API Development Services, security and the DPDP Act: a compliance checklist
No service is compliant in the abstract; your implementation either is or is not. An API handling personal data of people in India must carry a purpose with every read, restrict access by role, log who saw what, enforce retention automatically and delete on request. Those five controls belong in the specification.