Fact
As India’s Digital Personal Data Protection (DPDP) Act compliance deadline approaches, startups are rushing to understand their obligations. A survey of 550 ecosystem participants, including 350 startups, 100 VC firms, and 100 incubators, found that 44% identified data governance and digital trust regulations as their primary regulatory concern, per Mint. Legal experts cite confusion over exemptions, data governance requirements, AI use, and vendor management as driving a surge in compliance requests.
Interpretation
D2C brands are among the most exposed entities under DPDP. They collect personal data, name, address, payment information, purchase history, behavioral data, at scale through their own websites, apps, and third-party tools like CRM, marketing automation, and logistics partners. Any brand running email marketing, retargeting, WhatsApp campaigns, or loyalty programs needs to verify whether their data collection, consent, and deletion practices meet DPDP requirements. The 44% regulatory concern figure is especially notable: data governance ranking above GST, labor law, and platform fee disputes signals that the compliance burden is both real and underestimated by most founders.
Action
If you have not done a data audit in the last six months, do one now. Map every point where customer data is collected, website forms, checkout, app, WhatsApp, every vendor that touches that data (CRM, ESP, logistics partner), and every consent flow. The DPDP framework requires explicit, granular consent for most personal data uses. If your privacy policy or consent flow predates 2023, it is almost certainly non-compliant.
Watch Next
When the DPDP rules are formally notified by the central government, as opposed to the Act itself which is already passed. The rules notification triggers the formal compliance clock and will define the specific obligations, exemptions, and penalties that businesses need to operationalise.