Connected devices and IoT sensors continuously collect data — location, usage, sometimes audio, video or health readings — and where that data can identify an individual, the DPDP Act applies. The hard part for IoT is meaningful notice and consent: a small device with no screen still has to give users a real understanding of what it collects and obtain a valid consent, typically through a companion app or setup flow. This checker assesses whether your IoT or connected-device deployment collects personal data with proper notice, consent, retention limits and security under DPDP.
Connected devices collect data constantly, often with no screen to show a notice. Check whether your IoT deployment's consent and data handling meet DPDP.
The defining challenge of IoT compliance is meaningful notice and consent on hardware that often has no display. A smart speaker, a wearable, or a sensor cannot show a consent screen, yet the DPDP Act still requires a lawful basis for the personal data it collects. The workable answer is to move the notice and consent into the setup experience — the companion app, the onboarding flow, or the account registration that pairs with the device. That is where users can be shown, in plain language, what the device collects, why, and where the data goes, and where they can give a clear affirmative consent rather than being deemed to have agreed by simply powering the device on.
The quality of that setup-stage consent matters. A pre-ticked box, a bundled all-or-nothing agreement, or a disclosure buried in a manual will not create the free, informed, specific consent DPDP requires. Because IoT devices frequently collect sensitive signals — location, audio, video, health metrics — the standard is higher, not lower. Niti Bharat helps device makers and IoT deployers design onboarding flows where consent is genuine and legible, so a connected product does not launch with a latent compliance defect baked into every unit shipped.
Always-on collection is what separates IoT from most other data-collection points. A connected device can accumulate an enormous, continuous stream of personal data, which makes retention limits, minimisation, and user control essential rather than optional. Under DPDP's storage-limitation expectation, personal data should be kept only as long as needed for its purpose, so an IoT deployment needs a defined retention policy and automatic deletion rather than an ever-growing archive. Minimisation at the point of collection — capturing only the signals the service actually requires — reduces both obligations and the harm from a potential breach.
Users also need practical control: a clear way to pause collection, stop it, or delete their device data, which supports the data principal rights under S.11 to S.14. And because IoT almost always sends data to the cloud, any processor handling that data must be bound by a data processing agreement, with cross-border transfer rules considered if processing occurs outside India. Niti Bharat's fixed-price DPDP engagements cover IoT consent design, retention, user controls and processor agreements together, giving connected-device businesses a defensible posture ahead of full enforcement expected around May 2027.
A practical checklist for making a connected or IoT device DPDP-compliant — setup-stage consent, plain-language notice, minimisation, retention limits, user controls and cloud processor agreements.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.