DPDP Act for Website Owners: What to Change Before May 2027
If your website has a contact form, a newsletter box, Google Analytics or a chat widget, you are collecting personal data. Under India's Digital Personal Data Protection Act, that makes you a "Data Fiduciary", which is the law's term for anyone who decides why and how personal data gets used.
Most of the Act's obligations become enforceable on **13 May 2027**. The penalties are large. Failing to keep reasonable security safeguards can cost up to ₹250 crore. Size does not save you either. A five-person agency site and a large e-commerce store are both in scope.
The Act applies to digital personal data processed in India. It also covers businesses outside India if they offer goods or services to people in India.
The good news is that most websites need the same handful of fixes. Here they are, area by area.
---
Table of Contents
1. [Your forms](#1-your-forms)
2. [Cookies and trackers](#2-cookies-and-trackers)
3. [Your chatbot](#3-your-chatbot)
4. [Your privacy policy](#4-your-privacy-policy)
5. [The backend work behind the front end](#5-the-backend-work-behind-the-front-end)
6. [A realistic plan](#a-realistic-plan)
7. [A note on the deadline](#a-note-on-the-deadline)
8. [More sources to explore](#more-sources-to-explore)
---
1. Your forms
Look at every form on your site: contact, demo request, newsletter, job application, checkout, login.
**Ask for less.** Does a newsletter signup really need a phone number? If you can't name the reason for a field, remove it.
**Show a notice at the point of collection.** It should say what data you are collecting, why, how the person can withdraw consent, and how to complain to the Data Protection Board. Write it in plain language. The Rules also expect that people can get the notice in English or any of the 22 languages in the Constitution's Eighth Schedule.
**Kill the pre-ticked box.** Consent has to be a clear action by the person. Don't bundle it either. If someone fills a contact form to get a quote, that doesn't mean they agreed to your weekly marketing emails. Give marketing its own unticked checkbox.
**Keep a record.** Store the timestamp, what the person agreed to, and which version of your notice they saw. If a complaint comes in, this is your proof.
**Make withdrawal easy.** If someone can sign up in one click, they should be able to unsubscribe in one click. Don't make them email three people.
**Watch for children.** Anyone under 18 counts as a child. You need verifiable parental consent before processing their data, and tracking or targeted ads aimed at children are not allowed. If your audience includes students, this matters a lot.
**Set a deletion rule.** Once the purpose is done, the data should go. Decide how long you keep old leads and enquiries, write it down, and actually delete them.
---
2. Cookies and trackers
The Act doesn't use the word "cookie". But if a cookie or pixel can be tied to a person, it is personal data, and you need a lawful basis to use it. For analytics, ad pixels and heatmaps, that basis is consent.
What to check:
---
3. Your chatbot
Chatbots are the part most sites forget. People type things into a chat box that they'd never put in a form: phone numbers, addresses, health worries, payment problems.
---
4. Your privacy policy
If your policy came from a free template or a GDPR copy-paste, rewrite it. A DPDP-ready policy should cover:
Put a date and version number on it. Link it in your footer and beside every form. Keep it readable. A policy nobody can understand doesn't protect you.
---
5. The backend work behind the front end
Fixing the front end isn't enough. Three backend items decide whether you pass or fail.
**Security.** Use HTTPS, encrypt stored data, restrict who can access it, use strong passwords with two-factor login, and keep logs. This is exactly the area where the ₹250 crore penalty sits.
**Breach response.** If personal data leaks, you must tell the Data Protection Board and every affected person. A detailed report to the Board is due within 72 hours. Write a one-page plan now so you aren't inventing one during a crisis.
**A request process.** Someone has to receive access, correction and erasure requests and respond in time. A dedicated email address and a shared spreadsheet is a fine start for a small business.
---
A realistic plan
You don't need a big project. Try this over about six weeks:
| Week | Task |
|------|------|
| 1 | List every form, tracker, plugin, chatbot and vendor on your site. This is your data map. |
| 2 to 3 | Fix forms and notices. Set up a cookie banner that blocks scripts until consent. |
| 4 | Rewrite the privacy policy and publish your contact for data questions. |
| 5 | Sort out vendor agreements, chatbot settings and retention rules. |
| 6 | Test everything yourself. Submit a fake deletion request and see what happens. |
Then keep reviewing every quarter, because every new plugin or tool you add is a new data flow.
---
A note on the deadline
Some reports suggested the government might shorten the timeline from 18 months to 12. That was proposed in consultation but hasn't been formally confirmed. Treat **13 May 2027** as the date, and finish early if you can. Starting in April is too late.
This post is general information and not legal advice. For anything sensitive, such as health, finance or children's data, talk to a lawyer who works on data protection.
---
More sources to explore
**Official**
**Explainers**
The explainers are written by compliance vendors, so read them as guides and confirm any date or clause against the official Gazette text on MeitY's site.
