KNOWLEDGE
NOTE |
DATA PROTECTION & PRIVACY LAW
Data Protection in the Startup Lifecycle
A Founder’s Guide to the Digital Personal Data Protection Act,
2023
From the first sign-up form to the data room of a Series A due
diligence, every stage of a startup’s life runs on personal data. This note
sets out what founders, CXOs and in-house teams need to know about India’s data
protection law — its statutory architecture, the constitutional judgments
behind it, and a practical compliance roadmap.
WHY THIS LAW BELONGS ON THE FOUNDER’S DESK, NOT JUST IT’S
Most Indian founders first encounter data
protection law as a due-diligence checklist item raised by an investor’s
counsel, or worse, as a notice from a regulator after something has already
gone wrong. Neither is the right starting point. The Digital Personal Data
Protection Act, 2023 (“DPDP Act”) is India’s first comprehensive, standalone
data protection statute, and it touches virtually every function of a startup —
the sign-up flow, the HR database, the CRM, the analytics stack, the vendor
contracts, and increasingly, the investor data room itself.
The Act received Presidential assent on 11
August 2023, but Parliament left its operational detail to subordinate rules
and a phased commencement schedule. That wait ended when the Ministry of
Electronics and Information Technology (MeitY) notified the Digital Personal
Data Protection Rules, 2025 in mid-November 2025, simultaneously constituting
the Data Protection Board of India. The law is therefore no longer a future
compliance obligation — it is a live, phased-in regime with hard deadlines
already running.
“A registered trademark protects a name. A DPDP
compliance framework protects the trust that name is built on.”
THE CONSTITUTIONAL FOUNDATION: FROM PUTTASWAMY TO THE DPDP ACT
The DPDP Act did not emerge in a vacuum. It
is the legislative response to a line of constitutional jurisprudence that took
nearly two decades to mature into a standalone right, and then into statute
law.
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1 — A nine-judge Bench of the Supreme Court
unanimously held that the right to privacy is a fundamental right protected
under Article 21 (and as part of the freedoms under Part III) of the
Constitution. The judgment traced privacy to notions of dignity, autonomy and
informational self-determination — the individual’s right to control the
dissemination of her own personal data. This is the doctrinal root of every
provision in the DPDP Act; the statute is, in essence, Parliament
operationalising the Puttaswamy right through a regulatory and enforcement
framework.
Justice K.S. Puttaswamy (Aadhaar-5J.) v. Union of India (2019) 1 SCC 1 — In
the Aadhaar judgment, a five-judge Bench applied the Puttaswamy privacy test —
legality, legitimate State aim, and proportionality — while upholding the core
Aadhaar framework with modifications. The proportionality standard articulated
here continues to inform how courts and the Data Protection Board are expected
to assess whether a data-processing activity, or a restriction on it, is
proportionate to its stated purpose.
Justice K.S. Puttaswamy (Retd.) v. Union of India
(Review) (2018) 15 SCC 578 — The Court clarified aspects of the earlier
Aadhaar reference and reaffirmed that any State or private action affecting
informational privacy must satisfy the three-fold test of law, legitimate
purpose and proportionality — a test the DPDP Act’s own “legitimate uses”
provisions (Section 7) were drafted to satisfy.
India also has an emerging line of “right to
be forgotten” orders from various High Courts (for instance, matters before the
Delhi, Kerala, Karnataka and Orissa High Courts between 2016 and 2023)
directing removal or de-indexing of personal information from judicial records
and search results in appropriate cases, pending a comprehensive statutory
framework. The DPDP Act now supplies that framework through the Data
Principal’s right to erasure under Section 12, though the right to be forgotten
in the context of open court records continues to be worked out by the
constitutional courts on a case-by-case basis, since the Act itself does not
displace the principle of open justice.
Because the Data Protection Board of India
was constituted only in November 2025 and is still being staffed with its
Chairperson and Members, there is, as yet, no developed body of DPDP-specific
adjudicatory precedent. For the next few years, the privacy jurisprudence
founders should actually rely on remains this constitutional line — Puttaswamy
and its progeny — read together with the plain text of the Act and Rules. This
note will be updated as the Board begins issuing orders.
KEY DEFINITIONS EVERY FOUNDER MUST KNOW
The Act’s obligations turn entirely on a
small set of defined terms. Getting these right is the difference between
correctly scoping a compliance programme and either over- or under-building
one.
|
Term |
What It
Means |
|
Personal
Data (S. 2(t)) |
Any data about an individual who is identifiable by or in
relation to such data — names, phone numbers, device IDs, location data,
biometric data, employment and transaction records, and any other data that
can be linked back to a natural person. |
|
Data
Principal (S. 2(j)) |
The individual to whom the personal data relates. Where the
individual is a child, or a person with a disability who has a lawful
guardian, the parent or lawful guardian is treated as the Data Principal for
consent purposes. |
|
Data
Fiduciary (S. 2(i)) |
Any person who, alone or with others, determines the purpose
and means of processing personal data. A startup collecting user or employee
data — in almost every case — is a Data Fiduciary. |
|
Data
Processor (S. 2(k)) |
Any person who processes personal data on behalf of a Data
Fiduciary — typically a vendor: a cloud host, a payroll processor, an
SMS/email gateway, an analytics or CRM provider. |
|
Significant
Data Fiduciary (S. 10) |
A class of Data Fiduciaries the Central Government may notify
based on factors such as volume and sensitivity of data processed, risk to
Data Principals’ rights, and potential impact on electoral democracy, State
security or public order. SDFs face enhanced obligations — a Data Protection
Officer based in India, an independent data auditor, and periodic Data
Protection Impact Assessments. |
|
Consent
Manager (S. 2(g)) |
A registered, accountable intermediary through which a Data
Principal may give, manage, review or withdraw consent across multiple Data
Fiduciaries — conceptually similar to the Account Aggregator model in
financial services. |
THE CONSENT ARCHITECTURE
Consent is the default legal basis for
processing personal data under the Act, and the statute is unusually
prescriptive about what makes consent valid.
Section 6(1), DPDP Act, 2023
“Every request for the
consent of the Data Principal shall be presented to her in a clear and plain
language … and shall contain, in itemised form, the personal data proposed to
be processed and the purpose of such processing.”
Read with Section 4 and 5, the Act requires
consent to be free, specific, informed, unconditional, unambiguous, and given
through a clear affirmative act — a standard borrowed conceptually from the
GDPR’s “opt-in” model, and a decisive break from the bundled, pre-ticked
checkbox consent common on Indian sign-up flows today. The notice accompanying
the request for consent must independently, and in itself, be comprehensible
without reference to any other document, and must be available in English and
every language listed in the Eighth Schedule to the Constitution.
•
Withdrawal — consent can be withdrawn at any time, as easily as it
was given, and the Data Fiduciary must cease processing (and cause its Data
Processors to cease) within a reasonable time of withdrawal
•
Legacy consent — consent given before the Act’s commencement continues
to be valid, provided the Data Fiduciary gives the Section 5 notice “as soon as
reasonably practicable” after commencement
•
Consent Managers — a Consent Manager registered with the Board may be
used by Data Principals to manage consent across platforms; startups building
consent infrastructure should track this framework closely as it becomes
operative
PROCESSING WITHOUT CONSENT: SECTION 7 “LEGITIMATE USES”
Consent is not the only lawful basis. Section
7 carves out a closed list of “legitimate uses” where personal data may be
processed without fresh consent — a provision startups frequently overlook, and
one that can meaningfully reduce their consent-collection burden where it
genuinely applies.
•
Voluntary provision — where the Data Principal has voluntarily provided her
data for a specified purpose and has not indicated she does not consent to its
use
•
State functions — for the State to provide a subsidy, benefit, service,
certificate, licence or permit
•
Legal compliance — to comply with a judgment, decree, order, or any law
for the time being in force in India
•
Emergencies — for a medical emergency, or during an epidemic,
disaster, or breakdown of public order
•
Employment — for employment-related purposes, including preventing
corporate espionage, safeguarding trade secrets, and provision of any service
or benefit to employees
The employment ground is directly relevant to
every startup with a payroll: routine HR processing — attendance, appraisals,
background checks, benefits administration — does not require a fresh Section 6
consent flow, though the Section 8 fair-processing obligations (below) still
apply in full.
GENERAL OBLIGATIONS OF A DATA FIDUCIARY — SECTION 8
Section 8 is the operative backbone of the
Act. It applies irrespective of any contract to the contrary, and it cannot be
contracted away to a vendor — a Data Fiduciary remains liable for a Data
Processor’s non-compliance.
Section 8(1), DPDP Act, 2023
“A Data Fiduciary shall,
irrespective of any agreement to the contrary or failure of a Data Principal to
carry out the duties provided under this Act, be responsible for complying with
the provisions of this Act and the rules made thereunder in respect of any
processing undertaken by it or on its behalf by a Data Processor.”
1.
Engage Data Processors only
under a valid, written contract.
2.
Ensure completeness,
accuracy and consistency of personal data used for decisions affecting a Data
Principal or shared with another Data Fiduciary.
3.
Implement appropriate
technical and organisational measures to give effect to the Act and Rules.
4.
Implement reasonable
security safeguards to prevent a personal data breach — the single
highest-penalty obligation in the Schedule.
5.
Notify the Board and every
affected Data Principal of a personal data breach, in the form and manner
prescribed by the Rules — regardless of the breach’s scale.
6.
Erase personal data once
the specified purpose is no longer being served, or upon withdrawal of consent,
unless retention is required by law (data minimisation and storage limitation).
7.
Publish the business
contact details of a Data Protection Officer or other responsible person able
to answer Data Principal questions.
8.
Establish an effective
mechanism to redress Data Principals’ grievances.
A
Special Word on Children’s Data — Section 9
For any startup in edtech, gaming, social, or
consumer apps with a plausible teenage or child user base, Section 9 deserves
particular attention. It requires verifiable parental consent before processing
a child’s personal data, prohibits tracking, behavioural monitoring and
targeted advertising directed at children, and bars processing that is likely
to cause detrimental effect on a child’s wellbeing. The DPDP Rules carve out
limited, conditional relaxations for certain platforms (such as for educational
or child-safety purposes), but the default position is stringent, and the
penalty ceiling for non-compliance — up to ₹200 crore — sits just below the
highest slab in the Schedule.
RIGHTS OF THE DATA PRINCIPAL — SECTIONS 11 TO 14
|
Term |
What It
Means |
|
Right to
Information (S. 11) |
A summary of the personal data being processed, the processing
activities undertaken, and identities of Data Fiduciaries and Data Processors
with whom the data has been shared, along with a description of the data. |
|
Right to
Correction and Erasure (S. 12) |
The right to have inaccurate or misleading data corrected,
incomplete data completed, outdated data updated, and processed data erased —
unless retention is necessary for a specified purpose or under law. |
|
Right to
Grievance Redressal (S. 13) |
The right to a readily available grievance-redressal mechanism
from the Data Fiduciary or Consent Manager before approaching the Board. |
|
Right to
Nominate (S. 14) |
The right of a Data Principal to nominate another individual
to exercise her rights in the event of death or incapacity. |
Correspondingly, Section 15 places a short
list of duties on the Data Principal herself — not to impersonate another
person, not to suppress material information while providing her own data for a
document, and not to register false or frivolous grievances or complaints,
breach of which carries a modest penalty of up to ₹10,000, payable by the
individual rather than the enterprise.
CROSS-BORDER DATA TRANSFER — SECTION 16
Unlike the sectoral data-localisation
mandates startups may already know from RBI or other regulators, the DPDP Act
adopts a permissive, “blacklist” approach to cross-border transfer: personal
data may be transferred outside India to any country or territory, except one
that the Central Government notifies by restriction. As of this note, no
general restricted-country list has been notified, though the Rules preserve
the government’s power to prescribe sector-specific or country-specific
conditions, and existing sectoral localisation requirements under other laws
(for example, certain RBI payment-data directions) continue to apply
independently and are not overridden by the Act’s general permissiveness.
THE DATA PROTECTION BOARD OF INDIA, APPEALS AND PENALTIES
The Data Protection Board of India (“Board”)
is constituted under Section 18 as the Act’s dedicated adjudicatory and
enforcement body, headquartered in the National Capital Region. Its functions
under Sections 27 and 28 include directing remedial or mitigating action after
a data breach, inquiring into complaints and Board-initiated references, and
imposing monetary penalties. Proceedings before the Board are digital-by-design
— filings, hearings and orders are conducted electronically as far as practicable.
A Data Fiduciary facing an inquiry may, under
Section 32, offer the Board a voluntary undertaking — including specific
remedial steps and timelines — in lieu of, or in mitigation of, further
proceedings. Appeals from Board orders lie to the Telecom Disputes Settlement
and Appellate Tribunal (TDSAT) under Section 29, and from there, on a question
of law, to the Supreme Court of India.
Penalties
under the Schedule to the Act
|
Default |
Provision |
Maximum
Penalty |
|
Failure to
take reasonable security safeguards to prevent a personal data breach |
S. 8(5) |
Up to ₹250
crore |
|
Failure to
notify the Board and affected Data Principals of a personal data breach |
S. 8(6) |
Up to ₹200
crore |
|
Breach of
additional obligations relating to children’s data |
S. 9 |
Up to ₹200
crore |
|
Breach of
additional obligations of a Significant Data Fiduciary |
S. 10 |
Up to ₹150
crore |
|
Any other
breach of the Act or Rules by a Data Fiduciary |
— |
Up to ₹50
crore |
|
Breach of
duties by a Data Principal (e.g. false or frivolous complaints) |
S. 15 |
Up to
₹10,000 |
These are ceilings, not tariffs — the Board
determines the actual quantum having regard to the nature and gravity of the
default, the type of personal data affected, repetitive conduct, any gain
accrued or loss avoided, mitigating remedial action taken, and proportionality
of the penalty to the default. Multiple, distinct defaults arising from a
single incident can each attract a separate penalty, so a poorly handled breach
can, in principle, expose an enterprise to cumulative liability well beyond any
single Schedule figure.
A practical caution for founders: the
₹250-crore ceiling is not a small-company carve-out. The Schedule fixes
absolute rupee amounts, not a percentage of turnover, so the exposure on paper
is the same whether the Data Fiduciary is a listed unicorn or a three-person
seed-stage team. The Board’s mitigating factors — not the size of the company —
are what is expected to do the work of proportionality in practice.
AN EXPLICIT NOD TO STARTUPS — SECTION 17 EXEMPTIONS
Section 17(2)(a) empowers the Central
Government to exempt specified classes of Data Fiduciaries — including
startups, having regard to the volume and nature of personal data processed —
from certain obligations, such as the detailed notice requirements under
Section 5, parts of Section 8, and the data-retention limitation in Section
8(7). No general startup-wide exemption notification has been issued as of this
note; any relief will be class-specific and conditional, and founders should
not assume exempt status without checking the current notification. The safer
default, until such a notification names a startup’s specific class, is full
compliance.
A PRACTICAL COMPLIANCE ROADMAP, STAGE BY STAGE
At
Incorporation
•
Data mapping — Maintain a data inventory from day one — what personal
data is collected, from whom, why, and where it is stored
•
Notice & consent — Draft user-facing privacy notices and consent flows
that meet the Section 5/6 itemisation and plain-language standard, rather than
reusing a generic template
•
Processor contracts — Build a written vendor-contract template for every
Data Processor — cloud hosting, payment gateways, analytics, communication
tools — addressing purpose limitation, security and sub-processing
At Seed
/ Early Product Stage
•
Breach readiness — Put a breach-response runbook in place before it is
needed — detection, containment, and the Section 8(6) notification timeline to
the Board and affected users
•
Children’s data — If the product touches minors even incidentally
(schools, family apps, gaming with mixed audiences), design age-gating and
parental-consent flows under Section 9 into the product, not as an afterthought
•
Grievance officer — Designate a named, reachable person (formal DPO not
yet mandatory below SDF threshold) to handle Data Principal requests and
grievances under Section 13
At
Series A and Fundraising Due Diligence
•
DD readiness — Investor counsel increasingly ask for the data
inventory, the DPA/vendor contract stack, and any breach history as a standard
due-diligence item — treat this the same way secretarial and IP due diligence
is treated today
•
Cross-border flows — Where a cap table, investor update, or KYC process
moves personal data across group entities or to overseas investors, confirm the
transfer does not touch a restricted destination under Section 16 and is
documented
At Scale
— Significant Data Fiduciary Risk
•
SDF monitoring — Monitor whether the government’s SDF notification
criteria could bring the company within Section 10 — at that point, an
India-based DPO, an independent data auditor and periodic impact assessments
become mandatory
•
Security by design — Build the technical and organisational measures under
Section 8(4) into the engineering roadmap — encryption, access controls,
logging — well ahead of the Phase III substantive-compliance deadline of 13 May
2027
PITFALLS WE SEE MOST OFTEN IN FOUNDER DATA PRACTICES
•
Bundling consent for
marketing, analytics and product functionality into a single pre-ticked
checkbox, rather than itemised, purpose-specific consent
•
Treating a privacy policy
written for GDPR or CCPA as automatically DPDP-compliant — the itemised-notice
and plain-language requirements under Sections 5 and 6 are distinct and must be
checked independently
•
No written contract with a
critical Data Processor (a common gap with early-stage analytics or messaging
vendors), which leaves the Data Fiduciary fully exposed under Section 8(1) for
the vendor’s failures
•
Indefinite retention of
user data “just in case”, with no purpose-linked deletion schedule — a direct
exposure under Section 8(7)
•
No internal owner for data
protection until an investor’s due-diligence checklist forces the issue — by
which point remediation is rushed and visible to the very counterparties
assessing the company
THE ROAD AHEAD
The DPDP Act’s phased rollout gives founders
a rare commodity in Indian regulatory practice: advance notice. Phase I is
already in force. Phase II brings the Consent Manager ecosystem into operation
in November 2026. Phase III, in May 2027, brings the full weight of the
Schedule’s penalties into force. Startups that treat the intervening months as
a build-out window — rather than waiting for the Board’s first enforcement
order to take the law seriously — will be the ones for whom a DPDP compliance
framework becomes a genuine differentiator in fundraising, enterprise sales and
customer trust, rather than a late, expensive scramble.
As with trademark protection, the right time
to build a data protection framework is before it is tested — not after a
breach, a regulator’s notice, or a due-diligence red flag forces the question.
VNC CORPORATE
& LEGAL
Advocates & Solicitors
Nimesh Kumar, Advocate & Partner
G-22 Basement, Lajpat Nagar-III, New Delhi – 110024
www.vnclaw.com
Corporate & Commercial Advisory |
Startup & Fundraising Counsel
| Data Protection & Privacy
Compliance | M&A and Shareholder Disputes |
Secretarial & Regulatory Compliance
Disclaimer: This note is intended solely for general legal
information and awareness. It does not constitute legal advice for any
particular matter, does not create an advocate-client relationship, and does
not guarantee any outcome. Legal rights and the appropriate strategy depend on
the facts and circumstances of each case; readers should seek specific advice
before acting on any information in this note.