DPDP Act Compliance Checklist for Apps and Software
What the Digital Personal Data Protection Act and the 2025 Rules require an app or software product to do: notices, consent, security, breach reporting, retention and user rights.

India's Digital Personal Data Protection Act, 2023 became workable when the DPDP Rules were notified on 13 November 2025. The main obligations on businesses apply from 13 May 2027. This checklist turns the Act and Rules into things a product team builds, screen by screen and table by table.
Who it applies to
The Act covers digital personal data processed in India, and processing outside India when it relates to offering goods or services to people in India. If your app stores a name, phone number, email, location or device identifier of a person, you are a Data Fiduciary. Vendors who process data for you, such as cloud, SMS, analytics and payment providers, are Data Processors, and you remain responsible for what they do.
Notice and consent
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. The notice has to stand on its own and be understandable without reading the rest of your terms.
Security safeguards
The Rules list minimum safeguards. Failure to take reasonable security safeguards carries the highest penalty in the Act, up to ₹250 crore.
You can outsource processing. You cannot outsource the responsibility.
Breach response
There is no minimum size of breach. Every personal data breach has to be reported to affected users and to the Data Protection Board.
Retention and deletion
Personal data must be erased when consent is withdrawn or the purpose is served, unless a law requires you to keep it. Large e-commerce, online gaming and social media platforms above user thresholds have a specific rule: erase after three years of user inactivity, with 48 hours' notice before erasure.
User rights and grievances
Users can ask for a summary of their data and how it is processed, correction, updating, erasure, and can nominate someone to exercise their rights. You must publish how to make these requests and resolve grievances within a period you publish, which cannot exceed ninety days.
Children, large platforms and transfers abroad
Anyone under 18 is a child under the Act. Processing a child's data needs verifiable consent from a parent, and tracking, behavioural monitoring and advertising targeted at children are prohibited, subject to limited exemptions. Significant Data Fiduciaries, designated by the government, must also carry out an annual data protection impact assessment and audit. Transfers outside India are allowed except to countries or under conditions the government restricts.
A sensible order of work
Start with a data inventory: every field of personal data, why you hold it, where it lives and which vendors see it. That inventory drives the notice, retention rules and breach plan. Then build consent logging, the privacy centre and deletion. Leave policy documents until the product actually does what they will say.
- Digital Personal Data Protection Act, 2023 (MeitY)
- Digital Personal Data Protection Rules, 2025: notification summary (Press Information Bureau)
This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.





