DPDP Act readiness for Indian SaaS
Statutory obligations, safeguards, breach reporting, evidence. We map where personal data actually sits, build the safeguards the Rules expect and the breach runbook that goes with them, and do the testing that backs it, so that if you are ever asked you can produce the evidence rather than start assembling it.
What DPDP Act actually asks for
The Digital Personal Data Protection Act, 2023 governs digital personal data of individuals in India. A Data Fiduciary owes notice and consent, purpose limitation, accuracy, retention limits, reasonable security safeguards, and honouring data principal rights. DPDP Rules 2025 were notified by MeitY on 13 November 2025 and add specificity on safeguards and on breach reporting, with an eighteen-month phase-in from publication. A Significant Data Fiduciary designated under Section 10 carries more: a Data Protection Officer based in India, periodic Data Protection Impact Assessments, and an independent audit.
Our part
A readiness assessment against the obligations that apply to you, a data map of where personal data actually sits, consent and notice review, the security safeguards the Rules expect, a breach response runbook built to the reporting clock, and the evidence to show it is in place. Where the safeguards need technical validation, the penetration test produces it.
Where the work needs a penetration test, it is the plan you already see on the pricing page: Startup at INR 74,999 for one scope, Growth at INR 1,79,999 for two. Growth is the plan that carries the SOC 2 and ISO 27001 control mapping in the report. The sample report shows the format an auditor will be handed.
What we hand over, and who signs it off
What we deliver is the evidence that the obligations were met, and the ability to produce it on demand: the data map, the consent and notice trail, the safeguards the Rules expect, and the breach runbook built to the reporting clock. DPDP is judged on what you actually do, by the Data Protection Board of India, and no certificate exists for anyone to issue in advance. On the legal reading of your obligations your counsel leads and we supply the technical evidence they ask for.
Where a penetration test fits, and where it does not
The Act asks for reasonable security safeguards to prevent a personal data breach and does not enumerate tests. A penetration test is how a SaaS company demonstrates it looked for the weaknesses that cause breaches, and for a Significant Data Fiduciary it feeds the periodic audit and the DPIA directly.
If you are still deciding which one first
DPDP Act questions we are asked
Is there a DPDP certification?
No. No DPDP certificate exists, and nobody can issue one. The Digital Personal Data Protection Act is a statute, and compliance is judged by the Data Protection Board of India against what you actually do, not against a certificate you hold. Anyone selling you DPDP certification is selling something that does not exist.
What is the breach reporting timeline under the DPDP Rules?
On becoming aware of a personal data breach, a Data Fiduciary must intimate the Data Protection Board of India without delay, then furnish a detailed report within 72 hours. The first obligation has no grace period, which is why the runbook matters more than the report template: the clock starts at awareness, not at confirmation.
Are we a Significant Data Fiduciary?
It is a designation made under Section 10, based on factors including the volume and sensitivity of the personal data you process and the risk to data principals. If you are designated, additional duties follow: a Data Protection Officer based in India, periodic Data Protection Impact Assessments, and an independent audit. Most startups are not designated, but the test is applied to you rather than chosen by you.
Does DPDP require a penetration test?
The Act asks for reasonable security safeguards to prevent a personal data breach and does not enumerate tests. A penetration test is how a SaaS company demonstrates it looked for the weaknesses that cause breaches, and for a Significant Data Fiduciary it feeds the periodic audit and the Data Protection Impact Assessment directly.
What we have written about DPDP Act
Tell us what the deadline is
An auditor booked, a customer security review, an investor asking, or a renewal due. The date changes the scope and the order of the work, so it is the first thing we ask. Both co-founders are on the call.
Where these requirements come from
Everything this page says about the standards body or regulator's requirements is taken from their own published documentation, linked below and last checked on 2026-10-06. We quote the requirement rather than our reading of it wherever the difference matters.
- Digital Personal Data Protection Act, 2023 (MeitY)
- India Code: Digital Personal Data Protection Act, 2023
Checked 2026-10-06. The MeitY page loaded; the India Code entry did not respond on that date. The Act text is also published by MeitY at the link above.
Our aim is to describe these requirements as accurately and as currently as we can, and to show you where to check us. We are reading someone else's documentation: a standards body or a regulator can revise it without an announcement, and our reading of it can be imprecise or go out of date.
How we source, draft and review what we publish, including where software sits in the drafting, is set out in our editorial policy. A page like this is only as good as the date on it, so we re-read the sources on a standing audit, date what we checked, and update the page when a source moves or when we can state something more precisely.
If something here no longer matches the source, tell us at errors@cybersecify.com. We will review it against the source and tell you what we decide; where it needs changing we change it and date the change.
This page is published for information. It is a best-effort account of someone else's published requirements, not a commitment about your engagement: what we deliver, and what it costs, is set out in the Statement of Work both parties sign, and our terms state that where website content and a signed agreement differ, the signed agreement governs.