
- 11-August,2026
Data Privacy for Small Businesses: What DPDP Act Compliance Actually Requires
If you collect customer names, phone numbers, or payment details, even on WhatsApp or Excel, the DPDP Act applies to you, and compliance simply means asking for consent, storing data safely, and deleting it when it is no longer needed.
Most owners hear "DPDP Act" and think it is only for big IT companies. It is not. A shop in Pune, a clinic in Chennai, or a small online store keeping customer numbers on a spreadsheet is already covered.
Quick Overview: DPDP Act For Small Business
|
What |
Details |
|
Law name |
Digital Personal Data Protection Act, 2023 |
|
Rules notified |
14 November 2025 |
|
Full compliance deadline |
13 May 2027 |
|
Who it applies to |
Any business collecting digital personal data of Indian residents |
|
Maximum penalty |
Up to ₹250 crore per violation |
|
Breach reporting window |
72 hours |
What is the DPDP Act, in simple words?
The DPDP Act is India's law that tells businesses how to collect, store, and use a customer's personal data responsibly, and it gives customers the right to know and control what happens to their own information.
Think of it this way. A customer sharing their phone number for a delivery update is trusting you with something personal. The DPDP Act puts that trust into a written rulebook, saying you cannot use that number for anything they did not agree to.
Does a small business really need to comply?
Size does not matter here. If you process personal data of anyone in India, through an app, a website form, or even a paper register linked to digital records, the law applies to you as a Data Fiduciary.
There is no exemption slip for small shops or startups. What changes with size is not whether the law applies, but how simple compliance can be. A clear consent message and a basic data log can be enough to start.
What counts as personal data under this law?
Personal data is any information that can identify a person, and this includes names, phone numbers, email IDs, addresses, photos, and even device or location data collected through your app or website.
This is broader than most owners expect. It is not just Aadhaar or PAN numbers. A simple order form with a name and phone number already counts, and so do WhatsApp Business chats used to confirm orders.
What does consent actually need to look like?
Consent means the customer clearly agreed, in plain language, to a specific use of their data, and they must be able to withdraw that consent as easily as they gave it.
Here is what proper consent looks like in practice:
-
A short, clear message explaining what data you are collecting and why
-
No pre-ticked boxes or hidden checkboxes
-
Separate consent for marketing versus order updates
-
An easy way to opt out, like replying "STOP" on WhatsApp
This is where many businesses stumble. Bundling "I agree to receive offers" inside a payment confirmation is not valid consent anymore.
What happens if there is a data breach?
If personal data is leaked, stolen, or accessed without permission, the business must inform the Data Protection Board and the affected customers within 72 hours, along with what happened and what steps are being taken.
Seventy two hours sounds like a lot until it happens. A hacked billing system, a lost laptop, or a file sent to the wrong person can all count as a breach. A basic one page response plan saves precious hours when the clock is running.
What are the penalties for non-compliance?
Penalties under the DPDP Act can go up to ₹250 crore per violation, decided by the Data Protection Board based on how serious the failure was and how many people were affected.
Warning: This is not a small fine meant to be ignored. Even a small business can face scrutiny if a breach involves thousands of records with no consent process at all. The penalty depends on the failure, not your business size.
A simple DPDP compliance checklist for small businesses
A few basic steps this month put you ahead of most small businesses in India.
Quick Checklist:
List every place you collect customer data (forms, WhatsApp, POS, apps)
Write one simple, honest consent message for each use case
Store customer data only as long as you actually need it
Set up basic password protection and limited access for staff
Create a one page breach response plan
Note down where you send customer data, including third party tools
Most small businesses lose data not to hackers but to weak passwords, shared logins, or an old laptop nobody wiped clean.
When is the actual deadline to comply?
The DPDP Rules were notified on 14 November 2025, and the full compliance deadline for all businesses is 13 May 2027, though the Data Protection Board is already active and can act on serious cases before that.
Some parts of the law, like the Board's complaint powers, are already live. The 18 month window is for building systems, not delaying action.
How is this different from just having a privacy policy?
A privacy policy is a document, while DPDP compliance is an ongoing practice covering consent, data storage, staff access, and breach response, all working together, not just written on a page.
Many businesses already have a privacy policy copied from a template. That alone does not meet the requirement, since the law expects the practice behind the page to match what is written.
In Short
-
The DPDP Act applies to any business collecting digital personal data of Indian customers, regardless of size
-
Personal data includes names, phone numbers, addresses, and WhatsApp order chats
-
Consent must be clear, specific, and easy to withdraw, not bundled or pre-ticked
-
Breaches must be reported within 72 hours to the Board and affected customers
-
Penalties can reach ₹250 crore per violation based on severity
-
Full compliance deadline is 13 May 2027, but the Board is already active
-
A basic checklist covering consent, storage, access, and breach response is a strong start
-
A privacy policy alone is not enough without matching practices behind it
DPDP Act compliance for small businesses does not have to feel like a legal maze. Start with one honest consent message and one clear list of where your customer data lives, and you are already ahead of most businesses around you. If you want help setting this up properly, you can reach out to the VSNAP Technology team and they will walk you through it, one small step at a time.
Thanks for reading ❤