azyware
Business

React Native development company, security and the DPDP Act: a compliance checklist

EZ
Eazyware
· 7 min read
Quick answer

Is React Native development company compliant with the DPDP Act?

No framework is compliant or non-compliant, and React Native is no exception. The DPDP Act 2023 regulates how you collect, store, share and delete personal data. Your app becomes compliant through consent design, permission discipline, SDK governance, retention rules and deletion that reaches every copy.

No framework is compliant or non-compliant on its own, and React Native is no exception. India's Digital Personal Data Protection Act 2023 regulates what you collect, why, where it sits, who you share it with and when you delete it. React Native development company security work makes an app compliant through consent design, permission discipline, SDK governance and deletion that reaches every copy.

This is a working checklist rather than a legal opinion. It covers what the Act asks of you as a Data Fiduciary, the four places mobile apps leak personal data that web applications do not, the architecture that makes deletion and residency provable, and the evidence to keep so an audit takes a day instead of a quarter.

What the DPDP Act asks of an app

The Digital Personal Data Protection Act 2023 is India's general data protection law. It applies to digital personal data processed within India, and to processing outside India where goods or services are offered to people in India. The entity that decides the purpose and means of processing is the Data Fiduciary, which is you, not your development partner. The Act and its rules are published by the Ministry of Electronics and Information Technology at meity.gov.in.

Four duties do most of the work in practice. Consent must be free, specific, informed and unconditional, requested through a notice in plain language that lists the purpose. Collection must be limited to what that purpose needs. Personal data must be erased once the purpose is served or consent is withdrawn. And a personal data breach must be notified to the Data Protection Board and to affected individuals.

Your React Native development partner is a processor acting on your instructions. That relationship has to be written down, with the security obligations, the sub-processors and the deletion duties named. Eazyware signs an NDA before the first working session and hands over code, infrastructure and documentation at the end, which is the arrangement that leaves you holding the accountability you legally cannot delegate anyway. The broader obligations are set out in DPDP Act 2023: what Indian companies must do and defined in the DPDP Act glossary entry.

Obligation by obligation, in mobile terms

DPDP obligationWhat it means inside the appEvidence to keep
Notice and consentA purpose-specific screen before first collection, not buried in the termsScreenshot, copy version, consent event with timestamp
Purpose limitationEach permission requested at the point of use, with a stated reasonPermission manifest and a justification per entry
Withdrawal of consentAn in-app control that stops collection and propagates to SDKsWithdrawal events and the resulting SDK opt-out calls
ErasureDelete request reaching device cache, back end, backups and analyticsDeletion log with a completion timestamp per system
Data minimisationNo device identifiers or precise location unless the feature needs themData inventory reviewed each release
Security safeguardsKeychain and Keystore for tokens, TLS everywhere, no secrets in the bundlePenetration test report and dependency scan output
Processor contractsWritten terms with every SDK vendor and your build partnerSigned agreements and a current sub-processor list
Breach notificationA rehearsed path from crash triage to board notificationIncident runbook and the date it was last exercised

Where mobile apps leak personal data

Third-party SDKs

Every analytics, advertising, crash-reporting or attribution SDK in your bundle collects data and sends it somewhere. Each one is a processor in your chain, and you are answerable for all of them. Both stores now require you to declare this: Apple's privacy nutrition labels and Google Play's Data safety form are attestations you sign, and the Play requirements are documented at developer.android.com. Keep a list of every SDK, what it collects, where it sends it and which contract covers it, and review that list at each release.

Data at rest on the device

React Native's convenient storage options are not encrypted by default. Tokens, personal identifiers and cached records belong in the iOS Keychain and the Android Keystore, not in plain key-value storage. Assume a lost handset is an unlocked handset and design accordingly: short-lived tokens, a server-side revocation path, and no personal data in logs or crash breadcrumbs.

Over-permissive permission requests

Asking for contacts, precise location or storage at first launch, before the user knows why, fails both the consent test and the store review. Request each permission at the moment the feature needs it, with a sentence saying what it is for, and make the app work in a reduced form if the user says no.

The build pipeline

API keys checked into the repository, verbose logging left on in a release build, and source maps uploaded publicly are the three findings we see most often. Secrets in a JavaScript bundle are readable by anyone who downloads the app. The patching discipline that keeps this from drifting is covered in security patching cadence for production applications.

Residency: where the data actually sits

DPDP as drafted allows transfer outside India except to countries the government restricts, so general residency is a commercial and contractual decision rather than a blanket legal one. Sector rules are stricter. Payments and lending data fall under RBI expectations on storage and access, health data brings its own constraints, and enterprise buyers routinely make an Indian region a procurement condition. Decide the region before the first back-end deployment; migrating a live database and its backups later is a project, not a setting. The concept is explained in the data residency glossary entry, and payment-specific handling in payments in mobile apps in India.

One residency detail specific to React Native: over-the-air update services host your JavaScript bundle on infrastructure you may not have chosen, and some of them log device identifiers on every update check. The bundle itself is code rather than personal data, but the update telemetry is not. Put the update service on your SDK register and check which region its logs sit in before you promise a client that nothing leaves India.

The checklist

  • Data inventory. One table of every personal data field the app touches, its purpose, its retention period and its destination.
  • Consent screen. Purpose-specific, plain language, versioned, with the consent event stored against the user and the copy version.
  • Permission audit. Each platform permission justified in writing, requested in context, and removed if no feature needs it.
  • SDK register. Every third party in the bundle, what it collects, its contract, and its opt-out mechanism wired to consent withdrawal.
  • Secure storage. Tokens and identifiers in Keychain and Keystore, certificate pinning where the threat model justifies it, no personal data in logs.
  • Deletion path. A tested request that clears device cache, application database, back end, analytics and backup within your stated window.
  • Access control. Role-based access to production data, with an audit log that records who read what.
  • Breach runbook. A named owner, a notification template, and a rehearsal date within the last twelve months.

What compliance work costs and when to do it

Built in from the start, this is not a separate line item. Consent screens, permission discipline, secure storage and a deletion path are two to five days of engineering inside a React Native programme that runs from $17,500 or ₹11,20,000 to $70,000 or ₹46,40,000; the starting figures are on the pricing page, with the service detail on the React Native mobile development page. Retrofitted after launch, the same work is a multiple of that, because deletion has to reach data you already copied into four systems.

Ongoing, the cost is patching and review. A Care Plan from $1,000 or ₹68,000 a month at Essential, $2,500 or ₹1,60,000 at Standard, or $5,250 or ₹3,40,000 at Enterprise with a named engineer covers dependency updates, store policy changes and the annual review of the SDK register. Both stores change their privacy requirements more often than most annual audits run.

Where this checklist is not enough

It is not legal advice, and it does not cover sector regulation. If you handle lending, payments or insurance data, RBI, SEBI or IRDAI expectations sit above DPDP and change the answers on residency, retention and outsourcing. If you handle health data, consent and access rules are stricter again. And if your users include children, the Act imposes additional duties that a general consent screen does not satisfy.

It is also not enough on its own to pass enterprise procurement. Large buyers ask for penetration test reports, a documented software development lifecycle, sub-processor lists and incident history. The pattern for small teams is set out in the SaaS security checklist, and our own posture is published on the trust page.

A worked example

An NBFC onboarding customers needed identity documents captured on a phone and processed without the raw images spreading across systems. The design decisions that mattered were retention windows on the original files, redaction before anything reached a downstream service, and an access log that showed exactly who had opened which document. The build is described in the KYC document intelligence case study. The lesson generalises: compliance is mostly about where copies of data end up, and copies are made by convenience, not by design.

React Native development company in India covers the commercial and delivery side of working with an Indian partner, and questions to ask a React Native development company vendor includes the security questions worth asking before you sign. If you need this reviewed against your own data map, start on the contact page.

Compliance in a mobile app is an inventory problem before it is a legal one: you cannot delete, justify or defend data you have not written down.

Frequently asked questions

Does the DPDP Act apply to a React Native app built outside India?

▾

It applies to digital personal data processed in India, and to processing outside India where goods or services are offered to people in India. Where the app was built is irrelevant. What matters is whose data you process and whether you offer your service to people located in India.

Do we have to store Indian users' data in India?

▾

DPDP as drafted permits transfer outside India except to countries the government restricts, so general residency is contractual rather than absolute. Sector regulators are stricter: payments and lending data carry RBI expectations, and many enterprise buyers make an Indian region a procurement requirement regardless.

Who is responsible for compliance, us or our development partner?

▾

You are. The Act makes the Data Fiduciary, the entity deciding purpose and means, accountable. Your partner acts as a processor under written instructions covering security, sub-processors and deletion. Accountability cannot be outsourced, which is why the processor contract and the SDK register both matter.