Skip to content
Suvysoft Solutions
← All ArticlesWebsite Development

DPDP Act compliance for your website: what Indian businesses need to fix before 2027

By the Suvysoft Solutions team7 min read
DPDP Act compliance for your website: what Indian businesses need to fix before 2027

Most Indian business websites collect personal data every single day without a second thought — a name and phone number on a contact form, an email address for a newsletter signup, a delivery address at checkout, a resume upload on a careers page. Almost none of them have formally answered a specific legal question that now has a real, ticking clock attached to it: is this collection actually compliant with India's data protection law?

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive personal data protection law, and its Rules — notified in November 2025 — set out a phased timeline that brings the substantive obligations on notice, consent, security and data-breach handling into full force by mid-2027. Any business whose website collects personal data from Indian users is very likely a 'data fiduciary' under the Act, whether that business has ten employees or ten thousand.

Who the DPDP Act actually applies to

The Act uses two core roles. A Data Principal is the individual the personal data belongs to — your website visitor, customer or job applicant. A Data Fiduciary is whoever decides why and how that data is processed — in practice, your business. If your website has a contact form, an account login, a newsletter signup, an e-commerce checkout or a careers page, your business is almost certainly a data fiduciary already, regardless of size. There is no small-business exemption written into the Act itself; obligations scale with the type and sensitivity of data handled, not with headcount.

Where the timeline actually stands in September 2026

The Rules were notified in November 2025, and they came with a deliberately phased runway rather than a single hard switch-on date — which is exactly why so many businesses have quietly deferred acting on this.

  1. November 2025 — the Data Protection Board of India, the body that will hear complaints and impose penalties, was formally established, along with the Act's core definitions.
  2. November 2026 — the framework for registered Consent Managers, third-party intermediaries that individuals can use to manage consent across services, becomes operational. This phase mainly affects platforms that want to operate as Consent Managers, not most ordinary business websites directly.
  3. May 2027 — the substantive day-to-day obligations become fully enforceable: clear notice at the point of collection, verifiable consent, data-breach notification, honouring data-principal rights (access, correction, erasure) and reasonable security safeguards. This is the deadline that actually matters for most business websites.

May 2027 can feel comfortably far away from September 2026. It isn't, once the actual work is accounted for: rewriting a privacy policy properly, redesigning consent flows on every form that collects data, auditing what data is even being collected and why, and putting a genuine breach-notification process in place are not weekend tasks for most businesses. The realistic planning window is now, not the quarter before the deadline.

The DPDP Act doesn't punish businesses for collecting data. It punishes businesses that collect data without being able to explain, clearly and in writing, why they collected it and what they did to protect it.

What this actually means for your website

A privacy policy that reflects reality, not a template

A generic, copy-pasted privacy policy is one of the most common gaps found on Indian business websites. Under the Act, a privacy notice needs to say plainly what personal data is collected, why, how long it's kept, who it might be shared with, and how a person can withdraw consent or request their data be corrected or deleted — in clear language, not legal boilerplate translated from a template built for a different country's law.

Consent that's actually specific and revocable

A pre-ticked checkbox or a buried 'by using this site you agree' line will not hold up. Consent under the Act needs to be freely given, specific to the purpose, and as easy to withdraw as it was to give. In practice, that means separate, clear consent for separate purposes — marketing emails and order processing are not the same consent — and a genuinely working way to withdraw it, not a support email nobody answers.

Data minimisation, not data hoarding

If a form asks for a date of birth, a company size or a physical address that the business never actually uses, that's now a liability rather than 'nice to have someday' data. The safer, and legally cleaner, default is collecting only what a specific, stated purpose actually requires.

Reasonable security safeguards

The Act requires 'reasonable security safeguards' to prevent a personal data breach, without prescribing one specific checklist — which is precisely why an independent read on where a business's website and systems actually stand matters. This overlaps heavily with ordinary good practice: enforced HTTPS, current CMS and plugin versions, access controls on who can see submitted form data, and encrypted storage of anything sensitive. A broader IT security audit is a reasonable way to establish that baseline before treating it as a compliance checkbox.

A real data-breach notification process

If personal data is compromised, the Act requires notifying the Data Protection Board and affected individuals. Most SMEs currently have no defined process for this at all — no one assigned to make the call, no template notification, no clarity on timelines. Writing this down before an incident happens is far cheaper than improvising it during one.

What happens if a business doesn't comply?

The Act's penalty schedule is genuinely large on paper: up to ₹250 crore for failing to implement reasonable security safeguards around a personal data breach, up to ₹200 crore for failing to notify the Board or affected individuals of a breach, up to ₹200 crore for violations involving children's personal data, and up to ₹150 crore for breaches of the additional obligations placed on Significant Data Fiduciaries. The Data Protection Board weighs the severity and volume involved, the business's mitigation efforts and its compliance history before setting an actual figure — so these are ceiling numbers, not automatic fines. The realistic takeaway for a small business isn't 'we might be fined ₹250 crore'; it's that the framework rewards having a documented, genuine compliance effort in place well before anything goes wrong, and penalises businesses that never tried.

A practical DPDP readiness checklist

  • List every place your website collects personal data: contact forms, checkout, account signup, newsletter, careers page, live chat, cookies and analytics tools.
  • For each one, write down the specific purpose the data is collected for — if there isn't a clear, honest answer, that's a field or a tool worth removing.
  • Rewrite the privacy policy in plain language reflecting what's actually collected and done with it, not a generic template.
  • Separate consent by purpose, with a working, visible way to withdraw it — not a single blanket checkbox at the bottom of a form.
  • Add extra care around any data from minors: the Act requires verifiable parental consent, which most current website forms don't attempt at all.
  • Confirm HTTPS, current CMS and plugin versions, and sensible access controls on wherever submitted form data actually lands.
  • Write a simple internal breach-response process: who gets told first, who decides whether it's notifiable, and roughly how fast that decision needs to happen.

Should you handle this yourself or bring in help?

Reading the Act's plain-language guidance and updating an honestly-written privacy policy is well within reach for most business owners to start themselves. Where it gets harder is auditing exactly what data your existing website, forms and third-party tools are silently collecting — most businesses are surprised by what analytics pixels, chat widgets and old plugins have been gathering for years — and translating 'reasonable security safeguards' into specific, verifiable technical changes rather than a vague intention.

DPDP readiness is exactly the kind of work that sits between IT consultancy and ongoing website care at Suvysoft Solutions: mapping what your website actually collects and why, tightening the security and access controls that back up your privacy commitments, and keeping the policy and consent flows current as regulations and the site itself evolve — rather than treating this as a one-time document swap. If you're not sure where your website currently stands against the Act, that assessment is a natural starting point for a free consultation.

Topics:DPDP Act website complianceDPDP Act India businessDigital Personal Data Protection Act checklistwebsite privacy policy DPDP

QUESTIONS

Frequently asked questions.

Does the DPDP Act apply to small businesses, or only large companies?

It applies regardless of size. The Act doesn't carve out an exemption for small businesses — if your website collects personal data from individuals in India for any purpose, your business is very likely a data fiduciary under the Act. Obligations scale with the type and sensitivity of the data handled, not with company headcount.

What is the actual deadline businesses need to worry about?

The Data Protection Board became operational in November 2025 and the Consent Manager registration framework activates in November 2026, but the day-to-day obligations that apply to most ordinary business websites — clear notice, valid consent, breach notification and data-principal rights — become fully enforceable by May 2027. That's the deadline worth planning toward now, since the preparation work takes real time.

Do we need a cookie consent banner under the DPDP Act?

The Act doesn't mandate a specific banner format the way some other countries' laws do, but it does require clear notice and specific, revocable consent wherever personal data is processed — which in practice means most websites using analytics, advertising pixels or similar tracking will need a genuine consent mechanism, not just a policy link in the footer.

What counts as 'personal data' under the Act?

Any data that can identify an individual, directly or indirectly — names, phone numbers, email addresses, physical addresses, and other identifiers collected through forms, accounts, cookies or analytics tools. If a website can connect a piece of data back to a specific person, it's personal data under the Act.

WORK WITH US

Want help putting this into practice?

Start with a free 30-minute consultation. We'll give you an honest assessment of what would help your business most.

Book Free ConsultationView All Services