Sector wise readiness
Crypto and VDA exchanges: decentralised is not exempt
- Does DPDP apply to crypto exchanges and Web3 platforms?
- Yes, in full, if you serve Indian users. Decentralised and global does not make Indian data law sit lightly. You hold some of the most targeted data in the country while carrying KYC and AML duties that stop you erasing on request.
- Who this affects
- Exchanges, wallets and Web3 platforms with Indian users.
- What to do about it
- Hold a high security bar, and document the reconciliation between the erasure duty and your KYC and AML retention.
A misconception I keep seeing when crypto and Web3 teams read DPDP checklists: "we are decentralised and global, so Indian data law sits lightly on us."
It does not. If you run an exchange, a wallet or a Web3 platform serving Indian users, you hold some of the most sensitive, most targeted data in the country, and DPDP lands on it in full.
This sector is defined by two forces pulling at once. You are a high value attack target, so your security bar is unforgiving. And you carry heavy KYC and AML duties, so you cannot simply erase on request. Getting both right at once is the whole game.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent and easy withdrawal
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What crypto lives and dies on from day one
- ✅ KYC and identity security. Encrypt or tokenise KYC and identity data, with strict access control. These are the crown jewels, and it is a day one duty, not a scale duty.
- ✅ Retention reconciliation. DPDP says erase when the purpose ends. PMLA and VDA reporting rules say keep. The lawful hook for holding data past the DPDP purpose is the Rule 8(3) proviso, retention where another law requires it. Document that basis dataset by dataset. Do not assume "crypto keeps everything."
- ✅ Cross border and custody mapping. Offshore infrastructure and custody are the norm here. Map every transfer out of India, and meet any Central Government restriction on a destination.
- ✅ Breach and wallet security. As a high value target, breach detection has to be genuinely fast, tuned to the 72 hour clock and to attackers who are actively hunting you.
What may not apply yet, and stays separate
- ❌ SDF obligations. Large exchanges are plausible candidates to assess, but Significant Data Fiduciary status comes only on Government notification, not from trading volume or user count.
- ❌ A mandatory Data Protection Officer, independent audits and algorithmic due diligence. These attach to SDF status once notified.
The better question
The better question is not "does global crypto really have to follow this?"
It is "can I secure KYC data to a target grade bar, and prove a lawful basis for everything I retain past its purpose?"
Law creates obligations. Scale and risk influence implementation. But KYC security and retention reconciliation are day one disciplines. Neither waits for you to get big.
If you run a VDA platform, is your retention basis documented dataset by dataset, or assumed?