GDPR and DPDP Compliance for Your Draftly Website
Privacy regulation is tightening. The DPDP Act in India and GDPR for European visitors create specific obligations for how you collect and handle user data.
What Data Does Your Draftly Site Collect?
- Form submissions (name, email, phone, messages)
- Analytics data (via Google Analytics, if enabled)
- Cookies (first-party and third-party)
- IP addresses (logged by the server)
DPDP Act Requirements (India)
India's Digital Personal Data Protection Act 2023:
- You must have a clear privacy policy
- Obtain consent before collecting personal data
- Tell users what their data will be used for
- Allow users to request deletion of their data
- Don't share data with third parties without disclosure
GDPR Requirements (EU Visitors)
If any of your visitors are in EU countries:
- Cookie consent banner required before setting non-essential cookies
- Privacy policy must be comprehensive and accessible
- Data retention limits must be defined
- Right to erasure must be honoured
What to Do in Draftly
1. Privacy Policy page — create and publish at `/privacy-policy`
2. Cookie consent banner — add via CookieYes or similar (Custom Code)
3. Form consent checkbox — for Draftly forms, add a 'I agree to the privacy policy' required checkbox
4. Google Analytics configuration — enable IP anonymisation in GA4 settings
5. Data retention — in Draftly Leads, delete old leads you no longer need (demonstrates compliance)
Does Your Site Actually Need This?
If you're a pure local service business with no EU customers and collecting only names and phone numbers via WhatsApp — the risk is low. But implementing basics (privacy policy + consent form checkbox) takes 30 minutes and eliminates the risk entirely.



