If your business collects a customer’s phone number on a WhatsApp order form, stores employee Aadhaar copies in Google Drive, or runs an app with a sign-up page, India’s new data protection law applies to you. It doesn’t matter whether you have five employees or five hundred.
The Digital Personal Data Protection Act, 2023 (the DPDP Act) is no longer a distant idea. The DPDP Rules, 2025 were notified in November 2025, and the main compliance obligations take effect on 13 May 2027. Many founders we speak to assume this is “something big companies need to worry about”. It isn’t. The law applies to anyone processing digital personal data, and the maximum penalties run into hundreds of crores.
The good news is that DPDP compliance for a small business is very manageable if you start early. This guide gives you a practical DPDP Act compliance checklist, explains what the DPDP Rules actually require, and covers the penalties and legal remedies, for businesses and for individuals whose data is misused.
The DPDP Act and DPDP Rules in plain English: who must comply and by when
Does the DPDP Act apply to my business? Almost certainly, yes. The DPDP Act applies to personal data processed in digital form in India, including data collected on paper and later digitised. It also applies to businesses outside India if they offer goods or services to people in India. There’s no turnover threshold and no exemption based on size. The main exclusions are data processed for purely personal or domestic purposes, and personal data that the individual has made publicly available themselves.
You’ll keep seeing a few terms, so here they are in simple words:
- Data Principal: the person the data is about, such as your customer, employee or app user. For a child, this includes the parent.
- Data Fiduciary: the business that decides why and how the data is processed. That’s you.
- Data Processor: a vendor that processes data on your behalf, such as a CRM, a cloud host or a payroll provider.
- Significant Data Fiduciary (SDF): a business the government notifies as high-risk, based on data volume and sensitivity. SDFs have extra duties. Most small businesses won’t be one.
- Consent Manager: a registered platform that lets people give, manage and withdraw consent across businesses.
The DPDP compliance timeline
The DPDP Rules, 2025 were notified on 13 November 2025 with an 18-month phased rollout (PIB). The provisions come into force in three stages (Wikipedia, citing the official notification):
| Date | What comes into force |
|---|---|
| 13 November 2025 | Definitions, the Data Protection Board of India and its procedures |
| 13 November 2026 | Registration and regulation of Consent Managers |
| 13 May 2027 | Everything else: notice, consent, security, breach reporting, retention, user rights, children’s data and penalties |
One thing to watch: in January 2026, MeitY consulted industry on a proposal to compress the timeline from 18 months to 12, which would bring the relevant deadline forward to 13 November 2026 (Mondaq). Reports differ on whether it would cover all obligations or mainly those of Significant Data Fiduciaries. As of recent reports, the proposal had not been made law and 13 May 2027 remains the deadline (ConsentOS). Even so, our advice is simple: plan as if the earlier date could arrive.
DPDP compliance checklist, part 1: notice, consent, children’s data and vendors
DPDP compliance starts with one unglamorous exercise. Before you change a single form, find out what personal data you actually hold.
Map your data
List every place personal data enters your business: website forms, apps, WhatsApp, payment gateways, CVs, employee files, CCTV and so on. For each, note what you collect, why, where it’s stored, who can access it and which vendors touch it. In our experience, most small businesses discover they collect far more than they use. Under the DPDP Act, collecting less is the cheapest compliance step there is.
Identify the legal basis for each use
Under the DPDP Act, you can process personal data either with consent (Section 6) or for a “legitimate use” under Section 7. Legitimate uses include data a person voluntarily gives you for a specific purpose without objecting (a customer who shares their address for delivery), compliance with a law or court order, medical emergencies, and certain employment purposes. Everything else needs consent.
Rewrite your privacy notice
Section 5 and Rule 3 of the DPDP Rules require a notice that stands on its own, not buried in your terms and conditions. It must be in clear and plain language and set out an itemised description of the personal data you collect, the specific purpose for each item, and the goods or services it enables. It must also include a link for withdrawing consent and exercising rights, and explain how the person can complain to the Data Protection Board. Users must be able to read the notice in English or in any of the 22 languages in the Eighth Schedule to the Constitution.
Fix your consent flows
Valid consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose. In practice, that means no pre-ticked boxes, no “by using this site you agree” banners, and no bundling marketing consent with order processing. Withdrawing consent must be as easy as giving it. Keep records, because if a dispute arises, the burden of proving consent lies on you.
Handle children’s data with extra care
Under the DPDP Act, anyone under 18 is a child, a much higher age than many foreign laws use. Section 9 requires verifiable consent from a parent before you process a child’s data, and bans tracking, behavioural monitoring and targeted advertising directed at children. Rule 10 explains how to verify the parent, for example using identity details you already hold reliably, a virtual token from an authorised entity, or DigiLocker (Ruleexpert). Edtech, gaming and kids’ products should treat this as their top priority. For gaming in particular, see our guide to the Online Gaming Act 2025. A similar guardian consent rule applies to persons with disabilities who cannot make decisions for themselves.
Sign proper contracts with your vendors
You can use a data processor only under a valid contract, and you remain responsible for what your vendors do with the data. Every CRM, cloud, payroll, marketing or analytics vendor should be bound by written terms covering security safeguards, breach reporting to you, use of data only on your instructions, and deletion when the contract ends.
DPDP compliance checklist, part 2: security, breaches, retention and user rights
This half of the DPDP compliance checklist carries the biggest penalties, so give it the most attention.
Put reasonable security safeguards in place
Section 8(5) of the DPDP Act requires reasonable security safeguards to prevent a personal data breach, and failure here carries the highest penalty in the Act. Rule 6 spells out the minimum: encryption, masking or tokenisation of personal data, access controls, monitoring and logging to detect unauthorised access, and backups to keep data available. Access and processing logs must be kept for at least one year (Tsaaro). For a small business, that usually means switching on multi-factor authentication everywhere, limiting who can download customer lists, encrypting laptops and databases, and turning on audit logs in the tools you already use.
Prepare your breach response before you need it
Under Rule 7, when you become aware of a personal data breach, you must notify every affected person without delay, and notify the Data Protection Board without delay too. You then have 72 hours to send the Board a detailed report, unless it allows more time on a written request (Rule 7 text). Unlike some foreign laws, there’s no minimum size for a breach to count. A single misdirected spreadsheet qualifies. Write a one-page breach plan now: who decides, who informs customers, who drafts the Board report, and which lawyer you’ll call. If the incident is a cyber attack, CERT-In’s six-hour reporting clock also applies; see our CERT-In 6-hour rule guide. Employees pasting customer data into AI tools is a common source of breaches, covered in our guide to AI tools at work.
Set retention and deletion rules
Under the DPDP Act, you must erase personal data once its purpose is served or consent is withdrawn, unless another law requires you to keep it. Tax and company law records, for instance, still need to be kept for the periods those laws set. Large platforms have specific rules. E-commerce and social media businesses with two crore or more registered users, and online gaming businesses with 50 lakh or more, must erase a user’s data after three years of inactivity, with 48 hours’ notice before deletion (KPMG).
Publish a contact person and a rights process
Your website or app must show the business contact details of a person who can answer questions about personal data. Data Principals have the right to access a summary of their data, to correct, complete, update and erase it, to nominate someone to act for them, and to grievance redressal. You must publish how to make these requests and resolve grievances within 90 days (Shardul Amarchand Mangaldas). A simple ticketing system with a dedicated email address is enough for most small businesses.
Check your cross-border transfers
The DPDP Act allows personal data to be transferred outside India, except to countries the government restricts by notification. Sector-specific rules that are stricter, such as RBI’s data localisation requirements for payment data, continue to apply alongside it.
Know whether you could be an SDF
If the government notifies your business as a Significant Data Fiduciary, you must also appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits. Fast-growing consumer apps, fintechs and AI startups should keep an eye on this.
Penalties, enforcement and legal remedies under the DPDP Act
The penalty schedule
DPDP Act penalties are civil financial penalties imposed by the Data Protection Board. They are not criminal fines, but they are large. The maximum amounts set by the Schedule to the Act are:
| Breach | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach | ₹250 crore |
| Failure to notify the Board or affected persons of a breach | ₹200 crore |
| Breach of obligations on children’s data | ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | ₹150 crore |
| Breach of a voluntary undertaking accepted by the Board | Up to the penalty for the original breach |
| Any other breach of the Act or Rules | ₹50 crore |
| Breach of a Data Principal’s own duties, such as filing a frivolous complaint | ₹10,000 |
These are maximums for each instance, and one incident can trigger more than one of them (PrivyByIDfy). When fixing the amount, the Board must consider the nature, gravity and duration of the breach, the type of data, whether it was repeated, any gain made or loss avoided, the steps taken to mitigate it, and whether the penalty is proportionate. In practice, a small business that can show genuine compliance efforts and a quick response is in a far better position than one that did nothing.
How DPDP enforcement works
A person must first raise a grievance with the business itself. Only after that process is exhausted can they complain to the Data Protection Board, which is designed to work entirely online. The Board can inquire into the complaint, order urgent steps to contain a breach, refer the dispute to mediation, or accept a voluntary undertaking from the business, which closes the proceedings if honoured. If the Board imposes a penalty, an appeal lies to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days, and from there to the Supreme Court. Civil courts cannot entertain matters that fall within the Board’s jurisdiction. Where a business has been penalised more than once, the government can, on the Board’s reference, block public access to its platform.
A practical note: although the Board was formally established in November 2025, reports as of August 2026 indicated that its Chairperson and Members had not yet been appointed (LiveLaw). Expect enforcement to ramp up quickly once the Board is staffed and the May 2027 obligations take effect.
Remedies for individuals whose data is misused
Penalties under the DPDP Act go to the government, not to the victim. The Act does not itself provide compensation to the affected person, so it’s worth knowing the other legal remedies:
- Complaint to the Data Protection Board, after first using the business’s grievance process, to secure corrective directions and penalties.
- Compensation under Section 43A of the IT Act, 2000, for negligent handling of sensitive personal data. This route remains available until Section 44(2) of the DPDP Act takes effect in May 2027 and removes it. Claims of up to ₹5 crore go to the adjudicating officer.
- Criminal complaint under Section 72A of the IT Act, where a person discloses personal information in breach of a lawful contract, with intent to cause wrongful loss or gain. The punishment is up to three years’ imprisonment, a fine of up to ₹5 lakh, or both.
- Consumer complaint before the Consumer Commission, where the misuse amounts to a deficiency in service or an unfair trade practice.
- Writ petition under Article 226 or 32 where a government body violates the right to privacy recognised in K.S. Puttaswamy v. Union of India (2017).
If your business receives a complaint, respond within your grievance timeline, document everything, contain the issue, and get legal advice early. Offering a voluntary undertaking at the right stage can save a small business from a penalty altogether.
A practical DPDP action plan for small businesses and startups
A DPDP compliance programme doesn’t need a big consulting budget. It needs an owner, a plan and steady progress. Here’s how we’d break the work down for a small business or early-stage startup between now and the deadline.
Now to December 2026: understand your data
Name one person as the internal owner of DPDP compliance. Complete your data map and vendor list. Delete data you have no reason to keep. Switch on the basic security measures straight away: multi-factor authentication, encryption, role-based access and audit logs. These cost little and address the ₹250 crore risk directly.
January to March 2027: fix what customers see
Rewrite your privacy notice to meet Rule 3, rebuild your consent flows, add age checks and parental consent if children use your product, and sign data processing terms with every vendor. Draft a retention schedule that says how long each type of data is kept and when it is deleted.
April to May 2027: get ready for a bad day
Finalise your breach response plan and run a mock drill against the 72-hour timeline. Publish your contact person and rights request process, set up a grievance ticketing system with a 90-day limit, and train your team, especially sales and support staff who handle customer data every day. Keep written records of all of this, because documented effort counts when the Board decides a penalty.
If MeitY’s proposal to shorten the timeline is notified, compress this plan into the time left. That’s why starting now is the safer choice.
What about a startup exemption?
Section 17(3) of the DPDP Act allows the government to notify certain data fiduciaries, including startups, as exempt from some obligations: the notice requirement, accuracy and erasure duties, SDF obligations and the right of access. As far as we are aware, no such notification has been issued. Don’t build your plans around an exemption that may never arrive.
Quick answers
Does the DPDP Act apply to my offline shop?
Only to personal data in digital form, or paper records that you later digitise. A billing app, a customer WhatsApp list or a scanned register brings you within the Act.
Do I need to appoint a Data Protection Officer?
A Data Protection Officer is mandatory only for Significant Data Fiduciaries. Every other business must still publish the contact details of a person who can answer data protection questions.
Is GDPR compliance enough for DPDP compliance?
It’s a good start, but not enough. The DPDP Act treats everyone under 18 as a child, requires breach reporting with no minimum threshold, and requires notices to be available in Indian languages.
Related reading: gig and platform workers under the Social Security Code and the new labour codes for startups; also Consent managers going live in November 2026, children’s data and AI chatbots and AI in hiring and employee monitoring; also India’s DPDP Act for US SaaS companies; also Indian AI teams and US client data; also India’s DPDP Act for UK businesses and UK GDPR transfers to India.
Final word
The DPDP Act is the most important new compliance law Indian businesses have faced in years, but it rewards the prepared. A clear data map, honest notices, real consent, basic security and a tested breach plan will cover most of what a small business needs, and they also build customer trust.
At Halverton & Co., we help startups, SaaS and fintech companies and small businesses with DPDP Act compliance, from data mapping and privacy notices to vendor contracts, breach response and representation before the Data Protection Board. We practise in Jharkhand, Maharashtra and before the Supreme Court of India, and work as fractional legal counsel for technology-driven businesses. Halverton & Co.: Where tech needs law!
Write to us at office@halvertonandco.com, or get in touch, to begin your DPDP compliance review. Related reading: trademark registration for startups and deepfakes and personality rights in India.
This article reflects the DPDP Act, 2023, the DPDP Rules, 2025 and developments reported up to early October 2026. Timelines may change; check the latest MeitY notifications before acting.
Related practice area
Technology & AI Law
Contracts, data protection and AI policies for products that handle other people’s data.
View the practice area



