The Digital Personal Data Protection Act (DPDP Act) governs how organisations in India collect, store, and use personal data. In November 2025, the Ministry of Electronics and Information Technology government notified the act and the DPDP Rules, and organisations have until May 2027 to become compliant. The act applies to any entity that collects personal data, which includes nonprofits. For a sector that has long relied on field staff, offline forms, and informal channels such as WhatsApp to collect and share information about the people it serves, the act means rethinking how data moves through an organisation, from the point it is collected to the point it is deleted.
In my experience leading the DPDP vertical within Project Tech4Dev’s Fractional CXO team, the following questions emerge most frequently in discussions with nonprofits about the act.
1. Why should nonprofits care about the DPDP Act? Does it apply differently to a small organisation as opposed to a large one?
The act applies to nonprofits just as it does to any other entity that collects personal data. It is particularly challenging for this sector because programmes often run in silos, without consistent processes for collecting, storing, or managing personal data. A lot of the work happens through offline field technology, and information is often shared over WhatsApp simply because it’s a convenient channel. This makes it harder to have oversight of what is being shared, how it is transferred, and what is being collected in the first place.
Nonprofits also work in sensitive areas such as education involving minors, or health, including maternal or mental health, which means they end up collecting confidential personal data. Many of the people they work with come from vulnerable communities who may not be aware of their data rights. This places a greater responsibility on nonprofits to handle data carefully and protect the populations they serve.
Unlike a multinational company, where the entire relationship with a customer is digital, from sign-up to consent and the withdrawal thereof, most nonprofit relationships are not. Data collection usually happens through field staff, and information may be collected through various apps or could be gathered physically before being digitised. This makes it harder to map the entire data journey and fortify points where information could leak.
For smaller nonprofits, compliance with the act is about building better processes around the tools they already use.
On the question of size, the act distinguishes between a data fiduciary and a significant data fiduciary, though the rules have not yet clarified what qualifies an organisation as the latter. In practice, the biggest difference between large and small nonprofits is complexity. Larger nonprofits have more programmes, work across more states and schemes, and often run multiple systems in parallel, so they have to do more work to bring every aspect onto the same page. Regardless of size, every organisation should have one person internally responsible for DPDP compliance, even if they are not legally required to appoint a data protection officer (DPO).
But this does not necessarily mean hiring someone new. Smaller organisations without in-house tech teams often add this as a responsibility for one of their existing staff members. The important thing is that the appointed person should also have the authority to make changes, so the responsibility does not end up sitting with everyone and no one at once.
The act also does not prescribe a particular kind of platform for data collection or storage. It is therefore acceptable for data to sit in a Google Sheet, for example. The real questions are how securely it sits there, who has access to it, and whether an organisation can monitor how it is shared and used. For smaller nonprofits, compliance with the act is therefore about building better processes around the tools they already use as opposed to necessarily spending on new technology.
2. In your experience, what gaps commonly need to be addressed by nonprofits aiming to be compliant?
Through Project Tech4Dev’s interactions with organisations so far, the biggest gaps consistently show up around governance and the rights of individuals. Most organisations were already doing something around taking basic consent, storing data with some security, and using it with reasonable responsibility, even if they were not fully compliant. What is new is the idea that a data principal, the person the data belongs to, now has the right to ask an organisation what data it holds about them, have that data deleted, review or revoke consent, and raise a complaint if needed.
Equally new is the expectation of auditable governance, meaning organisations need a process to respond to complaints or questions from data principals, and have the ability to identify and report a data breach as required. These processes largely did not exist before, which is why they show up as the weakest areas in the assessments that we did.
3. What counts as personal data? Would previously collected data need to be re-categorised?
The act uses a broad definition of personal data, which is different from how laws in other countries separate categories like personally identifiable information and sensitive data. As per the act, personal data refers to anything that can help identify a person and exists in a digital format. This includes information collected physically and later digitised.
Identifiability is interpreted broadly too. It covers direct identifiers such as a name, phone number, or Aadhaar number, as well as indirect identifiers—information that on its own does not identify someone but does so when combined with other data points. It also includes sensitive data such as health information, or caste, which is firstly confidential, and secondly may not identify a person by itself but can when combined with other details.
The act applies retrospectively, so historical data is also covered. Nonprofits need to check what data they hold and what consent, if any, was taken for it. Where proper consent was not taken, organisations are expected to either go back and obtain consent or anonymise or erase the personal data altogether.
4. What does meaningful consent look like as per the act?
Meaningful consent has to be simple, clear, and explicit. It should not be buried inside a larger document. It should be presented on its own, in simple terms rather than legal wording, and in a language the person actually understands, which matters especially for nonprofits working across rural India.
The consent itself needs to be itemised, spelling out what data is being collected, such as an e-mail address or phone number, and why that data is being collected, such as registering someone for a service. It also needs to disclose anything else the organisation plans to do with the data, and the expected retention period. Finally, it needs to inform people of their rights, including the right to withdraw consent at any time, and give them a specific way to do so, such as a phone number or an e-mail address.

5. What should nonprofits stop doing? Can they still share data with funders, researchers, or partners?
A few common practices need to change immediately. Sharing personal or confidential information over WhatsApp is convenient but not secure. Sending personal or sensitive data through unencrypted, unprotected e-mails or spreadsheet attachments, whether internally or externally, also needs to stop. Instead, organisations can rely on restricted-access Google Drive folders for smaller datasets, and secure transfer systems like S3 buckets for larger or more sensitive ones. Broadly, default access to data, where everyone in an organisation can see everything, should be replaced with need-based access, so people only see what is relevant to their role. Organisations should also only collect what they actually need for a stated purpose. Holding less personal data reduces the compliance burden, so there is no reason to collect identifiers like Aadhaar or PAN details unless the work genuinely requires it. If such identifiers are needed, they should be accessed via secure services like DigiLocker, or stored under strong encryptions.
Given how broad the act’s requirements can feel, it helps for organisations to prioritise where their biggest risks actually are, rather than trying to fix everything at once. This could mean focusing first on the project collecting the most sensitive information or the highest volume of personal data. Losing an e-mail address is a relatively smaller problem, since it might lead to spam, but losing PAN details could expose someone to financial fraud, which is a much bigger risk. Securing the highest-risk areas first gets an organisation most of the way there, even if it is not fully compliant everywhere at once.
The act does not prevent nonprofits from sharing data with funders, researchers, or partners. It just requires special considerations with adequate security mechanisms for sharing data. The law places the decision-making power with the data principal, so sharing is allowed as long as consent has been taken for it. This should be built in at the point of collection, specifying that data may be shared with a funder for audit purposes, for instance. The same principle of data minimisation applies to sharing. A funder conducting an audit may only need names and numbers rather than a person’s full health record, and organisations should work that out before sharing any information. Data should move through secure channels rather than unencrypted attachments. Partners and vendors should also be made aware of their own obligations under the act, ideally through contracts or MOUs that specify what can be shared, require the partner to follow reasonable safeguards as a data processor, and require them to delete the data once its purpose is served, such as within three months of an audit ending. As the data fiduciary, the organisation carries the legal responsibility if something goes wrong, so it is worth ensuring partners are not, for example, downloading shared data onto personal devices.
The same thinking extends to annual reports and impact stories. The act does not prohibit publishing personal data if consent for that has been taken, but most organisations anyway tend to use aggregated numbers rather than identifying individuals. Many are also moving towards AI-generated images instead of real photographs, taking group photos from a distance that do not identify anyone, or changing names when telling a person’s story. These are all ways to protect someone’s identity while still painting a meaningful picture of ground impact.
6. What can a small organisation without a dedicated data or IT resource do if it detects a data breach?
A data breach can happen in several ways, through human error like attaching the wrong file to an e-mail, a phishing attack that tricks an employee into handing over access, an unencrypted platform or server that gets hacked, a leak caused by a third party, or in some cases an employee acting with malicious intent. Detecting a breach starts with setting up basic monitoring across the platforms an organisation uses. This includes watching for unusual account activity, such as access during off hours, unauthorised user creation, or sudden additions to an admin group. It also includes monitoring data movement, such as unexpected spikes in outgoing data volume, unusual billing surges, or an internal system communicating repeatedly with an unknown server. Sometimes a breach only comes to light because a data principal reports it directly.
As soon as a breach is discovered, the organisation must notify the DPDP board under the government, with basic details of what happened and who was affected.
The immediate, practical steps once a breach is identified are to change passwords and credentials quickly, since password leaks are one of the most common ways breaches happen, and to remove any data that may be sitting in an unprotected or exposed location. Where the organisation lacks in-house technical or legal expertise, it should bring in outside help quickly, since the act carries specific statutory obligations. As soon as a breach is discovered, the organisation must notify the DPDP board under the government, with basic details of what happened and who was affected, and follow up within 72 hours with a more detailed written report that includes a root cause analysis and the steps taken to address it. Organisations are also required to inform the affected data principals directly as quickly as possible, including what data was affected and what they can do to protect themselves.
7. What rights do the communities nonprofits work with now have?
Organisations must seek communities’ consent in their own language so they understand what personal data is being collected and why. As parents and legal guardians, their verifiable consent needs to be sought before their child’s personal data is collected.
Data principals can ask an organisation at any time what data it holds about them, and have that data corrected if it is wrong. This request should go to the person or e-mail address named in the consent notice and may come via various channels. They can request erasure, meaning their personal data is completely removed from an organisation’s systems. They can raise a complaint to the organisation or DPDP board if they feel their data has been used inaccurately or if a breach has occurred. A data principal can also assign someone else, such as a family member, to exercise these rights on their behalf. This matters particularly for nonprofits, since many of them work with marginalised communities whose access to technology and data literacy is often limited. Further, the penalties under DPDP are significant. That makes it especially important for nonprofits to collect and use data responsibly on their behalf and make grievance redressal as easy as possible.
8. What’s the biggest prevailing misconception about the act?
The act can feel like a massive compliance burden when looked at as a whole. A preferred approach here is to break it down into smaller, tangible tasks, such as fixing a privacy policy document, adding encryption to a data warehouse, or setting up an access log, rather than treating it as one enormous project. Another common gap in understanding is around how the data of minors or people with disabilities who have a legal guardian needs to be treated differently when it comes to consent and processing. This is important as many organisations work with children and people with disabilities and must prepare for the additional responsibilities in collecting their personal data.
It is good practice to anonymise the data once it has served its research purpose.
Another common misconception concerns the research exemption provision. The act does provide an exemption from notice and consent requirements when data is collected for research. However, this exemption has limits. The data cannot be used to make individual-level decisions or build individual-level models. It is only permitted when the research produces aggregated inferences. Organisations still have to follow security safeguards around how personal data is stored and processed, and cannot be careless with it. Data principals also retain some of their rights under this exemption, such as the right to know what is held about them and to ask for a correction. It is good practice to anonymise the data once it has served its research purpose. Overall, the exemption reduces part of the compliance burden but does not remove all obligations.
9. Beyond compliance, what does responsible data stewardship look like? Can the act ultimately strengthen the bond between organisations and the communities they serve?
This is a real opportunity for nonprofits to build better data practices generally, since the sector has historically had weaker data processes than the for-profit world, often holding on to data indefinitely. Good data stewardship starts with data minimisation, collecting only what is needed and not retaining data once its purpose is over, such as personal information from a project that ended a decade ago. It also means putting in reasonable safeguards, restricting access to those who need it, and avoiding unsecured channels for sharing.
Compliance itself is a mix of technology, such as encryption and secure password storage, legal steps like putting formal contractual obligations on vendors and partners, and, most importantly, changes to everyday processes and field SOPs covering how data is collected, handled, stored, and accessed. Much of this depends on staff training and helping people within the organisation understand why these changes matter, since shifting long-standing ways of working tends to meet resistance. Useful steps include regular information sharing on the topic, creating new SOPs, and having designated data or DPDP champions across different teams.
With respect to trust, the act changes the historical one-way flow of communication between nonprofits and communities, where people share personal details and are the subjects of surveys without much in return. By requiring organisations to explain what data they are collecting, the reason for data collection, and what people can do if they are not comfortable with it, the act puts both parties on more equal footing. Nonprofits are also well placed to become a source of data literacy in rural India, since for many people, a nonprofit may be the first place they hear about the DPDP act and their rights under it.
—
Know more
- Learn more about how nonprofits can ensure compliance with India’s data protection regulations.
- Read this primer about the DPDP act and how it applies to nonprofits.






