DPDP Act 2023: What Every Indian Website Owner Must Know
- The DPDP Act covers any personal data you collect from users; consent and clear notices are non-negotiable.
- You must tell users why you collect their data, store it safely, and let them request or delete it.
- Start with a privacy policy, user consent forms, and a basic data audit; building compliance into your site from day one is far easier than retrofitting.
What Is the DPDP Act and Why It Matters
India's Digital Personal Data Protection Act came into effect recently and applies to every website, app, and business that collects user data. It doesn't matter if you're a startup, e-commerce store, or SaaS platform. If you collect names, emails, phone numbers, addresses, or browsing behaviour, the DPDP Act applies to you.
This law is India's answer to protecting people's personal information online. Think of it as the rulebook for how you must handle customer data.
What Counts as Personal Data?
Personal data is any information that identifies or could identify a person. Common examples include:
- Names, email addresses, phone numbers
- Home or office addresses
- Payment information
- IP addresses and device identifiers
- Browsing history linked to a user
- Location data
- Even combination of data that together identify someone
If you're unsure whether something is personal data, ask yourself: could this identify or harm the person? If yes, treat it as personal data.
The Three Core Rules: Consent, Purpose, and Notice
Consent comes first. You cannot collect or use personal data without the person's clear, informed consent. Not a tick-box that's pre-ticked. Users must actively opt in.
State your purpose clearly. Before collecting data, tell users exactly why you need it. "Marketing emails", "payment processing", "customer support"—be specific. Don't collect data for vague reasons and then use it for something else.
Give a privacy notice. Users have the right to know what data you hold, how long you keep it, and who can see it. Your privacy policy must be clear, not buried in legal mumbo-jumbo.
Practical Steps to Comply Right Now
1. Write or update your privacy policy. Say what data you collect, why, how long you keep it, and who has access. Keep language simple.
2. Add consent forms to your website. Whether it's a newsletter signup, contact form, or payment checkout, add a clear consent checkbox. Users must tick it themselves—no pre-ticked boxes.
3. Audit your current data. List all the personal data your site holds, where it comes from, and where it's stored. This also helps you spot unnecessary data you can delete.
4. Secure your data. Use HTTPS (SSL certificates), encrypt sensitive information, and limit who on your team can access user data.
5. Create a data deletion process. Users can ask for their data to be deleted. Make sure you can do this and have a log of when you do it.
6. Train your team. Everyone handling customer data should know the basics of the DPDP Act.
One Key Advantage: Build Compliance Early
Many businesses scramble to retrofit compliance after launching. A well-built website, designed with data protection in mind from the start, makes all this straightforward. Your forms request only necessary data, consent flows are built in, and security is baked into the architecture.
Keep Going
The DPDP Act isn't designed to punish small businesses. It's designed to protect users and build trust. Compliance actually reassures customers that you take their privacy seriously.
Note: This is general information, not legal advice. For compliance specifics to your business, consult a data protection lawyer or compliance professional.
Need a website that is compliant and secure from day one?
We build data-driven websites, web apps and platforms with compliance and security handled properly. Tell us about your project.
Get a free quoteThis article is general information, not legal advice. For your specific situation, please consult a qualified professional.
