5 Things Your App Is Doing Illegally (And You Have No Idea)

 You downloaded an app this week. Maybe it was a food delivery app. Maybe a fitness tracker. Maybe a legal document tool.


You clicked "I Agree" without reading a word. So did everyone else.


Here's the uncomfortable truth: that app is almost certainly breaking Indian law. Not in a minor, technical way. In ways that directly affect your data, your rights, and your choices — and the founders building these apps likely have no idea either.


India's Digital Personal Data Protection Act, 2023 (the DPDP Act) has changed the rules. The era of "collect everything, ask forgiveness later" is over — at least on paper. Let's look at five things your favourite app is probably doing illegally right now.



1. Collecting Data It Doesn't Actually Need


Open the permissions screen on any random app. You'll find it asking for your location, contacts, microphone, and camera. A flashlight app asking for your contacts is not a feature. It's a red flag.


The DPDP Act requires that data collection be limited to what is strictly necessary for the stated purpose. This is called the principle of data minimisation. If an app collects your location to "improve your experience" but never explains how, that vague justification doesn't hold up legally. Purpose must be specific, clear, and lawful — not buried in a 47-page privacy policy no one reads.



2. Using Your Data for Something You Never Agreed To


You signed up for a recipe app. Three weeks later, you're getting targeted ads for weight loss supplements on a completely different platform. Coincidence? Rarely.


Under the DPDP Act, consent must be free, specific, informed, and unambiguous. It cannot be bundled. You cannot get someone to consent to recipe suggestions and silently use that same consent to sell their dietary preferences to a third-party advertiser. Each new purpose requires a fresh, explicit consent. Most apps don't do this. Most apps assume that one checkbox at signup covers everything, forever.



3. Making It Nearly Impossible to Withdraw Consent


Here's one most people never think about: the law gives you the right to withdraw consent. But try actually doing it on most apps.


You'll hunt through settings menus, find nothing, email a support address that bounces, or get a reply six weeks later saying your request is "under review." The DPDP Act requires that withdrawing consent be as easy as giving it. If it took you three taps to sign up, it should take roughly three taps to opt out. If the exit door is hidden, that's not a design oversight. That's a legal violation.



4. No Grievance Officer You Can Actually Reach


Every significant data fiduciary — which is the DPDP Act's term for any entity processing personal data at scale — is required to appoint a Data Protection Officer or grievance redressal mechanism. There must be a real human, or at least a real process, that responds to your complaints within a defined timeframe.


Check the privacy policy of the last five apps you used. Most will list a generic email address. Many won't list anything at all. And the ones that do? Try sending an email and timing the response. The requirement isn't just to have a name on a page — it's to actually respond. Silence is not compliance.



5. Transferring Your Data Abroad Without Proper Safeguards


Your data is not staying in India. The moment you use an app built on AWS servers in Singapore, or a SaaS platform with analytics tools hosted in the US, your personal data has crossed a border.


The DPDP Act places restrictions on cross-border data transfers. Data can only be transferred to countries notified by the Central Government as permissible destinations. That list is still being finalised. Which means right now, a significant number of apps are transferring Indian users' data internationally without a clear legal basis to do so. The data is already gone. The rules to govern its transfer are still being written.



So What Does This Mean For You?


If you're a user: you have more rights than you think. You can ask what data is held about you, demand corrections, and withdraw consent. Start exercising those rights. Companies will only take compliance seriously when users do.


If you're a founder or product manager: the DPDP Act is not a future problem. The rules are here. The penalties are significant — up to ₹250 crore per violation. Compliance isn't a legal formality. It's a product decision.


If you're a lawyer: this is your decade. Data protection is the new corporate law. Learn it deeply.


The apps on your phone are not neutral tools. They are legal relationships. And right now, most of those relationships are built on shaky ground.


Here's my question for you: Have you ever actually read an app's privacy policy? And if you did — did you understand it? Let me know in the comments.

Comments

Popular posts from this blog

Use of AI in the World of Multi-Facet Entrepreneurship

Navigating Justice: The Law and Judiciary's Role in Addressing Violent Protests for Democracy

Brewing Coffee, Coding SOPs, and Building the Extropian Vision