India's DPDP law forces startups to overhaul data handling by 2027
India's Digital Personal Data Protection Act will become enforceable by May 2027, obligating startups of all sizes to secure consent, limit use, and honor user rights over personal data.
India's Digital Personal Data Protection Act, slated to be fully active by May 2027, imposes comprehensive duties on any company that collects or processes personal information, regardless of its size. Startups must obtain explicit user consent, use data solely for declared purposes, implement strong security safeguards, and respond to access or deletion requests. Legal and cybersecurity specialists say compliance goes beyond revising privacy policies; it requires a full-scale redesign of data collection, storage, and governance structures.
Many founders still cannot pinpoint what personal data they hold or who can access it, and they often lack dedicated grievance officers or enforceable agreements with vendors. The law also mandates breach notification to the Data Protection Board of India within 72 hours, demanding robust incident-response capabilities. Experts highlight that fragmented data stores, excessive employee access, and inadequate vendor oversight create the biggest security gaps, while AI tool usage adds new compliance complexities. Companies like Zoho that have integrated privacy-by-design practices are better positioned, but the consensus is that most Indian startups remain unprepared for the upcoming enforcement deadline.
Why it matters
Non-compliance could trigger penalties, hurt funding prospects and limit market access for Indian startups.
In this story