DPDP Act 2023 and tender data: what changed
The DPDP Act has implications for any platform handling Indian business data. Here is our compliance playbook.
The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive data-protection law. For any platform that handles business and personal data — including tender intelligence platforms — it sets clear expectations around consent, purpose limitation, and data security.
Here is how we read the Act and how we built TenderGuruji to comply from day one.
Public data vs. customer data
Tender notices and historical results are public-domain government information. Customer data — your keyword libraries, saved searches, team members, and usage — is different, and we treat it accordingly. The two are kept architecturally separate and isolated per tenant.
Consent, purpose, and minimisation
We collect only the data we need to deliver the service, use it only for the purpose it was collected, and give customers clear control over it. Purpose limitation and data minimisation are not just legal requirements under the DPDP Act — they are good engineering defaults.
What this means for you
As a customer, your competitive intelligence — the keywords you track, the buyers you watch — stays yours. It is never shared across tenants, and it is protected with the security controls the DPDP Act expects. Compliance is built into the product, not bolted on later.
See how this works inside TenderGuruji.
Live tenders, 22M+ historical results, and BOQ-level pricing in one workspace.
Start free