Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

DPDP compliance checklist for startups

Compliance

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 2 min read

How should a startup approach DPDP compliance?

The short answer

Settle applicability once with a traceable answer, map what personal data you hold and why, then work 5 clusters in dependency order: the notice and consent surfaces, the security safeguard minimums, breach readiness, retention timers, and the rights and grievance machinery. The main operational duties compute to May 2027, a date that is interpretation until confirmed, which is runway a small team should spend deliberately.

More answered questions →

Summary infographic headed 'Startup checklist for DPDP'
The infographic states that applicability and your role are settled first, that you then map what personal data you hold and why, that the work falls into 5 clusters of notice, security, breach, retention and rights, and that a startup should use its runway to sequence the work deliberately. A board and a 5 stage runway repeat the sequence from assessing applicability and role to going live and reviewing.

A startup does not need a privacy department to get this right. It needs sequence.

First, settle 2 questions once

Does the framework apply to you, and what role do you hold per data flow, Data Fiduciary or Data Processor? Both have deterministic answers from the Act's application section and definitions, and does the DPDP Act apply to startups works that application section through in full, including the 3 places where company size does change the duty set. Run the applicability check and the role checker; each result traces to the exact provisions, and each takes minutes.

Second, map the data

1 page is enough at startup scale: what personal data, from whom, for what purpose, in which systems, owned by whom. Every later duty consumes this map: the itemised notice, the retention timers, the breach blast radius.

Then work 5 clusters in dependency order

Notice and consent. The standalone plain language notice with an itemised data description, and withdrawal of consent with ease comparable to giving it. Draft depends on the data map.

Security floor. The named safeguard minimums are mostly controls a small engineering team wants anyway: encryption, access control, logging, backups.

Breach readiness. A 1 page runbook naming who detects, drafts, approves and files, because the clocks start on awareness and do not scale down for headcount.

Retention timers. Design the schedule before building the timers and the 48 hour warning; retrofitting retention is the expensive version.

Rights and grievance machinery. Published request channels, the grievance response period, and the contact who answers data questions.

Spend the runway deliberately

Rule 1(4) gives the main operational group 18 months from publication; on the calendar that lands at 13 May 2027, a computed date treated as interpretation until confirmed. The cheapest compliance work you will ever do is the work built into systems while they are still small.

What to do

Generate the company plan with the founder lens: it holds the full picture with owners and dependencies even when several owners are the same person. The startup guide covers where the framework usually bites first.

The startup guide →

StartupsChecklist

Share this: