← Blog/Legal & Compliance

India's DPDP Act 2023: What Every SMB Needs to Do Before the Deadline

24 April 2026·9 min read·AAbhijeet Gavali
India's DPDP Act 2023: What Every SMB Needs to Do Before the Deadline

Your customer fills out a lead form on your website. Your HR team stores employee Aadhaar numbers in a shared Google Sheet. Your CRM vendor is hosted on servers in Singapore. You send promotional WhatsApp messages to a list you bought three years ago.

Every one of these scenarios is now regulated under India's Digital Personal Data Protection (DPDP) Act, 2023 - and if you haven't started your compliance journey, you're already behind.

The Ministry of Electronics and Information Technology (MeitY) notified the Act in August 2023. The rules are being finalised, and enforcement is expected to begin in 2025–26. The Data Protection Board of India (DPBI) - the adjudicatory body - is being constituted. For Indian SMBs, the window to prepare is closing fast.

This isn't a law built only for tech giants. A Pune-based HR software startup, a Mumbai logistics company, a Bengaluru e-commerce retailer - all of you are Data Fiduciaries under this Act. And the penalties for non-compliance go up to ₹250 crore per instance.

Let's break down exactly what you need to do.


Understanding the DPDP Act: The Basics Every SMB Must Know

What Is "Personal Data" Under the Act?

The DPDP Act defines personal data as any data about an individual who is identifiable - directly or indirectly. This is broader than most SMBs realise. It includes:

  • •Names, phone numbers, email addresses
  • •Aadhaar numbers, PAN, passport details
  • •IP addresses, device IDs, location data
  • •Biometric data (fingerprints, facial recognition)
  • •Financial information (bank account numbers, transaction history)
  • •Health records

If your business collects, stores, processes, or shares any of this - even for internal HR purposes - you are a Data Fiduciary.

Who Is a Data Fiduciary vs. a Data Processor?

RoleDefinitionExample
**Data Fiduciary**Determines the purpose and means of processingYour company
**Data Processor**Processes data on behalf of the fiduciaryYour CRM vendor, payroll software
**Data Principal**The individual whose data is being processedYour customer, employee

As a Data Fiduciary, you bear primary legal responsibility. Your vendors (Data Processors) must be contractually bound to comply - and you are responsible for ensuring they do.

Significant Data Fiduciaries: Are You One?

MeitY will designate certain entities as Significant Data Fiduciaries (SDFs) based on volume of data processed, sensitivity, and national security implications. SDFs face additional obligations including appointing a Data Protection Officer (DPO), conducting periodic Data Protection Impact Assessments (DPIAs), and algorithmic audits.

Most SMBs will not be SDFs initially - but if you're in fintech, healthtech, edtech, or handle data of minors at scale, watch this space closely.


The Seven Core Obligations You Must Fulfil

1. Lawful Basis: Consent Is Now a Legal Requirement

Under the DPDP Act, you can only process personal data if you have:

  • •Free, specific, informed, unconditional, and unambiguous consent from the Data Principal, OR
  • •A legitimate use (employment purposes, medical emergencies, legal obligations, etc.)

What this means practically:

  • •Your pre-ticked checkboxes are illegal.
  • •Bundled consent ("by using our service, you agree to everything") is illegal.
  • •You need a Consent Manager - a mechanism to record, manage, and honour consent.

Action: Audit every data collection touchpoint - website forms, app onboarding, sales CRM entries, HR onboarding forms. Each must have a clear, standalone consent mechanism.

2. Notice Requirements

Before or at the time of collecting data, you must provide a notice in clear, plain language (and in all 22 scheduled languages if your users speak them) that explains:

  • •What personal data is being collected
  • •The purpose of processing
  • •How to exercise rights
  • •How to withdraw consent

Common SMB mistake: Burying this in a 10-page privacy policy written in legalese. The Act requires it to be accessible and understandable.

3. Data Principal Rights You Must Honour

Your customers and employees now have enforceable rights:

  • •Right to Access: They can ask what data you hold about them.
  • •Right to Correction: They can ask you to correct inaccurate data.
  • •Right to Erasure: They can ask you to delete their data (with some exceptions).
  • •Right to Grievance Redressal: You must have a mechanism to address complaints within a defined timeframe.
  • •Right to Nominate: They can nominate someone to exercise rights on their behalf in case of death or incapacity.

Action: Build a simple internal process - even a dedicated email address and a response SOP - to handle these requests. You have a legal obligation to respond.

4. Data Localisation and Cross-Border Transfers

The DPDP Act allows cross-border data transfers to countries that MeitY approves via a whitelist. This list is yet to be published, but the direction is clear: you cannot freely send Indian personal data to any country.

Immediate action for SMBs:

  • •Map where your data goes. Which SaaS tools store data outside India? (Salesforce, HubSpot, Slack, AWS US regions, etc.)
  • •Review vendor contracts for data processing agreements (DPAs).
  • •Prefer vendors with India-region data storage options where possible.

5. Data Retention and Deletion

You cannot retain personal data beyond the purpose for which it was collected. Once the purpose is served, you must delete it - unless retention is required by law.

Common violations:

  • •Keeping ex-employee records indefinitely
  • •Retaining customer data from abandoned carts for years
  • •Never purging old lead databases

Action: Define a Data Retention Policy with specific timelines for each data category. Automate deletion where possible.

6. Security Safeguards

You must implement "reasonable security safeguards" to prevent data breaches. While the Act doesn't prescribe specific technical standards, the expectation is proportionate to the sensitivity and volume of data you handle.

Baseline measures every SMB should have:

  • •Encrypted storage for sensitive data (Aadhaar, financial records)
  • •Role-based access controls (not everyone needs access to everything)
  • •Regular access audits
  • •Vendor security assessments

7. Breach Notification

If a data breach occurs, you must notify the Data Protection Board and affected Data Principals as soon as possible. The rules will specify exact timelines, but expect something in the 72-hour range (similar to GDPR).

Action: Create a Data Breach Response Plan now, before you need it. Identify who is responsible, what constitutes a breach, and what the notification process looks like.


The Penalty Structure: Why SMBs Can't Afford to Ignore This

ViolationMaximum Penalty
Failure to implement security safeguards₹250 crore
Failure to notify breach₹200 crore
Non-fulfilment of Data Principal rights₹50 crore
Non-compliance by Data Processor₹10 crore
Minor violations₹10,000

These are per-instance penalties. A single breach affecting 10,000 customers could trigger multiple violations simultaneously.

For context: a ₹250 crore penalty would be existential for most Indian SMBs. This is not a compliance checkbox - it's a business continuity issue.


Your 90-Day DPDP Compliance Roadmap

Days 1–30: Discovery and Assessment

Week 1–2: Data Mapping

  • •List every system that collects, stores, or processes personal data
  • •Document what data is collected, from whom, for what purpose, and where it's stored
  • •Identify all third-party vendors who receive personal data

Week 3–4: Gap Analysis

  • •Compare current practices against DPDP obligations
  • •Identify highest-risk gaps (no consent mechanism, no breach plan, uncontrolled cross-border transfers)
  • •Prioritise by risk and effort

Days 31–60: Policy and Process Building

  • •Draft or update your Privacy Policy (plain language, comprehensive)
  • •Create a Consent Management Process for each data collection touchpoint
  • •Draft Data Processing Agreements for all vendors
  • •Build a Data Subject Rights Request handling process
  • •Define your Data Retention Schedule

Days 61–90: Implementation and Training

  • •Implement consent mechanisms on all digital touchpoints
  • •Train customer-facing and HR teams on data handling
  • •Conduct a tabletop exercise for your Data Breach Response Plan
  • •Document everything - the DPBI will want evidence of compliance efforts

Special Considerations for Indian SMB Sectors

E-commerce and D2C Brands

You collect payment data, delivery addresses, browsing behaviour, and purchase history. Your consent flows at checkout and account creation need an immediate overhaul. Also review your marketing automation tools - bulk SMS and email campaigns require valid consent.

HR and Staffing Companies

Employee data is explicitly covered. Aadhaar-based verification, salary details, performance records - all regulated. Your HRMS vendor must sign a DPA. Background verification agencies you use are Data Processors under your responsibility.

Fintech and Lending Platforms

You likely handle the most sensitive data categories. Expect to be scrutinised early. If you use bureau data (CIBIL, Experian), review those data sharing agreements immediately.

SaaS Companies Selling to Indian Businesses

You are both a Data Fiduciary (for your own employee and user data) and a Data Processor (for your customers' data). Your customers will start asking for DPAs. Get ahead of this - it's becoming a sales requirement.


Building a Compliance Culture, Not Just a Compliance Checklist

The DPDP Act is not a one-time project. It requires ongoing compliance - regular audits, updated notices when you change data practices, re-consent when you expand data use, and continuous vendor management.

The SMBs that will navigate this well are those that treat data privacy as a business value, not a legal burden. Customers increasingly choose vendors they trust with their data. A clear, honest privacy practice is a competitive differentiator.

Start with the basics: know what data you have, why you have it, and who can access it. Everything else builds from there.


Ready to Get Compliant Without the Overwhelm?

IdeaSprout's Legal & Compliance product gives Indian SMBs a structured, guided path to DPDP Act compliance - from data mapping templates and consent management workflows to vendor DPA tracking and breach response playbooks.

Explore IdeaSprout Legal & Compliance →

Don't wait for enforcement to begin. The SMBs that start now will be the ones that aren't scrambling when the Data Protection Board opens its doors.

DPDP Actdata privacycomplianceIndian SMBdata protection
A

Abhijeet Gavali

Builder at IdeaSprout. Writing about software, operations, and building products for Indian businesses.