DPDP Act for NGOs in India: A Simple Compliance Guide
Your NGO holds donor PAN, phone numbers and beneficiary records. India's data protection law now covers all of it. Here is what to do, and by when.
Vivek Bhos
10 min read

Think about what your NGO actually holds.
Donor names, phone numbers, email addresses and PAN numbers. Volunteer ID copies. Staff salary records. And beneficiary files that often contain the most sensitive information of all — health conditions, disability, caste, income level, and details of children.
India now has a law covering every bit of that.
The Digital Personal Data Protection Act applies to any organisation handling people's digital personal data. There is no exemption for being a non-profit. If you hold it, you are responsible for it.
The good news: you have time. The bad news: most NGOs have not started, and the requirements will take longer than people expect.
The dates you need
India's data protection framework arrives in three stages.
Date | What happens |
|---|---|
13 November 2025 | Rules notified. Data Protection Board constituted. Complaints can already be filed. |
13 November 2026 | Consent Manager registration opens. Enforcement machinery becomes operative. |
13 May 2027 | Full compliance required — notice, consent, security, data rights, breach reporting, children's data, retention and deletion |
Your working deadline is 13 May 2027. No grace period is expected, because the Board already exists and is already able to receive complaints.
One thing to watch: in early 2026 there was discussion about compressing the 18-month window to 12 months for large-volume data handlers. That has not been confirmed by notification, so 13 May 2027 stands. But the asymmetry favours starting early — being ready sooner costs you a few idle months, whereas being caught short means rebuilding systems under pressure.
The words you need to know
Only three, and they are simple.
Data Principal — the person whose data it is. Your donor, volunteer, staff member or beneficiary.
Data Fiduciary — the organisation deciding what to do with that data. This is you. The word "fiduciary" is deliberate: you are holding something on trust for someone else.
Personal data — anything that can identify a person. Name, phone, email, PAN, photo, address.
The law covers digital personal data. Paper registers sitting in a cupboard are outside it — but the moment someone photographs that register or types it into Excel, it is in scope.
Where NGOs are most exposed
Be honest about which of these describe your organisation.
Donor PAN numbers in a spreadsheet. You collect PAN for Form 10BD. That file is often emailed between the office and the CA, sits in someone's personal Drive, and has no access control at all.
WhatsApp groups full of phone numbers. Every member can see everyone else's number. Nobody consented to that.
Beneficiary photos on social media. Especially photos of children. Often taken years ago, with no record of consent.
ID copies in shared folders. Aadhaar and PAN copies of volunteers and staff, in a folder half the office can open.
Data that is never deleted. Donor lists from 2014. Beneficiary files from programmes that closed. Under the law, you should delete personal data once its purpose has been served.
Staff using personal devices and accounts. Programme data on a field worker's personal phone, in a personal Gmail account.
If you recognised three or more, you are in the same position as most Indian NGOs. That is not a reason to panic, but it is a reason to start.
The obligations, in plain language
1. Give clear notice
Before or when you collect someone's data, tell them plainly: what you are collecting, why, and how they can complain or withdraw.
It must be a standalone notice in simple language, not a clause buried in a long document. It should also be available in English and Indian languages.
2. Get real consent
Consent must be free, specific, informed and unambiguous — a clear affirmative action.
Pre-ticked boxes do not count. "By donating you agree to everything" does not count.
And consent must be as easy to withdraw as it was to give. If someone signed up by tapping a button, they must be able to leave just as easily.
3. Collect only what you need
Ask for data you actually use. If you collect a beneficiary's caste, income and family details, be able to explain why each one is necessary. "We always have" is not a reason.
4. Keep it secure
Reasonable security safeguards are required. For most NGOs that means basics done properly: access limited to people who need it, passwords not shared, sensitive files not sitting in open folders, devices locked.
5. Delete it when done
Data should not be kept forever. When the purpose is finished, erase it. This means actually building deletion into your processes rather than accumulating files indefinitely.
6. Handle requests from people
Individuals can ask what data you hold, ask you to correct it, and ask you to erase it. You need a named person and a working process to answer those requests.
7. Report breaches
If data is lost, leaked or exposed, you must notify the Board and the affected people. Losing a laptop with beneficiary files is a breach.
Children's data: the part NGOs must read twice
If your NGO works with children — education, child protection, nutrition, sponsorship — this section applies directly to you.
Processing a child's data requires verifiable consent from a parent or guardian. Not the child's consent. Not the school's. The parent's, verifiably obtained.
There are also restrictions on tracking and behavioural advertising directed at children.
Think about what this means in practice:
A child sponsorship programme sharing a child's photo, name and story with a donor
Case files on children in a protection programme
Photographs of children posted on social media
Attendance and assessment records in an education project
Every one of these needs parental consent, documented. If your consent records are a verbal understanding from four years ago, that gap needs closing.
The penalties in this area are among the highest in the Act. More importantly, this is about the safety and dignity of children you exist to protect.
What it costs to get this wrong
Penalties under the Act run into hundreds of crores — up to ₹250 crore for failing to take reasonable security safeguards, with separate ceilings for other failures including those involving children's data.
Realistically, a small NGO is not the Board's first target. But three things should still concern you:
Complaints can already be filed. A disgruntled former employee, an unhappy donor, or a beneficiary's family can complain today.
Funders will start asking. Corporate CSR partners and international funders are already adding data protection questions to due diligence. A weak answer costs you funding long before any regulator appears.
A breach involving children is not survivable reputationally. Whatever the fine, that is the risk that should actually motivate you.
A realistic plan
You have until May 2027. Spread it out.
Now to December 2026 — find out what you have
☐ List every place personal data lives: spreadsheets, Drive folders, WhatsApp, email, paper, phones, your website
☐ For each, note what data, why you have it, and who can access it
☐ Delete what you no longer need. This is free and reduces your risk immediately
☐ Name one person as responsible for data protection
Early 2027 — fix the collection points
☐ Add a clear, plain-language privacy notice to your donation page and every form
☐ Replace pre-ticked boxes with genuine opt-in
☐ Add a proper consent step for photographs and stories
☐ Build parental consent into every process involving children
☐ Write a short privacy policy and put it on your website
Before May 2027 — tighten operations
☐ Restrict folder access to people who need it
☐ Stop storing ID copies in shared folders
☐ Move programme data off personal devices and personal email accounts
☐ Write a simple process for handling access, correction and erasure requests
☐ Write a simple breach response plan — who is told, in what order
☐ Set retention periods and actually delete on schedule
Five things you can do this week
None of these cost money.
Delete old data you do not need. Closed programmes, lapsed donor lists, duplicate spreadsheets.
Check who can access your donor file. Remove anyone who does not need it.
Stop sending PAN lists over email and WhatsApp.
Add one line to your donation form explaining why you collect PAN and how you use their data.
Ask whether you have parental consent for every child photo currently on your website and social media. Take down anything you cannot account for.
Common questions
We are a tiny NGO with three staff. Does this really apply? Yes. The Act does not exempt organisations by size or by non-profit status. What is expected of you is proportionate, but the obligations exist.
All our records are on paper. Are we covered? The Act deals with digital personal data. Purely paper records fall outside it — but almost every NGO has some digital data, and scanning a register brings it into scope.
Do we need to appoint a Data Protection Officer? A formal DPO is required for organisations designated as Significant Data Fiduciaries, which most NGOs will not be. But name someone internally anyway — data protection with nobody accountable does not happen.
What about donor data our CA holds? When you share data with someone processing it for you, you remain responsible. Ask your CA how they store it.
We have photos of beneficiaries from years ago with no consent record. What now? Review them. Remove anything sensitive, anything involving children, and anything you cannot justify. Going forward, take consent in writing at the time.
Does this affect foreign funding or FCRA? They are separate laws, but they overlap in practice. Donor and beneficiary data linked to foreign-funded programmes sits under both. Keep both sets of records clean.
Is 13 May 2027 definitely the deadline? It is the operative date today. There has been discussion of compressing the timeline for large data handlers, unconfirmed so far. Plan for May 2027 and start early.
The honest summary
Most Indian NGOs are not close to compliant, and most do not yet know it.
But this is not primarily a legal problem. The people who trust you with their data are the same people you exist to serve — a mother giving her child's photograph, a donor giving their PAN, a beneficiary describing their circumstances. Handling that carefully is the same duty you already hold.
Start with deletion and access control. They cost nothing and remove most of your immediate risk.
Sevastack keeps donor, volunteer and beneficiary data in one controlled system with role-based access, consent recorded against each record, and retention you can actually manage — instead of spread across spreadsheets, Drive folders and WhatsApp. Start free — no credit card needed.
This article is general information, not legal advice. The DPDP framework is being implemented in stages and guidance continues to develop. Please take professional advice on your organisation's position.
Related guides
Vivek Bhos
Written by the Sevastack team, who build and maintain the 80G receipt, FCRA, and Form 10BD/10BE automation used by Indian NGOs on the platform every day. Compliance guidance is reviewed against current Income Tax Act and FCRA rules before publishing.
Read next
Never miss a filing date
Sevastack keeps your NGO's compliance calendar and reminds you by email and WhatsApp before each return is due. Donors, 80G receipts and accounts sit in the same place.


