Compliance · 10 min read
DPDP Act 2023 Compliance Checklist for Small Businesses India — What You Must Do
By the India Law Simplified editorial team · Verified against primary government sources (bare Acts & official portals) · Last updated 2026-07-27
India's Digital Personal Data Protection Act 2023 (DPDP Act) is a landmark privacy law that places obligations on any business that collects, stores or processes personal data of Indians — whether online or offline. The DPDP Rules 2025 were notified on 14 November 2025, starting an 18-month phased compliance window that runs to 14 May 2027 — this is no longer a future law to prepare for, it is already partly in force. Here is a plain-English checklist of what small and medium businesses need to do right now.
1Who must comply: are you a 'Data Fiduciary'?
Under the DPDP Act, a 'Data Fiduciary' is any person or entity that determines the purpose and means of processing personal data. If you collect any of the following, you are a Data Fiduciary: names, email addresses, phone numbers, PAN/Aadhaar details, location data, health information, financial details of individuals. This includes virtually every business with a website, customer database, employee records or mobile app.
Exemptions: Purely personal/domestic data processing, data processed by courts for judicial functions, and some government functions are exempt. There is no revenue-based 'small business' exemption — all Data Fiduciaries must comply, though the government may notify specific thresholds through Rules.
2Checklist Part 1: Notice & Consent
- Audit what personal data you collect: List every personal data point you collect — from customers, employees, vendors — and why you collect it (the 'purpose').
- Draft a plain-English Privacy Notice: The DPDP Act requires notice to be given BEFORE or at the time of collecting data. It must: (a) clearly state what data is collected; (b) the purpose; (c) how to exercise data principal rights; (d) how to withdraw consent.
- Obtain valid consent: Consent must be free, specific, informed, unconditional and unambiguous (a clear affirmative action — pre-ticked boxes are not valid). Store proof of consent.
- Allow consent withdrawal: You must provide a mechanism to withdraw consent as easily as it was given. On withdrawal, you must stop processing that data (within a reasonable time specified in Rules).
- Separate consent forms: Do not bundle DPDP consent with terms & conditions. Consent for personal data processing must be a standalone, clear request.
3Checklist Part 2: Data Principal Rights
- Right to information: A Data Principal (the person whose data you hold) can ask what personal data you hold about them. You must respond within the timeframe set in the Rules.
- Right to correction and erasure: You must correct inaccurate, misleading or incomplete data on request, and erase data no longer necessary for the stated purpose.
- Right to grievance redressal: Appoint a Grievance Officer (name and contact) and publish these details, in your communications and in the public domain. You must respond to a grievance within a reasonable period, not exceeding 90 days — and the Data Principal must first exhaust this route with you before escalating to the Data Protection Board.
- Right to nominate: Data Principals can nominate another person to exercise their DPDP rights on their behalf in case of death or incapacity — you must have a mechanism to handle such nominations.
- Right to withdraw consent: Must be honoured — and you must stop processing within a reasonable period after withdrawal.
4Checklist Part 3: Data Processors & Cross-Border Transfers
- Identify your Data Processors: Any third party that processes data on your instructions (e.g. cloud hosting, email service provider, payment gateway, CRM, analytics tool) is a 'Data Processor'. You must have a written contract with each Data Processor specifying their processing obligations under the DPDP Act.
- Cross-border data transfers: The DPDP Act allows transfer of personal data to countries NOT specifically restricted by the government. Watch for the approved/restricted country list to be notified. For now: transfers to countries not on the restricted list are permitted.
- Data Localisation: The 2023 Act does NOT mandate general data localisation (unlike the 2018/2019 draft bills). However, specific sectors (finance, health) have separate localisation rules — check your sector.
5Checklist Part 4: Security & Breach Response
- Implement reasonable security: The DPDP Act requires 'reasonable security safeguards' — encryption for sensitive data in transit and at rest, access controls, employee training, regular vulnerability assessment.
- Data breach notification: A personal data breach must be notified to: (a) the Data Protection Board of India (DPBI) — as soon as the breach is discovered; (b) each affected Data Principal — in the manner prescribed in Rules. There is no 72-hour clock like GDPR but prompt notification is required.
- Retain only what is necessary: Personal data must be erased when the purpose is fulfilled or consent is withdrawn. Do not hold customer data indefinitely 'just in case'. Set a data retention policy and automate deletion where possible.
- Children's data: Special obligations apply to processing data of children (under 18) — you need verifiable parental consent and must not profile or track children.
6Significant Data Fiduciary — do the heavier obligations apply to you?
The government can designate certain Data Fiduciaries as a 'Significant Data Fiduciary' (SDF) based on the volume and sensitivity of personal data they process, the risk to Data Principals' rights, and similar factors. Most small businesses will not be designated an SDF — this status is aimed at large-scale processors, not a typical local business with a customer database.
If you are designated one, the obligations step up considerably: appointing an India-based Data Protection Officer, undertaking a Data Protection Impact Assessment and an independent data audit once every twelve months, reporting the significant findings of both to the Board, and exercising due diligence over any algorithmic software used to make sure it does not pose a risk to Data Principals' rights. You would also need to watch for any government-specified restriction on transferring certain categories of data outside India.
Unless and until you are formally notified as an SDF, these heavier obligations do not apply — but it is worth tracking whether your business grows into that category, since the notification is based on your own data footprint, not a self-declaration.
7Penalties — why you cannot ignore this
- Breach of child data obligations: Up to ₹200 crore per instance
- Failure to implement adequate security: Up to ₹250 crore per instance
- Breach of notification duty (Board/Data Principal): Up to ₹200 crore
- Other breaches of the Act: Up to ₹50 crore per instance
- The Data Protection Board of India (DPBI) is the adjudicating authority — it can take suo motu action and impose penalties without a complaint.
- Enforcement timeline: The DPDP Rules 2025 were notified on 14 November 2025. The provisions establishing the Data Protection Board of India and its Appellate Tribunal took effect immediately on notification. Consent Manager registration under Section 6(9) comes into force one year later, from 13 November 2026, once the interoperable consent-management infrastructure is ready. The overall phased compliance window closes 18 months after notification, on 14 May 2027 — after that, full enforcement applies.
8Quick-start action plan for small businesses
- This month: Do a data inventory — list every personal data point you collect and why
- This month: Update your Privacy Policy to DPDP-compliant language (plain English, purpose-specific)
- This month: Add a clear consent checkbox to your website contact/enquiry forms (not pre-ticked)
- Next month: Identify your Data Processors and ensure you have written contracts with each
- Next month: Appoint a Grievance Officer and publish contact details on your website
- 3 months: Implement a data retention and deletion policy
- 6 months: Review your security infrastructure — encryption, access controls, employee training
Frequently asked questions
Does the DPDP Act apply to employee data?
The Act applies to processing of 'digital personal data' broadly — including employee data (name, salary, bank details, Aadhaar, health records). Employers must comply with notice, consent and rights obligations for employee personal data. Employee data processed for employment purposes likely has a legitimate basis, but employees still have rights under the Act (correction, erasure, grievance redressal).
Is DPDP Act compliance the same as ISO 27001?
No — ISO 27001 is an information security management standard that covers systems, processes and controls for all types of data. DPDP Act compliance is a legal requirement focused specifically on personal data of Indian citizens. You can have ISO 27001 without being DPDP-compliant (if you lack consent mechanisms or a Grievance Officer), and vice versa.
Does the DPDP Act apply to customer data I collected before the Rules were notified?
Yes — the Act does not exempt data collected earlier, though it is not retrospectively punitive about how that consent was originally taken. For a customer whose consent predates the Act, you are required to send a notice as soon as reasonably practicable describing what data of theirs you hold and the purpose you continue to process it for, so they can exercise their rights going forward. You do not need to re-collect consent from scratch for your whole existing database, but every other obligation — security safeguards, breach notification, honouring correction and erasure requests — applies to that data exactly as it does to anything collected after 14 November 2025.
My website uses Google Analytics. Does that trigger DPDP obligations?
Using Google Analytics means you (as the website owner / Data Fiduciary) collect IP addresses and behavioural data of Indian visitors via Google (your Data Processor). You must: (a) disclose this in your Privacy Notice; (b) obtain consent before placing analytics cookies in states where cookies are personal data; (c) have a Data Processing Agreement with Google. Google's standard Data Processing Terms for GA satisfy (c); you need to handle (a) and (b).
Ask our free AI legal assistant →
Related guides
Free tools for this
Ask the AI Advocate (free) · Free legal & tax tools
📖 New to the jargon? Browse our plain-English legal & tax glossary →
India Law Simplified is an AI-assisted research & drafting tool, not a substitute for a licensed advocate or CA. Verify all figures and steps with a professional before acting. Statutory limits and fees change with each Finance Act / notification.