Draft DPDP rules give Indian startups a first real look at compliance costs
The Ministry of Electronics and Information Technology's release of draft rules under the Digital Personal Data Protection Act in early 2025 has given India's startup ecosystem its first concrete sight of what operationalising the country's data-protection law will actually require. The DPDP Act itself was passed in August 2023 but remained largely aspirational until the rules specified the machinery of implementation - the consent-manager ecosystem, the data-fiduciary obligations, the breach-notification timelines and the penalties framework. For startups with digital-first products and large user data sets, the draft rules carry several categories of compliance obligation that involve meaningful product and engineering effort. The consent-manager concept - a regulated intermediary that manages user consent flows on behalf of data fiduciaries - is a novel construct that requires startups to either build native integrations with approved consent managers or rely on third-party infrastructure that does not yet fully exist at scale. The consent-audit trail requirements, which demand granular records of what data was collected, for what purpose and on what basis, represent a significant backend build for any company that currently manages consent through simple app-level toggles. Child-data provisions are among the most operationally demanding elements of the draft rules. Companies are required to obtain verifiable parental consent before processing data of users below eighteen years of age, a requirement that will affect every major consumer platform in India - from e-commerce to social media to gaming - and for which the verification mechanisms are technically non-trivial and potentially friction-adding in ways that could affect user acquisition rates. The penalties framework - which can reach up to two hundred and fifty crore rupees for specified categories of violation, with a separate five hundred crore rupee ceiling for failures of major significance - has concentrated legal teams' attention more than any other provision. Indian startups are unaccustomed to GDPR-equivalent fine exposure, and legal counsel are advising boards to begin the gap-analysis and remediation process well before the rules are finalised and enforcement begins. What to watch: the timeline for finalisation of the rules following the public consultation period, how the Data Protection Board of India is constituted and what enforcement posture it adopts in its early decisions, and whether major international investors treat DPDP compliance infrastructure as a pre-condition for late-stage funding in the way that SOC2 certifications became expected in the SaaS category. How international companies with India operations plan their compliance architecture will shape the competitive dynamics between domestic and multinational digital businesses operating in India.
Original source: Mint