A practical compliance operations framework for Indian startups and SMEs navigating the DPDP Act 2023 and Rules 2025. Every obligation mapped to an automated workflow.
95% of Indian startups are handling DPDPA compliance manually - via spreadsheets, email replies, and improvised processes. Each of these is an active violation. The Data Protection Board is operational. Penalties are real.
India's Digital Personal Data Protection Act 2023 is now fully operative. The DPDP Rules 2025 were notified in November 2025, with obligations commencing in phases through 2027. The Data Protection Board of India is established in law. Penalties up to ₹250 crore per violation are no longer theoretical - they are the legal reality for every Indian startup collecting user data.
Yet the vast majority of Indian startups remain dangerously exposed. Not because they lack awareness - most founders have heard of DPDPA. The problem is operational infrastructure. Compliance is being handled through spreadsheets, email replies, and manual processes that are fundamentally incapable of meeting the Act's requirements at any meaningful scale.
95% of Indian startups handle consent in spreadsheets. Rights requests go to support inboxes. No SLA tracking. No audit trail. No breach workflow. No idea which vendors or cloud systems actually hold user data. Each of these is an active DPDPA gap.
18 compliance modules spanning consent, rights, breach, data discovery, vendor and cloud risk, and regulator reporting - each mapped to a specific DPDPA obligation and automated end to end. Go live in 30 minutes.
This whitepaper maps every key DPDPA obligation to a concrete operational workflow, explains why manual processes fail at scale, and demonstrates how DPDPA Shield converts legal requirements into automated, auditable systems that protect Indian startups from regulatory exposure.
The Digital Personal Data Protection Act 2023 received Presidential assent on 11 August 2023, establishing India's first comprehensive data protection framework. The DPDP Rules 2025 were notified on 13 November 2025, giving the Act full practical effect on a phased commencement schedule running through 2027.
The DPDP Rules 2025 give full practical effect to the Act. They specify consent notice formats, the rights request timeline, the two-stage breach notification procedure, and the additional obligations of Significant Data Fiduciaries. Cross-border data transfer follows a "negative list" model under Section 16 - transfer is allowed by default unless the Central Government has specifically restricted a destination country.
Core obligations apply from day one: valid consent, rights portal, breach notification, retention limits, and processor agreements. No minimum user threshold for basic compliance.
Additional obligations once notified: an India-based DPO, mandatory DPIAs, an independent data auditor, and targeted data localisation for specified categories under Rule 13(4).
Schedule 1 of the Act sets out seven penalty tiers. There is no graduated warning system - violations attract direct financial penalties imposed by the Data Protection Board after inquiry. The five that apply to a Data Fiduciary's own conduct:
The DPDPA places six foundational obligations on every Data Fiduciary - any entity that determines why and how personal data is processed. If your startup collects names, emails, phone numbers, or any other identifiable information from Indian users, these obligations apply to you today.
Consent must be free, specific, informed, unconditional, and unambiguous. Pre-ticked checkboxes, bundled approvals, and dark patterns are explicitly invalid. Withdrawal must be as easy as giving consent.
Before collecting any personal data, provide clear notice: what is being collected, for what purpose, how consent can be withdrawn, and how rights can be exercised. Must be in plain language.
Implement reasonable technical and organisational measures to protect personal data. This includes signed Data Processing Agreements with every vendor who handles your users' data.
On becoming aware of a breach, notify affected users and give the Board an initial description without delay, then a full report to the Board within 72 hours. Both steps are mandatory.
Honor the five rights of your users: Access, Correction, Erasure, Grievance Redressal, and Nomination. Respond to access, correction, and erasure requests within 90 days (Rule 14(3)).
Erase personal data once the purpose for which it was collected is fulfilled, or when consent is withdrawn. Direct all Data Processors to do the same.
Each of these six obligations is not a policy statement - it is a technical and operational requirement. Meeting them demands automated workflows, timestamped records, SLA tracking, and cryptographic audit trails. None of this is achievable through spreadsheets or manual processes at startup scale.
Most Indian startups today manage DPDPA obligations manually. Consent is stored in database flags. Rights requests arrive via support email. Breach response is improvised. Nobody has a current list of every vendor or cloud system holding user data. This approach has a fundamental ceiling: it fails precisely when it matters most - under regulatory scrutiny, at scale, or in a breach scenario.
DPDPA Shield is a compliance operations platform - not a document generator. The next page lists every module currently live on the platform, grouped by the part of the compliance lifecycle it automates. Every module maps to a specific DPDPA obligation and replaces a manual process with an auditable workflow.
All 18 are live in production today. Growth+, Business+, and Enterprise tags mark modules bundled from that plan tier upward — everything else ships on every plan, including Starter.
| Module | What It Automates | Plan |
|---|---|---|
| Consent & Rights | ||
| Consent Management | Sections 5-7 notice builder, SDK, webhooks, re-consent campaigns | Starter+ |
| Cookie & Tracker Consent (Shield CMP) | Section 6 for web cookies and trackers | Starter+ |
| Data Principal Rights Portal | Sections 11-14, 90-day SLA engine | Starter+ |
| Breach & Data Governance | ||
| Breach Incident Management | Section 8(6), Rule 7 two-stage notification | Starter+ |
| Data Inventory & RoPA | Section 8 processing records | Starter+ |
| Data Map & PII Discovery | Section 8 - find data you didn't know you held | Starter+ |
| Privacy Policy Manager | Section 7 notice lifecycle, AI-assisted drafting | Enterprise |
| Vendor & Cloud Risk | ||
| Vendor Risk Intelligence | Section 8(5) processor oversight, DPA tracking | Growth+ |
| Vendor Software / SBOM Tracking | Section 8(5), CERT-In, NTIA, SEBI CSCRF | Add-on |
| Cloud Security Mapping (AWS) | Section 8(5) cloud configuration | Business+ |
| Regulatory Radar | Ongoing monitoring of DPDPA developments | Growth+ |
| Cyber Risk Quantification (FAIR) | Section 8 risk-based accountability | Growth+ |
| Risk Register | Section 8 risk tracking | Growth+ |
| Module | What It Automates | Plan |
|---|---|---|
| Governance & Trust | ||
| Trust Center | Public accountability page for customers and auditors | Starter+ |
| GRC Suite (167 frameworks) | ISO 27001, SOC 2, NIST, HIPAA, GDPR alongside DPDPA — Controlled Documents, Audit Tracker, Access Review | Add-on |
| Specialised Obligations | ||
| Children's Data Module | Section 9 parental consent | Business+ |
| SDF & DPIA Builder | Section 10 Significant Data Fiduciary duties | Enterprise |
| Add-ons | ||
| Shield Collect | Section 6 offline/QR consent capture | Add-on |
Valid consent under Section 6 is not a checkbox. It is a legally defensible event that must be timestamped, purpose-specific, version-tracked, and retrievable as evidence.
WYSIWYG notice builder generates legally structured consent notices: data categories, processing purpose, retention period, withdrawal mechanism, and rights. Supports all 22 languages in the Eighth Schedule. Version-controlled.
Drop the Consent Widget SDK on any website, or the native SDKs on Android, Flutter, or React Native apps. Captures granular, purpose-specific consent with full audit metadata: timestamp, notice version, and consent scope.
Every consent event stored with a SHA-256 hash in write-once storage. When the Board asks for proof of consent, it takes seconds to export a tamper-evident record.
A separate consent layer for web cookies and trackers - scans your site, classifies what it finds, and renders a localized banner. Bundled with every plan.
Withdrawal is as easy as giving consent - Section 6(4) mandate. When a notice changes materially, the platform flags it and can run a re-consent campaign that lets each recipient adjust their choices purpose by purpose.
Every Data Principal has five enforceable rights. When a user exercises any of them, the 90-day response clock in Rule 14(3) starts. The Rights Request Portal and SLA Engine handle the complete workflow - from OTP-verified receipt to closure.
Rule 7 sets out two separate steps, and treating it as a single 72-hour deadline is a common and costly misreading. First, affected Data Principals and the Board must both receive an initial description without delay - no fixed hour count, but as soon as reasonably possible. Second, the Board must receive a fuller report - circumstances, mitigation, and root cause - within 72 hours of the organisation becoming aware. Missing either step is a separate ₹200 crore exposure under Section 8(6).
Incidents are auto-classified by data category, scope, and impact. Classification determines the escalation path and drives both notification clocks.
The moment an incident is created, both clocks start visibly. The system drafts the initial description and the fuller Board report in the structure Rule 7 expects.
Users affected by the breach are notified with delivery receipts, describing the nature of the breach, likely consequences, and remedial actions taken.
The complete incident timeline - classification, every notification sent, delivery confirmations, and remedial actions - is sealed in immutable storage, regulator-ready in one download.
You cannot comply with the DPDPA's deletion, retention, and processor obligations without first knowing what data you hold, where it lives, and who processes it.
Catalog every system, database, and SaaS tool holding personal data. Tag by sensitivity and data location.
Document each activity: purpose, legal basis, data categories, retention period, and linked processors.
Every vendor catalogued with DPA status, contract type, and expiry alerts. Sub-processor relationships tracked per processor — name, country, DPA status, and their own expiry — so the full chain of data handling is visible in one place.
One-click Record of Processing Activities export, delivered to your DPO. Answer the regulator in minutes, not weeks.
A Record of Processing Activities is only as accurate as the discovery behind it. Most organisations cannot list every database, vendor, or cloud account that actually touches personal data. This is the part of the platform that finds it.
A lightweight scanner agent connects to your Postgres, MySQL, SQL Server, or MongoDB databases in read-only mode and identifies personal-data columns, feeding candidate entries straight into your RoPA.
Every Data Processor from your Data Inventory is scored on domain security posture, certification signals, and breach history - continuous oversight rather than a one-time questionnaire.
Software bills of material for vendor-supplied code, cross-checked against public vulnerability feeds and scored against CERT-In, NTIA, and SEBI CSCRF minimum elements.
Connects to your AWS account through a customer-controlled IAM role and checks cloud configuration - encryption, public access, logging - against the safeguards Section 8(5) expects.
DPDPA guidance keeps evolving through Board orders, gazette notifications, and government clarifications. Regulatory Radar monitors official sources continuously and surfaces updates relevant to your specific modules, so a rule change never arrives as a surprise from a client or a headline.
A compliance score tells you where the gaps are. A rupee figure tells your board why closing them is worth the budget. DPDPA Shield produces both.
A Factor Analysis of Information Risk model, adapted for DPDPA obligations, converts your open gaps into an annualised loss exposure estimate across regulatory, breach, and operational risk - with a board-ready PDF report.
A real-time score from 0 to 100, penalty-anchored so modules carrying higher Schedule 1 exposure weigh more. Every point maps back to a DPDPA section and a specific open task.
An AI assistant grounded in your own tenant data - consent records, open incidents, control status - answers DPO-facing questions directly inside the dashboard instead of a generic chatbot.
For teams juggling more than DPDPA: a 167-framework catalogue including ISO 27001, SOC 2, NIST CSF, HIPAA, and GDPR, with the same assessment and evidence workflow as the DPDPA modules.
| Score Category | Weight | DPDPA Ref | Max Penalty |
|---|---|---|---|
| Security & Breach Response | 28% | S.8(5) + S.8(6) | ₹250Cr + ₹200Cr |
| Consent & Notice | 24% | S.5 + S.6 | ₹50Cr |
| Data Inventory & Processors | 20% | S.8(2) + S.8(7) | ₹50Cr + Processor liability |
| Data Principal Rights | 18% | S.11-14 | ₹50Cr |
| Policy & Governance | 10% | S.5(2) + S.8(9)+(10) | ₹50Cr |
Section 9 requires verifiable parental consent before processing the personal data of any user below 18. This is not limited to platforms explicitly targeting children - it applies to any platform where a minor might register. EdTech, gaming, social, e-commerce - the obligation is universal.
Behavioral tracking of minors. Targeted advertising directed at children. Any processing that causes detrimental effect on child wellbeing. These are absolute prohibitions.
Age gate at registration. Parental consent workflow with OTP verification. Auto-blocks ad-targeting APIs for under-18 accounts. Auto-upgrades accounts on the 18th birthday. Business plan and above.
A Significant Data Fiduciary - notified by the Central Government based on data volume, sensitivity, and risk to sovereignty or public order - carries obligations beyond the baseline: an India-based Data Protection Officer, mandatory Data Protection Impact Assessments, an independent data auditor, and targeted data localisation under Rule 13(4) for specified categories of data.
A structured, scored questionnaire that produces an exportable Data Protection Impact Assessment before you launch anything that processes sensitive data - not just for notified SDFs.
Tracks the India-based DPO appointment, independent audit cadence, and the evidence an SDF needs on hand when the Board asks for it. Enterprise plan.
A handful of modules exist specifically for organisations with more complex identity, branding, or data collection needs than a standard rights-and-consent flow covers.
Upload a hashed mapping between your own customer IDs and the consent records DPDPA Shield holds. When a rights request arrives, the platform can tell your DPO whether the requester is a recognised user - a signal, never a gate on exercising their rights.
A public page for your own customers - what data you collect, your certifications, your security posture, and a live SSL/TLS grade - the same accountability tools the Act asks of you, made visible to the people it protects.
Your rights portal, trust page, and consent pages carry your own name, logo, and colour scheme instead of DPDPA Shield branding. Enterprise plan.
A running inventory of what is encrypted, with what method, who owns the key, and when it last rotated - the evidence Section 8(5) expects you to be able to produce.
A standalone add-on for offline and QR-code consent capture - useful for retail counters, events, or field operations where there is no app or website to embed a widget into. Every submission still writes a proof-backed consent record.
For teams also answering to GDPR or other regimes, the same consent and rights infrastructure extends without a second system to maintain, subject to the specific rules of each jurisdiction.
Compliance infrastructure has to live inside the product an engineering team is already shipping, not beside it. Every capability in this whitepaper is also reachable directly by your own developers.
A lightweight JavaScript widget for any website or single-page app. Captures granular, purpose-specific consent with full audit metadata in a couple of lines of code.
Native Kotlin SDK for Android and a native plugin for Flutter, plus a React Native wrapper around the same Android core. iOS apps built on React Native or Flutter get consent capture through those wrappers.
A documented REST API covers consent records, rights requests, notices, and analytics. Webhooks push real-time events - consent recorded, consent withdrawn, rights request submitted or resolved, breach reported - into your own systems.
The Data Map scanner agent authenticates over HMAC-signed requests, so on-premises or cloud database scanning never needs to expose long-lived credentials to the platform.
Every request is served from AWS Mumbai (ap-south-1). Consent proofs are stored in write-once storage with AES-256 encryption. Notices and widgets render in all 22 languages of the Eighth Schedule.
Assign team roles (DPO, Auditor, Analyst, Viewer), connect your website and apps. No engineers needed.
Works on React, Vue, Angular, or plain HTML, plus native mobile SDKs. Live in minutes.
Link the public rights portal. Set breach thresholds. Import consent records via CSV.
Real-time compliance score. Shield AI assistant on hand. One-click regulator submission.
Larger organisations layer on the modules from Section 04 as they need them - vendor and cloud risk in week two, the Children's Data module before a consumer launch, the SDF compliance pack once notified. Nothing has to be configured before it is needed, and nothing blocks going live on day one.
| Feature / Capability | DPDPA Shield | GDPR Tools / Consultants |
|---|---|---|
| Built for DPDPA Act 2023 & Rules 2025 | ✓ | ✗ |
| 22 Indian scheduled languages | ✓ | ✗ |
| Two-stage breach notification workflow (Rule 7) | ✓ | ✗ |
| 90-day rights request SLA engine (Rule 14(3)) | ✓ | Built for 30 days |
| Data discovery agent + vendor & cloud risk scoring | ✓ | Partial |
| AWS Mumbai data residency (India only) | ✓ | Partial |
| SHA-256 cryptographic proof vault | ✓ | ✗ |
| Native mobile SDKs (Android, Flutter, React Native) | ✓ | Rare |
| Pricing for Indian SMEs | Rupee-priced | ₹2L-5L/yr |
Consent SDK, Rights Portal + 90-day SLA, Breach workflow, Compliance score, Data Inventory, Trust Center, Cookie Manager. Email support.
Everything in Starter + Regulatory Radar, Vendor Risk Intelligence, Risk Register, Cyber Risk Quantification (FAIR), Re-consent Campaigns. Priority support.
Everything in Growth + Children's Data module, Cloud Security Mapping, board reports. SLA support.
Everything in Business + SDF/DPIA pack, Policy Builder, White-Label portals, multi-entity tenancy, dedicated CSM.
Vendor Software / SBOM tracking, GRC Suite, and Shield Collect are available as add-ons independent of plan tier - ask your onboarding contact which combination fits your stack.