now.
Frequently Asked Questions
Q: We're a B2B SaaS. Our customers are companies, not individuals. Does DPDPA still apply?
Yes, if your product processes data of individuals, even employees of your B2B customers, you're in scope. Your B2B customers' employee data, end-user data, or beneficiary data all counts.
Q: We're a foreign company with Indian users. Are we covered?
Absolutely. The DPDP Act has explicit extraterritorial reach. If you offer goods or services to Indian residents, or profile them, the law applies, regardless of where your company is incorporated.
Q: Are startups exempt from DPDPA?
No. The Central Government can exempt certain categories of startups based on volume and nature of data processed, but this exemption must be explicitly notified. Until it is, assume you're fully covered.
Q: What counts as a data breach we need to report?
Any unauthorized processing, accidental disclosure, sharing, or alteration of personal data that compromises its confidentiality, integrity, or availability. Even accidentally emailing a customer's data to the wrong recipient is a reportable breach.
Q: Can I use personal data for AI model training?
This is a grey area. If users didn't explicitly consent to their data being used for AI training, you likely cannot. Data minimisation and purpose limitation principles apply. AI training requires a fresh, specific consent.
Conclusion
The DPDP Act 2023 represents the biggest shift in how Indian startups must think about user data since the internet went mainstream in India. It is not a compliance checkbox exercise, it is a fundamental change in the relationship between your product and your users.
Building DPDP compliance is easy and not a burden. It's a forcing function to clean up your data practices, reduce the data you carry (and the liability that comes with it), and build the kind of user trust that actually drives retention.
The startups that treat 2026 as their build year will be ahead. The ones that wait for the May 2027 deadline will be scrambling, under active enforcement, with the DPBI already flexing its muscles.
Start today. Your users' data deserves it. So does your business.
(This article is written by Adv Shreya Verma and edited by Harkeerat Kaur, Strategic Growth Consultant at Outsource 360 Business Solutions. This article is for informational purposes only and does not constitute legal, financial, tax, accounting, compliance, investment, or marketing advice. Readers should seek professional advice before making decisions based on the information provided)





Comments