Skip to content

DPDP duties for websites apply in full from 13 May 2027. Check your site free

DPDPWeb
Book a free call Free website check

The website guide to the DPDP Act

What the Digital Personal Data Protection Act, 2023 (DPDP Act, or DPDPA) and the DPDP Rules, 2025 mean for your website. What to change, step by step, with the original source for every rule.

Shuruthi Sellamuthu

Written by . Last reviewed .

A plain-language summary, not legal advice.

The short version

India's Digital Personal Data Protection (DPDP) Act sets rules for how a company collects, uses, stores and shares the personal data of people in India. A website is one of the main places this happens: sign-up forms, KYC pages, contact forms, cookie banners and analytics tags all collect personal data.

  • Your company is the "Data Fiduciary" (it decides why and how data is used). Your visitor or customer is the "Data Principal" (the person the data is about).
  • Four duties matter most: say why you collect data, get a clear yes, let people control their data, and report a breach fast.
  • The main duties apply in full from 13 May 2027. Start now, because changes to forms, banners and databases take time.
  • The largest fine is up to ₹250 crore, for failing to keep personal data secure.
  • The Act covers digital personal data collected in India, and also processing outside India when it relates to offering goods or services to people in India (Act Section 3).

How to read this guide

Part A explains the law in plain words. Part B is five steps to fix your website. Part C covers fines, a deadline checklist and a map of sources.

In every table, "Act" means the DPDP Act, 2023 and "Rule" means the DPDP Rules, 2025. Links to all the original documents are in the source map at the end.

Part A. Understand the law

Key dates

Key dates
DateWhat happensWhere it is mentioned
13 Nov 2025Rules notified. Data Protection Board established. Definitions and Board provisions start.Rule 1 (Rules, G.S.R. 846(E)); G.S.R. 844(E); G.S.R. 843(E)
13 Nov 2026Consent Manager registration starts (Rule 4, Act Section 6(9)).Rule 1; G.S.R. 843(E)
13 May 2027Notice, consent, rights, security, breach reporting, children's data and penalties apply in full.Rule 1 (Rules 3, 5 to 16, 22, 23); G.S.R. 843(E) (Act Sections 3 to 5, 6(1) to 6(8), 6(10), 7 to 17, 28 to 34)

Is it personal data?

Personal data is any data about an individual who can be identified by or in relation to that data (Act Section 2(t)). Name, phone number and email address count in the same way as PAN and Aadhaar. A simple contact form that asks for name, phone and email needs the same care as a KYC form.

What counts as personal data
DataCounts as personal data?Where it is mentioned
Name, phone number, email addressYesAct Section 2(t); Section 3 (digital personal data).
PAN, Aadhaar, bank or transaction detailsYesAct Section 2(t).
IP address, device ID, cookie IDLikely, when they can be linked to a personNot listed by name. This follows from the wording of Section 2(t). Ask legal if you rely on the difference.

Two legal bases for using the data. Most website data needs the person's consent (Section 6). One exception helps with simple forms: if a person gives you their name, phone or email for a specific purpose, such as asking for a callback, and does not object, Section 7(a) can allow you to use it for that purpose without a separate consent. Using the same data for marketing, or sharing it with partners, still needs consent. Confirm with legal which route applies to each form.

Part B. Fix your website in five steps

A team mapping website data with sticky notes on a glass wall

Step 1

Step 1. Know your data

You cannot protect or explain data you have not mapped. List every place your website collects personal data, then fill in one row per item. This table becomes the base for your notices, privacy policy and retention schedule.

Example data map
Where collectedDataWhyLegal basisShared withKeep for
Contact formName, phone, emailReply to the enquirySection 7(a) or consentCRM, email toolTo be set (see Step 4)
Sign-up and KYC formName, PAN, AadhaarVerify identityConsent (Section 6)Partner bank, KYC providerRBI KYC period
Cookie bannerCookie ID, IPAnalytics, adsConsent (Section 6)Analytics and ad vendorsCookie lifespan
Newsletter boxEmailSend updatesConsent (Section 6)Email toolUntil unsubscribe

Example only. Replace each row with your own facts.

Not sure what your site collects today? A DPDP website audit checks which cookies and tags load before consent and how each form asks for it.

Step 2

Step 2. Fix the website itself

2.1 Cookie banner and tracking

The law has no cookie-specific rule. A banner is treated as a request for consent, so the consent rules apply to it.

Cookie banner and tracking
What to doWhere it is mentioned
Do not load analytics or marketing trackers until the user says yes. Essential cookies, such as login or payment security, can load.Act Section 6(1): consent must be free, specific, informed, unconditional and unambiguous, shown by a clear affirmative action.
Offer separate choices (for example analytics on, marketing off). No pre-ticked boxes.Act Section 6(1): consent is specific and covers only the data necessary for the stated purpose.
Make Reject as easy as Accept, and keep a visible link so users can change their mind.Act Section 6(4): withdrawing consent must be as easy as giving it. Rule 3: the notice must include a link to withdraw.
Write the banner in plain language, with English or any of the 22 Eighth Schedule languages available on request.Act Sections 5(3) and 6(3).
Keep a record of each consent and the notice version shown.Act Section 6(10): the company must prove that notice was given and consent was valid. Logging itself is good practice.
Without DPDPA
  • One Accept button, no way to say no
  • Trackers load before any choice
  • Vague wording, no link to change later
With DPDPA
  • Reject is as easy as Accept
  • Separate choices, nothing pre-ticked
  • Plain words and a link to change later
Figure 1: Cookie banner without and with DPDPA (illustrative mock-up, not a real company)

We do this work as a service: DPDP cookie consent banner setup, and Google Consent Mode v2 and GTM tag gating for the trackers behind it.

2.2 Sign-up and KYC forms

Sign-up and KYC forms
What to doWhere it is mentioned
Show a short notice next to the form: what data, for what purpose, and how to withdraw or complain.Act Section 5(1). Rule 3: an itemised list of the data, the specific purpose, and links to withdraw consent, use rights and complain to the Board.
Ask only for what the service needs. Remove optional fields such as marital status or social profile links.Act Section 6(1): consent is limited to the personal data necessary for the stated purpose.
Keep the Terms of Service separate from data-sharing consent. Both boxes start unticked.Act Section 6(1). Rule 3: the notice is presented on its own, in clear and plain language.
Do not make optional marketing consent a condition of using the basic service.Act Section 6(1): consent must be unconditional.
Name the partners you share data with and say why.Rule 3. Act Section 11: users can ask who their data was shared with.
Without DPDPA
  • Asks for more than the service needs
  • One pre-ticked box bundles Terms, data and marketing
  • No notice saying what is collected or why
With DPDPA
  • Only the fields the service needs
  • A short notice next to the form
  • Separate boxes, all unticked, marketing optional
Figure 2: Sign-up and KYC form without and with DPDPA (illustrative mock-up, not a real company)

We do this work as a service: DPDP consent for website forms.

2.3 Rights and complaints

Rights and complaints
What to doWhere it is mentioned
Give users a way to see a summary of their data and who it was shared with.Act Section 11.
Let users correct, complete, update and erase their data.Act Section 12. Act Section 8(7): erase data when consent is withdrawn or the purpose ends.
Run a visible complaints channel and answer on time.Act Section 13. Rule 14: how rights are exercised. Rule 14(3): not more than 90 days.
Let users nominate someone to use their rights for them.Act Section 14.
Publish a contact point for questions. A named Data Protection Officer is required only for large ("significant") companies.Act Section 8(9) and Rule 9 (contact). Act Section 10(2)(a) (Data Protection Officer).

2.4 Children

If your website may be used by people under 18, get verifiable consent from a parent or guardian before processing their data. Do not track them, monitor their behaviour or target advertising at them.

Children
What to doWhere it is mentioned
Treat anyone under 18 as a child and get verifiable parental consent first.Act Section 9(1) and Section 2(f). Rule 10: how parental consent is verified.
Do not track, monitor or target ads at children.Act Section 9(3).
Check the exemptions in Rule 12 and the Fourth Schedule before relying on them.Rule 12; Fourth Schedule.

Step 3

Step 3. Write your three pages

The law does not require a privacy policy, a Terms page or a cookie policy by name. It requires a notice at the point where you ask for data (Section 5, Rule 3) and a published contact for questions (Section 8(9), Rule 9). In practice you should update all three pages, because each has a different job.

Pages to update
WhereUpdate it?What to put on itWhere it is mentioned
Notice at the form and the bannerYes. This is the legal core.What you collect (name, phone, email and so on), why, and links to withdraw consent, use rights and complain to the Board. It must stand on its own.Act Section 5. Rule 3.
Privacy policy pageYes. The full detail lives here.All the data you collect and why; who receives it; how long you keep it; how to see, correct, erase and withdraw; how to complain, including to the Board; the contact for questions; the languages offered.Act Sections 5, 8(9) and 11 to 14. Rules 3, 9 and 14.
Terms pageYes, a small update.Keep it about the service. Do not put data consent inside it. Add a line pointing to the privacy policy, and state that marketing consent is optional.Act Section 6(1). Rule 3.
Cookie policy pageYes, if you use analytics, ads or other trackers.A table of each cookie: name, provider, purpose, lifespan and category. How to change or withdraw choices. A link to it from the banner.Not required by name. It supports Act Sections 5, 6(1) and 6(4) and Rule 3.

Example rows for the data table in your privacy policy (replace the wording with your own facts):

Example privacy policy data table
DataWhy we collect itWho receives itHow long we keep it
Name, phone number, email addressTo reply to your enquiry and to set up your accountOur CRM and email tools (name each one)12 months after your last contact, unless you become a customer
PAN, AadhaarTo verify your identity for a loanOur partner bank and KYC provider (name them)As the RBI KYC rules require

We draft the privacy policy and cookie policy pages as a service, for your legal contact to approve: DPDP privacy policy and cookie policy drafting.

What the law does not say

Some online checklists present these as legal requirements. They are good practice, not law:

  1. No cookie-specific rule. Cookies are covered by the general consent rules.
  2. Consent does not have to expire automatically after a set period.
  3. A Data Protection Officer is only for significant data fiduciaries (Section 10(2)(a)). Everyone must publish a contact point (Section 8(9)).
  4. The notice must be available in English or any one of the 22 languages on request, not all 22 at once (Sections 5(3), 6(3)).
  5. Logging each consent is not named, but Section 6(10) puts the burden of proof on you, so logging is the safest route.
  6. A privacy policy, Terms page and cookie policy are not required by name.
  7. There is no single retention period for general data (see Step 4).

Step 4

Step 4. Set retention and deletion

The law does not set one fixed period for general data such as name, phone and email. The rule is based on purpose: keep the data only while the purpose you stated is still being served, then erase it. You choose the period, write it down and be ready to explain it. A few Rules and sector laws set specific periods.

Retention periods
SituationHow longWhere it is mentioned
General rule (enquiry forms, sign-ups, newsletters)Erase when the user withdraws consent, or when it is reasonable to assume the purpose has ended, whichever comes first. The user can also ask for erasure.Act Section 8(7) and Section 12(3).
A law requires you to keep itKeep it for the period that law sets, then erase.Act Sections 8(7) and 12(3).
Regulated financial entities: KYC and transactionsTransaction records: 5 years from the date of the transaction. Identity and address records: at least 5 years after the customer relationship ends. This is an RBI rule, not a DPDP rule.RBI Master Direction, Know Your Customer Direction 2016, paragraph 46.
Logs of access to personal dataKeep the logs for one year.Rule 6(1)(e).
Purposes listed in the Seventh ScheduleKeep personal data, traffic data and logs for at least one year for those purposes, then erase unless a law requires longer.Rule 8(3).
Large e-commerce, online gaming and social media platformsErase 3 years after the user last contacted you (or after the Rules start, if later), with at least 48 hours' warning, unless a law requires keeping it. Most company websites are not in these classes.Rules 8(1) and 8(2). The classes and user thresholds are in the Third Schedule. Check the PDF for the current thresholds.
Consent recordsKeep them as long as you rely on that consent, so you can prove it. The exact period is good practice, not stated in the law.Act Section 6(10).

Suggested starting point (good practice, not from the law). Agree your own periods with legal:

  • Enquiry and demo forms that never became customers: review after 12 months with no contact, then delete or ask again.
  • Newsletter list: keep until the person unsubscribes.
  • Customers: keep for the relationship plus the sector retention period, then delete.
  • Set up an automatic delete job and publish the periods in your privacy policy.

Step 5

Step 5. Secure the data and plan for breaches

Security and breaches
What to doWhere it is mentioned
Put reasonable security safeguards in place: encryption or masking, access controls, activity logs and backups.Act Section 8(5). Rule 6: the minimum safeguards.
Have a breach plan with a named owner: tell each affected user without delay, tell the Board without delay, and send the Board a detailed report within 72 hours.Act Section 8(6). Rule 7.
Remember you stay responsible for data handled by vendors (analytics, CRM, KYC, email tools). Use written contracts with each one.Act Sections 8(1) and 8(2). Rule 6 (safeguards extend to processors).
Large companies the government designates as significant data fiduciaries have extra duties (Data Protection Officer, audits, impact assessments).Act Section 10.

Part C. Penalties, checklist and sources

Penalties

The Data Protection Board decides penalties after hearing the company. Each amount is a maximum, not a fixed fine.

Maximum penalties
FailureMaximumWhere it is mentioned
Not keeping personal data secure₹250 croreSchedule to the Act, read with Section 8(5)
Not reporting a breach to the Board and users₹200 croreSchedule, read with Section 8(6)
Breaking the rules for children's data₹200 croreSchedule, read with Section 9
Not meeting extra duties of a significant data fiduciary₹150 croreSchedule, read with Section 10
Any other breach of the Act or the Rules (including notice and consent)₹50 croreSchedule to the Act. Penalties are imposed under Section 33.

Checklist by deadline

Checklist by deadline
DoneTaskSuggested bySource
Map every form, cookie and tool that collects personal data (Step 1)Dec 2026Act Section 5
Decide the legal basis and retention period for each item (Steps 1 and 4)Dec 2026Act Sections 6, 7, 8(7)
Replace the cookie banner with one that blocks trackers until the user agreesFeb 2027Act Section 6
Rewrite notices at each form, separate from the TermsFeb 2027Rule 3
Update the privacy policy, Terms page and cookie policy (Step 3)Mar 2027Act Sections 5, 8(9)
Build rights and complaints handling, with a 90 day answer limitMar 2027Act Sections 11 to 14; Rule 14
Sign contracts with vendors and review safeguards (Step 5)Apr 2027Act Section 8; Rule 6
Write the breach plan with the 72-hour Board report and test itApr 2027Act Section 8(6); Rule 7
Set up automatic deletion jobs; check RBI record rules with legal firstApr 2027Act Section 8(7); Rule 8
Final review. Full duties apply.13 May 2027Rule 1

Suggested dates are planning targets, not legal deadlines. The only legal date is 13 May 2027.

A website keeps changing after the checklist is done. A monthly DPDP Care Plan rescans the site, reviews new cookies and tags and retests the banner.

Source map and original documents

Use this table to jump to the exact place in the original text.

Source map
TopicActRulesOther
Personal data definitionSection 2(t)
NoticeSection 5Rule 3
Consent and withdrawalSection 6Rule 3
Voluntarily provided dataSection 7(a)
Security and breachSection 8(5), 8(6)Rules 6, 7
Erasure and retentionSections 8(7), 12(3)Rule 8RBI KYC para 46
Contact and complaintsSections 8(9), 8(10), 13Rules 9, 14
ChildrenSection 9Rules 10, 12
User rightsSections 11 to 14Rule 14
Significant data fiduciarySection 10Rule 13
PenaltiesSection 33; Schedule

Before you quote an exact wording or number, read the rule in the PDF. In particular, confirm the Third Schedule thresholds and the Seventh Schedule purposes used in Rule 8, and the Rule 12 and Fourth Schedule exemptions for children's data. This guide is a summary and not legal advice.

Questions about the DPDP Act and websites

Does the DPDP Act mention cookies?

No. The Act has no cookie-specific rule. A cookie banner is treated as a request for consent, so the consent rules in Section 6 apply to it.

Does every form need a consent checkbox?

Not always. If a person gives their details for a specific purpose, such as a callback, Section 7(a) can cover that purpose without a separate consent. Using the same details for marketing, or sharing them, needs consent. Confirm the route for each form with your legal contact.

Do I need a Data Protection Officer?

Only if the government designates your company a significant data fiduciary (Section 10(2)(a)). Every company must still publish a contact point for questions (Section 8(9), Rule 9).

Do notices have to be in all 22 languages?

No. The notice must be available in English or any one of the 22 Eighth Schedule languages on request, not all 22 at once (Sections 5(3) and 6(3)).

How long can I keep enquiry data?

The Act sets no fixed period for general data. Keep it while the stated purpose is still being served, then erase it (Section 8(7)). A common starting point is to review enquiry data after 12 months with no contact. Agree your own periods with your legal contact.

Free website check

Want this checked on your own site?

Send your URL for a free check of your homepage.

Get a free website check