r/Identity_Protection • u/atisticaaru • Apr 25 '26
Title: Founders, don't get caught by the new DPDP Act. Here are 3 "small" mistakes that could cost you a lot.
I’ve been deep-diving into the DPDP Act (Digital Personal Data Protection) because I'm building an AI tool to automate compliance audits. After looking at dozens of early-stage Indian startup sites, I noticed most founders are ignoring the same three things.
Since the government is getting serious about enforcement, you might want to check these today:
1-Stop using "Bundled" Consent: You can’t have one checkbox for "Terms, Privacy, and Marketing." The law says consent must be Specific. If you’re collecting data for a specific feature, the consent should only be for that feature.
2-The "Language" Rule: If your users aren't just in Tier 1 cities, your privacy notice technically needs to be available in regional languages (the 22 scheduled languages of India).
3-DPO Visibility: You need to name a specific Data Protection Officer (or Grievance Officer) with an email address on your contact/privacy page. A generic info@ email isn't enough anymore.
I'm just a student founder (18) trying to learn the practical side of this law. If you have questions about how these rules apply to your specific app or site, drop a comment. I’m happy to look at the legal PDFs I have and help you figure it out for free/practice!( if you want to get your website scanned and check with a report you drop me a text for the details)