Back to Blog
Security

DPDP Act Compliance Checklist: What Indian Businesses Must Fix in Their Software by 2026

Priya Sharma

CTO

8 min read1.5K viewsJul 12, 2026

With the Digital Personal Data Protection Act's rules now taking effect, Indian businesses have a narrowing window to fix consent flows, data retention, and breach reporting in their software. A practical, engineering-focused compliance checklist.

The Digital Personal Data Protection Act, 2023 (DPDP Act) marks India's first comprehensive, cross-sector data protection law, and with its rules now progressively coming into force, Indian businesses — and any global company processing Indian users' data — have a narrowing window to move from policy intent to working software. Unlike some earlier voluntary guidance, the DPDP Act carries real financial penalties, reaching up to ₹250 crore for serious breaches of data protection obligations, which has moved this firmly onto CTO and product leadership agendas.

Consent Under DPDP: Stricter Than Most Existing Implementations

The DPDP Act requires consent to be free, specific, informed, unconditional and unambiguous, communicated in clear and plain language, with an option in English and each language listed in the Eighth Schedule of the Constitution. For most Indian software products, this means the existing 'accept our terms' checkbox pattern doesn't meet the bar.

  • Purpose-specific consent — bundled, all-or-nothing consent for multiple unrelated purposes is not compliant; each purpose needs its own clear consent capture.
  • Easy withdrawal — withdrawing consent must be as easy as giving it, which means a genuine self-service mechanism, not a support ticket.
  • Consent Manager compatibility — the Act introduces the concept of registered Consent Managers as intermediaries; larger platforms should architect for interoperability with this model.
  • Notice requirements — a clear notice, independent of the privacy policy, describing what personal data is collected and for what purpose, before or at the time of consent.

Data Principal Rights Your Software Must Support

  • Right to access a summary of personal data processed and the processing activities undertaken.
  • Right to correction and erasure of personal data.
  • Right to grievance redressal, with a defined, accessible process — not just an email address that goes unanswered.
  • Right to nominate another individual to exercise these rights on the data principal's behalf in case of death or incapacity — a provision distinct from most global privacy laws.

Significant Data Fiduciaries: A Higher Bar

Businesses notified as Significant Data Fiduciaries (based on volume and sensitivity of data processed, among other factors) face additional obligations: appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, and independent data audits. Growing platforms should model whether their trajectory puts them into this category before it becomes an urgent, reactive project.

The businesses handling DPDP well aren't the ones treating it as a one-time legal review. They've built consent, access, and deletion as product features — because under this Act, that's exactly what they are.

Priya Sharma, CTO, Alliance Corporation

Breach Notification: A Tighter Obligation Than Many Expect

Unlike some frameworks with a harm-based threshold, the DPDP Act requires notification to the Data Protection Board and affected data principals for personal data breaches without the same materiality carve-outs — making breach detection and reporting readiness a baseline requirement, not a judgment call made after the fact.

A Practical Engineering Checklist

  • Rebuild consent capture as purpose-specific, unbundled, and available in required languages.
  • Build a genuine self-service consent withdrawal and data access/correction/erasure flow — not a manual, support-driven process.
  • Implement data retention limits tied to the specified purpose, with automated deletion once the purpose is fulfilled.
  • Map all cross-border data transfers and monitor for any country-specific restrictions the government notifies.
  • Establish breach detection and a notification workflow that can meet the Act's reporting obligations without manual reconstruction of what happened.
  • Assess whether your data volume and category profile could classify you as a Significant Data Fiduciary, and prepare accordingly.

Alliance Corporation builds DPDP-ready custom software and consent management systems for Indian businesses. Talk to our team about a DPDP compliance architecture review.

#DPDP Act#Data Protection#Compliance#Consent Management

Priya Sharma

CTO · Alliance Corporation

Part of the Alliance Corporation leadership team, shaping technology strategy across AI, cloud and enterprise software for clients in 50+ countries.

DPDP Act Compliance Checklist: What Indian Businesses Must Fix in Their Software by 2026 | Alliance Corporation Blog