DPDP Act: what a small business should prepare
India's data protection law is notified, but most business duties start around May 2027. What the Act and Rules say, what is phased, where to start.
Share on WhatsApp
Conceptual image · created with AI
The Digital Personal Data Protection Act, 2023 passed in August 2023 and the Digital Personal Data Protection Rules, 2025 were notified in November 2025. Together they set out how businesses must handle the personal data of individuals, from a customer list to a staff record. The Rules give time to prepare: some parts are in force, others start about one year, and the main business duties about eighteen months, after notification.
This is a general summary for awareness, not legal advice, and it is limited to provisions we could check in the official text of the Act and Rules. Dates and clarifications can change, so check the MeitY website and take advice before relying on this for your own business.
What you should come away with
- The Act and Rules are notified, and the main duties on businesses are phased to around May 2027
- The Act has no general exemption for small businesses, though it lets the Government exempt some classes, including startups, from certain duties
- Notice, consent, reasonable safeguards, breach intimation and respect for people's rights are the core duties
- Penalties in the Act's Schedule are large ceilings, set after an inquiry that must weigh the facts
- A one-page list of what personal data you hold, and why, is the best first step
- Check the official notification for dates before you plan around them
Start with the vocabulary, because the law uses its own. A Data Fiduciary is the person or business that decides why and how personal data is processed. A Data Processor handles it on the fiduciary's behalf, as a payroll provider or a cloud tool might. A Data Principal is the individual the data is about. If you run a shop that keeps customers' phone numbers, a clinic with an appointment list, or a coaching centre with students' details, you are very likely a Data Fiduciary. The Act applies to digital personal data and to personal data collected on paper and then digitised. It does not cover personal data processed by an individual for purely personal or domestic purposes.
Now the dates, which matter most. The Rules were published in the Gazette in November 2025. Rule 1 brought some rules into force at once, mainly those on the Data Protection Board. Rule 4, on registering Consent Managers, applies one year after publication, which is around November 2026. Rules 3, 5 to 16, 22 and 23, which include notice, safeguards, breach intimation and people's rights, apply eighteen months after publication, which is around May 2027. In January 2026 the press reported that the ministry was considering shortening some timelines. We have not found a notified change, and government statements since have described the eighteen-month schedule, but check the MeitY website and the Gazette for the position on the day you read this.
Does the law spare small businesses? Not as a general rule. The Act does allow the Central Government to notify certain Data Fiduciaries or classes, including startups, as exempt from some provisions, such as the notice, accuracy and erasure duties. Check whether any such notification covers your business before assuming it does.
What will the law ask of you? Four things stand out. The first is notice and consent. When you ask for consent, you must give a notice that says what data you want and for what purpose, how the person can exercise their rights, and how to complain to the Board. Under Rule 3 the notice must be understandable on its own, in clear and plain language, with an itemised description of the data and the specific purpose. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for that purpose. The person must be able to withdraw it as easily as they gave it. You must be able to prove that you gave notice and got consent. The Act also lists legitimate uses where consent is not needed, such as using data a person voluntarily gave you for the purpose they gave it.
The second is safeguards. The Act requires reasonable security safeguards, and Rule 6 lists minimum measures, including encryption, masking or virtual tokens, controls on access, logs and monitoring, backups, appropriate contract terms with processors, and keeping certain logs and data for one year. For a small business, this translates into strong passwords, two-step login, updated software, restricted access and tested backups.
The third is breach reporting. On becoming aware of a breach, you must tell each affected person without delay, in plain language, and tell the Board without delay, followed by fuller details within seventy-two hours unless the Board allows longer. A one-page plan, naming who to call, is far easier to follow on a bad day than to invent.
The fourth is people's rights. Individuals can ask for a summary of their data, ask for correction and erasure, use a grievance system, and nominate someone to act for them. Under Rules 9 and 14 you must publish a contact person and the way to make requests, and respond to grievances within a period that cannot exceed ninety days. You must erase data once consent is withdrawn or the purpose is served, unless a law requires you to keep it, and tell your processors to do the same. If you deal with anyone under eighteen, additional duties apply, including verifiable parental consent and a bar on tracking or targeted advertising directed at children, with stated exemptions for some classes such as certain clinics and educational institutions.
Penalties are real but should be read carefully. The Schedule to the Act sets maximum penalties, for example up to two hundred and fifty crore rupees for failing to take reasonable security safeguards and up to two hundred crore rupees for failing to give breach notice. These are ceilings. The Board may impose a penalty only after an inquiry, and must weigh the nature, gravity and duration of the breach, the steps taken to reduce harm, and whether the penalty is proportionate.
Where should a small owner begin? First, write the one-page list: what personal data you collect, why, where it sits, who can open it, and which vendors handle it. Second, read your privacy notice and forms against that list. Third, name a person who will answer data questions. Fourth, ask your vendors how they protect and delete your data. Fifth, draft your breach plan. Sixth, ask a lawyer or data-protection professional which duties and dates apply to you.
And be wary of anyone who sells a certificate that says you are compliant. The law does not provide one. What it asks for is that you know what you hold, say what you do with it, protect it, and respond to people who ask.