Security Insights

DPDP Act 2023: What Every Indian Startup Must Do Before It Is Too Late

By Aditya Kumar— Founder & CEO, CyberSharcx
June 19, 20267 min read1,421 words
Share
DPDP Act 2023: What Every Indian Startup Must Do Before It Is Too Late

India passed the Digital Personal Data Protection Act in August 2023. Most Indian startup founders either have not read it, do not think it applies to them, or are waiting to see if enforcement actually happens.

All three of those positions are going to be expensive.

The DPDP Act is not like previous Indian data regulations that existed mostly on paper. It has a dedicated enforcement body, specific penalty amounts written into the law, and it applies to virtually every Indian company that processes personal data — including startups with 10 employees running on AWS.

This post explains exactly what the DPDP Act requires, what the penalties are, and what your startup needs to do right now.

What Is the DPDP Act and Who Does It Apply To

The Digital Personal Data Protection Act 2023 is India's first comprehensive data protection law. It governs how organizations collect, store, process, and share personal data of Indian citizens.

It applies to you if your startup does any of the following:

  • Collects names, emails, phone numbers, or addresses from users
  • Processes payment information or financial data
  • Stores health records or medical history
  • Runs any kind of user account or profile system
  • Uses cookies or tracking technology on Indian users

In practice, this means almost every Indian startup is covered. A 15-person SaaS company with a user login system is a Data Fiduciary under the Act — with the same legal obligations as a large enterprise.

What the DPDP Act Actually Requires

The Act creates specific obligations for any company handling personal data.

1. Consent before collection You cannot collect personal data without clear, informed consent from the user. The consent request must be in plain language — not buried in a 40-page privacy policy. Users must be able to withdraw consent at any time.

2. Purpose limitation Data collected for one purpose cannot be used for another. If a user signs up for your newsletter, you cannot use their email for targeted ads without separate consent.

3. Data minimization You can only collect data that is actually necessary for the stated purpose. Collecting extra fields "just in case" is no longer legally safe.

4. Security safeguards Organizations must implement "reasonable security safeguards" to protect personal data. The Act does not define exactly what reasonable means — but active monitoring, access controls, and breach detection will almost certainly be the baseline expectation.

5. Breach notification If a data breach occurs, you must notify both the Data Protection Board and affected users. Delays in notification are themselves a violation.

6. Data Principal rights Users have the right to access their data, correct it, and request deletion. Your startup needs a process to handle these requests within the timeframes the rules will specify.

The Penalties — Why This Is Not Optional

This is where most founders sit up and pay attention.

The DPDP Act prescribes financial penalties of up to ₹250 crore for serious violations — specifically for failing to implement adequate security safeguards that result in a data breach.

Other violations carry penalties up to ₹200 crore. Failing to notify the Data Protection Board of a breach can attract up to ₹200 crore. Non-compliance with data principal rights requests carries up to ₹50 crore.

For a startup raising its first round, a ₹50 crore penalty is not a business setback. It is the end of the business.

What "Reasonable Security Safeguards" Actually Means For a Startup

The phrase "reasonable security safeguards" appears in Section 8(5) of the Act. The rules will define this further — but based on comparable data protection frameworks globally, reasonable safeguards for a startup processing personal data will include:

Access controls — Not everyone on your team should have access to user data. Role-based access with the principle of least privilege is the baseline.

Encryption — Personal data stored at rest and in transit should be encrypted. Unencrypted databases containing user PII are an immediate liability.

Monitoring and detection — Knowing when your systems are being accessed in unusual ways is not optional under a law that requires breach notification. If you have no monitoring, you will not know a breach occurred until it is too late to notify anyone.

Incident response — You need a documented process for what happens when a breach is discovered. Who is notified internally? Who contacts the Data Protection Board? Who notifies users?

A startup that deploys honeypot-based threat detection, behavioral monitoring, and automated alerting is in a demonstrably stronger position under the Act than one running on default cloud configurations with no visibility into access patterns.

What You Need to Do Right Now — A Practical Checklist

Do not wait for enforcement to begin before taking these steps.

Audit what data you collect Map every data point you collect from users. Why do you collect it? Where is it stored? Who has access? This exercise will immediately surface data you are collecting with no clear purpose.

Fix your consent flow Your signup form, cookie banner, and terms of service need to reflect DPDP Act requirements. Bundled consent hidden in terms is not valid consent under the Act.

Appoint a point of contact Designate someone internally — even at an early stage startup this should be the founder — who is responsible for data protection compliance and breach response.

Implement basic security monitoring This is the step most startups skip because they assume it is expensive or complex. It does not have to be. Monitoring for unusual login patterns, unauthorized access attempts, and suspicious data access is achievable without a dedicated security team.

Create a breach response process Before a breach happens, document what you will do. Who decides whether a breach has occurred? What is the notification timeline? Where is the Data Protection Board contacted?

Review third-party contracts If you share user data with third parties — analytics providers, payment processors, marketing tools — your contracts need to address their DPDP Act obligations as well.

The Connection Between Cybersecurity and DPDP Compliance

Most founders think of DPDP Act compliance as a legal problem and cybersecurity as a technical problem. They are the same problem.

Section 8(5) of the Act explicitly requires security safeguards. A breach that triggers the penalty provisions is almost always a cybersecurity failure — an undetected intrusion, a misconfigured database, an unmonitored access pattern that ran for months before anyone noticed.

The 194-day average breach detection window documented in IBM's 2024 research is precisely the window in which a DPDP Act violation occurs without the company even knowing. By the time the breach is discovered, the obligation to notify has already been violated.

Early detection is not just a security argument. Under the DPDP Act, it is a legal one.

Frequently Asked Questions — DPDP Act for Indian Startups

Does the DPDP Act apply to early-stage startups? Yes. The Act applies to any entity that processes personal data of Indian citizens, regardless of company size or revenue. A pre-revenue startup with 100 users is covered.

When does DPDP Act enforcement begin? The Act received presidential assent in August 2023. The rules are being finalized by the government. Enforcement begins once rules are notified — companies should be preparing now rather than waiting for the notification date.

What is the Data Protection Board of India? The Data Protection Board is the regulatory body established under the DPDP Act. It will adjudicate complaints, investigate violations, and impose penalties. It is equivalent to the Information Commissioner's Office in the UK or the CNIL in France.

What counts as personal data under the DPDP Act? Personal data means any data that can identify an individual — names, email addresses, phone numbers, location data, financial information, health records, device identifiers, and IP addresses all qualify.

What should a startup do if it discovers a data breach? Contain the breach immediately. Notify the Data Protection Board as soon as possible. Notify affected users. Document everything. The Act requires prompt notification — delays compound the legal exposure.

How does early threat detection help with DPDP compliance? Early detection shortens the window between breach and discovery — which is the window in which compliance obligations are being violated without the company's knowledge. A platform that detects intrusions during reconnaissance rather than after exfiltration gives you the ability to respond before notification obligations are triggered.


CyberSharcX is an early-warning cyber threat detection platform for Indian startups and SMEs. Built for DPDP Act readiness — honeypot-based detection, behavioral analytics, and automated alerting — starting at ₹5,000 per month. Learn more at cybersharcx.in

CyberSharcx

Secure Today, Stronger Tomorrow

Compliance-led breach detection for startups and SMEs — honeypot-verified alerts in minutes, with CERT-In and DPDP regulator-ready reports.

© 2026 CyberSharcx Inc. All rights reserved.