The Digital Personal Data Protection Act was passed in August 2023. The Rules were notified in 2025. Enforcement begins in May 2027.
We wanted to know: how ready are Indian companies, really?
So we audited over 300 of them. Manually. One by one.
We crawled their websites, read their privacy policies, mapped their legal frameworks against every relevant DPDP section, reviewed their consent flows, detected trackers and cookies firing before consent, mapped third-party data flows, and checked cross-border transfer mechanisms.
This wasn't a survey. Nobody self-reported. We used our browser-based compliance agent to visit live websites and verify what's actually happening — not what companies claim is happening.
Why We Did This
Every week we talk to founders who believe their privacy policy is "good enough" because a lawyer reviewed it two years ago, or because they're "already GDPR compliant."
We wanted data, not opinions. We wanted to know what the actual compliance landscape looks like across Indian startups — fintech, edtech, and healthtech — so we could tell founders exactly where the gaps are and how common they really are.
What We Found
The headline number: fewer than 5% of the companies we audited reference the DPDP Act correctly in their privacy policies.
That's not a typo. Out of 300+ companies, fewer than 1 in 20 even mention the law they'll be held accountable under starting May 2027.
Across the full audit, we identified 20 recurring compliance gaps, grouped into four categories:
Consent — 6 findings. How companies collect, bundle, and manage consent. This is where the most widespread violations sit. Roughly 9 in 10 companies still use "consent by browsing" — a mechanism that directly contradicts Section 6(1) of the Act. Marketing consent is bundled into registration at 7 in 10 companies. And about 8 in 10 have English-only consent notices, despite serving users across non-English-speaking states.
Transparency — 4 findings. What companies actually disclose in their privacy policies. Around 85% have no DPDP Act reference at all. Some actively block their privacy policy from being indexed by search engines. Others require JavaScript to render the policy — meaning users on low-end devices see a blank page where their data rights should be.
Children's Data — 4 findings. How platforms handle data from users under 18. About 4 in 10 use the wrong age threshold entirely — defining "child" as under 13 (the US COPPA standard) instead of under 18 as DPDP requires. 9 in 10 children's platforms lack verifiable parental consent mechanisms.
Governance — 6 findings. The structural and legal framework gaps. Around 6 in 10 companies list GDPR-only rights (like data portability) as though they apply under Indian law. 9 in 10 have no mention of the Data Protection Board complaint route. And about half use GDPR transfer mechanisms like Standard Contractual Clauses for Indian data transfers — mechanisms that have no legal basis under DPDP.
Why This Matters Now
May 2027 isn't distant anymore. It's less than 12 months away.
The companies that scramble to comply in the last 90 days will pay 5-10x more than those who start now. We saw this play out with GDPR in 2018 — the companies that moved early locked in better rates, built compliance into their product architecture, and avoided the panic-driven consulting engagements that drained budgets across Europe.
More importantly, compliance pressure isn't only coming from the regulator. Enterprise procurement teams are already asking about DPDP in vendor assessments. International investors are asking about it during diligence. And if you're a B2B company selling to banks, NBFCs, or insurance companies, your clients are regulated entities who will require you to demonstrate DPDP compliance as a contractual condition.
The window to get ahead of this is closing.
What's Coming Next
This is the first post in a five-part series where we break down the specific findings in detail:
-
The 6 Biggest Consent Mistakes Indian Companies Still Make Under DPDP — Why "by using this website, you agree" doesn't work anymore, and what to do instead.
-
Privacy Policies Are Still Broken: 5 Transparency Failures Under DPDP — Dead legislation, hidden policies, JavaScript-only notices, and copy-paste errors.
-
Children's Data Under DPDP: Why Most EdTech Companies Are Getting It Wrong — Wrong age thresholds, no parental verification, and behavioural tracking of minors.
-
The Hidden Governance Problems in Indian Privacy Policies — GDPR rights listed as Indian law, missing grievance officers, and cross-border transfer gaps.
Each post includes the specific DPDP section reference, the percentage of companies we found violating it, what "good" looks like, and what to fix first.
If you want to know where your company stands before the enforcement deadline, we can run the same audit on your website and privacy policy. It takes less than a day, and you'll get a 28-point DPDP Readiness Score covering consent architecture, notice and transparency, data principal rights, children's data, third-party and cross-border flows, and governance.