DPDP compliance suite for websites, online stores and customer portals

Does your website meet India’s new data protection law?

The Digital Personal Data Protection (DPDP) Act sets the rules for how your website, online store or portal asks for, uses and protects people’s personal details. The main duties become enforceable on 13 May 2027. Take the two-minute check to see where you stand.

₹250 crore
Highest fine for a single failure to protect customer data
–
Days until 13 May 2027, when the main duties become enforceable
72 hrs
To send the Data Protection Board full details after a data breach
2 min
For our self-check: no signup and no technical knowledge needed
Why this matters

If your site collects a name, phone number or email, this law applies to you

It is already law, and the countdown has started

The DPDP Act passed in 2023 and its Rules were notified on 13 November 2025. The Data Protection Board already exists. The main duties, including notices, consent, security and breach reporting, become enforceable on 13 May 2027.

It covers more than you think

A contact form, checkout, login, newsletter box, chat widget or analytics tag all collect personal data. The law is not limited to large companies, and it also reaches businesses outside India that serve customers in India.

Your customers now have rights over their data

They can ask what you hold, correct it, have it deleted, withdraw their consent and complain, first to you and then to the Board. Every request needs a tracked answer.

Fines are large, and they can stack

The ceiling is ₹250 crore for failing to protect data, with separate fines for not reporting a breach or mishandling children’s data. These are maximums, not predictions, but one incident can trigger more than one.

Three terms you’ll see, in plain words

Personal data
Anything that identifies a person: name, phone, email, address, photo, or activity linked to them.
Data Fiduciary
That’s you: the business that decides why and how personal data is used.
Data Principal
That’s your customer, visitor or user: the person the data is about.
Highest fine for each kind of failure Not protecting customer data ₹250 crore Not reporting a data breach ₹200 crore Mishandling children’s data ₹200 crore Other duties (consent, notices, requests) ₹50 crore Ceilings per instance, set by the DPDP Act. Separate failures are fined separately, so they can add up.
Spot the signs

The same signup form, twice

Many websites have a form like the one on the left. Nothing looks broken, yet each numbered point is a gap under the DPDP Act. The version on the right shows what “ready” looks like.

Common today: four gaps
  1. 1
    No reason given. The form asks for a mobile number without saying what it will be used for.
  2. 2
    Pre-ticked, and bundled. The box is already ticked, and one tick covers two different things. That is not valid consent.
  3. 3
    Consent by default. “By signing up you agree” with a link to a long policy is not a notice, and not consent.
  4. 4
    No way out. Nothing says how to withdraw consent, ask for the data or who to contact.
DPDP-ready: same form, fixed
  1. 1
    A short notice, right there. It says what you collect and why, and links to the full notice.
  2. 2
    Every box starts empty. Nothing is ticked on the customer’s behalf.
  3. 3
    One choice per purpose. Offers and sharing are separate, and both are optional.
  4. 4
    A clear way out. Withdrawing is as easy as signing up, and a real contact is named.
Check your own website

Ten quick questions cover the forms, trackers and back-end basics.

Where it usually goes wrong

Pick what you run, and see where sites like yours fall short

Enquiry and callback forms with no notice

Contact forms collect names, numbers and emails, but nothing beside the button says what happens to them or how to withdraw.

Trackers that start before the visitor chooses

Analytics, ad pixels, chat widgets and embedded videos switch on as the page loads, and a cookie banner that hides “Reject” doesn’t fix that.

Careers pages that collect CVs and never delete them

Job applications hold phone numbers, photos and work history. Old ones often sit in an inbox for years.

Newsletter boxes with pre-ticked consent and no easy exit

Signing up takes one click. Unsubscribing means writing an email, which breaks the “as easy to withdraw as to give” rule.

Running a company website?

We review your live pages, forms and scripts and send a plain-language gap report with a fix list in priority order.

Get a review of my website

Checkout that bundles marketing with the order

The customer needs to give an address and phone number to buy. That is not permission to send offers, and it needs its own, optional choice.

Cart reminders and WhatsApp offers sent without asking

Abandoned-cart emails and promotional messages need the customer’s clear consent, and a working way to stop them.

Old accounts and guest orders kept forever

Years of customer records pile up “just in case”. The law expects deletion once the purpose is over, and a bigger pile means a bigger leak.

Payment, courier, CRM and ad tools with no data-protection terms

Each one receives customer data, and you stay responsible for what they do with it. Contracts need to say so.

Running an online store?

We check your checkout, account pages, scripts and vendor connections, then send a plain-language gap report with a fix list in priority order.

Get a review of my store

Sensitive records with broad staff access and no access log

IDs, KYC documents, financial or health details are often visible to more people than need them, with no record of who looked.

No self-service way to download, correct or delete data

Users can’t see what you hold or close their account without emailing support, and nobody tracks how long the reply takes.

Tracking and third-party SDKs on by default

Analytics, notification and support tools inside the portal or app share user data before anyone has agreed to it.

No rehearsed plan for a breach

Who decides it is a breach, who tells the customers, and who sends the Board full details within 72 hours? Most teams have never practised.

Running a portal or app?

We map what your platform stores and who can see it, then send a plain-language gap report with a fix list in priority order.

Get a review of my portal
Two-minute self-check

Ten questions. No jargon. No signup.

Answer for the one website, store or portal you run. Where you don’t know, choose “Not sure”. That counts as a gap, because a regulator will ask for proof, not confidence.

Look at your website

You can check these yourself in a few minutes.

1Do your forms say why you’re asking for personal details?

Open your contact, signup or checkout form. Right beside the button, is there a short line saying what you collect, why, and how to withdraw? A link to a long policy doesn’t count.

The law expects a clear notice at the moment you ask. It has to list what you collect and why, how people can withdraw consent, and how to complain. It should be readable in English or an Indian language your customers use.

2Are consent boxes empty until the customer ticks them, with marketing kept separate?

Look for boxes that are already ticked, or one “I agree to everything” box that covers orders, offers and data sharing together.

Consent must be freely given, specific and given by a clear action. A pre-ticked box or a bundled “agree to all” isn’t valid, and you can’t make marketing a condition of placing an order.

3Do analytics, ad pixels and chat widgets wait for the visitor’s choice?

Open your site in a private window. Does a banner appear? Can you click “Reject” as easily as “Accept”? Or do tracking tools switch on before you choose?

Trackers that collect data about identifiable visitors need a valid basis, and for most websites that basis is the visitor’s consent. A banner where “Reject” is buried, or where tools load before the choice, doesn’t hold up.

4Can a customer withdraw consent as easily as they gave it?

If they agreed with one tick, can they undo it in one click, like an unsubscribe link or a privacy settings page? Or do they have to email someone?

The law says withdrawing consent must be as easy as giving it. Once someone withdraws, you must stop using their data for that purpose.

5Can customers ask to see, correct or delete their data, and do they know who to contact?

Is there a request form or a named contact on your site? And does someone actually answer within a set time?

People have the right to see, correct and erase their data, and to complain. You must publish who they can contact and answer grievances within the time the Rules allow, which is up to 90 days.

6If someone under 18 could sign up, do you check their age and ask a parent first?

Could a teenager create an account, buy or log in? If so, is there an age check and a parent’s verified permission? If your service is only for adults and blocks minors, choose “Doesn’t apply”.

Data about anyone under 18 needs a parent’s verifiable consent, and tracking or targeted ads aimed at children are banned. This category carries a fine of up to ₹200 crore.

Ask your tech team

These happen behind the scenes. Forward this page to whoever manages your hosting or software.

7Is customer data encrypted and locked down to the people who need it?

Ask: is personal data encrypted when stored and when sent, is access limited by role, and are access logs kept for at least a year?

“Reasonable security safeguards” carries the biggest fine in the Act, up to ₹250 crore. The Rules spell out encryption, access control, monitoring and keeping logs for a year.

8Do you have a written plan for telling customers and the Board if data leaks?

Who decides it’s a breach? Who tells the customers? Could you send the Data Protection Board full details within 72 hours?

After a breach you must tell every affected person without delay, and give the Board full details within 72 hours. Failing to notify carries its own fine of up to ₹200 crore, separate from any fine for the leak itself.

9Do you delete personal data when you no longer need it?

Old accounts, abandoned carts, job applications, expired enquiries: is there a rule for when each is deleted, or is everything kept forever?

You may keep personal data only as long as the purpose needs it, unless another law requires longer. Keeping everything “just in case” is a gap, and it makes any leak bigger.

10Do the companies that handle your customers’ data have to protect it too?

Payment gateways, CRM, email tools, hosting, delivery partners: is there a contract that requires each one to follow the same rules?

You stay responsible for data your vendors handle for you. The law expects a valid contract with each of them, so a vendor’s mistake doesn’t become only your problem to explain.

Your answers stay in this browser tab. Nothing is sent anywhere.

The DPDP compliance suite

We don’t just hand you a report. We fix it in your website.

Milleniance is a software team, so the forms, banners, portals and databases get changed in your real product, not only described in a document. Each part answers specific checks from the self-check above.

Audit and data map

Starts every project

We scan your website, app and databases to find every form, tracker, third-party script and stored record that touches personal data, and every vendor it flows to.

  • Map of what you collect and where it goes
  • Inventory of third-party scripts
  • Plain-language gap report

Notices and consent

Answers checks 1 to 4

Notices at every point of collection, one consent choice per purpose, a banner that waits for the visitor’s decision, and a record of who agreed to what and when.

  • Notice text and placement
  • Consent banner and preferences page
  • Consent records you can show an auditor

Customer rights portal

Answers checks 4 and 5

A self-service place where customers can see, correct and delete their data and withdraw consent, with identity checks, tracked requests and response deadlines.

  • Request and complaint forms
  • Admin workflow with deadline tracking
  • Published grievance contact

Security and breach readiness

Answers checks 7 and 8

Encryption, role-based access, logging and monitoring that match what the Rules expect, plus a breach-response plan that has been rehearsed before it is needed.

  • Encryption and access controls
  • Log retention and monitoring
  • Breach runbook and alert flow

Data lifecycle and vendors

Answers checks 9 and 10

Retention periods for each kind of record, automated deletion, and a register of every vendor that handles your customers’ data, with the contract terms to match.

  • Retention schedule
  • Automated deletion
  • Vendor register and contract checklist

Children’s data

Answers check 6

For sites that young people can reach: an age check, a parent-verification flow, and tracking and targeted ads switched off for minors.

  • Age check at signup
  • Parental consent flow
  • Minor-safe tracking settings
How it works

From first scan to audit-ready in four steps.

01

Scan and map

We find every form, tracker, script, database and vendor that touches personal data on your website, store or portal.

02

Gap report in plain language

You get a prioritised list of what’s missing, what each gap could cost and what fixing it involves. Your legal counsel can review it alongside.

03

Fix it in your product

We build the notices, consent, rights portal, security and deletion changes into your live platform, and test each one.

04

Prove it and keep it that way

We hand over the evidence you would need in an audit, and keep watching as you add new forms, vendors and features.

Frequently asked

Questions people ask before they get in touch.

The Digital Personal Data Protection Act, 2023 is India’s data privacy law. It says that a business collecting people’s personal details must tell them why, ask for their consent, protect the data, delete it when it is no longer needed, and respect their right to see, correct and erase it.

If your website, store or portal collects personal data such as a name, phone number, email address or postal address from people in India, yes. That includes contact forms, checkouts, logins, newsletter sign-ups and job applications. It also applies to companies outside India that offer goods or services to people in India.

The DPDP Rules were notified on 13 November 2025. The main duties, including notices, consent, security safeguards, breach reporting and customer rights, become enforceable on 13 May 2027. The work usually takes months, so starting early is safer than starting in the final weeks.

The Act sets maximum fines of ₹250 crore for failing to protect personal data, ₹200 crore for failing to report a breach, ₹200 crore for breaking the rules on children’s data and ₹50 crore for other breaches. These are ceilings per instance. The Data Protection Board decides the actual amount based on how serious the failure was and what you did about it.

No. A privacy policy is a start, but the law expects a short notice at the moment you collect data, real consent choices, a way for people to use their rights, security safeguards and a breach plan. Most of that is built into your website or software, not written on a page.

The Act doesn’t mention cookies by name, but trackers such as analytics, ad pixels and chat widgets that collect data about identifiable visitors need a valid basis, and for most websites that basis is the visitor’s consent. A banner where “Reject” is as easy as “Accept”, and where trackers wait for the choice, is the safest approach.

We handle the technical and design work: the audit, consent, notices, rights portal, security and deletion. How the law applies to your specific business is a question for your legal counsel, and we are happy to work alongside them.
See where you stand

Find out what’s missing on your website before a customer or a regulator does.

Share your website address and we’ll send a plain-language gap report. A person on our team reads every request, and we reply within one business day.

Talk to a DPDP expert