BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

DPDP Compliance Checklist

Ask a general AI assistant about DPDP and it will answer you in GDPR. Answer a few real questions about how your product handles user data and get a readiness check against India's own Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, including the duties that never reach a company your size.

This tool is free. Prefer we just handle it for you?

Legal basis

ConceptIndia

DPDP Security Safeguards & Breach Notification

Rule 6 requires encryption, access controls, masking, monitoring, incident-response plans, and processor security clauses. Rule 7 requires breach notification to the Board and every affected Data Principal without undue delay, with a detailed report within 72 hours and no internal 'materiality' filter.

DefinitionIndia

Significant Data Fiduciary (SDF)

A Data Fiduciary specifically notified by the Central Government (S.10) — not a self-assessment by size or user count — that carries added obligations: an India-based DPO, annual DPIA and independent audit, and algorithmic-risk review.

ConceptIndia

DPDP Notice & Consent Standard

Notice must be standalone and precede consent (S.5, Rule 3); consent must be free, specific, informed, unconditional, and unambiguous via clear affirmative action (S.6) — DPDP has no GDPR-style 'legitimate interest' basis, and withdrawal must be as easy as giving consent.

LawIndia

Digital Personal Data Protection Rules, 2025

Operational rules under the DPDP Act, notified 13 November 2025. Translate the Act's principles into concrete detail: notice format, consent-manager registration, security controls, breach timelines, retention defaults, children's-data verification, and cross-border transfer conditions.

ConceptIndia

DPDP Retention & Erasure Rules

Personal data must be erased once its specified purpose is no longer served (S.8(7)) — purpose-tied, not 'as long as necessary.' Rule 8 layers a 48-hour pre-erasure notice, a one-year minimum log-retention floor, and a 3-year default erasure window for entities above defined scale thresholds.

ConceptIndia

DPDP Children's & Disability Data Rules

DPDP sets the 'child' threshold at under 18 (not COPPA's 13 or GDPR's 16), requires verifiable parental/guardian consent via an actual verification method, and absolutely bars tracking or targeted advertising directed at anyone flagged under 18 — a prohibition that cannot be unlocked even with parental consent.

LawIndia

Digital Personal Data Protection Act, 2023

India's cross-sector data protection statute — 44 sections across 9 chapters, Presidential assent 11 August 2023. Governs how Data Fiduciaries handle the digital personal data of Data Principals; phased commencement runs through 13 May 2027.

ConceptIndia

DPDP Section 17(3) Startup Exemption — Not Yet Notified

S.17(3) lets the Central Government exempt DPIIT-recognised startups from notice, accuracy, erasure, and Significant Data Fiduciary obligations — but as of the last verification for BuildWright's internal DPDP checklist, that notification has not been issued. DPIIT recognition alone changes nothing under DPDP today.

DefinitionIndia

Data Principal (DPDP Act)

The individual to whom the personal data relates — the DPDP Act's term for the person holding rights under the Act (consent, access, correction, erasure, grievance, nomination).

DefinitionIndia

Data Fiduciary (DPDP Act)

Any entity that, alone or with others, determines the purpose and means of processing personal data — the DPDP Act's term for the party bearing compliance obligations (S.2(i)).

ConceptIndia

DPDP Penalty Framework (Section 33)

All DPDP penalties are purely monetary, imposed by the Data Protection Board after inquiry — no criminal sanctions. Range: ₹10,000 (Data Principal duty breach) up to ₹250 crore (security-safeguard failure leading to a breach), with up to a 2x enhancement for serious/repeat violations.

Learn the details

Guides that walk through every step.

Guide

buildwright.co.in

What Your Website Legally Needs in India: Terms, Privacy, Refunds, and the E-Commerce Rules

A live Indian website needs Terms of Use, a DPDP-compliant Privacy Policy, and a Refund Policy if it takes payment. Selling to consumers pulls in the Consumer Protection (E-Commerce) Rules 2020, with a B2B exclusion most founders get wrong.

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.