Web Application Security

DPDPA Compliance for Indian Websites — Digital Personal Data Protection Act 2023

By Domain India Team · DomainIndia EngineeringPublished 10 min read
Knowledge base article
Contents (13 sections)

India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 set out how any business that collects personal data online must handle it. This guide turns the law into practical steps for a website or app: the consent notice, user rights, breach handling, retention and the code to support them.

Key takeaways

If your website collects names, emails, phone numbers or other personal data, the DPDP Act almost certainly applies to you. You need a clear notice, valid consent (or a permitted legitimate use), reasonable security, a breach plan, a way for people to exercise their rights, and a deletion schedule. Most business obligations are scheduled to apply from May 2027. The Act does not require data to be stored in India.

General information, not legal advice

This article summarises public law as of September 2026 and gives technical examples. It is not legal advice and does not describe how any particular business, including Domain India, complies. Read the official texts and consult a qualified lawyer for your situation.

1. What the DPDP Act covers

The Act received assent in August 2023. The DPDP Rules, 2025 were notified in November 2025 with staggered dates: the Data Protection Board provisions applied at once, the consent manager framework is scheduled for November 2026, and most obligations on businesses for May 2027. Dates can change, so check MeitY's data protection page.

It applies to digital personal data: any data about an identifiable person, such as a name, email address, phone number, location, IP address or login history.

  • Data Fiduciary: you, the business that decides why and how data is processed.
  • Data Processor: a service that processes data for you, such as your hosting provider, email service, CRM or payment gateway. You remain responsible for choosing and binding them by contract.
  • Data Principal: the person the data is about.

2. Does it apply to your website?

SituationDoes the Act apply?
Indian business with Indian customersYes
Indian business serving foreign customersUsually yes, because processing happens in India (some outsourcing contracts are exempt)
Foreign business offering goods or services to people in IndiaYes
Blog or community site with sign-ups, comments or a newsletterLikely yes; purely personal or domestic use by an individual is exempt
Static site with no formsLimited, but server logs still hold IP addresses

A single contact form collects personal data, so most business websites are in scope.

Before or when you ask for consent, give a notice that states what data you collect and why, how the person can withdraw consent and exercise their rights, and how to complain to the Data Protection Board. The person must be able to read it in English or in any language listed in the Eighth Schedule of the Constitution. Offering the languages your customers actually use is good practice, but the Act does not require a regional language in addition to English.

Valid consent is free, specific, informed, unconditional and unambiguous, given by a clear action. In practice:

  • Use unticked checkboxes. A pre-ticked box is not a clear action.
  • Ask for each purpose separately (order updates, marketing, analytics).
  • Make withdrawing as easy as giving consent.
  • Load analytics and marketing tags only after the visitor opts in.

Consent is not the only ground: some "legitimate uses" in the Act, such as data a person voluntarily gives you for a specific purpose, do not need separate consent.

A short example notice:

text
We use your email address to send updates about your order.
You can withdraw consent or ask us to correct or delete your data
at [email protected]. If you are not satisfied with our reply,
you can complain to the Data Protection Board of India.

[ ] I agree to receive order updates by email.

4. Rights you must honour

People can ask you for:

  • a summary of the personal data you hold and who you shared it with;
  • correction, completion, updating or erasure of their data;
  • grievance redressal;
  • nomination of someone to act for them in case of death or incapacity.

Publish how to make a request, and publish the business contact details of a person who can answer questions about your processing (a Data Protection Officer, if you have one). The Rules set an outer limit of 90 days for resolving grievances; aim for much faster.

5. Breaches, children and larger businesses

Personal data breach
Inform the Data Protection Board and each affected person without delay, and send the Board a detailed report within 72 hours of becoming aware.
Children's data
For anyone under 18, get verifiable consent from a parent or guardian. Don't track, behaviourally monitor or target advertising at children.
Significant Data Fiduciaries
The central government may designate large or high-risk processors. They must appoint a Data Protection Officer in India and run audits and impact assessments.

A breach can also be a cyber incident that CERT-In's 2022 directions require you to report within 6 hours. The two regimes are separate; see the DPDP Act and CERT-In guide for both.

6. Technical implementation

Store what the person saw and when, so you can prove consent later:

sql
CREATE TABLE consent_records (
    id           bigserial PRIMARY KEY,
    user_id      uuid REFERENCES users(id),
    purpose      text NOT NULL,        -- 'order_updates', 'marketing', 'analytics'
    notice_text  text NOT NULL,        -- exact text shown
    language     text NOT NULL,        -- 'en', 'hi', 'ta' ...
    granted_at   timestamptz NOT NULL DEFAULT now(),
    withdrawn_at timestamptz
);

When someone withdraws, set withdrawn_at rather than deleting the row, and stop the processing.

Keep optional checkboxes unticked, and load scripts only when the visitor saves a choice:

javascript
function saveConsent() {
  const choices = {
    analytics: document.getElementById('consent-analytics').checked,
    marketing: document.getElementById('consent-marketing').checked,
  };
  document.cookie = 'consent=' + encodeURIComponent(JSON.stringify(choices)) +
    '; path=/; max-age=31536000; SameSite=Lax; Secure';
  fetch('/api/consent', {
    method: 'POST',
    headers: { 'Content-Type': 'application/json' },
    body: JSON.stringify(choices),
  });
  if (choices.analytics) loadAnalytics(); // never before this point
}

Export and erasure

Give signed-in users a way to download and erase their data. An Express example:

javascript
app.get('/api/me/export', requireLogin, async (req, res) => {
  const id = req.user.id;
  const data = {
    profile: await db.user.findUnique({ where: { id } }),
    orders: await db.order.findMany({ where: { userId: id } }),
    consents: await db.consent.findMany({ where: { userId: id } }),
  };
  res.attachment('my-data.json').json(data);
});

app.post('/api/me/erase', requireLogin, async (req, res) => {
  const id = req.user.id;
  // Anonymise; keep invoices only where another law requires it
  await db.user.update({
    where: { id },
    data: { email: `erased-${id}@invalid`, name: 'Erased user', phone: null, erasedAt: new Date() },
  });
  await db.order.updateMany({ where: { userId: id }, data: { customerName: 'Erased', customerEmail: null } });
  req.session.destroy(() => res.json({ ok: true }));
});

Retention and logs

Erase personal data when its purpose is served or consent is withdrawn, unless another law (tax or accounting, for example) requires you to keep it, and tell your processors to erase it too. Logs need a policy of their own:

  • The DPDP Rules require you to keep logs relevant to your processing for at least one year.
  • If CERT-In's directions apply to you, ICT system logs must be kept for 180 days within Indian jurisdiction.
  • Logs contain IP addresses, so restrict and record who can read them.

Run the clean-up as a scheduled job (cron) rather than by hand.

Security safeguards

Use HTTPS everywhere, hash passwords with bcrypt or Argon2, give least-privilege access with two-factor login for admins, keep software patched, and keep encrypted, tested backups (see automated backups with cron and rclone). Penalties go up to ₹250 crore for failing to take reasonable security safeguards.

7. Cross-border transfers and where you host

The DPDP Act does not require personal data to be stored in India. Transfers abroad are allowed except to countries the central government restricts by notification. Sector rules can be stricter; RBI rules on payment data are one example. Know where your data lives (server, backups, email, analytics, CRM, AI APIs, payments) and disclose it.

Domain India's live VPS page lists its VPS servers as located in Germany. For shared hosting, business email or any other service, ask support where your service is hosted before you write your privacy notice. On a VPS you have root access and control your own logs, retention and encryption; see essential security tips for your VPS. Shared hosting also keeps weekly account backups (see JetBackup backup and restore), so include them in your data map.

8. Privacy notice checklist

Cover who you are and how to contact you, what you collect and why, who you share it with, where it is stored, how long you keep it, how to exercise rights and complain to the Board, and the date it was last updated.

Do I need to register with the government under the DPDP Act?

No. The Act has no general registration requirement for Data Fiduciaries. The central government may designate some businesses as Significant Data Fiduciaries, which then have extra duties such as appointing a Data Protection Officer and running audits.

Must the consent notice be in English and a regional language?

No. The Act requires that the person can access the notice in English or in any language listed in the Eighth Schedule of the Constitution. Offering the languages your customers use is good practice.

Can I host my website outside India?

Yes. The DPDP Act allows transfers outside India except to countries the central government restricts by notification. Sector rules, such as RBI rules on payment data, can still require storage in India, and you should disclose where data is stored.

How quickly must I report a data breach?

Under the DPDP Rules you must inform the Data Protection Board and each affected person without delay, and send the Board a detailed report within 72 hours. Specified cyber incidents must also be reported to CERT-In within 6 hours.

What are the penalties?

The Act's schedule sets penalties up to ₹250 crore, the highest being for failing to take reasonable security safeguards. The Data Protection Board decides the amount in each case, up to that limit.

I use Cloudflare, Google Analytics or an AI API. Is that allowed?

Yes, as long as you disclose these processors in your privacy notice, bind them by contract, load tracking only after consent where it is needed, and the destination country is not restricted by the government.

Ready to check your own setup? Read the official texts on the MeitY and CERT-In websites, see the DPDP Act and CERT-In guide for the reporting and log rules, or open a support ticket to ask where your Domain India service is hosted.

Questions about where your data is hosted?

Ask our team where your service is hosted and what access you have to its logs and backups.

Open a support ticket

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
DPDP Act 2023 Compliance for Indian Websites | Domain India