Compliance · 10 min read

DPDP Act 2023 Compliance Checklist for Small Businesses India — What You Must Do

By the India Law Simplified editorial team · Verified against primary government sources (bare Acts & official portals) · Last updated 2026-07-27

⚡ Quick answer

India's Digital Personal Data Protection Act 2023 (DPDP Act) is a landmark privacy law that places obligations on any business that collects, stores or processes personal data of Indians — whether online or offline. The DPDP Rules 2025 were notified on 14 November 2025, starting an 18-month phased compliance window that runs to 14 May 2027 — this is no longer a future law to prepare for, it is already partly in force. Here is a plain-English checklist of what small and medium businesses need to do right now.

Share:WhatsAppX / TwitterFacebook

1Who must comply: are you a 'Data Fiduciary'?

Under the DPDP Act, a 'Data Fiduciary' is any person or entity that determines the purpose and means of processing personal data. If you collect any of the following, you are a Data Fiduciary: names, email addresses, phone numbers, PAN/Aadhaar details, location data, health information, financial details of individuals. This includes virtually every business with a website, customer database, employee records or mobile app.

Exemptions: Purely personal/domestic data processing, data processed by courts for judicial functions, and some government functions are exempt. There is no revenue-based 'small business' exemption — all Data Fiduciaries must comply, though the government may notify specific thresholds through Rules.

3Checklist Part 2: Data Principal Rights

4Checklist Part 3: Data Processors & Cross-Border Transfers

5Checklist Part 4: Security & Breach Response

6Significant Data Fiduciary — do the heavier obligations apply to you?

The government can designate certain Data Fiduciaries as a 'Significant Data Fiduciary' (SDF) based on the volume and sensitivity of personal data they process, the risk to Data Principals' rights, and similar factors. Most small businesses will not be designated an SDF — this status is aimed at large-scale processors, not a typical local business with a customer database.

If you are designated one, the obligations step up considerably: appointing an India-based Data Protection Officer, undertaking a Data Protection Impact Assessment and an independent data audit once every twelve months, reporting the significant findings of both to the Board, and exercising due diligence over any algorithmic software used to make sure it does not pose a risk to Data Principals' rights. You would also need to watch for any government-specified restriction on transferring certain categories of data outside India.

Unless and until you are formally notified as an SDF, these heavier obligations do not apply — but it is worth tracking whether your business grows into that category, since the notification is based on your own data footprint, not a self-declaration.

7Penalties — why you cannot ignore this

8Quick-start action plan for small businesses

Frequently asked questions

Does the DPDP Act apply to employee data?

The Act applies to processing of 'digital personal data' broadly — including employee data (name, salary, bank details, Aadhaar, health records). Employers must comply with notice, consent and rights obligations for employee personal data. Employee data processed for employment purposes likely has a legitimate basis, but employees still have rights under the Act (correction, erasure, grievance redressal).

Is DPDP Act compliance the same as ISO 27001?

No — ISO 27001 is an information security management standard that covers systems, processes and controls for all types of data. DPDP Act compliance is a legal requirement focused specifically on personal data of Indian citizens. You can have ISO 27001 without being DPDP-compliant (if you lack consent mechanisms or a Grievance Officer), and vice versa.

Does the DPDP Act apply to customer data I collected before the Rules were notified?

Yes — the Act does not exempt data collected earlier, though it is not retrospectively punitive about how that consent was originally taken. For a customer whose consent predates the Act, you are required to send a notice as soon as reasonably practicable describing what data of theirs you hold and the purpose you continue to process it for, so they can exercise their rights going forward. You do not need to re-collect consent from scratch for your whole existing database, but every other obligation — security safeguards, breach notification, honouring correction and erasure requests — applies to that data exactly as it does to anything collected after 14 November 2025.

My website uses Google Analytics. Does that trigger DPDP obligations?

Using Google Analytics means you (as the website owner / Data Fiduciary) collect IP addresses and behavioural data of Indian visitors via Google (your Data Processor). You must: (a) disclose this in your Privacy Notice; (b) obtain consent before placing analytics cookies in states where cookies are personal data; (c) have a Data Processing Agreement with Google. Google's standard Data Processing Terms for GA satisfy (c); you need to handle (a) and (b).

Ask our free AI legal assistant →

Related guides

Free tools for this

Ask the AI Advocate (free)  ·  Free legal & tax tools

📖 New to the jargon? Browse our plain-English legal & tax glossary →

Share:WhatsAppX / TwitterFacebook

India Law Simplified is an AI-assisted research & drafting tool, not a substitute for a licensed advocate or CA. Verify all figures and steps with a professional before acting. Statutory limits and fees change with each Finance Act / notification.