DPDP Act for Website Owners: What to Change Before May 2027

If your website has a contact form, a newsletter box, Google Analytics or a chat widget, you are collecting personal data. Under India's Digital Personal Data Protection Act, that makes you a "Data Fiduciary", which is the law's term for anyone who decides why and how personal data gets used.

Most of the Act's obligations become enforceable on **13 May 2027**. The penalties are large. Failing to keep reasonable security safeguards can cost up to ₹250 crore. Size does not save you either. A five-person agency site and a large e-commerce store are both in scope.

The Act applies to digital personal data processed in India. It also covers businesses outside India if they offer goods or services to people in India.

The good news is that most websites need the same handful of fixes. Here they are, area by area.

---

Table of Contents

1. [Your forms](#1-your-forms)

2. [Cookies and trackers](#2-cookies-and-trackers)

3. [Your chatbot](#3-your-chatbot)

4. [Your privacy policy](#4-your-privacy-policy)

5. [The backend work behind the front end](#5-the-backend-work-behind-the-front-end)

6. [A realistic plan](#a-realistic-plan)

7. [A note on the deadline](#a-note-on-the-deadline)

8. [More sources to explore](#more-sources-to-explore)

---

1. Your forms

Look at every form on your site: contact, demo request, newsletter, job application, checkout, login.

**Ask for less.** Does a newsletter signup really need a phone number? If you can't name the reason for a field, remove it.

**Show a notice at the point of collection.** It should say what data you are collecting, why, how the person can withdraw consent, and how to complain to the Data Protection Board. Write it in plain language. The Rules also expect that people can get the notice in English or any of the 22 languages in the Constitution's Eighth Schedule.

**Kill the pre-ticked box.** Consent has to be a clear action by the person. Don't bundle it either. If someone fills a contact form to get a quote, that doesn't mean they agreed to your weekly marketing emails. Give marketing its own unticked checkbox.

**Keep a record.** Store the timestamp, what the person agreed to, and which version of your notice they saw. If a complaint comes in, this is your proof.

**Make withdrawal easy.** If someone can sign up in one click, they should be able to unsubscribe in one click. Don't make them email three people.

**Watch for children.** Anyone under 18 counts as a child. You need verifiable parental consent before processing their data, and tracking or targeted ads aimed at children are not allowed. If your audience includes students, this matters a lot.

**Set a deletion rule.** Once the purpose is done, the data should go. Decide how long you keep old leads and enquiries, write it down, and actually delete them.

---

2. Cookies and trackers

The Act doesn't use the word "cookie". But if a cookie or pixel can be tied to a person, it is personal data, and you need a lawful basis to use it. For analytics, ad pixels and heatmaps, that basis is consent.

What to check:

  • **Essential cookies** (login sessions, cart, security) don't need a consent prompt.
  • **Analytics, Meta Pixel, Google Ads tags, Hotjar and similar tools** should not fire until the visitor says yes.
  • **Your banner should be real, not decorative.** Many banners show a popup while the scripts load anyway. Open your browser's developer tools, decline cookies, and look at the Network tab. If trackers still load, your banner isn't doing its job.
  • **Accept and reject should look equally easy.** No giant green button next to a tiny grey link.
  • **Let people change their mind later.** A small "Cookie settings" link in the footer does the job.
  • **List your third parties.** Google, Meta, your CRM, your email tool and your hosting all process data for you. You stay responsible for what they do, so have proper agreements with them.
  • ---

    3. Your chatbot

    Chatbots are the part most sites forget. People type things into a chat box that they'd never put in a form: phone numbers, addresses, health worries, payment problems.

  • **Show a short notice when the chat opens.** Say that messages are stored, why, and link to your privacy policy.
  • **Collect only what the conversation needs.** Configure the bot so it doesn't ask for Aadhaar, PAN or medical details unless your service truly requires them.
  • **Know where transcripts go.** Find out which vendor stores them, in which country, for how long, and whether they are used to train models. Get this in the vendor contract.
  • **Don't keep chats forever.** Set an auto-delete period.
  • **Handle deletion requests.** If someone asks you to erase their chat history, you need to be able to find and remove it.
  • **Tell people it's a bot.** The DPDP Act doesn't demand this, but people trust you more when you're upfront.
  • ---

    4. Your privacy policy

    If your policy came from a free template or a GDPR copy-paste, rewrite it. A DPDP-ready policy should cover:

  • Every type of personal data you collect
  • The purpose behind each one
  • Who you share it with (payment gateway, CRM, analytics, chat vendor)
  • How long you keep it
  • The rights people have: to get a summary of their data, correct it, erase it, get grievances resolved, and nominate someone to act for them
  • How to withdraw consent
  • The contact details of a named person who can answer questions about data, published where visitors can see it
  • How to complain to the Data Protection Board if you don't resolve the issue
  • Put a date and version number on it. Link it in your footer and beside every form. Keep it readable. A policy nobody can understand doesn't protect you.

    ---

    5. The backend work behind the front end

    Fixing the front end isn't enough. Three backend items decide whether you pass or fail.

    **Security.** Use HTTPS, encrypt stored data, restrict who can access it, use strong passwords with two-factor login, and keep logs. This is exactly the area where the ₹250 crore penalty sits.

    **Breach response.** If personal data leaks, you must tell the Data Protection Board and every affected person. A detailed report to the Board is due within 72 hours. Write a one-page plan now so you aren't inventing one during a crisis.

    **A request process.** Someone has to receive access, correction and erasure requests and respond in time. A dedicated email address and a shared spreadsheet is a fine start for a small business.

    ---

    A realistic plan

    You don't need a big project. Try this over about six weeks:

    | Week | Task |

    |------|------|

    | 1 | List every form, tracker, plugin, chatbot and vendor on your site. This is your data map. |

    | 2 to 3 | Fix forms and notices. Set up a cookie banner that blocks scripts until consent. |

    | 4 | Rewrite the privacy policy and publish your contact for data questions. |

    | 5 | Sort out vendor agreements, chatbot settings and retention rules. |

    | 6 | Test everything yourself. Submit a fake deletion request and see what happens. |

    Then keep reviewing every quarter, because every new plugin or tool you add is a new data flow.

    ---

    A note on the deadline

    Some reports suggested the government might shorten the timeline from 18 months to 12. That was proposed in consultation but hasn't been formally confirmed. Treat **13 May 2027** as the date, and finish early if you can. Starting in April is too late.

    This post is general information and not legal advice. For anything sensitive, such as health, finance or children's data, talk to a lawyer who works on data protection.

    ---

    More sources to explore

    **Official**

  • [Ministry of Electronics and IT (MeitY)](https://www.meity.gov.in): the home for the Act, the DPDP Rules 2025 and any notifications.
  • [India Code](https://www.indiacode.nic.in): the full text of the Digital Personal Data Protection Act, 2023.
  • Data Protection Board of India: for complaint procedures and updates as it builds out its work.
  • **Explainers**

  • [Tech Observer: DPDP compliance deadline May 2027](https://techobserver.in/news/egov/dpdp-compliance-deadline-may-2027-india-data-protection-328129/): covers the government's August 2026 statement to Parliament.
  • [ProtectComply: DPDP Rules 2025 timeline](https://protectcomply.com/blog/dpdp-rules-2025-timeline): a rule-by-rule breakdown of what starts when.
  • [Seclore: DPDP Rules 2025 guide](https://www.seclore.com/fundamentals/dpdp-rules-2025-compliance-guide/): explains the Rules and the proposed 12-month acceleration.
  • [TCSA: implementation roadmap](https://www.tcsa.in/resources/dpdp-rules-2025-implementation-roadmap): phase-wise checklists and rough budget ranges.
  • The explainers are written by compliance vendors, so read them as guides and confirm any date or clause against the official Gazette text on MeitY's site.