Data Protection Risk and Compliance in Startup Investments: A Due Diligence Framework under the Digital Personal Data Protection Act, 2023
Abstract
The Digital Personal Data Protection Act of 2023 took its first real bite on 13 November 2025, when the Ministry of Electronics and Information Technology notified the operative Rules and set the clock for full enforcement to 13 May 2027. Indian venture capital was busy with other things. The industry deployed about USD 12 billion across 159,157 DPIIT-recognised startups in 2025 without any standard way of asking whether those startups could survive the new law. This paper builds the missing tool. It is a complete due diligence framework calibrated to the DPDP, designed for use by venture capital firms, private equity funds, angel networks, accelerators, and the lawyers who serve them. The framework has four parts: a twelve-stage diligence sequence that walks the investor through every place a DPDP problem can hide; a Startup Data Risk Score on one hundred points that converts diligence findings into a single number; a Privacy Compliance Maturity Model with five tiers that lets the investor compare one startup against another; and an Investor Risk Rating Framework that turns the score into term-sheet line items — how much to discount the valuation, how large an indemnity to take, how much to keep in escrow, and how long the survival period should run. The urgency is not theoretical: the IBM Cost of a Data Breach Report 2025 records that the average breach in India now costs INR 220 million, and incidents at Byju’s, Hathway, boAt, BSNL and Mobikwik confirm the same risk lives at every layer of the Indian digital economy.