Web Development Company in Pune: What the DPDP Act's 2025 Rules Mean for Your Website in 2026
If you're briefing a web development company in Pune for a new site or a redesign in 2026, one requirement now sits alongside "make it fast" and "make it rank": make it compliant with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology on 13 November 2025. This isn't a distant, theoretical concern for large enterprises — it applies to any business, NGO or professional whose website collects a name, phone number, email address or payment detail from an Indian resident, which in practice means almost every commercial website in the country. The compliance clock has started, and the businesses that get ahead of it now will spend far less fixing things later than the ones who wait for the deadline to arrive.
This guide explains what the Act and its Rules actually require, the phased timeline you need to plan around, and — most usefully — the concrete checklist a web development company in Pune should be building into every new site and every website audit from this year onward.
What the DPDP Act Actually Requires, in Plain English
The Act uses two core terms worth understanding before anything else makes sense. A "Data Fiduciary" is the entity that decides why and how personal data is processed — for a business website, that's you, the site owner, not your web developer or hosting provider. A "Data Principal" is the individual whose data it is — your website visitor, newsletter subscriber, or customer.
The Act's central obligation is consent: before you collect and process someone's personal data, you need their clear, specific, informed agreement, given through an unambiguous affirmative action. In practical website terms, this rules out a few common patterns that are still widespread on Indian business sites today:
- Pre-ticked checkboxes on a newsletter signup or contact form ("Yes, I agree to receive marketing communications" ticked by default) no longer meet the bar. The Act requires an affirmative opt-in action, not a default the visitor has to notice and untick.
- Vague, bundled consent language ("By using this site you agree to our Terms and Privacy Policy") isn't itemised or specific enough on its own for distinct processing purposes — collecting an email for order confirmation and collecting the same email for marketing newsletters are, in principle, different purposes that deserve distinguishable consent.
- No easy way to withdraw consent. The Act requires that withdrawing consent be "as easy as" giving it — if a visitor can subscribe with one click, unsubscribing or asking for data deletion needs to be a comparably low-friction path, not a support ticket that takes two weeks to resolve.
Alongside consent, the Act grants Data Principals specific rights: to know what data of theirs is being processed and why, to have inaccurate data corrected, to have it erased once the purpose it was collected for is served, to a grievance redressal mechanism, and — a distinctly Indian addition — the right to nominate another person to exercise these rights on their behalf in the event of death or incapacity.
The Compliance Timeline: What's Due When
The DPDP Rules 2025 set out a deliberately phased rollout rather than a single hard deadline, which gives businesses genuine planning room — but only if they use it.
| Phase | Date | What it means in practice |
|---|---|---|
| Phase 1 | November 2025 | The Data Protection Board of India is established as the enforcement and adjudication body. |
| Phase 2 | 13 November 2026 | The Consent Manager framework becomes operational — registered, Board-approved platforms through which a Data Principal can give, review and withdraw consent across multiple organisations from one place. |
| Phase 3 | 13 May 2027 | The hard compliance deadline. All substantive obligations — consent notices, breach reporting, data principal rights, security safeguards, and the extra requirements for Significant Data Fiduciaries — must be fully in place. |
Eighteen months between the Rules being notified and the hard deadline sounds generous, but website compliance work — rewriting consent flows, auditing every form and third-party script on a site, building a working grievance mechanism, training whoever handles support tickets — is not something to start in April 2027. A website rebuild or redesign already scheduled for 2026 is the natural, lowest-cost point to build this in, rather than retrofitting a finished site under deadline pressure a year from now.
What This Means for a Website Being Built or Rebuilt in 2026
Consent notices, not a checkbox buried in a privacy policy
Every point on a website where personal data is collected — a contact form, a newsletter signup, an account registration, a quote request, a donation form — needs a clear, itemised notice explaining what's being collected, why, and for how long, presented at the point of collection rather than left to a separate privacy policy page most visitors never open. The notice must be available in English or one of the languages listed in the Eighth Schedule to the Constitution, and it needs to describe the actual purpose in plain language — "so we can respond to your enquiry" rather than a generic legal phrase.
Cookies and analytics tracking
Analytics tools like Google Analytics, Meta Pixel, and most marketing automation scripts collect data that can identify or profile an individual, which brings them within scope of the Act. A cookie or tracking-consent banner that only exists to look compliant, without actually blocking non-essential scripts until consent is given, does not meet the underlying requirement — the consent needs to be genuinely obtained before non-essential processing starts, not logged after the fact.
Data minimisation in form design
A contact form asking for a visitor's date of birth, gender, or full address when all you need is a name, email and message is now a compliance liability as well as bad UX. The Act's data minimisation principle means collecting only what's genuinely necessary for the stated purpose — which, helpfully, also tends to improve form completion rates.
A working grievance mechanism
The Rules require organisations to respond to data-related grievances (a request to correct, erase, or explain data use) within a reasonable period, capped at 90 days. In practice this means your website needs a clearly listed Grievance Officer or equivalent contact point — not just a generic "info@" inbox that nobody monitors — and an internal process for actually resolving requests within that window.
Children's data
If your website's audience plausibly includes anyone under 18 — an ed-tech platform, a school, a youth-focused NGO programme — processing their personal data requires verifiable parental consent, and the Act specifically prohibits behavioural tracking or targeted advertising directed at children. This is a meaningfully stricter bar than most Indian websites currently meet.
Breach readiness
The Rules require a Data Fiduciary to notify both the Data Protection Board and every affected Data Principal without delay in the event of a personal data breach. Beyond the exact procedural timeline set out in the Rules, the practical requirement for a website is having a security setup — access logging, encrypted storage, a documented incident response plan — that can actually detect a breach and support a timely notification, rather than discovering one from a customer complaint months later.
Penalties: Why This Isn't a "Nice to Have"
Section 33 of the Act gives the Data Protection Board real financial teeth, and the amounts are large enough that no business — however small — should treat this as optional paperwork.
| Violation | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards, resulting in a data breach | ₹250 crore |
| Failure to notify the Board and affected individuals of a personal data breach | ₹200 crore |
| Non-compliance with the additional obligations around children's data | ₹200 crore |
| Non-compliance with other general obligations under the Act | ₹50 crore |
The Board considers factors such as the nature and gravity of the breach, the type of personal data affected, whether the violation was repetitive, and any mitigating steps taken, before setting the final amount within these ceilings — and can double the penalty for repeat or particularly serious violations. For a small or mid-size business, the realistic exposure in a genuine dispute is far below the statutory ceiling, but the ceiling itself signals how seriously the framework is meant to be taken, and reputational damage from a publicised data breach or Board order can matter more to a smaller business than the fine itself.
Significant Data Fiduciaries: When Extra Rules Apply
The government can designate certain organisations as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of personal data they process, or other risk factors. SDFs face additional obligations: appointing a Data Protection Officer based in India, conducting periodic Data Protection Impact Assessments, and independent data audits. Most small and mid-size business websites in Pune will not meet the threshold for SDF designation, but it's worth knowing the category exists — a business that processes large volumes of sensitive personal data (health records, financial data, biometric data) at scale should factor this possibility into its longer-term compliance planning, even if it isn't an immediate concern for a standard business or NGO website.
When Consent Isn't Required: The Act's "Legitimate Uses" Exceptions
Consent isn't the only lawful basis for processing under the Act — Section 7 lists a set of "legitimate uses" where a business can process personal data without seeking fresh consent each time. The ones most relevant to a typical business or NGO website are: data the individual has voluntarily provided for a specified purpose and hasn't indicated they don't consent to (for example, someone emailing you their details to request a quote), processing required to comply with a legal obligation or court order, processing for employment purposes (payroll, HR records), and processing in a medical emergency or during a public health event. This list is narrower than it might first appear — it does not create a general "legitimate interest" basis of the kind GDPR practitioners may be used to, so a business shouldn't assume broad marketing or profiling activity falls under it without a specific, applicable ground.
Cross-Border Data Transfer: A Simpler Model Than GDPR, With a Catch
Unlike the GDPR's "adequacy" model, which restricts data transfers to a specific approved list of countries, the DPDP Act takes a blacklist approach: personal data can be transferred outside India freely, except to countries the Central Government specifically restricts by notification. In practice this means most Indian businesses using cloud hosting, email marketing platforms, or analytics tools based outside India (many of which route data through servers in the US, Singapore, or the EU) face fewer transfer restrictions than a comparable EU business would under GDPR — but the restricted-country list can change, and a business handling data that might plausibly be considered sensitive at scale should keep an eye on Ministry notifications rather than assume the current permissive position is permanent.
How the DPDP Act Differs From the GDPR, for Anyone Comparing the Two
Business owners who've heard of GDPR often assume the DPDP Act is simply India's version of the same law, but there are meaningful differences worth knowing before you brief a developer:
- No broad "legitimate interest" basis. GDPR lets a business process data based on a documented "legitimate interest" balanced against the individual's rights, covering a wide range of routine business activity. The DPDP Act's Section 7 exceptions are narrower and more specifically enumerated, which means Indian businesses generally need to lean on explicit consent more heavily than an EU counterpart would.
- A blacklist, not a whitelist, for cross-border transfer, as above — generally more permissive by default.
- No independent "right to be forgotten" jurisprudence yet. The right to erasure exists in the Act, but India doesn't yet have the same body of case law GDPR has built up over its ten-plus years of enforcement, so some edge cases (how erasure interacts with statutory retention duties under other Indian laws, for instance) are less settled in practice.
- A single, simpler penalty ceiling structure rather than GDPR's turnover-linked fines (up to 4% of global annual turnover) — DPDP penalties are fixed rupee ceilings per violation type, set out in the Schedule to the Act.
None of these differences make DPDP compliance a lighter lift than GDPR compliance for a website already built with EU visitors in mind — if anything, a site that's already GDPR-compliant is most of the way to DPDP-compliant, since consent-first design satisfies both. The gap tends to be smaller for GDPR-aware businesses and larger for businesses that have never had to think about data protection law at all.
A Practical Checklist to Take to Your Web Development Company in Pune
- Does every form on the site have a clear, itemised consent notice at the point of collection, not just a link to a general privacy policy?
- Are all consent checkboxes opt-in by default, with no pre-ticked boxes?
- Is there a genuinely working, low-friction way to withdraw consent or request data deletion — not just a promise in a policy document?
- Does the cookie/analytics consent mechanism actually block non-essential tracking scripts until consent is given, rather than just displaying a banner?
- Is there a named Grievance Officer or equivalent contact point listed, with a real internal process to act on requests within 90 days?
- If the audience includes minors, is there a verifiable parental consent mechanism, and is targeted advertising to children disabled entirely?
- Is personal data collected on the site limited to what's genuinely needed for the stated purpose?
- Is there a documented plan — even a simple one — for detecting and reporting a data breach without delay?
How This Fits Into a Redesign or Maintenance Plan
If your site is already due for a refresh, this is the moment to build compliance in during the redesign rather than as a bolt-on afterward — our guide on website redesign versus rebuild covers how to scope that decision. If your site isn't due for a full rebuild, a lot of this can be addressed through an existing maintenance relationship instead; see our guide on what a website maintenance AMC should actually include for what that ongoing work looks like in practice.
How We Approach This at Govindani Infotech
We've delivered 650+ websites out of Pune, and DPDP-aligned consent flows, grievance contact points, and data-minimised form design are now a standard part of our website design and development process for new builds, alongside the accessibility and performance work we already treat as design constraints rather than afterthoughts. Our own privacy policy reflects the same principles we build into client sites — it's a reasonable starting reference for what a compliant notice should look like in practice, though every business's specific data flows will differ.
If you're planning a new website or a redesign in 2026 and want DPDP compliance built in from the first wireframe rather than retrofitted under deadline pressure next year, get in touch through our contact page to talk through what your specific site needs to change.
A note on scope: this article explains the DPDP Act and Rules as they apply to typical business website data collection. It is not legal advice, and organisations processing large volumes of sensitive personal data, or operating close to the Significant Data Fiduciary threshold, should consult a qualified data protection professional for their specific compliance obligations.
Sources: PIB — Digital Personal Data Protection Rules, 2025, notified, Wikipedia — Digital Personal Data Protection Rules, 2025, Mondaq — DPDP Act and Rules 2025: The 2026 Compliance Milestones, DPDPA.com — Section 33 Penalties with Interpretation, Vinsys — DPDP Act Compliance Deadline 2026