DPDP Act explained: Are startups ready for India's new data protection law?
India's Digital Personal Data Protection (DPDP) Act, set to take effect in May 2027, imposes strict data handling requirements on all companies, including startups. Experts emphasize that compliance requires a fundamental shift in data governance rather than just updating privacy policies.
Why it matters
The DPDP Act represents a significant regulatory shift for the Indian tech ecosystem, necessitating substantial operational changes for businesses handling user data.
NEW DELHI: India's Digital Personal Data Protection (DPDP) Act is no longer just a law on paper. With most of its provisions expected to come into force by May 2027, every company that collects or processes personal data—including startups—will have to comply with a new set of legal and technical obligations.The law does not exempt startups simply because they are small or still growing. Whether it is a fintech app, an AI startup, an online marketplace or a SaaS company, businesses will need to obtain clear user consent before collecting personal data, use it only for the purpose it was collected, protect it with appropriate security measures and respond to requests from users who want to access or delete their information.On paper, these requirements appear straightforward. But legal experts, cybersecurity professionals and startup leaders say complying with the DPDP Act is much more than updating a privacy policy.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in