Wittier Software Solutions Get a Quote
Compliance

DPDP Act 2023: What Your Indian Website Must Do Right Now

6 August 2026 · 3 min read · Wittier Software Solutions
DPDP Act 2023: What Your Indian Website Must Do Right Now
Key takeaways
  • Personal data includes any information that identifies a user (name, email, phone, IP address, cookies); you must collect it only with clear consent.
  • You must post a privacy policy, get explicit consent before collecting data, and honour user requests to delete or access their information.
  • Start with a compliant privacy policy, audit what data you collect, use secure tools, and keep records of consent—a well-built website handles this from day one.

What Is the DPDP Act 2023?

India's Digital Personal Data Protection Act 2023 is the main privacy law for online businesses. It applies to almost every website and app that collects personal data from Indian users—which means you, unless your site is purely informational and collects nothing.

The law is not yet fully in force, but provisions are rolling out. Compliance is no longer optional.

What Counts as Personal Data?

Personal data is any information that identifies a person. On your website, this includes:

If you're collecting it, the DPDP Act applies.

The Three Core Rules

1. Get Clear Consent First

You must ask users explicitly before collecting personal data. A pre-ticked checkbox or buried consent in fine print does not count.

Your consent request must be clear, specific, and easy to withdraw. If someone says no, you cannot collect their data—no exceptions.

2. Publish a Privacy Policy

Your privacy policy is non-negotiable. It must clearly state:

Bury it on a hard-to-find page and you're inviting trouble. Link it clearly in your footer or header.

3. Honour User Rights

Users can request:

You must respond to these requests within 30 days.

Practical Steps to Get Compliant

Audit your data flows

Map what personal data you collect, where it lives, who has access, and how long you keep it. Most breaches start because no one knew what data existed.

Rewrite your privacy policy

Use a lawyer or a compliance tool, not a generic template. Be specific about your business and your data practices.

Fix your consent collection

Replace auto-checked boxes with explicit, easy-to-read consent forms. Make consent withdrawal as easy as giving it.

Secure your systems

Use HTTPS on every page, encrypt sensitive data, and limit access to personal information. Breaches hurt your users and your brand.

Document everything

Keep records of consent, deletion requests, and data audits. If regulators ask, you need proof that you followed the rules.

Set up a complaint process

Make it simple for users to contact you about data issues. Slow responses breed distrust.

Don't Do This

A Reminder

This is general information, not legal advice. For compliance with the DPDP Act, consult a privacy lawyer or data protection professional familiar with Indian law.

A well-built website with security and compliance baked in from day one saves you headaches, fines, and lost customer trust. Starting right is cheaper than fixing it later.

Need a website that is compliant and secure from day one?

We build data-driven websites, web apps and platforms with compliance and security handled properly. Tell us about your project.

Get a free quote

This article is general information, not legal advice. For your specific situation, please consult a qualified professional.

Get our weekly insights

Short, practical guides on building better websites, compliance, SEO and AI. One email a week, no spam.

© 2026 Wittier Software Solutions · wittier.in · All articles