NEW DELHI: India's Digital Personal Data Protection (DPDP) Act is no longer just a law on paper. With most of its provisions expected to come into force by May 2027, every company that collects or processes personal dataâincluding startupsâwill have to comply with a new set of legal and technical obligations.
The law does not exempt startups simply because they are small or still growing. Whether it is a fintech app, an AI startup, an online marketplace or a SaaS company, businesses will need to obtain clear user consent before collecting personal data, use it only for the purpose it was collected, protect it with appropriate security measures and respond to requests from users who want to access or delete their information.
On paper, these requirements appear straightforward. But legal experts, cybersecurity professionals and startup leaders say complying with the DPDP Act is much more than updating a privacy policy. It requires companies to rethink how they collect, store, use and secure personal data across their entire organisation.
What does the DPDP Act mean for startups?The DPDP Act applies to every data fiduciaryâthe person or company that decides why and how personal data is processed.
In simple terms, this includes almost every startup that collects customer information through websites, apps or online services.
That means startups cannot simply collect user information because it may become useful later. They must clearly explain why they are collecting the data, seek consent wherever required and ensure that the information is not used beyond the purpose for which it was collected.
According to Priti Suri, Founder and Managing Partner at PSA, one of the biggest misconceptions among startups is that DPDP compliance only means updating privacy policies.
"Many startups believe DPDP governance is simply about updating their privacy policy or collecting user consent. That is an incorrect premise,"
Suri says.
She explains that the law requires companies to follow principles such as purpose limitation, data minimisation, users' rights to access and erase their data, mandatory breach reporting and clear accountability within the organisation.
"A mere refresh of a privacy policy, without the institutional architecture to operationalise user rights, constitutes performative compliance. The statute demands proper infrastructure and not an ornamental one," she said.
Why are experts saying startups aren't ready?While awareness of the DPDP Act has increased, experts believe most startups are still at an early stage of compliance.
Suri says many founders still do not know exactly what personal data their companies hold, where it is stored or who has access to it.
"Most startups hold personal data without knowing exactly what, where or why. They have no grievance officer with real authority, and they rely on third-party processors without binding data agreements in place," she added.
She warns that these are not minor procedural issues but governance failures that could expose companiesâand even foundersâto regulatory action. The consequences also go beyond penalties under the law.
Investors are increasingly asking detailed questions about data governance during funding rounds, while enterprise customers are beginning to make privacy compliance a condition before signing contracts.
"In contemporary transactions, investors interrogate data governance as a core element of due diligence. In case of deficiencies, startups could see valuation cuts or aborted term sheets," Suri further added.
She believes startups should view DPDP compliance as a business advantage rather than simply another regulatory burden. According to her, companies that demonstrate strong governance send a positive signal to investors, customers and partners that they are prepared to handle personal data responsibly.
What are the biggest technical challenges for startups?Legal compliance is only one part of the DPDP Act. The bigger challenge, experts say, is whether startups have the systems needed to actually protect personal data and respond quickly when something goes wrong.
According to Gaurav Batra, Co-Founder and CEO of FOCTTA, many companies make the mistake of investing in expensive cybersecurity tools before they even understand what personal data they have.
He says companies first need to identify what personal data they collect, why they collect it, where it is stored, who can access it, who it is shared with and how long it is kept.
"The first reasonable safeguard is visibility. You cannot secure what you do not know you have," Batra says.
He explains that organisations often spend heavily on protecting one system while sensitive personal data continues to be copied into spreadsheets, shared drives, testing environments or third-party applications that nobody is tracking. As a result, even companies that appear secure on paper may have serious blind spots.
Why is the 72-hour breach reporting rule a challenge?Under the DPDP framework, companies must report personal data breaches to the Data Protection Board of India and notify affected users within prescribed timelines.
But Batra says the deadline itself is not the biggest problem. The real challenge is whether a startup has the internal systems needed to detect a breach, investigate it and decide who is responsible for responding.
"The 72-hour requirement creates urgency, but the real challenge is much broader," Batra says.
According to him, every organisation should already know who will investigate a cyber incident, who will assess the legal impact, who will communicate with affected users and who will coordinate with outside vendors.
When a breach occurs, companies should immediately be able to answer basic questions such as what happened, when it happened, which systems were affected and what personal data may have been exposed.
"That requires more than a policy. It requires an up-to-date data inventory, appropriate logging and monitoring, clear escalation channels, defined decision-making authority and a tested incident-response plan," he says.
Without these systems, meeting regulatory timelines could become extremely difficult.
Why is deleting user data harder than it sounds?The DPDP Act gives users the right to seek access to and deletion of their personal data.
While this may sound simple, Batra says many startups are not technically prepared to handle such requests. Personal data is often spread across multiple databases, cloud services, internal software tools and backup systems. Removing it completely may require coordination across several teams and vendors.
"If privacy rights are dependent entirely on someone manually searching multiple systems every time a person makes a request, the organisation's data architecture is already creating a compliance risk," Batra says.
He also points out that companies cannot always delete every piece of information immediately. Some records may need to be retained because of legal requirements, security logs or backup systems. That is why organisations need clearly documented processes explaining what data can be deleted, what must be retained and for how long.
What are the biggest security gaps today?Batra believes India's startup ecosystem is highly uneven. Some startups already have mature privacy and security programmes, while others are still trying to identify what personal data they actually possess.
The biggest problems, he says, are usually not sophisticated cyberattacks. Instead, they are basic operational failures.
These include employees having unnecessary access to customer information, former employees continuing to retain access to systems, poor oversight of third-party vendors, storing personal data in multiple locations and the absence of a proper incident-response process.
"A privacy policy cannot protect data. People, processes and technology have to work together to do that," Batra says.
What new risks do AI tools create?The rapid adoption of AI has added another compliance challenge. Employees increasingly use AI tools to improve productivity, but many organisations do not know whether staff are uploading customer information or confidential company data into these platforms.
According to Batra, companies should create clear internal rules around AI usage instead of banning such tools altogether.
"The better approach is to create a controlled environment: identify approved tools, define what data may be used, conduct appropriate vendor and security assessments, establish contractual protections and train employees on what must not be shared," he says.
He says the goal should be to make secure innovation the easiest option for employees rather than relying on blanket restrictions.
How are startups preparing for DPDP compliance?While many startups are still trying to understand what DPDP compliance requires, Gautam Varma, Global Head, Zoho for Startups, says Zoho has been working towards compliance well before the law comes into force. He says the company treats privacy as an ongoing operational function rather than a one-time legal exercise.
"We have diligently analysed the requirements of the DPDP Act and assessed our compliance level as an organisation and are working towards being compliant ahead of the enforcement deadlines," Varma says.
According to him, Zoho already has dedicated privacy, security, legal and compliance teams, and the DPDP Act has become part of their day-to-day responsibilities. He says one of the biggest changes has been redesigning how the company manages user consent, as the law no longer allows companies to process personal data simply by claiming a legitimate business interest.
"One of the more significant changes introduced by DPDPA has been the re-architecture of consent and notice. Unlike earlier, the DPDP Act doesn't allow companies to process data just by claiming a legitimate business interest," he says.
Varma says Zoho has also embedded privacy into product development by making privacy-by-design, data protection impact assessments and privacy reviews a standard part of the software development process. For AI-powered products, he says the company follows data minimisation, purpose limitation and transparency, and does not use customer data to train AI models without a lawful basis.
Looking at the broader startup ecosystem, Varma believes most companies are still not ready for DPDP compliance. While the Act allows exemptions for certain classes of startups from specific provisions, he points out that the core obligations apply to every data fiduciary, irrespective of its size.
"Most startups are not prepared for DPDP compliance and the problem is limited awareness and a lack of urgency," he says.
One of the biggest challenges, according to Varma, is that startups often store customer data across multiple disconnected tools, making it difficult to fully erase personal data when users make such requests. Even if a third-party vendor fails to delete the data, he says, the responsibility still rests with the startup.
He says startups should focus on streamlining their data pipelines and using integrated systems so that customer data can be managed from a single source instead of being scattered across multiple platforms. According to him, startups in sectors such as fintech, banking, insurance and telecom are generally better prepared because compliance is already part of their operations, while companies in traditional sectors like MSMEs, offline retail, manufacturing and real estate are likely to face greater challenges as they often lack dedicated compliance budgets and have customer data spread across different systems.
So, are Indian startups ready for DPDP compliance?The experts agree that while awareness of the DPDP Act has grown, most Indian startups are still not fully prepared for compliance. Many still need to improve their data governance, consent management, cybersecurity and internal processes before the law is fully enforced.
At the same time, they say DPDP compliance should not be seen only as a legal obligation. With the expected May 2027 enforcement deadline approaching, the consensus is clear: companies that treat privacy as an ongoing business functionânot a last-minute compliance exerciseâwill be better placed when the law comes into force.