<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Forem: Aditya</title>
    <description>The latest articles on Forem by Aditya (@0x0elliot).</description>
    <link>https://forem.com/0x0elliot</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F776591%2Fcbb39ecc-b259-4195-9d2c-0791fa139153.png</url>
      <title>Forem: Aditya</title>
      <link>https://forem.com/0x0elliot</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://forem.com/feed/0x0elliot"/>
    <language>en</language>
    <item>
      <title>DPDPA will kick our asses, We need this checklist</title>
      <dc:creator>Aditya</dc:creator>
      <pubDate>Wed, 04 Feb 2026 22:22:17 +0000</pubDate>
      <link>https://forem.com/0x0elliot/dpdpa-will-kick-your-ass-you-need-this-checklist-2am8</link>
      <guid>https://forem.com/0x0elliot/dpdpa-will-kick-your-ass-you-need-this-checklist-2am8</guid>
      <description>&lt;p&gt;&lt;strong&gt;TL;DR:&lt;/strong&gt; DPDPA is law, not a certification. Fines go up to 250 crore. Full enforcement around May 2027. Small or large, you need to comply. Get proper opt-in consent, publish a DPO contact, delete data when users ask, sign Data Processing Agreements with every vendor (CMS, email tool, analytics, everything). If some random WordPress plugin leaks your user's data, YOU get fined, not them. Children = anyone under 18, no tracking, no targeted ads. If unsure whether a tool is compliant, assume it isn't.&lt;/p&gt;




&lt;p&gt;Howdy again!&lt;/p&gt;

&lt;p&gt;I've helped companies work through HIPAA, ISO 27001, GDPR. I get the tech side. I also run &lt;a href="https://zappush.com" rel="noopener noreferrer"&gt;zappush.com&lt;/a&gt; where we deal with user data daily. Figured I'd help confused indie devs and founders navigate this new regulation. There's both opportunity and a huge pain in the ass coming our way :)&lt;/p&gt;

&lt;p&gt;I'm an engineer, not a lawyer. None of this is legal advice, but I know what I'm talking about.&lt;/p&gt;

&lt;p&gt;DPDPA is India's version of GDPR. It's law, not a certification. Fines go up to 250 crore (~$30M), though I wouldn't expect small businesses to get hit that hard. Still, no need to get into locha over negligence.&lt;/p&gt;

&lt;h2&gt;
  
  
  DPDPA Timeline: Where We Are Now
&lt;/h2&gt;

&lt;p&gt;The act isn't fully enforced yet. &lt;a href="https://www.dpdpact2023.com/Section_1" rel="noopener noreferrer"&gt;Here's the official timeline&lt;/a&gt;.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Phase 1 (Nov 2025):&lt;/strong&gt; Skeleton laid down. The law exists on paper.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Phase 2 (by Nov 2026):&lt;/strong&gt; Operational rules for consent managers and the Data Protection Board. How complaints are filed, how notices are issued, etc.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Phase 3 (~May 2027):&lt;/strong&gt; Full enforcement. This is when business owners get fined.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The market has already started preparing. I've noticed a lot of compliance consultants popping up. &lt;a href="https://www.consently.in" rel="noopener noreferrer"&gt;Consently&lt;/a&gt;, &lt;a href="https://www.scrut.io/lp1/scrut-comparison" rel="noopener noreferrer"&gt;Scrut&lt;/a&gt;, and others. I also help companies with this stuff. If you need a hand, reach out through the contact form.&lt;/p&gt;

&lt;h2&gt;
  
  
  What YOU Need to Know About DPDPA
&lt;/h2&gt;

&lt;p&gt;Most of this comes from &lt;a href="https://www.dpdpact2023.com/" rel="noopener noreferrer"&gt;here&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Notice &amp;amp; Consent (Sections 3–5)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Clear notice:&lt;/strong&gt; Explain why you need each item of data before collecting it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Language:&lt;/strong&gt; Available in English or any Eighth Schedule language.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;User rights:&lt;/strong&gt; Tell users what you collect, why, and how they can access, correct, delete, or withdraw consent.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Grievance contact:&lt;/strong&gt; Publish your &lt;a href="https://dpo-india.com/Blogs/strategic-role/" rel="noopener noreferrer"&gt;Data Protection Officer (DPO)&lt;/a&gt; or someone from your team. You have 90 days to resolve grievances. If you don't, users can escalate to the Data Protection Board.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Core Fiduciary Duties (Sections 6(1)–6(8), 6(10))
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Data minimisation:&lt;/strong&gt; Collect only what you need. Don't collect the user's entire contact list if you can't explain what you'd do with it. (This is a loose example from the guidelines themselves :P)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Purpose limitation:&lt;/strong&gt; Use data only for stated purposes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;"Reasonable" security:&lt;/strong&gt; I found this bit very ambiguous. GDPR at least suggests pseudonymisation, encryption, and regular security testing. DPDPA doesn't get into what algorithms count as "reasonable." From personal experience, auditors for ISO 27001 or SOC 2 often use &lt;a href="https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program" rel="noopener noreferrer"&gt;NIST's published FIPS algorithms&lt;/a&gt;. I dislike DPDPA's skeleton for the lack of technical care.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Processor liability:&lt;/strong&gt; You are liable even if your data processor screws up. If AWS leaks YOUR user's data, you get fined. Not them. I do not like this personally. The party that screwed up should be penalised, not the business owner who trusted their infrastructure.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;DPA required:&lt;/strong&gt; All processors need a Data Processing Agreement with you.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Breach notification:&lt;/strong&gt; Notify the Data Protection Board and affected users if there's a breach.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deletion:&lt;/strong&gt; Delete data when consent is withdrawn or the purpose is served. Make sure your processors do the same.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Grievance mechanism:&lt;/strong&gt; Publish your DPO's contact so issues get handled before they escalate to the board.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Special Situations (Sections 7–10)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Consent exemptions:&lt;/strong&gt; Some processing is allowed without consent. Legal compliance, employment, medical emergencies, fraud prevention, public interest.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Children (under 18):&lt;/strong&gt; Verifiable parental consent required. No tracking, no targeted ads. Be careful with how Google Analytics tracks underage users and how you advertise to them. Meta already enforces a lot of this. If you have a social platform for teenagers, a gaming platform, or an adolescent audience, this will affect you.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Significant Data Fiduciaries:&lt;/strong&gt; The Government can designate certain entities as "Significant." These are bigger firms with more responsibilities.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Data Principal Rights (Sections 11–17)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Access &amp;amp; Correction&lt;/strong&gt;: Users can see what personal data is processed, why, with whom it is shared, and request correction, updating, or deletion where applicable.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Consent Control&lt;/strong&gt;: Users can withdraw consent at any time; processing must stop and data deleted unless legally required to retain it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Grievance &amp;amp; Escalation&lt;/strong&gt;: Users must have a clear grievance mechanism and can escalate unresolved complaints to the Data Protection Board.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Nomination&lt;/strong&gt;: Users may nominate another person to exercise their rights in case of death or incapacity.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Data Protection Board Powers (Sections 28–34)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Investigation:&lt;/strong&gt; Board can investigate and ask for evidence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Enforcement:&lt;/strong&gt; Board can issue orders and penalties.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Penalties &amp;amp; Appeals (Sections 36–37)
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Fines:&lt;/strong&gt; Proportional to the violation. Up to 250 crore.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Appeals:&lt;/strong&gt; Decisions can be appealed.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Rule-making (Section 44(2))
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Supporting rules:&lt;/strong&gt; Government will introduce additional rules and standards over time.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  DPDPA Compliance Checklist
&lt;/h2&gt;

&lt;h3&gt;
  
  
  1. Data Collection and Consent
&lt;/h3&gt;

&lt;p&gt;"Child" as per DPDPA: Person under 18 years of age or a person with disability who has a lawful guardian obtain.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Are you collecting &lt;strong&gt;only&lt;/strong&gt; what you need without ambigious permissions?&lt;/li&gt;
&lt;li&gt;Are you clearly telling them why you need it and how users can exercise their "rights" to withdraw, reach out for griences etc?&lt;/li&gt;
&lt;li&gt;Are you ensuring &lt;strong&gt;children's data (&amp;lt;18 years)&lt;/strong&gt; is not processed without verifiable parental consent.&lt;/li&gt;
&lt;li&gt;Are you NOT undertaking tracking or behavioural monitoring of children or targeted advertising directed at children?&lt;/li&gt;
&lt;li&gt;Are you using &lt;strong&gt;opt-in consent&lt;/strong&gt; for analytics, marketing, or tracking cookies (Google Analytics, Meta Pixel, etc.)?&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  2. Data Processing &amp;amp; Storage
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Are you using data &lt;strong&gt;only for the stated purpose&lt;/strong&gt;, Respecting the fact that cross-purpose usage requires fresh consent, As per the law?&lt;/li&gt;
&lt;li&gt;If using &lt;strong&gt;AWS, GCP, or other cloud services&lt;/strong&gt;, Can you confirm that data is &lt;strong&gt;processed securely&lt;/strong&gt; (encryption at rest with a good algorithm published from NIST's FIPS &amp;amp; in transit, regular backups, restricted access) AND DPDPA compliant?&lt;/li&gt;
&lt;li&gt;For &lt;strong&gt;CMS platforms, Or any other third party software processing the user's data&lt;/strong&gt;, Can you ensure they &lt;strong&gt;don't process personal data without compliance&lt;/strong&gt; and take measures to be compliant to DPDPA themselves, ideally? otherwise, you're liable as the fiduciary.&lt;/li&gt;
&lt;li&gt;Keep personal data &lt;strong&gt;accurate and complete&lt;/strong&gt;, especially if used for decisions affecting users.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;^ An interesting illustration stated for above is: X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X's personal data for the said period.&lt;/p&gt;

&lt;h3&gt;
  
  
  3. Security Measures
&lt;/h3&gt;

&lt;p&gt;Remember: DPDP is vague on technical standards, so relying on &lt;strong&gt;ISO 27001 / SOC 2 / NIST-approved algorithms&lt;/strong&gt; is safest.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Are you implementing reasonable security safeguards for all personal data?&lt;/li&gt;
&lt;li&gt;Is encryption applied at rest and in transit using strong, recognized algorithms (e.g., NIST-approved)?&lt;/li&gt;
&lt;li&gt;Have you applied pseudonymization or anonymization for sensitive personal data where feasible?&lt;/li&gt;
&lt;li&gt;Are access controls in place to restrict data to authorized personnel only?&lt;/li&gt;
&lt;li&gt;Do you maintain audit logs to track who accessed or modified personal data?&lt;/li&gt;
&lt;li&gt;Are you conducting regular security testing (e.g., vulnerability scans, penetration tests) to identify and fix risks?&lt;/li&gt;
&lt;li&gt;Do your security practices align with recognized standards (ISO 27001, SOC 2, NIST)?&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  4. Data Retention &amp;amp; Deletion
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Are you deleting personal data when it is no longer needed for the original purpose?&lt;/li&gt;
&lt;li&gt;Do you honor user requests to withdraw consent by deleting their personal data promptly?&lt;/li&gt;
&lt;li&gt;Are you ensuring that third-party processors also delete personal data when instructed?&lt;/li&gt;
&lt;li&gt;Are you retaining data only as long as legally required, and not beyond that period?&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  5. Data Principal Rights
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Can users easily access their personal data that you hold?&lt;/li&gt;
&lt;li&gt;Can users request correction or completion of inaccurate or incomplete data?&lt;/li&gt;
&lt;li&gt;Can users request deletion of their personal data or withdraw consent at any time?&lt;/li&gt;
&lt;li&gt;Do you have a clear grievance redressal mechanism that handles complaints promptly and effectively (not just an email or portal)?&lt;/li&gt;
&lt;li&gt;Is it clear who users should contact (DPO or authorised person) for exercising their rights?&lt;/li&gt;
&lt;li&gt;Can users nominate another person to exercise their rights in case of death or incapacitation?&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  6. Third-Party Processors &amp;amp; Analytics
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Are you using valid contracts (example &lt;a href="https://www.dpdpa.com/templates/dataprocessingtemplate.html?utm_source=chatgpt.com" rel="noopener noreferrer"&gt;here&lt;/a&gt;) with all third-party processors (e.g., database providers, analytics platforms, email marketing tools)?&lt;/li&gt;
&lt;li&gt;Do you avoid sending personal data to non-compliant third-party services, especially for minors?&lt;/li&gt;
&lt;li&gt;Are you minimizing third-party tracking and sharing by default?&lt;/li&gt;
&lt;li&gt;Where feasible, are you self-hosting analytics or similar services to reduce reliance on external processors? Reach out to &lt;a href="https://cal.com/zappush/30min" rel="noopener noreferrer"&gt;me&lt;/a&gt; if you need help with it.&lt;/li&gt;
&lt;li&gt;Do you know where your user data is stored and whether it's sent outside India?&lt;/li&gt;
&lt;li&gt;Are records of cross-border transfers maintained for audit and potential inspection by the Data Protection Board?&lt;/li&gt;
&lt;li&gt;Can you confirm if the data processor abroad complies with DPDPA as well?&lt;/li&gt;
&lt;li&gt;Have you checked whether any government guidelines or restrictions require certain types of data to remain in India, and are you compliant with them?&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  7. Monitoring &amp;amp; Compliance
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Are you keeping records of user consent and processing purposes for all personal data collected?&lt;/li&gt;
&lt;li&gt;Do you have a plan to respond to potential investigations or audits by the Data Protection Board?&lt;/li&gt;
&lt;li&gt;Are you actively monitoring for data breaches across all systems handling personal data?&lt;/li&gt;
&lt;li&gt;Do you have a breach notification plan to inform both affected users and the Data Protection Board promptly, as required under the law?&lt;/li&gt;
&lt;li&gt;Are periodic internal compliance checks conducted to ensure adherence to DPDPA obligations?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you're unsure about a tool, plugin, or CMS, &lt;strong&gt;assume it's non-compliant until proven otherwise&lt;/strong&gt;. Liability falls on you.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Do I need to comply if my company is registered outside India?&lt;/strong&gt;&lt;br&gt;
Yes, if you're processing personal data of people in India. Doesn't matter where your company is registered.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What counts as "personal data"?&lt;/strong&gt;&lt;br&gt;
Anything that can identify a person: name, email, phone, IP address, device IDs, location data. If you can trace it back to a specific human, it's personal data.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do I need a Data Protection Officer (DPO)?&lt;/strong&gt;&lt;br&gt;
The law requires you to publish contact information for someone who handles data protection queries and grievances. For small SaaS, this can be you or a co-founder. Larger companies designated as "Significant Data Fiduciaries" have stricter requirements.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What's a Data Processing Agreement (DPA)?&lt;/strong&gt;&lt;br&gt;
A contract between you and any third party that processes your users' data. Your database provider, email marketing tool, analytics platform, payment gateway, all of them. Many big vendors (AWS, Stripe, etc.) already have standard DPAs. Smaller tools might not. Ask them.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Does DPDPA apply to B2B SaaS?&lt;/strong&gt;&lt;br&gt;
Yes. If you're storing data about employees or contacts of your business clients, that's still personal data. B2B doesn't exempt you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What about data I collected before DPDPA?&lt;/strong&gt;&lt;br&gt;
You'll need to ensure it meets compliance standards. If you don't have proper consent records, you may need to re-obtain consent or delete the data.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can I transfer data outside India?&lt;/strong&gt;&lt;br&gt;
Yes, to most countries. The government will publish a list of restricted countries where transfer is not allowed. As of now, this list hasn't been finalized.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What triggers a breach notification?&lt;/strong&gt;&lt;br&gt;
Any unauthorized access, disclosure, or loss of personal data. You must notify the Data Protection Board and affected users. Timeline isn't specified yet, but "promptly" is the expectation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is Google Analytics compliant?&lt;/strong&gt;&lt;br&gt;
Depends on how you use it. You need opt-in consent before firing any tracking. The default "implied consent" banners won't cut it. Consider self-hosted alternatives like Plausible or Umami if you want to avoid the headache.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What if a user asks to delete their data but I need it for legal/tax reasons?&lt;/strong&gt;&lt;br&gt;
You can retain data if required by law. Example: banks must keep records for 10 years. But you can only keep what's legally required, nothing extra.&lt;/p&gt;

&lt;h2&gt;
  
  
  Conclusion
&lt;/h2&gt;

&lt;p&gt;I have mixed feelings about this law. On one side, the government can't do anything well. It is a deeply incompetent organization. On the other, the law itself, even with its faults and rigidity, tries to argue for consent and clarity. I agree with that ethic, on its own.&lt;/p&gt;

&lt;p&gt;This law will clearly make a lot of businesses more difficult to operate but, I hope that the accountable ones shine through. Hoping for liberty and a bright future.&lt;/p&gt;

&lt;p&gt;If you don't even have a company, what are you doing here? You should be reading &lt;a href="https://www.shipfast.blog/blog/indie-dev-first-time-founder-india-startup-guide/" rel="noopener noreferrer"&gt;this&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>dpdpa</category>
      <category>regulation</category>
      <category>privacy</category>
      <category>india</category>
    </item>
    <item>
      <title>How do you even register a company as an indie dev?</title>
      <dc:creator>Aditya</dc:creator>
      <pubDate>Tue, 03 Feb 2026 20:24:30 +0000</pubDate>
      <link>https://forem.com/0x0elliot/company-registration-primer-for-confused-indie-devsfirst-time-founders-58m9</link>
      <guid>https://forem.com/0x0elliot/company-registration-primer-for-confused-indie-devsfirst-time-founders-58m9</guid>
      <description>&lt;p&gt;&lt;strong&gt;TL;DR:&lt;/strong&gt; Go LLP if you have a co-founder and want to move fast without raising soon. Pvt Ltd if you're raising VC money and can stomach the compliance. Get a CA, virtual office, and bank account. Share capital minimum is ₹1 (not ₹1 lakh, that's outdated, though your CA might default to it out of habit). Total damage: ₹25k-40k. Took me about 3-4 months, but should ideally take less than a month. Also, get your Startup India certificate - it's free and saves you 3 years of taxes.&lt;/p&gt;




&lt;p&gt;Howdy!&lt;/p&gt;

&lt;p&gt;I started &lt;a href="https://www.zappush.com" rel="noopener noreferrer"&gt;zappush.com&lt;/a&gt; in August last year. The whole thing took me 3-5 months. After a lot of confused, frustrated nights staring at a product that was ready to make money but couldn't because I had no way to accept payments.&lt;/p&gt;

&lt;p&gt;Every payment gateway accepting International transactions I tried wanted documentation I didn't have.&lt;/p&gt;

&lt;p&gt;So I'm writing this for the engineer who's been so heads-down building that they forgot they need a legal entity to actually sell the thing. That was me.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Indie Devs and First-Time Founders Need a Legal Entity in India
&lt;/h2&gt;

&lt;p&gt;Here's why:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Payment gateways&lt;/strong&gt; won't let you accept international payments without one. This sucks especially if the indian market is too price sensitive and you have a money hungry product.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;WhatsApp Business API&lt;/strong&gt; requires it if you're planning to build on it (I wanted to back 2 years ago, And no one could get me access to it)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Banks&lt;/strong&gt; won't open a business account for you otherwise. You will have to use your personal account.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Clients&lt;/strong&gt; take you more seriously when there's a company behind the product&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Meta Ads&lt;/strong&gt; will flag your account if you increase ad spend too fast.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Liability&lt;/strong&gt; if something goes wrong, you're personally liable. With a legal entity, there is legal separation between you and your business.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Startup Registration Checklist India 2026: Step-by-Step
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Step 1: Get a CA
&lt;/h3&gt;

&lt;p&gt;No reason to not. Whether it's through razorpay rize, RegisterKaro, or a kind CA friend of a cousin. This stuff is not straight forward, and founders tend to love building. Let the professionals handle the boring stuff. This bureaucracy exists to slow you down by design.&lt;/p&gt;

&lt;p&gt;You can ALSO just get a company to do it for you. Razorpay Rize takes care of a lot of pains for you (From taking care of the address, to documents, to DIN etc).&lt;/p&gt;

&lt;p&gt;Razorpay rize does say that they charge 1499 + Govt fees for incoperation in &lt;a href="https://razorpay.com/rize/company-registration/campaign" rel="noopener noreferrer"&gt;here&lt;/a&gt;. In reality, They partner up with a company to take care of the virtual office address registration which also has a decent fee (this would easily charge you 17k-25k for the company address. They also usually have a more expensive GST registration plan that they try to sell you). Expect this going in!&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;About GST:&lt;/strong&gt; You can register GST for free, Feel free to tell the virtual office space provider that you will do it yourself instead of using their GST package and negotiate a good deal with your CA to sort this out instead. It will most likely be cheaper for you overall.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 2: LLP vs Pvt Ltd vs Sole Proprietorship - Which to Choose?
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Entity Type&lt;/th&gt;
&lt;th&gt;Who's involved&lt;/th&gt;
&lt;th&gt;When to use it&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Sole Proprietorship&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Just you&lt;/td&gt;
&lt;td&gt;Solo operation, but you're personally liable for everything&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;LLP&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;2+ partners&lt;/td&gt;
&lt;td&gt;Fast setup, less compliance, works great with a co-founder&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Pvt Ltd&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;2-15 directors&lt;/td&gt;
&lt;td&gt;Need to raise VC money, can handle the extra paperwork&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;I was super confused what to pick. Lawyer student friends were biased towards Private Limited Company, But ex-founders wanted to avoid the regulatory hassle they brought. I ended up finding myself a co-founder, And chose &lt;strong&gt;LLP&lt;/strong&gt;. This was regulatory wise simpler, While still allowing for multiple partners. Our bias towards speed made it the perfect choice.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The catch with LLP:&lt;/strong&gt; You'll have to convert to Pvt Ltd if you want to raise proper funding. People can't usually invest in LLPs unless they become partners. It makes things more complicated.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The catch with Sole Proprietorship:&lt;/strong&gt; There's no separation between you and the business. If the company gets sued, so do you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The catch with Pvt Ltd:&lt;/strong&gt; More regulatory burden. Still managable if you're ready!&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Resources if you want to DIY:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.bimakavach.com/blog/register-sole-proprietorship-india-step-by-step-guide/" rel="noopener noreferrer"&gt;Sole Proprietorship guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.setindiabiz.com/blog/stepwise-process-for-llp-registration" rel="noopener noreferrer"&gt;LLP guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cleartax.in/s/steps-to-register-private-limited-company" rel="noopener noreferrer"&gt;Pvt Ltd guide&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h4&gt;
  
  
  Notes from the community - r/indiehackersindia
&lt;/h4&gt;

&lt;p&gt;Also, the community gave some pretty good advice about their experiences:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fiufqqwef09380ciipiov.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fiufqqwef09380ciipiov.png" alt="Hey thanks for the clarification i too will be going with LLP soon i guess i will taking my brother as cofounder. Also i wanted to let people know, i started with sole proprietorship i didn't wait for registration and all to launch it was very easy with razorpay, matter of fact i have international payment full fledge enabled as well they did it themselves after one of my customer trying to buy from africa failed to pay and i raised a ticket with razorpay and as a solution to that ticket they enabled international payment" width="800" height="302"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ftwq0981uqpvmnql8g0j2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ftwq0981uqpvmnql8g0j2.png" alt="Good article but is missing a core aspect that many might need to know. Single owner but wants liability protection: OPC. OPC allows protection for a single owner similar to llp. Allows for easy conversion into llp in future. Disadvantage being - mandatory compliance audit irrespective of annual turnover." width="800" height="242"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 3: Digital Signature Certificate (DSC)
&lt;/h3&gt;

&lt;p&gt;Government forms need to be digitally signed. Get a DSC from eMudhra, Sify, or NSDL. They'll send you a USB dongle or email certificate.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.mca.gov.in/content/mca/global/en/mca/dsc-services-v3/acquire-dsc.html" rel="noopener noreferrer"&gt;Official MCA info&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 4: Get your DIN (Director Identification Number)
&lt;/h3&gt;

&lt;p&gt;Both you and your co-founder need one. Apply through the &lt;a href="https://www.mca.gov.in/content/mca/global/en/foportal/fologin.html" rel="noopener noreferrer"&gt;MCA Portal&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Heads up: Most tutorials online have dead links because MCA keeps changing their portal. The link above worked when I wrote this.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 5: Name approval
&lt;/h3&gt;

&lt;p&gt;Have 3-5 name options ready. The MCA will reject anything too similar to existing companies, and you can't use words like "National" or "Bank" without special approval.&lt;/p&gt;

&lt;p&gt;Your CA runs the names through MCA's RUN service. Once approved, you have 20 days to file for incorporation or the name gets released.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 6: File the forms
&lt;/h3&gt;

&lt;p&gt;Your CA handles these:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Form SPICe+ INC-32&lt;/li&gt;
&lt;li&gt;e-MOA and e-AOA&lt;/li&gt;
&lt;li&gt;PAN and TAN applications&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Let them deal with it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 7: Virtual office
&lt;/h3&gt;

&lt;p&gt;A virtual office costs ₹17k-22k for 11 months and gives you a proper business address that works for everything - GST, bank accounts, all of it.&lt;/p&gt;

&lt;p&gt;This was my biggest bottleneck. Should've done it first. I ended up wasting too much time figuring out how to get a proper business address, whether I have to rent a physical office or not. A quick google search would have made my life easier.&lt;/p&gt;

&lt;h3&gt;
  
  
  Step 8: Bank account
&lt;/h3&gt;

&lt;p&gt;Call any of the major banks - Axis, HDFC, whatever's convenient. They'll send someone to your door with the paperwork. Takes a few days, and you'll get a debit card for each partner.&lt;/p&gt;

&lt;p&gt;Two things I wish someone told me:&lt;/p&gt;

&lt;p&gt;First, you need "share capital" to incorporate. Before 2015, this was ₹1 lakh minimum. Some CAs still quote this number out of habit. The actual minimum today? ₹1. Literally one rupee. Don't let anyone convince you otherwise.&lt;/p&gt;

&lt;p&gt;Second, current accounts have minimum balance requirements. This varies by bank, so ask upfront. Nothing worse than getting hit with penalties because nobody mentioned this during onboarding.&lt;/p&gt;




&lt;h2&gt;
  
  
  Best Payment Gateways for Indian Startups (International Payments)
&lt;/h2&gt;

&lt;p&gt;Here's where things got frustrating.&lt;/p&gt;

&lt;p&gt;I had a working product in 2024-2025. I was ready to launch. Then I realized that I had no way to receive subscription money.&lt;/p&gt;

&lt;p&gt;After doing some research, I found that:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Stripe:&lt;/strong&gt; Invite-only in India. I wasn't invited. I asked a friend of a friend to invite me, but they never responded. It slowed things down more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Lemon Squeezy (MoR - Merchant on Record):&lt;/strong&gt; I had to apply for verification to get full access to their services. They rejected me because I wanted to build an AI video startup and they assumed it would be NSFW (it wasn't going to be).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PhonePe, Razorpay, PayU, CCAvenue:&lt;/strong&gt; They'd onboard me for domestic payments, but didn't allow international payments without a registered company. My product's target market was international and Indian pricing wouldn't keep the lights on. Talking to each of these vendors slowed things a few more weeks.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PayPal:&lt;/strong&gt; I ended up wanting to use this but I found a few too many reddit horror stories by indian indie devs and business owners about frozen accounts. It doesn't have a good reputation in the space.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Razorpay (again):&lt;/strong&gt; They create subscriptions packages in INR, but I needed USD billing. Looking back, I should've just launched with INR and figured it out later.&lt;/p&gt;

&lt;h3&gt;
  
  
  Best Payment Gateway for Indie Devs in India
&lt;/h3&gt;

&lt;p&gt;Go for a MoR (Merchant of Record) with subscription API support. MoRs handle tax compliance, chargebacks, and payment processing for you - they're the actual seller on paper.&lt;/p&gt;

&lt;p&gt;I SHOULD have just launched with Dodopayments. &lt;a href="https://dodopayments.com" rel="noopener noreferrer"&gt;DodoPayments&lt;/a&gt; (MoR) is designed for indie devs in exactly this situation. It's a great solution and I love the team behind it :)&lt;/p&gt;

&lt;p&gt;I am just afraid of any regulatory hammers that might come their way. Hoping for the best for them.&lt;/p&gt;

&lt;p&gt;Whatever you pick, make sure they have subscription API support. You don't want to find out they don't after you've integrated everything.&lt;/p&gt;




&lt;h2&gt;
  
  
  Startup Registration Cost in India 2026
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Item&lt;/th&gt;
&lt;th&gt;Cost&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;LLP Registration (through a service)&lt;/td&gt;
&lt;td&gt;₹8,000-15,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Virtual Office (11 months)&lt;/td&gt;
&lt;td&gt;₹17,000-22,000&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GST Registration&lt;/td&gt;
&lt;td&gt;Free, or whatever your CA does it for (can be 5k-10k)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;₹25,000-40,000&lt;/strong&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  How Long Does Company Registration Take in India?
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How much it should take
&lt;/h3&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Step&lt;/th&gt;
&lt;th&gt;Duration&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;DSC&lt;/td&gt;
&lt;td&gt;1-2 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DIN&lt;/td&gt;
&lt;td&gt;3-5 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Name Approval&lt;/td&gt;
&lt;td&gt;2-4 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Incorporation&lt;/td&gt;
&lt;td&gt;5-7 days&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Virtual Office&lt;/td&gt;
&lt;td&gt;1-2 weeks (Expect back and forth)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Bank Account&lt;/td&gt;
&lt;td&gt;1-2 weeks (Expect signature related troubles)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;GST Registration&lt;/td&gt;
&lt;td&gt;7-15 days&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h3&gt;
  
  
  How much it ended up taking me: 3-5 months
&lt;/h3&gt;

&lt;p&gt;What went wrong:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;I didn't know where to start.&lt;/strong&gt; Spent weeks asking friends, reading contradictory advice, going in circles.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Documents kept bouncing back.&lt;/strong&gt; missing signatures and forgot my 20 day name approval limit :) &lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Virtual office took forever.&lt;/strong&gt; Almost a month to finalize. Should've started here.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Payment gateway approval dragged on.&lt;/strong&gt; Even after registration, getting approved for international transactions took more weeks.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you know exactly what to do and have everything ready, you can probably finish in a month. Get yourself a professional to help you out for this.&lt;/p&gt;




&lt;h2&gt;
  
  
  Word of Advice
&lt;/h2&gt;

&lt;p&gt;Get yourself a &lt;a href="https://www.startupindia.gov.in/content/sih/en/blockchainverify/about.html" rel="noopener noreferrer"&gt;Startup India certificate&lt;/a&gt;. It saves you taxes for 3 financial years out of 10. You get to choose when to redeem it. It's free and worth doing early.&lt;/p&gt;




&lt;h2&gt;
  
  
  Need Help Registering Your Startup in India?
&lt;/h2&gt;

&lt;p&gt;I've been through this, and I'm happy to help other first-time founders and indie devs avoid my mistakes. Reach out: &lt;strong&gt;&lt;a href="mailto:aditya@zappush.com"&gt;aditya@zappush.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I'll share referrals, answer questions, whatever's useful. I genuinely believe more people should be starting companies, and this guide should help you get there faster than I did.&lt;/p&gt;

</description>
      <category>devjournal</category>
      <category>resources</category>
      <category>startup</category>
      <category>tutorial</category>
    </item>
  </channel>
</rss>
