PROGRAM ZERO 18-month live AI, LLM & full-stack programme · ₹5,999 for all 18 months · Starts 9 January 2027
Explore Program Zero →
Careers Ninza — business and startup leadership training
JOIN ZERO NINZA KIDS
JOIN ZERO NINZA KIDS
Careers Ninza
SOFTWARE 10 min read · Updated 24 September 2026

India’s DPDP Act for developers: what engineers need to know

The Digital Personal Data Protection Act, 2023 and the 2025 Rules, translated into engineering work: consent flows, withdrawal, erasure, breach notices, children’s data and user rights.

CN
Careers Ninza engineering faculty
Careers Ninza · Kolkata, India

India’s Digital Personal Data Protection Act, 2023 governs how apps collect and use personal data, and its Rules were notified on 14 November 2025 with an 18-month phased timeline. For developers it means building clear consent flows, easy withdrawal, purpose-limited collection, security safeguards, breach notices, erasure, parental consent for under-18s and user-rights requests.

Most articles on the DPDP Act are written for lawyers or compliance teams. This one is for the people who actually build the systems: what the law says, in plain language, and what it turns into in your code, database and product. It is not legal advice; the note at the end explains where to check the details.

What is the DPDP Act, and when does it apply?

Parliament enacted the DPDP Act on 11 August 2023, and the Government notified the DPDP Rules, 2025 on 14 November 2025, giving organisations an 18-month phased period to comply. The full text of the Act is on the Ministry of Electronics and IT website.

According to the Act, it applies to digital personal data processed in India, whether collected digitally or digitised later. It also applies to processing outside India if that processing is connected with offering goods or services to people in India. It does not apply to personal data used by an individual for personal or domestic purposes, or to data that the person has made publicly available themselves.

What are the key terms?

TermMeaningIn engineering terms
Data PrincipalThe individual the data is about (for a child, includes the parent)Your user
Data FiduciaryDecides why and how personal data is processedThe company that owns the app
Data ProcessorProcesses data on behalf of a Data FiduciaryYour cloud, email, analytics or support vendors
Consent ManagerA registered platform for giving, managing and withdrawing consentA possible integration for consent
Significant Data FiduciaryA fiduciary notified by the Government for extra obligationsLarger or higher-risk platforms
Data Protection BoardThe body that oversees compliance and inquires into breachesWho you notify and answer to

What does the Act say about consent?

Under section 6 of the Act, consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to the specified purpose. Users can withdraw consent at any time, and withdrawing must be as easy as giving it. The Rules require standalone, clear and simple consent notices explaining the specific purpose. The Act also requires that users can read the notice in English or any language in the Eighth Schedule of the Constitution.

What that means in your product:

—No pre-ticked boxes and no consent buried inside the terms of service.
—Separate, purpose-specific consent: agreeing to order delivery is not agreeing to marketing.
—A consent record for each user: purpose, notice version, timestamp and channel.
—A withdrawal option as easy to find as the sign-up button, which actually stops the processing downstream.
—Notices that can be shown in Indian languages, which means your notice text belongs in your localisation pipeline.

How long can you keep personal data?

The Act requires a Data Fiduciary to erase personal data when the user withdraws consent, or as soon as it is reasonable to assume the purpose is no longer being served, whichever is earlier, unless another law requires it to be retained. It must also make its Data Processors erase that data.

—Collect less. Every field you do not collect is a field you never have to protect or delete. Data minimisation is one of the Act’s core principles.
—Define retention per data type, and automate deletion with scheduled jobs rather than manual clean-ups.
—Propagate deletes to replicas, search indexes, analytics tools, logs and vendors, not just the main database.
—Keep what the law requires, such as financial records, separate and clearly labelled with the reason.

What happens if there is a data breach?

The Act requires reasonable security safeguards to prevent breaches, and, if a breach happens, intimation to both the Data Protection Board and each affected user. Under the Rules, users must be told in plain language what happened, the likely consequences, the steps taken, and whom to contact.

Penalties are significant. According to the Government’s explainer, failing to maintain reasonable security safeguards can attract a penalty of up to ₹250 crore; failing to notify a breach, or violating obligations relating to children, up to ₹200 crore each; and other violations up to ₹50 crore.

Engineering work that follows directly: encryption in transit and at rest, least-privilege access, secrets management, audit logs you can actually search, and an incident runbook that includes who drafts the user notice and how it is sent.

What are the rules for children’s data?

Under the Act, a child is anyone who has not completed 18 years. Before processing a child’s personal data, a Data Fiduciary must obtain verifiable consent from a parent or lawful guardian. It must not process data in ways likely to harm a child’s well-being, and must not undertake tracking, behavioural monitoring or targeted advertising directed at children. The Rules provide limited exemptions for purposes such as healthcare, education and real-time safety.

If you build for students, games, edtech or social features, this is likely the section that affects you most. Treat age checks, parental consent flows and switching off ad targeting for minors as product requirements, not afterthoughts.

What rights do users have, and how fast must you respond?

Users have the right to a summary of their personal data and how it is processed, to correction, completion, updating and erasure, to grievance redressal, and to nominate someone to exercise their rights in the event of death or incapacity. The Government says Data Fiduciaries must respond to such requests within a maximum of 90 days.

—Build self-service screens for viewing, editing and deleting profile data where you can.
—Provide a data export for access requests.
—Verify identity before acting on a request, so you do not hand one user’s data to another.
—Track each request with a ticket and a deadline, and show contact details for data queries, such as a designated officer or Data Protection Officer.

What extra duties do Significant Data Fiduciaries have?

The Government can notify some Data Fiduciaries as Significant, based on factors such as the volume and sensitivity of data. They must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments. The Rules add stronger due diligence for deployed technologies and government-specified restrictions on certain data, including localisation where required.

What about AI and machine learning?

The Act does not have a separate chapter on AI, but its principles apply to any system that processes personal data, including training data and prompts. Sensible engineering practices follow from it:

—Know whether your training or evaluation data contains personal data, and on what basis it was collected.
—Remove or mask personal data you do not need before training or indexing.
—Think about erasure: deleting a user from a database is easy, removing them from a trained model is not. Minimise first.
—Be careful about sending users’ personal data to third-party AI APIs; treat those providers as processors.

Handling personal data responsibly is part of building AI properly, not an afterthought. Program Zero, Careers Ninza’s 18-month live programme in AI, LLMs and full-stack development, teaches data handling and privacy alongside training and deploying the models themselves.

If you are building AI in Indian languages, the Act’s requirement for notices in scheduled languages connects with the work described in our guide to building AI for Indian languages.

A developer checklist

AreaWhat to build
ConsentPurpose-specific notices, consent records, one-click withdrawal
CollectionOnly the fields you need, documented by purpose
RetentionPer-type retention rules, automated deletion, delete propagation
SecurityEncryption, access control, secrets management, audit logs
BreachesDetection, runbook, Board and user notification templates
ChildrenAge handling, verifiable parental consent, no targeted ads or tracking
User rightsAccess, export, correction and erasure flows, with deadline tracking
VendorsKnow every processor, and make sure deletes reach them

For the wider security skills behind this checklist, see our overview of what a modern software development course should cover. Program Zero’s Phase 11 covers application, data and AI security, including OWASP Top 10, encryption, secrets management, data minimisation and privacy principles, before a hands-on security audit of your own capstone.

This article summarises the DPDP Act and official Government releases for developers and is not legal advice. The Rules phase in over 18 months from November 2025, so check the current Act and Rules on the Ministry of Electronics and IT website, and involve a qualified lawyer for decisions about your product.

Want to learn this live, with mentors?

Program Zero covers full-stack development, AI and security, including a hands-on security audit of your own capstone, over 18 months of live, mentor-led classes. ₹5,999 for all 18 months; the batch starts 9 January 2027.

Frequently asked questions

Does the DPDP Act apply to small apps and startups?+

Yes. The Act applies to any Data Fiduciary processing digital personal data in India, regardless of size, and to processing outside India connected with offering goods or services to people in India. Larger or higher-risk platforms notified as Significant Data Fiduciaries have extra duties such as audits and a Data Protection Officer. The Government describes the regime as facilitative for startups.

When do the DPDP Rules come into force?+

The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 and provide an 18-month phased compliance timeline, so different provisions take effect at different points within that period. Check the notified Rules on the Ministry of Electronics and IT website for which obligations apply when, and plan engineering work well ahead.

What is the difference between a Data Fiduciary and a Data Processor?+

A Data Fiduciary decides why and how personal data is processed, usually the company that owns the app. A Data Processor processes data on its behalf, such as a cloud host, email service or analytics tool. The Fiduciary remains responsible for compliance and must ensure its processors also erase data when required.

What are the penalties under the DPDP Act?+

According to the Government, failing to maintain reasonable security safeguards can attract a penalty of up to Rs 250 crore. Failing to notify the Board or affected users of a breach, or violating obligations relating to children, can each attract up to Rs 200 crore. Other violations by a Data Fiduciary can attract up to Rs 50 crore.

Related reading

We teach this, live

Every article here comes from something we teach. Sit in on a free masterclass and judge the mentors yourself.