Skip to content
WEB DEVELOPMENT

DPDP Act Compliance for Business Websites: A Practical Checklist for Indian Businesses

Quavento Team
Digital marketing & development, Pune
•
13 min read

Quick answer

To make a business website ready for the DPDP Act, list the personal data your forms, chat, analytics and payment tools collect, show a clear notice before collecting it, take consent with an unticked box for anything beyond the visitor's request, let people withdraw consent and raise grievances easily, secure and log the data, and plan how you will report a breach. Most duties apply from May 2027.

Cover graphic: DPDP Act website compliance checklist

Key Takeaways

  • The DPDP Act, 2023 applies to any business that collects personal data digitally, including through a website contact form, chat widget or WhatsApp opt-in.
  • The DPDP Rules were notified on 14 November 2025. Most duties for businesses, including notices, security, breach reporting and data rights, take effect 18 months later, around May 2027.
  • Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Pre-ticked boxes do not qualify.
  • Withdrawing consent must be as easy as giving it, and requests to access, correct or erase data must be answered within 90 days.
  • A breach must be reported to affected people without delay and to the Data Protection Board with a detailed report within 72 hours.
  • Penalties reach ₹250 crore for failing to protect data and ₹200 crore for failing to report a breach.
  • Start now with a data inventory of your website and the tools connected to it.

What is the DPDP Act, and does it apply to your website?

The Digital Personal Data Protection Act, 2023, usually called the DPDP Act, is India's first full law on personal data. Parliament enacted it on 11 August 2023. It governs how organisations collect, use, store and share personal data that is held in digital form, or collected offline and later digitised.

If your website has a contact form, a newsletter sign-up, a quote calculator, a chat widget, a login, a checkout or even an analytics tool that identifies visitors, you process personal data, and the Act applies to you. Size does not exempt you. A three-person clinic in Nashik collecting appointment requests online is covered just as a national retailer is, although the largest platforms carry extra duties.

The Act uses its own vocabulary. Your business is a Data Fiduciary, because it decides why and how the data is used. The visitor is a Data Principal. A company that handles data on your behalf, such as your hosting provider, CRM or email platform, is a Data Processor. You remain responsible for what your processors do with the data you give them.

NOTE

This guide is general information for business owners, written from a website and software developer's point of view. It is not legal advice. Have a lawyer review your notices and contracts.

When do the DPDP Rules take effect?

The Act needed rules to work in practice, and the government notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025 after a consultation that, according to the Press Information Bureau, received 6,915 inputs. The rules come into force in three stages.

TIP

Eighteen months sounds generous, but website changes, vendor contracts and staff training take time. Businesses that start in 2026 finish calmly. Those that start in April 2027 do not.

  • Immediately on notification: the rules that set up the Data Protection Board of India and how it works.
  • One year later, in November 2026: the rule on registration and obligations of Consent Managers.
  • Eighteen months later, around May 2027: the rules most businesses care about, covering notices, security safeguards, breach intimation, data retention, contact details, children's data and the rights of individuals.

What personal data does a typical business website collect?

More than most owners realise, because much of it is collected by tools rather than by the site itself. The first practical step is a data inventory: a simple sheet listing every place personal data enters the business through the website, what is collected, why, where it goes and who can see it.

Take a Pune interior design studio as an illustration. The studio is invented for this example, but the list is typical. Its website has an enquiry form asking for name, phone, email, budget and a description of the home. A WhatsApp chat button opens a conversation on the studio's business number. A cost calculator asks for the size of the flat and an email address to send the estimate. Google Analytics and the Meta pixel run on every page. Enquiries flow into a CRM, and a weekly newsletter goes out through an email platform. That is at least six systems holding personal data, each needing a purpose and a safeguard.

  • Forms: contact, quote, booking, careers and newsletter forms.
  • Chat: website chat widgets, chatbots and WhatsApp click-to-chat.
  • Accounts and orders: logins, checkout, addresses and order history.
  • Tracking: analytics, advertising pixels and session recording tools.
  • Back office: CRM, email marketing, spreadsheets, shared inboxes and backups.

When do you need consent, and when is it not required?

The Act allows processing on two broad grounds: consent, or what it calls certain legitimate uses. One legitimate use is especially relevant to websites. If a person voluntarily gives you their data for a specified purpose and has not said they object, you may use it for that purpose. The Act's own illustration is a pharmacy customer who gives her mobile number to receive a payment receipt. The pharmacy may send the receipt.

Applied to a website, someone who fills in your enquiry form to get a quote can be contacted about that quote. What you cannot assume is permission for anything else. Adding that person to a promotional newsletter, sending marketing WhatsApp messages, sharing their details with a partner or using them for targeted advertising needs separate consent.

Where consent is the basis, the Act sets a high bar. Consent must be free, specific, informed, unconditional and unambiguous, signified by a clear affirmative action, and limited to the data needed for the purpose. The Act gives a telemedicine example: an app that also asks for access to the user's contact list gets no valid consent for the contacts, because they are not needed for the service.

  • Use an unticked checkbox for marketing consent. Pre-ticked boxes and consent hidden in terms and conditions do not meet the standard.
  • Ask for marketing consent separately from the enquiry itself, so a person can get a quote without joining a mailing list.
  • Collect only the fields you need. If you do not use a date of birth, do not ask for it.

What must your privacy notice say?

Before or at the time you ask for consent, the Act requires a notice. The Rules say it must stand on its own, be understandable without reading other documents and be written in clear and plain language. At a minimum it must give an itemised description of the personal data, the specific purposes and the goods, services or uses the processing enables.

It must also tell people how to withdraw consent, how to exercise their rights and how to complain to the Data Protection Board, with the link to the relevant page on your website or app. The Act requires you to offer the notice in English or in any of the 22 languages in the Eighth Schedule to the Constitution, which matters for businesses serving customers in Hindi, Marathi, Tamil and other languages.

For a website, this usually means a short notice next to each form, with a link to a fuller privacy page, rather than a single legal document nobody reads.

  • What you collect, item by item, such as name, mobile number, email and project details.
  • Why you collect it, purpose by purpose.
  • How to withdraw consent, with a link or button.
  • How to access, correct or erase data, and how to raise a grievance.
  • How to complain to the Data Protection Board.
  • Contact details of the person who answers privacy questions.

How should withdrawal of consent and data requests work?

The Rules require that withdrawing consent be as easy as giving it. If consent was given with one tick on a form, it cannot be withdrawn only by sending a registered letter. Practical options are an unsubscribe link in every marketing email, STOP handling on WhatsApp and SMS, and a settings page for logged-in users.

Individuals can also ask to access a summary of their data, have it corrected or updated, have it erased in certain situations and nominate someone to act for them. The Rules require you to publish how these requests can be made and to respond to grievances within a period not exceeding 90 days.

Every Data Fiduciary must also publish, prominently on its website or app, the business contact details of a person who can answer questions about how personal data is processed, or of its Data Protection Officer where one is required. For a small business this can be a named role and a dedicated email address.

What security safeguards do the Rules expect?

The Rules list minimum safeguards rather than a single technical standard. They include protecting data through measures such as encryption, masking or tokenisation; controlling access to the systems that hold it; keeping logs and monitoring so that unauthorised access can be detected and investigated; backups and measures to keep working after an incident; and contracts with your processors that require reasonable safeguards.

Logs and the related personal data used for detecting and investigating unauthorised access must be kept for one year, unless another law requires otherwise. The Rules also require Data Fiduciaries to retain personal data, traffic data and processing logs for at least one year for purposes listed in the Rules.

For a website, the practical list is familiar: HTTPS everywhere, an up-to-date CMS and plugins, strong passwords and two-factor authentication for admins, form submissions stored in a protected system rather than a shared inbox, limited staff access, regular backups and a hosting provider that keeps access logs. Our website maintenance work covers much of this routine.

What happens if there is a data breach?

A personal data breach includes any unauthorised access, disclosure, alteration, loss or destruction of personal data, from a hacked database to a spreadsheet of enquiries emailed to the wrong person.

On becoming aware of a breach, you must inform each affected person without delay, in plain language, through their account or a contact method they registered with you. The message must describe the breach, its likely consequences for them, what you are doing about it, what they can do to protect themselves, and who to contact.

You must also inform the Data Protection Board without delay, and within 72 hours of becoming aware of the breach send a detailed report covering the facts, the cause, the steps taken, the person responsible if known and the notices sent to affected people. The Board can allow longer on a written request. Failing to report a breach can attract a penalty of up to ₹200 crore, so write a one-page breach plan now, while nothing is wrong.

WARNING

Breaches at small businesses often come from the website itself: an outdated plugin, an exposed form database or a shared admin password. Keeping the site updated is a compliance task, not just a technical one.

What about children's data?

Under the Act a child is anyone under 18, not 13 as in many other countries. Before processing a child's personal data, you need verifiable consent from a parent or lawful guardian, and the Rules describe how to check that the person giving consent is an identifiable adult. The Act also prohibits tracking, behavioural monitoring and targeted advertising directed at children.

This matters most for schools, coaching institutes, edtech platforms, gaming, youth sports and children's products. If students under 18 can register on your site, the sign-up flow needs a parental consent step, and advertising pixels should not track those users. Some classes of processing, such as certain educational and healthcare uses, have exemptions set out in the Rules. Violations of obligations relating to children can attract penalties of up to ₹200 crore.

How does DPDP affect WhatsApp, email and SMS marketing?

Marketing is where most Indian businesses will need to change habits. Buying lists, adding every enquiry to a promotional broadcast and messaging people who never asked are hard to justify under a law that requires specific consent for each purpose.

The good news is that permission-based marketing also performs better. WhatsApp itself requires businesses to have the user's opt-in before sending messages through the WhatsApp Business Platform. Recording when, where and for what each person opted in, and honouring opt-outs immediately, satisfies both WhatsApp's policies and the spirit of the Act.

Our WhatsApp and email marketing services build consent capture, opt-out handling and records into every campaign, so growth and compliance do not pull in opposite directions.

What did we change on our own website?

We applied these principles to quaventotechnologies.com, and you can check each one. Our cookie banner asks before turning on Google Analytics, and the same choice controls whether conversations with Buddy, our website assistant, are saved. If a visitor declines, chats are not stored. When a visitor sends their details through Buddy, a short note explains how they will be used, with a link to the privacy policy, and Buddy asks only for what we need to reply.

Submissions go into a database that the website can write to but cannot read back. Reading them requires a signed-in team member, which limits who can see personal data. The way the assistant and its back end were built is described in our Buddy chatbot case study.

We are not claiming this makes our site, or anyone's, fully compliant. It is a practical start that took days, not months, and every business website can do something similar now.

What is a practical DPDP checklist for your website?

Work through this list over the next few months, with your developer and, for the legal wording, your lawyer.

  • Inventory: list every form, widget, tool and back-office system that touches personal data.
  • Minimise: remove form fields and tracking you do not genuinely use.
  • Notices: add a plain-language notice beside each form and a full privacy page, with other languages if your customers need them.
  • Consent: use unticked, separate checkboxes for marketing and keep a record of each consent.
  • Cookie and tracking controls: let visitors decline analytics and advertising tags, and make sure declining actually stops them.
  • Withdrawal and rights: add unsubscribe and opt-out paths, and a simple way to request access, correction or erasure.
  • Contact: publish the contact details of the person who answers privacy questions.
  • Security: HTTPS, updates, two-factor admin logins, limited access, backups and log retention.
  • Processors: review contracts with your hosting, CRM, email and WhatsApp providers.
  • Breach plan: a one-page plan naming who does what in the first 72 hours.
  • Children: add parental consent if anyone under 18 can sign up.

Where should you start?

Start with the inventory, because every other step depends on knowing what you hold. Many businesses find that the quickest wins are removing data they never use and moving enquiries out of shared inboxes into a protected system.

If your site is old or built on many plugins, it may be simpler to rebuild with privacy designed in. Our website development company in India page explains how we plan such projects, and our guide to website development cost in India covers what drives the budget. For applications that hold customer accounts or health, finance or student data, see our software development company in India page. Accurate, consent-aware analytics is covered by our GA4 setup service, and businesses in Pune can speak to us directly through our website development company in Pune page.

Frequently Asked Questions

Does the DPDP Act apply to small businesses?

Yes. The Act applies to any organisation that processes digital personal data, regardless of size, including through a website form or chat. The largest platforms, notified as Significant Data Fiduciaries, have extra duties such as audits and impact assessments.

When do businesses have to comply with the DPDP Rules?

The Rules were notified on 14 November 2025. Rules on the Data Protection Board applied immediately, the Consent Manager rule after one year, and most duties for businesses, including notices, security, breach intimation and data rights, after 18 months, around May 2027.

Do I need consent to reply to a website enquiry?

Generally no, if the person voluntarily submitted their details to get a response and has not objected. That is a legitimate use under the Act. You do need separate consent to use those details for marketing or anything beyond the original request.

What is the penalty for not complying with the DPDP Act?

Penalties can reach ₹250 crore for failing to take reasonable security safeguards, ₹200 crore for failing to report a breach or for violating obligations relating to children, and ₹50 crore for other violations.

How quickly must a data breach be reported?

Affected individuals and the Data Protection Board must be informed without delay, and a detailed report must reach the Board within 72 hours of becoming aware of the breach, unless the Board allows more time on a written request.

Is a cookie banner required under the DPDP Act?

The Act does not mention cookies by name. But analytics and advertising tools that identify visitors process personal data, so asking for consent before turning them on, and respecting a refusal, is the safer approach. Ask your lawyer about your specific tools.

Sources & further reading

Tags:DPDP ActData ProtectionPrivacyWebsite ComplianceIndia
CONTINUE READING

Related Articles

READY TO COLLABORATE

Ready to get started?

Partner with Quavento to turn bold digital concepts into market-defining brands, scalable web platforms, and measurable commercial growth.

Detailed strategy proposal & honest milestone pricing
Direct access to senior strategy & engineering leads
Guaranteed response within 24 business hours

Get in Touch

Share your requirements and we will send a tailored proposal.