Compliance & Regulation

DPDP Act Compliance Checklist for Apps and Software

What the Digital Personal Data Protection Act and the 2025 Rules require an app or software product to do: notices, consent, security, breach reporting, retention and user rights.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
9 min read
Padlock on a laptop keyboard

India's Digital Personal Data Protection Act, 2023 became workable when the DPDP Rules were notified on 13 November 2025. The main obligations on businesses apply from 13 May 2027. This checklist turns the Act and Rules into things a product team builds, screen by screen and table by table.

01

Who it applies to

The Act covers digital personal data processed in India, and processing outside India when it relates to offering goods or services to people in India. If your app stores a name, phone number, email, location or device identifier of a person, you are a Data Fiduciary. Vendors who process data for you, such as cloud, SMS, analytics and payment providers, are Data Processors, and you remain responsible for what they do.

13 Nov 2025
Rules notified; Data Protection Board provisions in force
13 Nov 2026
Consent Manager registration opens
13 May 2027
Notice, consent, security, breach and rights obligations apply
02

Notice and consent

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The notice has to stand on its own and be understandable without reading the rest of your terms.

Standalone noticeAn itemised list of the personal data collected and the specific purpose for each, in plain language
Language choiceAvailable in English and the Indian languages listed in the Eighth Schedule to the Constitution
No pre-ticked boxesA clear action per purpose; do not bundle marketing with the core service
Withdrawal as easy as givingA link or setting to withdraw consent, with the same effort as granting it
Consent logWho consented, to which notice version, when and how, kept as evidence
Existing usersFor data collected on consent before the law applied, send a notice as soon as reasonably practicable
03

Security safeguards

The Rules list minimum safeguards. Failure to take reasonable security safeguards carries the highest penalty in the Act, up to ₹250 crore.

You can outsource processing. You cannot outsource the responsibility.

Protect the dataEncryption, masking, obfuscation or tokenisation as appropriate
Access controlOn the systems that hold personal data, by role
Logging and monitoringVisibility of access to personal data, to detect and investigate unauthorised access
BackupsSo processing can continue if data is lost or compromised
Log retentionKeep logs and relevant personal data for at least one year unless another law requires longer
Processor contractsSecurity obligations written into agreements with every vendor
04

Breach response

There is no minimum size of breach. Every personal data breach has to be reported to affected users and to the Data Protection Board.

Tell affected users without delayWhat happened, likely consequences, what you have done and what they can do, with a contact
Tell the Board without delayAn initial description of the breach
Detailed report within 72 hoursFacts, cause, mitigation, findings about who caused it and a report on notices sent to users
Build it nowAn incident runbook, a way to identify affected users and message templates ready to send
05

Retention and deletion

Personal data must be erased when consent is withdrawn or the purpose is served, unless a law requires you to keep it. Large e-commerce, online gaming and social media platforms above user thresholds have a specific rule: erase after three years of user inactivity, with 48 hours' notice before erasure.

Retention period per data typeAutomated deletion jobsDeletion from backups and vendorsAccount deletion in the app48-hour pre-erasure noticeDeletion log
06

User rights and grievances

Users can ask for a summary of their data and how it is processed, correction, updating, erasure, and can nominate someone to exercise their rights. You must publish how to make these requests and resolve grievances within a period you publish, which cannot exceed ninety days.

Privacy centre in the appView data, download summary, correct, delete and withdraw consent
Published contactA Data Protection Officer or named person who answers questions about processing
Grievance workflowTickets with deadlines and an audit trail
NominationA way to record a nominee
07

Children, large platforms and transfers abroad

Anyone under 18 is a child under the Act. Processing a child's data needs verifiable consent from a parent, and tracking, behavioural monitoring and advertising targeted at children are prohibited, subject to limited exemptions. Significant Data Fiduciaries, designated by the government, must also carry out an annual data protection impact assessment and audit. Transfers outside India are allowed except to countries or under conditions the government restricts.

08

A sensible order of work

Start with a data inventory: every field of personal data, why you hold it, where it lives and which vendors see it. That inventory drives the notice, retention rules and breach plan. Then build consent logging, the privacy centre and deletion. Leave policy documents until the product actually does what they will say.

Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact