DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Connected devices and IoT sensors continuously collect data — location, usage, sometimes audio, video or health readings — and where that data can identify an individual, the DPDP Act applies. The hard part for IoT is meaningful notice and consent: a small device with no screen still has to give users a real understanding of what it collects and obtain a valid consent, typically through a companion app or setup flow. This checker assesses whether your IoT or connected-device deployment collects personal data with proper notice, consent, retention limits and security under DPDP.

IoT Device Data-Collection & Consent Checker

Connected devices collect data constantly, often with no screen to show a notice. Check whether your IoT deployment's consent and data handling meet DPDP.

Check your IoT device data-collection compliance

DPDP essentials for connected / IoT devices

How do you get valid consent for a device with no screen?

The defining challenge of IoT compliance is meaningful notice and consent on hardware that often has no display. A smart speaker, a wearable, or a sensor cannot show a consent screen, yet the DPDP Act still requires a lawful basis for the personal data it collects. The workable answer is to move the notice and consent into the setup experience — the companion app, the onboarding flow, or the account registration that pairs with the device. That is where users can be shown, in plain language, what the device collects, why, and where the data goes, and where they can give a clear affirmative consent rather than being deemed to have agreed by simply powering the device on.

The quality of that setup-stage consent matters. A pre-ticked box, a bundled all-or-nothing agreement, or a disclosure buried in a manual will not create the free, informed, specific consent DPDP requires. Because IoT devices frequently collect sensitive signals — location, audio, video, health metrics — the standard is higher, not lower. Niti Bharat helps device makers and IoT deployers design onboarding flows where consent is genuine and legible, so a connected product does not launch with a latent compliance defect baked into every unit shipped.

How should continuous IoT data be retained and controlled?

Always-on collection is what separates IoT from most other data-collection points. A connected device can accumulate an enormous, continuous stream of personal data, which makes retention limits, minimisation, and user control essential rather than optional. Under DPDP's storage-limitation expectation, personal data should be kept only as long as needed for its purpose, so an IoT deployment needs a defined retention policy and automatic deletion rather than an ever-growing archive. Minimisation at the point of collection — capturing only the signals the service actually requires — reduces both obligations and the harm from a potential breach.

Users also need practical control: a clear way to pause collection, stop it, or delete their device data, which supports the data principal rights under S.11 to S.14. And because IoT almost always sends data to the cloud, any processor handling that data must be bound by a data processing agreement, with cross-border transfer rules considered if processing occurs outside India. Niti Bharat's fixed-price DPDP engagements cover IoT consent design, retention, user controls and processor agreements together, giving connected-device businesses a defensible posture ahead of full enforcement expected around May 2027.

Get the IoT device compliance checklist (free)

A practical checklist for making a connected or IoT device DPDP-compliant — setup-stage consent, plain-language notice, minimisation, retention limits, user controls and cloud processor agreements.

Frequently Asked Questions

Does DPDP apply to a device that only collects sensor telemetry?+
It depends on whether that telemetry can identify an individual. Pure, non-linkable machine telemetry falls outside DPDP, but the moment device data is linked to an account, a location, or a household in a way that identifies a person, it becomes personal data and DPDP applies.
How do we get consent for a device with no screen?+
Move notice and consent into the companion app or setup flow that pairs with the device. That is where you can present a clear, plain-language notice and obtain a genuine affirmative consent, rather than relying on packaging text or treating power-on as agreement.
Is a mention in the manual enough for notice and consent?+
No. A line in a manual or on the box does not meet the DPDP standard for informed, specific consent or accessible notice. Consent should be an explicit step in the setup experience, and the notice should be surfaced where users will actually see it.
What about always-on devices like smart speakers?+
Continuous collection raises the bar. You need clear disclosure that the device is always listening or sensing, tight retention limits, minimisation of what is captured and stored, and an easy user control to pause or stop collection. The sensitivity of always-on audio or video makes strong security essential.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
IRDAI Data Rules + DPDP Gap CheckerIs Your Background-Check Consent DPDP-Adequate? Fr…KPO Research Data DPDP Compliance CheckerDPDP Employee Training KitSee all Calculators tools →📝 Data Retention Periods DPDP Guide📝 DPDP Penalty Amount