Skip to content
All field notes
compliance

DPDP Act 2023 and tender data: what changed

The DPDP Act has implications for any platform handling Indian business data. Here is our compliance playbook.

COMPLIANCE 6 min readDECEMBER 2025By Founders

The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive data-protection law. For any platform that handles business and personal data — including tender intelligence platforms — it sets clear expectations around consent, purpose limitation, and data security.

Here is how we read the Act and how we built TenderGuruji to comply from day one.

Public data vs. customer data

Tender notices and historical results are public-domain government information. Customer data — your keyword libraries, saved searches, team members, and usage — is different, and we treat it accordingly. The two are kept architecturally separate and isolated per tenant.

Consent, purpose, and minimisation

We collect only the data we need to deliver the service, use it only for the purpose it was collected, and give customers clear control over it. Purpose limitation and data minimisation are not just legal requirements under the DPDP Act — they are good engineering defaults.

What this means for you

As a customer, your competitive intelligence — the keywords you track, the buyers you watch — stays yours. It is never shared across tenants, and it is protected with the security controls the DPDP Act expects. Compliance is built into the product, not bolted on later.

try it on real data

See how this works inside TenderGuruji.

Live tenders, 22M+ historical results, and BOQ-level pricing in one workspace.

Start free