India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 set out how any business that collects personal data online must handle it. This guide turns the law into practical steps for a website or app: the consent notice, user rights, breach handling, retention and the code to support them.
If your website collects names, emails, phone numbers or other personal data, the DPDP Act almost certainly applies to you. You need a clear notice, valid consent (or a permitted legitimate use), reasonable security, a breach plan, a way for people to exercise their rights, and a deletion schedule. Most business obligations are scheduled to apply from May 2027. The Act does not require data to be stored in India.
This article summarises public law as of September 2026 and gives technical examples. It is not legal advice and does not describe how any particular business, including Domain India, complies. Read the official texts and consult a qualified lawyer for your situation.
1. What the DPDP Act covers
The Act received assent in August 2023. The DPDP Rules, 2025 were notified in November 2025 with staggered dates: the Data Protection Board provisions applied at once, the consent manager framework is scheduled for November 2026, and most obligations on businesses for May 2027. Dates can change, so check MeitY's data protection page.
It applies to digital personal data: any data about an identifiable person, such as a name, email address, phone number, location, IP address or login history.
- Data Fiduciary: you, the business that decides why and how data is processed.
- Data Processor: a service that processes data for you, such as your hosting provider, email service, CRM or payment gateway. You remain responsible for choosing and binding them by contract.
- Data Principal: the person the data is about.
2. Does it apply to your website?
| Situation | Does the Act apply? |
|---|---|
| Indian business with Indian customers | Yes |
| Indian business serving foreign customers | Usually yes, because processing happens in India (some outsourcing contracts are exempt) |
| Foreign business offering goods or services to people in India | Yes |
| Blog or community site with sign-ups, comments or a newsletter | Likely yes; purely personal or domestic use by an individual is exempt |
| Static site with no forms | Limited, but server logs still hold IP addresses |
A single contact form collects personal data, so most business websites are in scope.
3. Notice and consent
Before or when you ask for consent, give a notice that states what data you collect and why, how the person can withdraw consent and exercise their rights, and how to complain to the Data Protection Board. The person must be able to read it in English or in any language listed in the Eighth Schedule of the Constitution. Offering the languages your customers actually use is good practice, but the Act does not require a regional language in addition to English.
Valid consent is free, specific, informed, unconditional and unambiguous, given by a clear action. In practice:
- Use unticked checkboxes. A pre-ticked box is not a clear action.
- Ask for each purpose separately (order updates, marketing, analytics).
- Make withdrawing as easy as giving consent.
- Load analytics and marketing tags only after the visitor opts in.
Consent is not the only ground: some "legitimate uses" in the Act, such as data a person voluntarily gives you for a specific purpose, do not need separate consent.
A short example notice:
We use your email address to send updates about your order.
You can withdraw consent or ask us to correct or delete your data
at [email protected]. If you are not satisfied with our reply,
you can complain to the Data Protection Board of India.
[ ] I agree to receive order updates by email.4. Rights you must honour
People can ask you for:
- a summary of the personal data you hold and who you shared it with;
- correction, completion, updating or erasure of their data;
- grievance redressal;
- nomination of someone to act for them in case of death or incapacity.
Publish how to make a request, and publish the business contact details of a person who can answer questions about your processing (a Data Protection Officer, if you have one). The Rules set an outer limit of 90 days for resolving grievances; aim for much faster.
5. Breaches, children and larger businesses
A breach can also be a cyber incident that CERT-In's 2022 directions require you to report within 6 hours. The two regimes are separate; see the DPDP Act and CERT-In guide for both.
6. Technical implementation
Record every consent
Store what the person saw and when, so you can prove consent later:
CREATE TABLE consent_records (
id bigserial PRIMARY KEY,
user_id uuid REFERENCES users(id),
purpose text NOT NULL, -- 'order_updates', 'marketing', 'analytics'
notice_text text NOT NULL, -- exact text shown
language text NOT NULL, -- 'en', 'hi', 'ta' ...
granted_at timestamptz NOT NULL DEFAULT now(),
withdrawn_at timestamptz
);When someone withdraws, set withdrawn_at rather than deleting the row, and stop the processing.
Load tags only after consent
Keep optional checkboxes unticked, and load scripts only when the visitor saves a choice:
function saveConsent() {
const choices = {
analytics: document.getElementById('consent-analytics').checked,
marketing: document.getElementById('consent-marketing').checked,
};
document.cookie = 'consent=' + encodeURIComponent(JSON.stringify(choices)) +
'; path=/; max-age=31536000; SameSite=Lax; Secure';
fetch('/api/consent', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify(choices),
});
if (choices.analytics) loadAnalytics(); // never before this point
}Export and erasure
Give signed-in users a way to download and erase their data. An Express example:
app.get('/api/me/export', requireLogin, async (req, res) => {
const id = req.user.id;
const data = {
profile: await db.user.findUnique({ where: { id } }),
orders: await db.order.findMany({ where: { userId: id } }),
consents: await db.consent.findMany({ where: { userId: id } }),
};
res.attachment('my-data.json').json(data);
});
app.post('/api/me/erase', requireLogin, async (req, res) => {
const id = req.user.id;
// Anonymise; keep invoices only where another law requires it
await db.user.update({
where: { id },
data: { email: `erased-${id}@invalid`, name: 'Erased user', phone: null, erasedAt: new Date() },
});
await db.order.updateMany({ where: { userId: id }, data: { customerName: 'Erased', customerEmail: null } });
req.session.destroy(() => res.json({ ok: true }));
});Retention and logs
Erase personal data when its purpose is served or consent is withdrawn, unless another law (tax or accounting, for example) requires you to keep it, and tell your processors to erase it too. Logs need a policy of their own:
- The DPDP Rules require you to keep logs relevant to your processing for at least one year.
- If CERT-In's directions apply to you, ICT system logs must be kept for 180 days within Indian jurisdiction.
- Logs contain IP addresses, so restrict and record who can read them.
Run the clean-up as a scheduled job (cron) rather than by hand.
Security safeguards
Use HTTPS everywhere, hash passwords with bcrypt or Argon2, give least-privilege access with two-factor login for admins, keep software patched, and keep encrypted, tested backups (see automated backups with cron and rclone). Penalties go up to ₹250 crore for failing to take reasonable security safeguards.
7. Cross-border transfers and where you host
The DPDP Act does not require personal data to be stored in India. Transfers abroad are allowed except to countries the central government restricts by notification. Sector rules can be stricter; RBI rules on payment data are one example. Know where your data lives (server, backups, email, analytics, CRM, AI APIs, payments) and disclose it.
Domain India's live VPS page lists its VPS servers as located in Germany. For shared hosting, business email or any other service, ask support where your service is hosted before you write your privacy notice. On a VPS you have root access and control your own logs, retention and encryption; see essential security tips for your VPS. Shared hosting also keeps weekly account backups (see JetBackup backup and restore), so include them in your data map.
8. Privacy notice checklist
Cover who you are and how to contact you, what you collect and why, who you share it with, where it is stored, how long you keep it, how to exercise rights and complain to the Board, and the date it was last updated.
Do I need to register with the government under the DPDP Act?
No. The Act has no general registration requirement for Data Fiduciaries. The central government may designate some businesses as Significant Data Fiduciaries, which then have extra duties such as appointing a Data Protection Officer and running audits.
Must the consent notice be in English and a regional language?
No. The Act requires that the person can access the notice in English or in any language listed in the Eighth Schedule of the Constitution. Offering the languages your customers use is good practice.
Can I host my website outside India?
Yes. The DPDP Act allows transfers outside India except to countries the central government restricts by notification. Sector rules, such as RBI rules on payment data, can still require storage in India, and you should disclose where data is stored.
How quickly must I report a data breach?
Under the DPDP Rules you must inform the Data Protection Board and each affected person without delay, and send the Board a detailed report within 72 hours. Specified cyber incidents must also be reported to CERT-In within 6 hours.
What are the penalties?
The Act's schedule sets penalties up to ₹250 crore, the highest being for failing to take reasonable security safeguards. The Data Protection Board decides the amount in each case, up to that limit.
I use Cloudflare, Google Analytics or an AI API. Is that allowed?
Yes, as long as you disclose these processors in your privacy notice, bind them by contract, load tracking only after consent where it is needed, and the destination country is not restricted by the government.
Ready to check your own setup? Read the official texts on the MeitY and CERT-In websites, see the DPDP Act and CERT-In guide for the reporting and log rules, or open a support ticket to ask where your Domain India service is hosted.
Ask our team where your service is hosted and what access you have to its logs and backups.
Open a support ticket