DPDP compliance by industry.
One law, different pressure points.
Every Data Fiduciary owes the same duties under the DPDP Act. What changes by sector is which duty is hardest to meet, and which one gets missed. This is what we see in each.
The obligation each sector misses
Same law, same duties. What differs is which one is hardest to meet in practice, and in every sector below, the commonly missed obligation is not an obscure one.
| Sector | Most often missed |
|---|---|
| Healthcare & diagnostics | Assuming health data is a special category |
| Financial services & fintech | Treating RBI retention and DPDP erasure as a conflict |
| EdTech & children's services | Believing parental consent unlocks advertising |
| E-commerce & D2C | Running advertising tags before the banner is answered |
| B2B SaaS & technology | Forgetting you hold both roles at once |
| Insurance | Retaining declined-proposal data indefinitely |
| Travel & hospitality | Cross-border transfer without recording where data went |
| Telecom & media | Assuming licence conditions displace the Act |
Healthcare & diagnostics
Typically holds: Patient identifiers, diagnoses, prescriptions, imaging, lab results, insurance details
This is the single most common misconception, and it runs the other way to what people expect. The DPDP Act creates no special category of sensitive personal data. Unlike GDPR Article 9, which singles out health data for additional conditions, the Act applies the same obligations to a diagnosis as to an email address. The only category-based carve-out in the whole statute is children's data under section 9.
That has two consequences, and hospitals tend to get both backwards. The first is that health data needs no special legal basis beyond ordinary consent: teams building elaborate consent architectures for clinical data are often solving a GDPR problem that does not exist here. The second is more serious: because there is no special category, there is also no special exemption. The routine sharing of patient data with labs, insurers and billing vendors is a disclosure to a processor like any other, and needs a notice, a purpose and an agreement.
The genuine complication is retention. Section 8(7) requires erasure once consent is withdrawn or the purpose is served, but medical record retention is mandated separately, and clinical establishment rules in most states require records to be kept for years. Those obligations do not contradict each other: retention required by law is an explicit exception. What the Act requires is that you can name the law you are relying on, per record, rather than keeping everything indefinitely because deleting is hard.
DPDP s.7(f) · s.8(7) · s.9
Financial services & fintech
Typically holds: KYC documents, transaction history, credit data, account numbers, device and location signals
RBI directions require KYC records to be retained for years after an account closes. Section 8(7) requires erasure when the purpose is served. Compliance teams read these as contradictory and usually resolve it by doing nothing.
They are not in conflict. Retention required by law is an exception to the erasure duty, but the Act expects you to identify which law, for which data, for how long. A blanket "we're regulated, we keep everything" is the position that fails an inspection, because it cannot distinguish the KYC document you must keep from the marketing preference you must not.
The second issue is specific to this sector: the Account Aggregator framework has its own consent architecture, governed by RBI, which is separate from and additional to DPDP consent. An AA consent artefact is not a DPDP notice, and holding one does not discharge section 5.
DPDP s.6(1) · s.8(7) · RBI KYC Directions
EdTech & children's services
Typically holds: Student names and ages, performance data, behavioural analytics, parent contact details
Section 9 is the hardest provision in the Act and the one most often misread. It requires verifiable parental consent for anyone under eighteen, which teams generally do implement. What they miss is the second half: tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright.
That is a hard prohibition, not a consent question. A parent cannot authorise it. No consent flow, however well built, makes behavioural advertising to a fifteen-year-old lawful. If your product runs an analytics SDK that profiles users and you serve under-18s, the fix is removing the SDK for those users, not adding a checkbox.
Eighteen is also higher than almost every comparable regime. COPPA sets thirteen; GDPR permits member states to set between thirteen and sixteen. A product built to a US or EU children's standard is not compliant here by default.
DPDP s.9(1) · s.9(2) · s.9(3)
E-commerce & D2C
Typically holds: Order history, addresses, payment tokens, browsing behaviour, marketing preferences
This sector has the most third-party tags of any, and the widest gap between what the banner says and what the page does. A scan of a typical Indian D2C site finds Meta Pixel, Google Ads, GA4 and two or three affiliate scripts firing on load, before the visitor has answered anything.
A banner that appears after the tags have fired does not create consent. It documents the absence of it, with a timestamp. That is materially worse than having no banner at all, because it demonstrates you knew the obligation existed.
The second exposure is retention. Purchase history is retained legitimately for warranty, returns and tax. Browsing behaviour attached to an identified customer usually is not, and is kept indefinitely because nobody set a period.
DPDP s.6(1) · s.8(7) · ePrivacy Art. 5(3)
B2B SaaS & technology
Typically holds: Customer end-user data as a processor, plus your own users, leads and website visitors
A B2B SaaS company is a Data Processor for the data its customers put into the product, and a Data Fiduciary for its own website visitors, trial signups, marketing list and employees. The obligations differ, and most teams build for one and forget the other.
As a processor, your duties come from the contract with your customer plus section 8(5) security safeguards. As a fiduciary for your own marketing site, you owe notice, consent, withdrawal and erasure directly to visitors: the same duties your customers owe theirs.
In practice the gap is almost always the marketing side. The product has audit logs, encryption and access control; the website has a cookie banner that was installed once and a HubSpot form with no consent record behind it.
DPDP s.8(2) · s.8(5) · GDPR Art. 28
Insurance
Typically holds: Health declarations, claims history, medical reports, nominee details, financial data
Underwriting collects a great deal of health and financial information from people who then do not become customers. The purpose, assessing a proposal, is served the moment the proposal is declined or lapses. Section 8(7) says erase.
In practice this data is retained, usually to detect fraud on future applications. That may be defensible, but it is a different purpose from the one consent was given for, and it needs its own basis and its own retention period rather than being carried silently.
IRDAI record-keeping requirements apply to policies issued. They do not automatically extend to proposals that were never accepted, which is the distinction that gets missed.
DPDP s.6(1) · s.8(7) · s.14
Travel & hospitality
Typically holds: Passport and ID data, itineraries, payment details, loyalty profiles, stay history
This sector moves personal data across borders constantly and as a matter of routine: to airlines, global distribution systems, hotel chains and overseas partners. Section 16 permits transfer except to countries the government restricts, which is a permissive regime compared with GDPR.
Permissive is not the same as unrecorded. The obligation that bites is knowing which data went where, because a rights request or an inspection asks exactly that. Most operators cannot answer it, since the transfer happens inside a booking integration nobody has mapped.
Passport and government ID data also attracts a higher practical standard under section 8(5), not because the Act says so explicitly, but because the consequence of losing it is severe and the Board will weigh that.
DPDP s.16 · s.8(5)
Telecom & media
Typically holds: Subscriber identity, CDRs, location, viewing and listening history, device identifiers
Telecom licensees operate under DoT conditions that already mandate subscriber verification and data retention. The common assumption is that these supersede DPDP. They do not: they sit alongside it, and licence-mandated retention is an exception to erasure, not an exemption from notice, purpose limitation or rights.
The exposure sits in the commercial layer rather than the regulated one. Location and viewing history used for advertising or recommendations is processing for a purpose the subscriber did not agree to when they bought a connection.
Media platforms have the additional question of age. If a meaningful share of your audience is under eighteen, section 9's prohibition on behavioural advertising applies to them regardless of what the account holder agreed to.
DPDP s.7 · s.9 · s.8(7)
What is the same everywhere
The sector determines the pressure point, not the duty. Regardless of what you sell:
- Notice before consent: section 5(1), in English or an Eighth Schedule language, stating what is collected and why.
- Consent that is specific: section 6(1). One consent for one purpose. Bundling is the most common defect we find.
- Withdrawal as easy as consent: section 6(4), and it has to reach your processors, not just stop your own processing.
- Erasure when the purpose is served: section 8(7), unless a named law requires retention.
- Proof: section 6(10) puts the burden on you. A boolean flag in a database is not proof of what someone was shown.
The last one is what the product exists for. A banner is a user interface; the record behind it is what you produce when the Board asks you to demonstrate consent.
Sector pages
Each sector in depth: the laws that apply, the obligation that gets missed, and a control checklist.
- Healthcare: DPDP, ABDM, telemedicine and medical records
- Fintech: DPDP with RBI, SEBI and PMLA
- EdTech: children's data and verifiable parental consent
- E-commerce: tags, dark patterns and erasure
- B2B SaaS: processor and fiduciary at once
- Insurance: DPDP with IRDAI's 2026 guidelines
- Travel and hospitality: transfers, guest reporting and PNR
- Telecom and media: TRAI, DLT and DoT rules
Regulator guides: RBI cybersecurity · SEBI CSCRF · IRDAI guidelines · India AI governance
The things people ask us
Does the DPDP Act treat health data as sensitive personal data?
No, and this is the most common misconception in the sector. Unlike GDPR Article 9, the Act creates no special category of sensitive personal data: the same obligations apply to a diagnosis as to an email address. The only category-based provision in the statute is section 9, on children. That cuts both ways: health data needs no special legal basis, and it gets no special exemption either.
Can a parent consent to behavioural advertising for their child?
No. Section 9 prohibits tracking, behavioural monitoring and targeted advertising directed at children outright: it is not a consent question, so parental consent cannot authorise it. The threshold is eighteen, which is higher than COPPA's thirteen or the GDPR's thirteen-to-sixteen, so a product built to a US or EU children's standard is not compliant here by default.
Do RBI retention rules conflict with the DPDP erasure duty?
No. Retention required by law is an exception to section 8(7). What the Act expects is that you can name which law, for which data, for how long: a blanket "we are regulated so we keep everything" fails, because it cannot distinguish the KYC document you must keep from the marketing preference you must not.
We are a B2B SaaS company. Are we a processor or a fiduciary?
Both, at the same time. You are a processor for the data your customers put into your product, and a fiduciary for your own website visitors, trial signups, marketing list and employees. Most teams build for the first and forget the second: the gap is almost always the marketing site rather than the product.
Does an Account Aggregator consent artefact satisfy the DPDP Act?
No. The AA framework has its own consent architecture governed by RBI, which is separate from and additional to DPDP consent. Holding an AA artefact does not discharge the section 5 notice obligation.
Which sector has the largest exposure?
In what we see, edtech and anything serving under-eighteens, because section 9 is a prohibition rather than a consent requirement, so it cannot be fixed with a better banner. E-commerce carries the most volume of routine breach, with advertising tags firing before the banner is answered on most sites we scan.
Find out what your site does today.
The scanner loads any site twice, with and without consent, and reports exactly what fired before permission was given. No account, no card.