DPDP Act: are compliance costs of privacy law crushing ed-tech businesses?
Must read — 2 past UPSC questions on this theme (Prelims GS-1 2018, Mains GS-2 2017).
2-minute summary
The implementation of India's Digital Personal Data Protection (DPDP) Act, 2023 is significantly reshaping the operational landscape for the education technology (ed-tech) sector. With the DPDP Rules notified in November 2025 and full compliance mandated by May 2027, companies are facing substantial recurring compliance costs. Ed-tech firms, which routinely collect sensitive student data like quiz scores, biometric identifiers, and AI tutor interactions, must now integrate with government-registered Consent Managers, conduct independent audits, and perform Data Protection Impact Assessments (DPIAs). Compliance costs are estimated to range from ₹3 lakh to ₹8 lakh per month for startups, rising up to ₹50 lakh for large enterprises. While some industry players view these expenses as a heavy regulatory burden that could stifle innovation, others argue that they represent necessary, long-deferred data governance measures essential for safeguarding vulnerable young internet users.
Why it's in the news
Following the notification of the DPDP Rules in November 2025, ed-tech companies are grappling with high compliance costs ahead of the upcoming enforcement of penalties and the mandatory consent manager registration system in late 2026, leading to debates on the balance between data privacy and the ease of doing business.
Background and context
The Digital Personal Data Protection (DPDP) Act, passed by Parliament in August 2023, is India's first comprehensive legislative framework dedicated to personal data protection. It emerged after years of deliberation following the landmark Supreme Court judgment in Justice K.S. Puttaswamy v. Union of India (2017), which declared the Right to Privacy a fundamental right under Article 21. The Act establishes a framework of rights and duties for 'Data Principals' (individuals) and obligations for 'Data Fiduciaries' (entities determining the purpose and means of processing data). It also introduces 'Significant Data Fiduciaries' (SDFs) based on factors like volume of data and risk to national security, requiring them to undertake extra measures like appointing a Data Protection Officer (DPO) and conducting regular data audits.
Constitutional provisions
- Article 21 — Guarantees the Right to Life and Personal Liberty. The Supreme Court in the Puttaswamy (2017) judgment ruled that the Right to Privacy is an intrinsic part of Article 21, which forms the constitutional basis for the DPDP Act.
Committees and reports
- Justice B.N. Srikrishna Committee on Data Protection — Formulated the draft Personal Data Protection Bill and laid down the foundational principles of data utility, consent-based processing, and data sovereignty that eventually shaped the DPDP Act, 2023.
International organisations
- European Union (General Data Protection Regulation - GDPR) — The global benchmark for data privacy laws. India's DPDP Act shares similarities with GDPR regarding consent, data principal rights, and penalties, though India's model introduces unique elements like 'Consent Managers'.
Previous UPSC questions on this theme
- Prelims GS-1 2018 — Right to Privacy is protected as an intrinsic part of Right to Life and Personal Liberty. Which of the following in the Constitution of India correctly and appropriately imply the above statement ? (a) Article 14 and the provisions under the 42nd Amendment to the Constitution (b) Article 17 and the Directive Principles of State Policy in Part IV (c) Article 21 and the freedoms guaranteed in Part III (d) Article 24 and the provisions under the 44th Amendment to the Constitution
- Mains GS-2 2017 — Examine the scope of Fundamental Rights in the light of the latest judgement of the Supreme Court on Right to Privacy.
Mains practice: While the Digital Personal Data Protection (DPDP) Act, 2023 is a landmark step towards securing citizen privacy, its compliance framework poses significant structural and financial challenges for India's startup ecosystem, particularly ed-tech. Discuss.
The Digital Personal Data Protection (DPDP) Act, 2023 represents a paradigm shift in India's digital governance, aiming to secure individual privacy while facilitating a robust digital economy. However, the transition to this strict regulatory regime has introduced substantial compliance hurdles for startups, particularly in the ed-tech sector.
**Compliance Challenges for the Ed-Tech Sector:**
• **High Financial Burden:** Compliance costs for startups and SMEs range from ₹3 lakh to ₹8 lakh monthly, driven by the need for technical retrofitting, independent audits, and legal consultations. This diverts scarce capital away from core product innovation and R&D.
• **Strict Safeguards for Children's Data:** Ed-tech platforms primarily process data of minors. The DPDP Act mandates verifiable parental consent and prohibits tracking, behavioral monitoring, or targeted advertising directed at children. Implementing these verification mechanisms is technically complex and costly.
• **Integration with Consent Managers:** Under the Act, data principals can give, manage, or withdraw consent through registered 'Consent Managers'. Ed-tech firms must build or license interoperable infrastructure to integrate with these platforms, adding operational layers.
• **Onerous Obligations for SDFs:** Companies classified as Significant Data Fiduciaries (SDFs) must appoint an India-based Data Protection Officer (DPO), conduct periodic Data Protection Impact Assessments (DPIAs), and undergo regular audits, creating sustained operational costs.
**The Counter-Perspective:**
Conversely, proponents argue that these compliance costs represent necessary, long-deferred data governance. Protecting vulnerable users (like children) from commercial exploitation, data leaks, and profiling is a non-negotiable public interest. Strong privacy compliance can also build consumer trust, helping Indian startups scale globally by aligning with international standards like GDPR.
**Conclusion:**
To prevent data protection from becoming 'regulatory cholesterol' for startups, the government should adopt a graded compliance approach. Providing compliance subsidies, simplified consent templates, and regulatory sandboxes for MSMEs can help balance the dual objectives of safeguarding privacy and fostering digital entrepreneurship.
Prelims practice questions
Q1. With reference to the Digital Personal Data Protection (DPDP) Act, 2023, consider the following statements: 1. A 'Data Principal' refers to the individual whose personal data is being processed. 2. A 'Consent Manager' is a data fiduciary registered with the Data Protection Board of India to enable individuals to give, manage, and withdraw consent. 3. The Act completely exempts startups from all compliance obligations to promote the ease of doing business. Which of the statements given above is/are correct?
- 1 and 2 only
- 2 and 3 only
- 1 and 3 only
- 1, 2 and 3
Answer: A. Statements 1 and 2 are correct. Under the DPDP Act, a Data Principal is the individual to whom the personal data relates. A Consent Manager is an entity that helps Data Principals manage their consent. Statement 3 is incorrect; while the government may exempt certain startups from specific provisions (like data retention limits or DPIAs), they are not completely exempt from all compliance obligations, especially regarding basic data security and children's data.
Q2. Under the Digital Personal Data Protection (DPDP) Act, 2023, which of the following are mandatory obligations for an entity classified as a 'Significant Data Fiduciary' (SDF)? 1. Appointing an India-based Data Protection Officer (DPO). 2. Conducting periodic Data Protection Impact Assessments (DPIAs). 3. Appointing an independent data auditor to carry out data audits. Select the correct answer using the code given below:
- 1 and 2 only
- 2 and 3 only
- 1 and 3 only
- 1, 2 and 3
Answer: D. All three are mandatory obligations for a Significant Data Fiduciary (SDF) under the DPDP Act, 2023. They must appoint a DPO who reports to the Board, conduct regular DPIAs, and hire an independent auditor to ensure compliance.
Q3. Which of the following bodies is established under the Digital Personal Data Protection Act, 2023 to resolve disputes, direct compliance, and impose penalties for data breaches?
- Unique Identification Authority of India (UIDAI)
- Data Protection Board of India (DPBI)
- Cyber Appellate Tribunal
- National Cyber Security Coordinator
Answer: B. The Data Protection Board of India (DPBI) is the statutory body established under the DPDP Act, 2023, tasked with monitoring compliance, directing inquiry into data breaches, and imposing financial penalties.
Revision flashcards
- What is a 'Data Fiduciary' under the DPDP Act, 2023? Any person or entity (alone or in association with others) that determines the purpose and means of processing personal data.
- What is a 'Consent Manager' under the DPDP Act? A data fiduciary registered with the Data Protection Board of India (DPBI) that enables a Data Principal to give, manage, review, and withdraw her consent through an accessible, transparent, and interoperable platform.
- What are the restrictions on processing children's data under the DPDP Act? Data fiduciaries must obtain verifiable parental consent, cannot process data that is likely to cause harm to a child, and are prohibited from tracking, behavioral monitoring, or targeted advertising directed at children.
- Who appoints the Data Protection Officer (DPO) under the DPDP Act, and what is their role? Significant Data Fiduciaries (SDFs) must appoint an India-based DPO who reports to the Board of Directors and serves as the point of contact for grievance redressal and compliance.
- What is a 'Data Protection Impact Assessment' (DPIA)? A mandatory process for Significant Data Fiduciaries to identify, analyze, and mitigate risks associated with processing personal data, ensuring compliance and privacy-by-design.