Data Protection in the Startup Lifecycle : A Founder’s Guide to the Digital Personal Data Protection Act, 2023

KNOWLEDGE NOTE  |  DATA PROTECTION & PRIVACY LAW

Data Protection in the Startup Lifecycle

A Founder’s Guide to the Digital Personal Data Protection Act, 2023

From the first sign-up form to the data room of a Series A due diligence, every stage of a startup’s life runs on personal data. This note sets out what founders, CXOs and in-house teams need to know about India’s data protection law — its statutory architecture, the constitutional judgments behind it, and a practical compliance roadmap.

WHY THIS LAW BELONGS ON THE FOUNDER’S DESK, NOT JUST IT’S

Most Indian founders first encounter data protection law as a due-diligence checklist item raised by an investor’s counsel, or worse, as a notice from a regulator after something has already gone wrong. Neither is the right starting point. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) is India’s first comprehensive, standalone data protection statute, and it touches virtually every function of a startup — the sign-up flow, the HR database, the CRM, the analytics stack, the vendor contracts, and increasingly, the investor data room itself.

The Act received Presidential assent on 11 August 2023, but Parliament left its operational detail to subordinate rules and a phased commencement schedule. That wait ended when the Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 in mid-November 2025, simultaneously constituting the Data Protection Board of India. The law is therefore no longer a future compliance obligation — it is a live, phased-in regime with hard deadlines already running.

“A registered trademark protects a name. A DPDP compliance framework protects the trust that name is built on.”

THE CONSTITUTIONAL FOUNDATION: FROM PUTTASWAMY TO THE DPDP ACT

The DPDP Act did not emerge in a vacuum. It is the legislative response to a line of constitutional jurisprudence that took nearly two decades to mature into a standalone right, and then into statute law.

Justice K.S. Puttaswamy (Retd.) v. Union of India  (2017) 10 SCC 1  —  A nine-judge Bench of the Supreme Court unanimously held that the right to privacy is a fundamental right protected under Article 21 (and as part of the freedoms under Part III) of the Constitution. The judgment traced privacy to notions of dignity, autonomy and informational self-determination — the individual’s right to control the dissemination of her own personal data. This is the doctrinal root of every provision in the DPDP Act; the statute is, in essence, Parliament operationalising the Puttaswamy right through a regulatory and enforcement framework.

Justice K.S. Puttaswamy (Aadhaar-5J.) v. Union of India  (2019) 1 SCC 1  —  In the Aadhaar judgment, a five-judge Bench applied the Puttaswamy privacy test — legality, legitimate State aim, and proportionality — while upholding the core Aadhaar framework with modifications. The proportionality standard articulated here continues to inform how courts and the Data Protection Board are expected to assess whether a data-processing activity, or a restriction on it, is proportionate to its stated purpose.

Justice K.S. Puttaswamy (Retd.) v. Union of India (Review)  (2018) 15 SCC 578  —  The Court clarified aspects of the earlier Aadhaar reference and reaffirmed that any State or private action affecting informational privacy must satisfy the three-fold test of law, legitimate purpose and proportionality — a test the DPDP Act’s own “legitimate uses” provisions (Section 7) were drafted to satisfy.

India also has an emerging line of “right to be forgotten” orders from various High Courts (for instance, matters before the Delhi, Kerala, Karnataka and Orissa High Courts between 2016 and 2023) directing removal or de-indexing of personal information from judicial records and search results in appropriate cases, pending a comprehensive statutory framework. The DPDP Act now supplies that framework through the Data Principal’s right to erasure under Section 12, though the right to be forgotten in the context of open court records continues to be worked out by the constitutional courts on a case-by-case basis, since the Act itself does not displace the principle of open justice.

Because the Data Protection Board of India was constituted only in November 2025 and is still being staffed with its Chairperson and Members, there is, as yet, no developed body of DPDP-specific adjudicatory precedent. For the next few years, the privacy jurisprudence founders should actually rely on remains this constitutional line — Puttaswamy and its progeny — read together with the plain text of the Act and Rules. This note will be updated as the Board begins issuing orders.

KEY DEFINITIONS EVERY FOUNDER MUST KNOW

The Act’s obligations turn entirely on a small set of defined terms. Getting these right is the difference between correctly scoping a compliance programme and either over- or under-building one.

Term

What It Means

Personal Data (S. 2(t))

Any data about an individual who is identifiable by or in relation to such data — names, phone numbers, device IDs, location data, biometric data, employment and transaction records, and any other data that can be linked back to a natural person.

Data Principal (S. 2(j))

The individual to whom the personal data relates. Where the individual is a child, or a person with a disability who has a lawful guardian, the parent or lawful guardian is treated as the Data Principal for consent purposes.

Data Fiduciary (S. 2(i))

Any person who, alone or with others, determines the purpose and means of processing personal data. A startup collecting user or employee data — in almost every case — is a Data Fiduciary.

Data Processor (S. 2(k))

Any person who processes personal data on behalf of a Data Fiduciary — typically a vendor: a cloud host, a payroll processor, an SMS/email gateway, an analytics or CRM provider.

Significant Data Fiduciary (S. 10)

A class of Data Fiduciaries the Central Government may notify based on factors such as volume and sensitivity of data processed, risk to Data Principals’ rights, and potential impact on electoral democracy, State security or public order. SDFs face enhanced obligations — a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments.

Consent Manager (S. 2(g))

A registered, accountable intermediary through which a Data Principal may give, manage, review or withdraw consent across multiple Data Fiduciaries — conceptually similar to the Account Aggregator model in financial services.

THE CONSENT ARCHITECTURE

Consent is the default legal basis for processing personal data under the Act, and the statute is unusually prescriptive about what makes consent valid.

Section 6(1), DPDP Act, 2023

“Every request for the consent of the Data Principal shall be presented to her in a clear and plain language … and shall contain, in itemised form, the personal data proposed to be processed and the purpose of such processing.”

Read with Section 4 and 5, the Act requires consent to be free, specific, informed, unconditional, unambiguous, and given through a clear affirmative act — a standard borrowed conceptually from the GDPR’s “opt-in” model, and a decisive break from the bundled, pre-ticked checkbox consent common on Indian sign-up flows today. The notice accompanying the request for consent must independently, and in itself, be comprehensible without reference to any other document, and must be available in English and every language listed in the Eighth Schedule to the Constitution.

      Withdrawal — consent can be withdrawn at any time, as easily as it was given, and the Data Fiduciary must cease processing (and cause its Data Processors to cease) within a reasonable time of withdrawal

      Legacy consent — consent given before the Act’s commencement continues to be valid, provided the Data Fiduciary gives the Section 5 notice “as soon as reasonably practicable” after commencement

      Consent Managers — a Consent Manager registered with the Board may be used by Data Principals to manage consent across platforms; startups building consent infrastructure should track this framework closely as it becomes operative

PROCESSING WITHOUT CONSENT: SECTION 7 “LEGITIMATE USES”

Consent is not the only lawful basis. Section 7 carves out a closed list of “legitimate uses” where personal data may be processed without fresh consent — a provision startups frequently overlook, and one that can meaningfully reduce their consent-collection burden where it genuinely applies.

      Voluntary provision — where the Data Principal has voluntarily provided her data for a specified purpose and has not indicated she does not consent to its use

      State functions — for the State to provide a subsidy, benefit, service, certificate, licence or permit

      Legal compliance — to comply with a judgment, decree, order, or any law for the time being in force in India

      Emergencies — for a medical emergency, or during an epidemic, disaster, or breakdown of public order

      Employment — for employment-related purposes, including preventing corporate espionage, safeguarding trade secrets, and provision of any service or benefit to employees

The employment ground is directly relevant to every startup with a payroll: routine HR processing — attendance, appraisals, background checks, benefits administration — does not require a fresh Section 6 consent flow, though the Section 8 fair-processing obligations (below) still apply in full.

GENERAL OBLIGATIONS OF A DATA FIDUCIARY — SECTION 8

Section 8 is the operative backbone of the Act. It applies irrespective of any contract to the contrary, and it cannot be contracted away to a vendor — a Data Fiduciary remains liable for a Data Processor’s non-compliance.

Section 8(1), DPDP Act, 2023

“A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor.”

1.    Engage Data Processors only under a valid, written contract.

2.    Ensure completeness, accuracy and consistency of personal data used for decisions affecting a Data Principal or shared with another Data Fiduciary.

3.    Implement appropriate technical and organisational measures to give effect to the Act and Rules.

4.    Implement reasonable security safeguards to prevent a personal data breach — the single highest-penalty obligation in the Schedule.

5.    Notify the Board and every affected Data Principal of a personal data breach, in the form and manner prescribed by the Rules — regardless of the breach’s scale.

6.    Erase personal data once the specified purpose is no longer being served, or upon withdrawal of consent, unless retention is required by law (data minimisation and storage limitation).

7.    Publish the business contact details of a Data Protection Officer or other responsible person able to answer Data Principal questions.

8.    Establish an effective mechanism to redress Data Principals’ grievances.

A Special Word on Children’s Data — Section 9

For any startup in edtech, gaming, social, or consumer apps with a plausible teenage or child user base, Section 9 deserves particular attention. It requires verifiable parental consent before processing a child’s personal data, prohibits tracking, behavioural monitoring and targeted advertising directed at children, and bars processing that is likely to cause detrimental effect on a child’s wellbeing. The DPDP Rules carve out limited, conditional relaxations for certain platforms (such as for educational or child-safety purposes), but the default position is stringent, and the penalty ceiling for non-compliance — up to ₹200 crore — sits just below the highest slab in the Schedule.

RIGHTS OF THE DATA PRINCIPAL — SECTIONS 11 TO 14

Term

What It Means

Right to Information (S. 11)

A summary of the personal data being processed, the processing activities undertaken, and identities of Data Fiduciaries and Data Processors with whom the data has been shared, along with a description of the data.

Right to Correction and Erasure (S. 12)

The right to have inaccurate or misleading data corrected, incomplete data completed, outdated data updated, and processed data erased — unless retention is necessary for a specified purpose or under law.

Right to Grievance Redressal (S. 13)

The right to a readily available grievance-redressal mechanism from the Data Fiduciary or Consent Manager before approaching the Board.

Right to Nominate (S. 14)

The right of a Data Principal to nominate another individual to exercise her rights in the event of death or incapacity.

Correspondingly, Section 15 places a short list of duties on the Data Principal herself — not to impersonate another person, not to suppress material information while providing her own data for a document, and not to register false or frivolous grievances or complaints, breach of which carries a modest penalty of up to ₹10,000, payable by the individual rather than the enterprise.

CROSS-BORDER DATA TRANSFER — SECTION 16

Unlike the sectoral data-localisation mandates startups may already know from RBI or other regulators, the DPDP Act adopts a permissive, “blacklist” approach to cross-border transfer: personal data may be transferred outside India to any country or territory, except one that the Central Government notifies by restriction. As of this note, no general restricted-country list has been notified, though the Rules preserve the government’s power to prescribe sector-specific or country-specific conditions, and existing sectoral localisation requirements under other laws (for example, certain RBI payment-data directions) continue to apply independently and are not overridden by the Act’s general permissiveness.

THE DATA PROTECTION BOARD OF INDIA, APPEALS AND PENALTIES

The Data Protection Board of India (“Board”) is constituted under Section 18 as the Act’s dedicated adjudicatory and enforcement body, headquartered in the National Capital Region. Its functions under Sections 27 and 28 include directing remedial or mitigating action after a data breach, inquiring into complaints and Board-initiated references, and imposing monetary penalties. Proceedings before the Board are digital-by-design — filings, hearings and orders are conducted electronically as far as practicable.

A Data Fiduciary facing an inquiry may, under Section 32, offer the Board a voluntary undertaking — including specific remedial steps and timelines — in lieu of, or in mitigation of, further proceedings. Appeals from Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under Section 29, and from there, on a question of law, to the Supreme Court of India.

Penalties under the Schedule to the Act

Default

Provision

Maximum Penalty

Failure to take reasonable security safeguards to prevent a personal data breach

S. 8(5)

Up to ₹250 crore

Failure to notify the Board and affected Data Principals of a personal data breach

S. 8(6)

Up to ₹200 crore

Breach of additional obligations relating to children’s data

S. 9

Up to ₹200 crore

Breach of additional obligations of a Significant Data Fiduciary

S. 10

Up to ₹150 crore

Any other breach of the Act or Rules by a Data Fiduciary

Up to ₹50 crore

Breach of duties by a Data Principal (e.g. false or frivolous complaints)

S. 15

Up to ₹10,000

These are ceilings, not tariffs — the Board determines the actual quantum having regard to the nature and gravity of the default, the type of personal data affected, repetitive conduct, any gain accrued or loss avoided, mitigating remedial action taken, and proportionality of the penalty to the default. Multiple, distinct defaults arising from a single incident can each attract a separate penalty, so a poorly handled breach can, in principle, expose an enterprise to cumulative liability well beyond any single Schedule figure.

A practical caution for founders: the ₹250-crore ceiling is not a small-company carve-out. The Schedule fixes absolute rupee amounts, not a percentage of turnover, so the exposure on paper is the same whether the Data Fiduciary is a listed unicorn or a three-person seed-stage team. The Board’s mitigating factors — not the size of the company — are what is expected to do the work of proportionality in practice.

AN EXPLICIT NOD TO STARTUPS — SECTION 17 EXEMPTIONS

Section 17(2)(a) empowers the Central Government to exempt specified classes of Data Fiduciaries — including startups, having regard to the volume and nature of personal data processed — from certain obligations, such as the detailed notice requirements under Section 5, parts of Section 8, and the data-retention limitation in Section 8(7). No general startup-wide exemption notification has been issued as of this note; any relief will be class-specific and conditional, and founders should not assume exempt status without checking the current notification. The safer default, until such a notification names a startup’s specific class, is full compliance.

A PRACTICAL COMPLIANCE ROADMAP, STAGE BY STAGE

At Incorporation

      Data mapping — Maintain a data inventory from day one — what personal data is collected, from whom, why, and where it is stored

      Notice & consent — Draft user-facing privacy notices and consent flows that meet the Section 5/6 itemisation and plain-language standard, rather than reusing a generic template

      Processor contracts — Build a written vendor-contract template for every Data Processor — cloud hosting, payment gateways, analytics, communication tools — addressing purpose limitation, security and sub-processing

At Seed / Early Product Stage

      Breach readiness — Put a breach-response runbook in place before it is needed — detection, containment, and the Section 8(6) notification timeline to the Board and affected users

      Children’s data — If the product touches minors even incidentally (schools, family apps, gaming with mixed audiences), design age-gating and parental-consent flows under Section 9 into the product, not as an afterthought

      Grievance officer — Designate a named, reachable person (formal DPO not yet mandatory below SDF threshold) to handle Data Principal requests and grievances under Section 13

At Series A and Fundraising Due Diligence

      DD readiness — Investor counsel increasingly ask for the data inventory, the DPA/vendor contract stack, and any breach history as a standard due-diligence item — treat this the same way secretarial and IP due diligence is treated today

      Cross-border flows — Where a cap table, investor update, or KYC process moves personal data across group entities or to overseas investors, confirm the transfer does not touch a restricted destination under Section 16 and is documented

At Scale — Significant Data Fiduciary Risk

      SDF monitoring — Monitor whether the government’s SDF notification criteria could bring the company within Section 10 — at that point, an India-based DPO, an independent data auditor and periodic impact assessments become mandatory

      Security by design — Build the technical and organisational measures under Section 8(4) into the engineering roadmap — encryption, access controls, logging — well ahead of the Phase III substantive-compliance deadline of 13 May 2027

PITFALLS WE SEE MOST OFTEN IN FOUNDER DATA PRACTICES

      Bundling consent for marketing, analytics and product functionality into a single pre-ticked checkbox, rather than itemised, purpose-specific consent

      Treating a privacy policy written for GDPR or CCPA as automatically DPDP-compliant — the itemised-notice and plain-language requirements under Sections 5 and 6 are distinct and must be checked independently

      No written contract with a critical Data Processor (a common gap with early-stage analytics or messaging vendors), which leaves the Data Fiduciary fully exposed under Section 8(1) for the vendor’s failures

      Indefinite retention of user data “just in case”, with no purpose-linked deletion schedule — a direct exposure under Section 8(7)

      No internal owner for data protection until an investor’s due-diligence checklist forces the issue — by which point remediation is rushed and visible to the very counterparties assessing the company

THE ROAD AHEAD

The DPDP Act’s phased rollout gives founders a rare commodity in Indian regulatory practice: advance notice. Phase I is already in force. Phase II brings the Consent Manager ecosystem into operation in November 2026. Phase III, in May 2027, brings the full weight of the Schedule’s penalties into force. Startups that treat the intervening months as a build-out window — rather than waiting for the Board’s first enforcement order to take the law seriously — will be the ones for whom a DPDP compliance framework becomes a genuine differentiator in fundraising, enterprise sales and customer trust, rather than a late, expensive scramble.

As with trademark protection, the right time to build a data protection framework is before it is tested — not after a breach, a regulator’s notice, or a due-diligence red flag forces the question.

 

VNC CORPORATE & LEGAL

Advocates & Solicitors

Nimesh Kumar, Advocate & Partner

G-22 Basement, Lajpat Nagar-III, New Delhi – 110024

www.vnclaw.com

Corporate & Commercial Advisory  |  Startup & Fundraising Counsel  |  Data Protection & Privacy Compliance  |  M&A and Shareholder Disputes  |  Secretarial & Regulatory Compliance

Disclaimer: This note is intended solely for general legal information and awareness. It does not constitute legal advice for any particular matter, does not create an advocate-client relationship, and does not guarantee any outcome. Legal rights and the appropriate strategy depend on the facts and circumstances of each case; readers should seek specific advice before acting on any information in this note.