One India user is enough to trigger DPDPA.
DPDPA applies extraterritorially. There is no minimum-user threshold. Fines reach ₹250 crore (~$30M USD) per failure. The Data Protection Board starts enforcing late 2026. $19 buys you the gap audit + the DPO letter template before the wave.
What you get
- Notice + consent gap audit (DPDPA §6, §7) — what you say today vs what India requires
- DPO appointment recommendation — when you cross the Significant Data Fiduciary threshold
- Data Principal rights checklist: access · correct · erase · nominate · grievance
- Significant Data Fiduciary tripwire analysis — volume / sensitivity / sovereignty criteria
- Children + minor-handling compliance (DPDPA §9) — explicit consent + harm prevention
- PDF report + auto-fill template for your DPO appointment letter
FAQ
When do DPDPA fines actually kick in?
The Digital Personal Data Protection Act, 2023 became law in August 2023. The rules + Data Protection Board enforcement framework finalized in 2025. Fine regime — up to ₹250 crore (~$30M USD) per failure — is expected to begin enforcement late 2026. This audit positions you before the wave.
Do I need this if I'm a US company?
If you have ANY India-resident users — paid or free — DPDPA applies extraterritorially. That includes a SaaS dashboard accessed from Bengaluru, a marketing email sent to a Mumbai contact, or an embed loading from a US CDN on an Indian site. There is no minimum-user threshold for the act to apply.
Why $19 one-time and not a subscription?
The gap audit is a one-shot diagnostic — it tells you whether you need to act and what to fix. Once you have the report, you act once (DPO letter, notice rewrite, consent flow). If you want ongoing monitoring after the act enforces, we offer Privacy Policy Auto-Refresh ($49/mo) which adds DPDPA to its 7-framework redline.
What's a Significant Data Fiduciary?
The Data Protection Board can designate any data fiduciary as "Significant" based on volume + sensitivity of data processed, risk to electoral democracy or sovereignty, and risk to data principals. Significant ones must: appoint a DPO based in India, conduct periodic Data Protection Impact Assessments, undergo independent audits. The tripwire analysis tells you if you're heading toward this designation.
Audit your India exposure today.
$19 one-time. PDF delivered within 24 hours.
Buy — $19 one-time →Decision-support, not legal advice. For binding DPDPA opinions, retain India-licensed counsel.