Most Indian startups can reach DPDP Act compliance for between INR 1 lakh and INR 8 lakh in external advisory cost, depending on sector, and the cheapest cohort, B2B software, sits at INR 1.5 to 3 lakh. The figure balloons only when a programme imports GDPR artefacts the Act does not require: data flow maps, a Record of Processing Activities, a Data Protection Officer, and Significant Data Fiduciary obligations that apply only after government notification. This guide sets out, sector by sector and requirement by requirement, what the Act actually asks of a startup, what it costs to do economically, and what to refuse to pay for.
A sector by sector guide to spending only what the law actually requires
Since the Digital Personal Data Protection Rules were notified on 13 November 2025, a great deal of advice has landed on Indian founders. Much of it is imported. It arrives in the shape of the GDPR, carrying data flow maps, Records of Processing Activities, Data Protection Officers and Data Protection Impact Assessments, and it arrives with a price tag that assumes every one of these is compulsory.
Most of them are not.
The Digital Personal Data Protection Act, 2023 is a shorter and considerably leaner statute than its European counterpart, and it makes different choices. It has no special category of sensitive personal data. It has no equivalent to Article 30 of the GDPR, which means no Record of Processing Activities. It imposes no general obligation to appoint a Data Protection Officer. It permits cross border transfer by default rather than by exception. It confines the heaviest obligations, being the annual audit, the Data Protection Impact Assessment and the mandatory India based DPO, to Significant Data Fiduciaries, and that status arises only when the Central Government notifies you as one under Section 10(1). It is not self assessed, and it is not triggered by the fact that you use artificial intelligence.
For a startup, the gap between building to the Act and building to an imported template is not cosmetic. It is routinely the difference between a two lakh engagement and a twenty lakh one, and the expensive version is often the less compliant of the two, because effort spent producing artefacts that no Indian regulator is empowered to call for is effort not spent on the two failures that carry the largest penalties.
That point should drive every rupee of the budget, so it is worth stating at the outset. The Schedule to the Act sets the maximum penalty for failure to take reasonable security safeguards at INR 250 crore, and for failure to give notice of a personal data breach at INR 200 crore. Obligations concerning children sit at INR 200 crore. Failure to meet the additional obligations of a Significant Data Fiduciary sits at INR 150 crore. Everything else, including every failure of notice and consent, falls into the residual head at INR 50 crore.
The statute is telling you where it intends to hurt. It is not the paperwork.
The operative obligations commence on 13 May 2027. What follows is a way of getting there without spending money you do not need to spend.
Part One: The three questions that fix your cost before you spend anything
Almost the entire cost variance between one startup and another is settled by three questions, asked before any consultant is engaged.
Are you a Data Fiduciary, a Data Processor, or both, and for which data?
A Data Fiduciary determines the purpose and means of processing. A Data Processor processes on another’s instruction. Under the Act, the substantive obligations of notice, consent, rights and breach reporting attach to the Fiduciary. The Processor’s position is contractual, arising under Section 8(2), which requires that a Fiduciary engage a Processor only under a valid contract.
Most B2B startups are Fiduciaries only in respect of their own corporate data, being human resources, finance, marketing and the website, and Processors in respect of everything flowing through the product. This single distinction typically removes seventy to eighty percent of what an imported scoping exercise would have covered. The product estate does not need its own consent architecture if the customer is the Fiduciary and the customer’s consent architecture governs.
Get this wrong in the direction of caution and you will pay to build a consent layer for data you were never obliged to obtain consent for.
Do you process the personal data of children?
This is the sharpest cost line in the Act. Section 9 requires verifiable consent of a parent or lawful guardian before processing the personal data of anyone under eighteen, and Section 9(3) prohibits tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 prescribes how that verifiable consent is to be obtained. The penalty head is INR 200 crore.
If your product is used by minors, whether by design or in practice, this is where your budget goes, and it is money well spent. If it is not, you can pass over a large part of what is written about DPDP for consumer businesses.
Note also that Rule 12, read with the Fourth Schedule, carves out clinical establishments, health professionals, educational institutions and childcare providers from parts of Section 9 for specified purposes. Healthtech and edtech founders frequently do not know this and pay to solve a problem the Rules have already partly solved for them.
Which of your retention periods are already fixed by another statute or regulator?
Section 8(7) requires erasure once the specified purpose is no longer being served, unless retention is necessary for compliance with any law. The fixed three year erasure clock under Rule 8, read with the Third Schedule, applies only to e-commerce entities with two crore or more registered users, online gaming intermediaries with fifty lakh or more, and social media intermediaries with two crore or more. Almost no startup is in that class.
So retention is not handed to you by the DPDP Act. It is handed to you by the Companies Act, by the income tax legislation, by labour and social security law, and, if you are regulated, by your sector regulator. For a regulated fintech, most of the retention question is already answered and costs nothing to determine. For an unregulated consumer app, the retention question is a business decision that no external adviser can take for you.
Part Two: DPDP Compliance cost Sector by sector
The table below sets the shape. The narrative that follows explains it.
| Sector | Where personal data actually sits | Principal cost driver | Safe to defer or skip | Indicative external advisory cost for the baseline |
|---|---|---|---|---|
| B2B SaaS, enterprise tech, AI and data platforms | HR, finance, website, marketing. Product side is processor work | Contractual: data processing agreements upstream and downstream | Product side consent architecture, RoPA, DPO | INR 1.5 to 3 lakh |
| Consumer apps, D2C and e-commerce | Everywhere, and at volume | Consent architecture, records of consent, withdrawal plumbing | Third Schedule erasure clock unless above threshold, SDF build | INR 3 to 7 lakh |
| Fintech, lending and insurtech | Customer onboarding, KYC, collections, the agent network | Processor contracting across a wide third party ecosystem | Retention analysis, largely pre answered by the regulator | INR 4 to 8 lakh |
| Healthtech and edtech | Patient or learner records, guardian data | Children’s data and verifiable consent, where applicable | Parts of Section 9, where the Fourth Schedule exemption applies | INR 3 to 8 lakh |
| Marketplaces, gig and logistics platforms | Two populations: customers and gig workers | Two notice sets, high volume of rights requests | Sensitive data classification, which the Act does not have | INR 3 to 6 lakh |
| Deeptech, hardware, B2G and infrastructure | HR and finance, and little else | Almost nothing. The risk is over buying | Most of it | INR 1 to 2 lakh |
B2B SaaS, enterprise tech, AI and data platforms
This is the cheapest cohort to bring into compliance and the one most consistently oversold to.
Your own fiduciary footprint is the corporate one: recruitment, the employee lifecycle, finance, the website and outbound marketing. That is four to six privacy notices, one consent layer on the website, one rights procedure and one breach procedure. The product estate, where you process your customers’ end user data on their instruction, is processor territory. The obligation there is contractual, not notice based.
Your real cost driver is contracting in both directions. Upstream, your enterprise customers will require a data processing agreement, and increasingly a DPDP specific one rather than a GDPR clone. Downstream, you need the same with your cloud host, your subprocessors, your analytics vendors and your support tooling. One well drafted template, drafted to Section 8(2) and usable in both directions, does the work of a dozen bespoke negotiations.
What to refuse to pay for: enterprise wide data flow mapping across the product estate, a Record of Processing Activities, and any scoping that treats your AI workloads as a trigger for Significant Data Fiduciary status. None of these is a requirement of Indian law, and the last is a misreading of Section 10.
Consumer apps, D2C and e-commerce
Here consent genuinely is the cost centre, because you are collecting directly, at volume, for multiple purposes, and you want to run marketing and analytics on top.
The economical build has three parts. First, be ruthless about which processing actually needs consent. Section 7 sets out legitimate uses that do not, and a surprising amount of operational processing sits there. Second, build one consent layer with purpose level granularity rather than a consent prompt per feature. Third, and this is where most consumer startups underspend, build the consent record and the withdrawal path properly. The Act requires that withdrawing consent be as easy as giving it, and a consent you cannot evidence is a consent you did not obtain.
Do not buy a consent management platform in year one unless your volume genuinely requires it. A well specified in house consent layer with a proper record table is cheaper, and the Rules do not require you to use a registered Consent Manager. Rule 4 governs entities that wish to be Consent Managers. It does not oblige you to engage one.
The Third Schedule erasure clock does not bite until two crore registered users for e-commerce. Build your architecture so that it can be switched on later, and do not pay to operate it now.
Fintech, lending and insurtech
The counterintuitive point about regulated financial services is that the most expensive part of DPDP for everyone else, being retention, is close to free for you. The RBI master directions, the PMLA record keeping requirements, SEBI and IRDAI have already fixed most of your retention periods. Your retention schedule is largely a transcription exercise.
Your cost sits elsewhere: in the third party ecosystem. Direct selling agents, collection agents, lending service providers, KYC vendors, credit bureaus, account aggregator flows. Each is a processor or a co fiduciary, and each needs to be contracted, instructed and, where the relationship is loose, tightened. That is where the effort goes.
The second cost is reconciling the erasure obligation under Section 8(7) with regulatory retention. The answer is straightforward in law, because Section 8(7) yields to retention required by law, but it needs to be documented once, clearly, so that your teams stop treating it as an unresolved conflict.
Where the sector overspends: buying a privacy tooling stack that duplicates the compliance tooling already in place for the sector regulator.
Healthtech and edtech
These are the two sectors where a real spend is justified, and also the two where the exemptions are most often missed.
If your users include minors, Section 9 and Rule 10 apply, and you must build verifiable guardian consent and switch off behavioural tracking and targeted advertising for those users. That is engineering work, not documentation work, and it should be budgeted as such.
But read Rule 12 with the Fourth Schedule before you budget. Clinical establishments, health professionals, educational institutions and childcare providers are exempted from parts of Section 9 for specified purposes connected to the delivery of health services, education and safety. An edtech delivering instruction to a school’s enrolled students sits differently from a consumer learning app selling directly to children. The two should not be priced the same.
Note also, and this genuinely saves money: the DPDP Act has no category of sensitive personal data. Health records and biometric data are personal data, treated alike. The elaborate data classification exercises inherited from the SPDI Rules and from the GDPR are, under DPDP, largely optional. They may still be worth doing for a security programme. They are not a compliance requirement.
Marketplaces, gig and logistics platforms
The distinguishing feature is that you have two populations with different relationships to you: customers on one side, and delivery partners, drivers or sellers on the other. You need two notice architectures, and the gig side often looks more like an employment relationship than the contracts suggest.
Your second cost driver is volume of rights requests. High churn populations generate access and erasure requests at a rate a single inbox will not survive. Build the procedure properly, name an owner, and set internal service standards below the statutory response period. This is process design, not software.
Deeptech, hardware, B2G and infrastructure
Many startups in this cohort process almost no personal data beyond their own employees, their finance function and a contact form. The correct budget is small, and the correct posture is to document that position clearly so that you can answer a customer questionnaire without commissioning a programme.
The risk here is not non compliance. It is buying a compliance programme sized for a consumer business.
Part Three: Requirement by requirement, and how to do each economically
| Requirement | Statutory anchor | The economical build | What is commonly oversold |
|---|---|---|---|
| Notice | Section 5, Rule 3 | One notice architecture, four to six notices, reused across collection points | A separate notice per form or per system |
| Consent | Sections 6 and 7, Rule 3 | Consent only where Section 7 does not already provide a legitimate use | Consent for employment processing, which Section 7 covers |
| Consent Manager | Rule 4, First Schedule | Not required. Registration governs those who wish to be Consent Managers | A paid CMP subscription in year one |
| Data principal rights | Sections 11 to 14, Rule 14 | One published route, one named owner, one template set, one register | Rights request software before volume justifies it |
| Security safeguards | Section 8(5), Rule 6 | Map your existing cloud controls to Rule 6 and close the gaps | A new security stack. Most of Rule 6 is already in your cloud configuration |
| Breach reporting | Section 8(6), Rule 7 | Fold into existing incident response. Rehearse it once | A standalone breach platform |
| Retention and erasure | Section 8(7), Rule 8, Third Schedule | Statutory floor plus a documented business decision | An automated retention engine, and consultant set periods where law is silent |
| Processor contracting | Section 8(2) | One template, used in both directions | Bespoke negotiation with every vendor |
| Children’s data | Section 9, Rules 10 and 12, Fourth Schedule | Build it properly if it applies. Check the exemption first | Building it when the Fourth Schedule exempts you |
| Contact person | Section 8(9), Rule 9 | Publish a named contact. This is not a DPO | Hiring a Data Protection Officer you are not required to have |
| Significant Data Fiduciary obligations | Section 10, Rule 13 | Do nothing until notified | DPIAs and annual audits for an entity that has not been designated |
| Cross border transfer | Section 16, Rule 15 | Permitted by default, subject to government restriction | Standard contractual clause machinery imported from the GDPR |
Three of these repay a closer look, because they are where the largest savings sit.
Consent, and the legitimate uses you are ignoring. Section 7 sets out uses for which personal data may be processed without consent. Among them is processing for the purposes of employment, and for safeguarding the employer from loss or liability. This means the great majority of your human resources processing does not run on consent at all. Startups that build a consent capture and withdrawal mechanism for employee data are solving a problem the statute has already solved, and creating an operational liability in the process, because consent once sought can be withdrawn.
Security safeguards, where the money should go. Rule 6 requires encryption, masking or tokenisation, access control, retention of logs for at least one year with monitoring, and business continuity measures. This is the INR 250 crore penalty head. For most startups on a modern cloud stack, the controls largely exist and are simply not documented or not consistently applied. The economical route is a mapping exercise against Rule 6 followed by targeted remediation, not a procurement cycle.
Breach readiness, the second largest penalty head. Rule 7 requires intimation to affected individuals without delay, and a two stage report to the Board: an initial intimation without delay, and a detailed report within seventy two hours. The cost of getting this wrong is INR 200 crore. The cost of getting it right is a procedure, a named decision maker, a set of templates and one rehearsal. It is among the cheapest things in the Act to do properly and among the most expensive to have neglected.
Part Four: Sequencing to 13 May 2027
Compliance spend fails when it arrives all at once. Three tranches work better, and they can be spread across two financial years.
Tranche one, now to the end of this financial year. Establish the position. Determine where you are Fiduciary and where you are Processor. Identify your collection points in the corporate functions and, if you are consumer facing, in the product. Draft the notice suite. Publish a contact person under Rule 9. This is the cheapest tranche and it is the one that determines whether the next two are correctly sized.
Tranche two, the following six months. Build the consent layer if you need one. Stand up the rights procedure and the breach procedure, and rehearse the latter. Issue your data processing agreement template and begin papering the vendor estate. Complete the Rule 6 mapping and remediate.
Tranche three, the final quarter before commencement. Test. Run a rights request through your own process end to end. Run a breach scenario. Close the retention decisions your business owners have been deferring. Refresh the notices for anything that changed.
Anything an adviser proposes that does not sit in one of these three tranches deserves a question about which provision of the Act it answers.
Part Five: The five most expensive mistakes
Building a Record of Processing Activities because the deck said so. There is no such obligation in the Act or the Rules. Build a collection point record instead, sized to your actual footprint. It achieves the same operational purpose at a fraction of the cost, and no regulator can demand the longer artefact.
Treating AI processing as a route to Significant Data Fiduciary status. Designation is by Central Government notification under Section 10(1), on stated factors. Volume of processing alone does not do it, and the use of machine learning certainly does not. Until you are notified, Rule 13 does not apply to you, and building DPIAs and annual audits against it is voluntary expenditure.
Hiring a Data Protection Officer you are not required to have. Section 8(9) and Rule 9 require you to publish the contact details of a person able to answer questions about your processing. The mandatory, India based, board reporting DPO is a Significant Data Fiduciary obligation under Section 10(2). For most startups, a named senior person with a published address discharges the requirement.
Running employee data on consent. Section 7 provides for employment purposes. Consent creates a withdrawal right you do not want in an employment context, and it invites a dispute you need not have.
Letting a consultant set your retention periods where the law is silent. Where a statute fixes the period, take it. Where it does not, the decision belongs to the business owner who understands why the record is held, and the risk of over retention belongs to the company. An adviser can and should tell you the statutory floor and tell you plainly when a practice is not defensible. The most common example is the retention of candidate resumes long after the recruitment purpose has been served, which is not supported by the Act and which almost every human resources function resists giving up. But an adviser cannot take the commercial decision for you, and any adviser who offers to should be asked on what basis.
Closing
The DPDP Act is a proportionate statute. It asks for notice that is clear, consent where consent is the basis, security that is reasonable, breach reporting that is prompt, rights that are honoured, and erasure when the purpose is spent. It does not ask for the apparatus that has grown up around European data protection, and an Indian startup that buys that apparatus is paying for insurance against a risk that does not exist while leaving the two largest penalty heads unaddressed.
Scope to the statute. Spend where the penalties are. Sequence the rest. And if anyone offers you a DPDP certificate at the end of it, read this first.
Frequently asked questions
No. There is no equivalent of GDPR Article 30 in the Act or the Rules. Section 8(1) requires a Data Fiduciary to be able to demonstrate compliance, which a collection point record sized to your footprint achieves at a fraction of the cost.
No. Significant Data Fiduciary status arises only by Central Government notification under Section 10(1). Until an entity is notified, the Rule 13 obligations of annual DPIA, audit and an India based DPO do not apply.
Not unless you are a Significant Data Fiduciary. Section 8(9) and Rule 9 require you to publish the contact details of a person able to answer questions about your processing, which a named senior person discharges.
Generally no. Section 7 permits processing for employment purposes without consent. Running employee data on consent creates a withdrawal right you do not want in an employment relationship.
No. Rule 4 governs entities that wish to register as Consent Managers. It does not oblige a Data Fiduciary to engage one, and an in house consent layer with a proper record is usually cheaper in year one.
The operative obligations on notice, consent, security safeguards, data principal rights and breach reporting commence on 13 May 2027. Rules were notified on 13 November 2025.
Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 16 September 2026. It is not legal advice. Indicative cost figures reflect market observation and will vary with scope, footprint and internal readiness. Last reviewed 16 September 2026.