Does the DPDP Act apply to my startup if we are small or early-stage?
Yes. The DPDP Act applies to any entity — regardless of size or revenue — that processes personal data of individuals in India. There is no small-business exemption. However, the government may notify different categories of Data Fiduciaries with scaled obligations, so it is worth tracking rules as they are released.
When does enforcement actually begin?
The DPDP Rules 2025 were notified in November 2025. Core enforcement is expected to begin on 13 May 2027. However, specific obligations may have earlier compliance deadlines, and a complaint can be filed against you from the date the relevant provision comes into force.
What is a Data Fiduciary, and am I one?
A Data Fiduciary is any person or entity that determines the purpose and means of processing personal data. If your organisation decides why and how personal data is collected and used — from customers, employees, or users — you are a Data Fiduciary and the DPDP Act's obligations apply to you directly.
Do I need to appoint a Data Protection Officer?
All Data Fiduciaries must designate an accountability owner for data protection. Significant Data Fiduciaries — a category to be formally notified by the government — will have additional requirements including a formal DPO, independent audits, and data protection impact assessments. For most startups, appointing an internal owner with a clear mandate is the starting point.
Is this tool's result legally sufficient for compliance sign-off?
No — and it does not claim to be. PrivPath is a self-assessment tool designed to help you understand your obligations and identify gaps. It is not a substitute for legal advice or a formal compliance audit. Use the results to brief a lawyer or compliance professional, or to structure your internal compliance programme.
What should I do after completing the assessment?
Start with the critical gaps — categories marked red in your results. Each gap comes with a specific action. Prioritise: (1) appointing a compliance owner, (2) drafting a privacy notice, (3) conducting a data inventory, and (4) building a consent mechanism. Then engage a legal professional to review your documentation before enforcement begins.