What the DPDPA expects from a website or app
The DPDPA applies to personal data in digital form. A website or app collects personal data through forms, accounts, cookies, analytics tags, advertising pixels, chat widgets and software development kits (SDKs). Each of these is processing under the Act when the data relates to an identifiable person.
The organisation that runs the site and decides why the data is collected is the Data Fiduciary. Third-party tools that process data on its behalf are Data Processors, and under Section 8(1) the Data Fiduciary stays responsible for what they do with that data.
The duties apply from 13 May 2027. A website or app is usually where people first see an organisation's notice and consent request, so gaps there are visible to anyone who visits.
Ten points to check on a website or app
The table lists each point, the provision behind it and what to look for.
| Point | Provision | What to check |
|---|---|---|
| Privacy notice | Section 5; Rule 3 | Clear and plain language, understandable on its own, listing each item of personal data and its purpose, with a link to withdraw consent, make a request and complain to the Board |
| Notice languages | Section 5(3) | An option to read the notice in English or in a language listed in the Eighth Schedule to the Constitution |
| Consent | Section 6 | A separate choice for each purpose, given by a clear affirmative action, with no pre-ticked boxes |
| Withdrawal | Section 6(4) | A way to withdraw consent that is as easy as giving it, such as a privacy settings link on every page |
| Forms | Section 6(1) | Only the fields needed for the stated purpose, with optional fields marked as optional |
| Cookies, pixels and SDKs | Sections 4, 6 and 8(2) | A list of each tool, what it collects, the lawful ground relied on, and a contract where it processes data for you |
| Children | Section 9; Rule 10 | If children are likely users: age checks, verifiable consent of a parent or lawful guardian, and no tracking or targeted advertising directed at children |
| Contact and rights | Sections 11 to 14; Rules 9 and 14 | Published contact details for privacy questions, and a published way to make access, correction, erasure and grievance requests |
| Security | Section 8(5); Rule 6 | Encryption, access control for admin panels, monitoring, and logs kept for at least one year |
| Hosting and tools abroad | Section 16; Rule 15 | Where data from the site is stored or sent outside India, and whether any destination is restricted by notification |
Under the Act, a child is anyone under 18 (Section 2(f)). Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children, subject to the exemptions in the Rules.
Third-party tools are processors you have appointed
A tag added through a tag manager, or an SDK added to an app, can send personal data to another company. Where that company processes the data on your behalf, it is a Data Processor, and Section 8(2) allows you to engage it only under a valid contract.
Some providers also use the data for their own purposes. For those activities they may act as Data Fiduciaries themselves. Record the role of each provider, activity by activity, and check that the contract matches it.
A hashed email or a device identifier that can be matched back to a person is still data about an identifiable person and should be treated as personal data.
Mobile apps: a permission is not consent
An Android or iOS permission gives an app technical access to data such as location, contacts or the camera. It does not, by itself, give the notice of purpose that Section 5 requires or the specific consent that Section 6 requires.
Show your own notice and choice before or alongside the system prompt, and ask only for the permissions a feature needs. SDKs inside the app are checked the same way as website tags.
Sector rules can add limits. For example, RBI's digital lending directions restrict what lending apps may access on a borrower's phone.
Design choices that undermine consent
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. A box that is already ticked is not an action by the visitor and is unlikely to meet that standard.
Other designs raise the same problem: a reject option hidden behind several screens, one consent covering many purposes, or a service refused unless the visitor agrees to processing the service does not need. The Central Consumer Protection Authority's Guidelines for Prevention and Regulation of Dark Patterns, 2023 also treat deceptive designs, such as false urgency and basket sneaking, as unfair trade practices.
Form data, accounts and retention
Data sent through contact forms, sign-ups and accounts follows the same rules as any other personal data. Under Section 8(7), it is erased once the purpose is served, unless a law requires it to be kept.
For certain large e-commerce, online gaming and social media platforms, the Third Schedule to the Rules sets a three-year period of inactivity after which personal data must be erased, with notice to the user at least 48 hours before.
Set a retention period for each form and account type, and make sure deletion also reaches copies in email inboxes, CRM tools and spreadsheets.

