DPDP Act Compliance: A Practical Guide for Small Businesses (2026)
India's Digital Personal Data Protection Act is now in its phased rollout. Here's what it actually requires of a small or mid-sized business, in plain language, with a checklist you can start on today.
Introduction
What Is the DPDP Act?
India's first comprehensive personal data protection law is now being operationalised in phases, and it applies to businesses of every size.
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive law governing how organisations collect, store, use and share the digital personal data of individuals in India. It received Presidential assent in August 2023, and the Digital Personal Data Protection Rules, 2025 — which turn the Act's principles into concrete operational requirements — were notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025.
Unlike sector-specific rules businesses may already be used to, the DPDP Act is broad: if your business collects names, emails, phone numbers, or any other digital personal data from customers, employees, or website visitors, you are a "Data Fiduciary" under the Act, and its obligations apply to you.
What this guide covers
- The three-phase enforcement timeline
- Who counts as a Data Fiduciary — and whether small businesses are exempt
- Core obligations: notice, consent, breach reporting, and data erasure
- Significant Data Fiduciary status and when it applies
- The penalty schedule
- A practical compliance checklist for SMBs
Rollout
The Three-Phase Enforcement Timeline
The Act isn't switching on all at once — it's being phased in over 18 months from the Rules' notification date.
Board & Foundational Provisions
The Data Protection Board of India (DPBI) is established as the digital-first adjudicatory body that will hear complaints, investigate violations, and impose penalties.
Consent Manager Registration
The framework for registering Consent Managers — third-party platforms that let individuals manage consent across services — opens for registration.
Full Substantive Compliance
Notice and consent requirements, data principal rights, breach notification duties, and Significant Data Fiduciary obligations all become enforceable.
Phase 3 is the one that matters most operationally — but "18 months away" is exactly the kind of deadline that arrives faster than expected once consent flows, privacy notices, and breach playbooks need to be rebuilt. Starting now avoids a scramble in early 2027.
Scope
Who Does the Act Apply To?
The Act applies to any "Data Fiduciary" — a person or organisation that determines the purpose and means of processing personal data — that processes digital personal data of individuals in India. This covers essentially any business with a website contact form, a customer database, an HR system, or an email marketing list.
It also applies to processing outside India if it relates to offering goods or services to individuals in India. A "Data Processor" — a vendor that processes data on a Fiduciary's behalf, such as a cloud host or SaaS tool — has its own set of contractual obligations under Rule 11, even though the primary compliance burden sits with the Fiduciary.
Is my business exempt?
- No general small-business exemption exists
- A 3-person company using a spreadsheet of customer emails is a Data Fiduciary, same as a large enterprise
- The Government can notify relief for specific classes, including startups — but this must be formally designated, not assumed
- What scales with your size is the complexity of compliance, not whether it applies at all
The core rules
What the Act Requires of Your Business
Four obligations form the operational core of DPDP compliance for most businesses.
Notice & Consent
A clear, plain-language notice is required at the point of data collection, itemising what data is collected, why, and how to withdraw consent. Consent must be free, specific, informed and given through clear affirmative action — pre-ticked boxes and bundled consent don't qualify.
Data Principal Rights
Individuals can request a summary of what data you hold on them and who you've shared it with, ask for corrections or erasure, escalate unresolved complaints to your grievance process and then the Board, and nominate someone to exercise these rights on their behalf.
Breach Notification
Every personal data breach — with no minimum severity threshold — must be reported to the Data Protection Board and to affected individuals without delay, within a 72-hour window under the Rules. Late or missed notification carries some of the Act's steepest penalties.
Retention & Erasure
Personal data must be erased once its purpose is served, consent is withdrawn, or a user goes inactive for the retention period you've defined — with at least 48 hours' notice before scheduled erasure so the individual can object.
Children's Data
Processing a child's (under-18) personal data requires verifiable parental consent, with limited exemptions notified for specific purposes and classes of Fiduciary.
Vendor Contracts
Rule 11 requires a written contract with every Data Processor — cloud hosts, SaaS tools, email platforms — covering purpose, data categories, required security measures, breach notification back to you, and deletion or return of data when the relationship ends.
Heightened obligations
Significant Data Fiduciaries (SDF)
When It Applies
The Government can designate any Data Fiduciary — or class of Fiduciaries — as an SDF based on factors including the volume and sensitivity of data processed, the risk of harm to individuals, and potential impact on India's sovereignty, security or electoral integrity.
- Most small and mid-sized businesses will not meet this bar
- Businesses handling large volumes of sensitive data (health, financial, biometric) at scale should monitor future notifications closely
Added Obligations
If designated, an SDF takes on obligations well beyond baseline compliance:
- Appoint a Data Protection Officer based in India
- Appoint an independent data auditor
- Conduct an annual Data Protection Impact Assessment (DPIA) and audit, reported to the Board
- Additional restrictions on certain cross-border data transfers
Enforcement
Penalties for Non-Compliance
The Schedule to the Act sets maximum penalties by violation type. The Data Protection Board decides the actual amount based on the nature, gravity and duration of the breach, the number of people affected, and the Fiduciary's compliance history.
| Violation | Provision | Maximum Penalty |
|---|---|---|
| Failure to implement reasonable security safeguards | Section 8(5) | ₹250 crore |
| Failure to notify the Board or affected individuals of a breach | Section 8(6) | ₹200 crore |
| Non-compliance with children's data provisions | Section 9 | ₹200 crore |
| Failure to fulfil additional Significant Data Fiduciary obligations | Section 10 | ₹150 crore |
| Breach of a voluntary undertaking accepted by the Board | Section 32 | Up to the underlying penalty |
| Failure of a Data Principal's own duties | Section 15 | ₹10,000 |
Getting started
A Practical Compliance Checklist for SMBs
You don't need to solve everything before May 2027 — but starting these now means you're not rebuilding under deadline pressure.
- Map what personal data you collect, where it's stored, and why — across your website forms, CRM, HR systems, and marketing tools
- Rewrite consent notices and checkboxes in clear, plain language, with an itemised description of data and purpose, and an easy way to withdraw consent
- Issue retrospective notices to individuals whose data you collected before your updated notice was in place
- Set up a process to respond to access, correction, and erasure requests within a reasonable timeframe
- Define data retention periods and build an erasure workflow, including the 48-hour advance notice
- Draft or update contracts with every vendor and processor that touches personal data on your behalf, per Rule 11
- Build a breach response plan that can realistically meet the 72-hour notification window
- Assign internal ownership for DPDP compliance, even if it's a part-time responsibility for now
Rua Technologies Recommendation: Start with data mapping and consent notices — they surface most of the downstream work automatically and are the two areas regulators and courts elsewhere have scrutinised first under similar laws.
Talk to Rua TechnologiesCommon questions
Frequently Asked Questions
Does the DPDP Act apply to small businesses, or only large companies?
Yes. The Act applies to every Data Fiduciary that processes digital personal data of individuals in India, regardless of size. There is no blanket small-business exemption, though the Government can notify specific relief for certain classes such as startups.
What counts as valid consent under the DPDP Act?
Consent must be free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and accompanied by an itemised notice covering what data is collected, why, and how to withdraw consent.
How quickly must a data breach be reported?
Breaches must be reported to the Data Protection Board and affected individuals without delay, with the Rules specifying a 72-hour window and no materiality threshold — meaning even small breaches must be reported.
What is a Significant Data Fiduciary and does it apply to my business?
A Significant Data Fiduciary is a category the Government designates based on factors like data volume, sensitivity and risk of harm. Most small and mid-sized businesses will not be designated, but any organisation handling large volumes of sensitive personal data should monitor this classification.
What are the penalties for non-compliance?
Penalties are set out in the Schedule to the Act and scale by violation type, ranging up to ₹250 crore for failing to implement reasonable security safeguards. The Data Protection Board sets the actual amount based on the nature, gravity and duration of the breach.
When does full enforcement begin?
The DPDP Rules were notified in November 2025 with a phased rollout. Most substantive compliance obligations, including consent, notice and breach-notification duties, become enforceable 18 months after notification, in May 2027.
Conclusion
The DPDP Act's 18-month runway is generous, but the businesses that start early on data mapping, consent notices, and vendor contracts will find the rest of compliance falls into place with far less disruption. If you'd rather have an IT partner help operationalise this alongside your existing Microsoft 365 and cybersecurity stack, that's exactly where Rua Technologies' consulting team can help.
Keep reading