Data Protection & Compliance

DPDP Act Compliance: A Practical Guide for Small Businesses (2026)

India's Digital Personal Data Protection Act is now in its phased rollout. Here's what it actually requires of a small or mid-sized business, in plain language, with a checklist you can start on today.

Updated: September 2026Reading time: 9 minCategory: Compliance
18 monthsPhased rollout to full enforcement
72 hoursBreach notification window
₹250 CrMaximum penalty per violation

Introduction

What Is the DPDP Act?

India's first comprehensive personal data protection law is now being operationalised in phases, and it applies to businesses of every size.

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive law governing how organisations collect, store, use and share the digital personal data of individuals in India. It received Presidential assent in August 2023, and the Digital Personal Data Protection Rules, 2025 — which turn the Act's principles into concrete operational requirements — were notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025.

Unlike sector-specific rules businesses may already be used to, the DPDP Act is broad: if your business collects names, emails, phone numbers, or any other digital personal data from customers, employees, or website visitors, you are a "Data Fiduciary" under the Act, and its obligations apply to you.

What this guide covers

  • The three-phase enforcement timeline
  • Who counts as a Data Fiduciary — and whether small businesses are exempt
  • Core obligations: notice, consent, breach reporting, and data erasure
  • Significant Data Fiduciary status and when it applies
  • The penalty schedule
  • A practical compliance checklist for SMBs
This guide is for general informational purposes and reflects the DPDP Act, 2023 and the DPDP Rules, 2025 as notified. It is not legal advice. Consult a qualified lawyer to confirm how the Act applies to your specific business.

Rollout

The Three-Phase Enforcement Timeline

The Act isn't switching on all at once — it's being phased in over 18 months from the Rules' notification date.

1November 2025

Board & Foundational Provisions

The Data Protection Board of India (DPBI) is established as the digital-first adjudicatory body that will hear complaints, investigate violations, and impose penalties.

2November 2026

Consent Manager Registration

The framework for registering Consent Managers — third-party platforms that let individuals manage consent across services — opens for registration.

3May 2027

Full Substantive Compliance

Notice and consent requirements, data principal rights, breach notification duties, and Significant Data Fiduciary obligations all become enforceable.

Phase 3 is the one that matters most operationally — but "18 months away" is exactly the kind of deadline that arrives faster than expected once consent flows, privacy notices, and breach playbooks need to be rebuilt. Starting now avoids a scramble in early 2027.

Scope

Who Does the Act Apply To?

The Act applies to any "Data Fiduciary" — a person or organisation that determines the purpose and means of processing personal data — that processes digital personal data of individuals in India. This covers essentially any business with a website contact form, a customer database, an HR system, or an email marketing list.

It also applies to processing outside India if it relates to offering goods or services to individuals in India. A "Data Processor" — a vendor that processes data on a Fiduciary's behalf, such as a cloud host or SaaS tool — has its own set of contractual obligations under Rule 11, even though the primary compliance burden sits with the Fiduciary.

Is my business exempt?

  • No general small-business exemption exists
  • A 3-person company using a spreadsheet of customer emails is a Data Fiduciary, same as a large enterprise
  • The Government can notify relief for specific classes, including startups — but this must be formally designated, not assumed
  • What scales with your size is the complexity of compliance, not whether it applies at all

The core rules

What the Act Requires of Your Business

Four obligations form the operational core of DPDP compliance for most businesses.

Notice & Consent

A clear, plain-language notice is required at the point of data collection, itemising what data is collected, why, and how to withdraw consent. Consent must be free, specific, informed and given through clear affirmative action — pre-ticked boxes and bundled consent don't qualify.

Data Principal Rights

Individuals can request a summary of what data you hold on them and who you've shared it with, ask for corrections or erasure, escalate unresolved complaints to your grievance process and then the Board, and nominate someone to exercise these rights on their behalf.

Breach Notification

Every personal data breach — with no minimum severity threshold — must be reported to the Data Protection Board and to affected individuals without delay, within a 72-hour window under the Rules. Late or missed notification carries some of the Act's steepest penalties.

Retention & Erasure

Personal data must be erased once its purpose is served, consent is withdrawn, or a user goes inactive for the retention period you've defined — with at least 48 hours' notice before scheduled erasure so the individual can object.

Children's Data

Processing a child's (under-18) personal data requires verifiable parental consent, with limited exemptions notified for specific purposes and classes of Fiduciary.

Vendor Contracts

Rule 11 requires a written contract with every Data Processor — cloud hosts, SaaS tools, email platforms — covering purpose, data categories, required security measures, breach notification back to you, and deletion or return of data when the relationship ends.

Heightened obligations

Significant Data Fiduciaries (SDF)

When It Applies

The Government can designate any Data Fiduciary — or class of Fiduciaries — as an SDF based on factors including the volume and sensitivity of data processed, the risk of harm to individuals, and potential impact on India's sovereignty, security or electoral integrity.

  • Most small and mid-sized businesses will not meet this bar
  • Businesses handling large volumes of sensitive data (health, financial, biometric) at scale should monitor future notifications closely

Added Obligations

If designated, an SDF takes on obligations well beyond baseline compliance:

  • Appoint a Data Protection Officer based in India
  • Appoint an independent data auditor
  • Conduct an annual Data Protection Impact Assessment (DPIA) and audit, reported to the Board
  • Additional restrictions on certain cross-border data transfers

Enforcement

Penalties for Non-Compliance

The Schedule to the Act sets maximum penalties by violation type. The Data Protection Board decides the actual amount based on the nature, gravity and duration of the breach, the number of people affected, and the Fiduciary's compliance history.

ViolationProvisionMaximum Penalty
Failure to implement reasonable security safeguardsSection 8(5)₹250 crore
Failure to notify the Board or affected individuals of a breachSection 8(6)₹200 crore
Non-compliance with children's data provisionsSection 9₹200 crore
Failure to fulfil additional Significant Data Fiduciary obligationsSection 10₹150 crore
Breach of a voluntary undertaking accepted by the BoardSection 32Up to the underlying penalty
Failure of a Data Principal's own dutiesSection 15₹10,000

Getting started

A Practical Compliance Checklist for SMBs

You don't need to solve everything before May 2027 — but starting these now means you're not rebuilding under deadline pressure.

  • Map what personal data you collect, where it's stored, and why — across your website forms, CRM, HR systems, and marketing tools
  • Rewrite consent notices and checkboxes in clear, plain language, with an itemised description of data and purpose, and an easy way to withdraw consent
  • Issue retrospective notices to individuals whose data you collected before your updated notice was in place
  • Set up a process to respond to access, correction, and erasure requests within a reasonable timeframe
  • Define data retention periods and build an erasure workflow, including the 48-hour advance notice
  • Draft or update contracts with every vendor and processor that touches personal data on your behalf, per Rule 11
  • Build a breach response plan that can realistically meet the 72-hour notification window
  • Assign internal ownership for DPDP compliance, even if it's a part-time responsibility for now

Rua Technologies Recommendation: Start with data mapping and consent notices — they surface most of the downstream work automatically and are the two areas regulators and courts elsewhere have scrutinised first under similar laws.

Talk to Rua Technologies

Common questions

Frequently Asked Questions

Does the DPDP Act apply to small businesses, or only large companies?

Yes. The Act applies to every Data Fiduciary that processes digital personal data of individuals in India, regardless of size. There is no blanket small-business exemption, though the Government can notify specific relief for certain classes such as startups.

What counts as valid consent under the DPDP Act?

Consent must be free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and accompanied by an itemised notice covering what data is collected, why, and how to withdraw consent.

How quickly must a data breach be reported?

Breaches must be reported to the Data Protection Board and affected individuals without delay, with the Rules specifying a 72-hour window and no materiality threshold — meaning even small breaches must be reported.

What is a Significant Data Fiduciary and does it apply to my business?

A Significant Data Fiduciary is a category the Government designates based on factors like data volume, sensitivity and risk of harm. Most small and mid-sized businesses will not be designated, but any organisation handling large volumes of sensitive personal data should monitor this classification.

What are the penalties for non-compliance?

Penalties are set out in the Schedule to the Act and scale by violation type, ranging up to ₹250 crore for failing to implement reasonable security safeguards. The Data Protection Board sets the actual amount based on the nature, gravity and duration of the breach.

When does full enforcement begin?

The DPDP Rules were notified in November 2025 with a phased rollout. Most substantive compliance obligations, including consent, notice and breach-notification duties, become enforceable 18 months after notification, in May 2027.

Conclusion

The DPDP Act's 18-month runway is generous, but the businesses that start early on data mapping, consent notices, and vendor contracts will find the rest of compliance falls into place with far less disruption. If you'd rather have an IT partner help operationalise this alongside your existing Microsoft 365 and cybersecurity stack, that's exactly where Rua Technologies' consulting team can help.