DPDP Act Basics: What Small Businesses in India Should Know
India's Digital Personal Data Protection Act changes how businesses must handle customer and staff data. This guide explains the main ideas in simple words and shows the security steps that support compliance.
What does DPDP Act compliance mean for a small business?
DPDP Act compliance means following India's Digital Personal Data Protection Act, 2023 when you collect and use personal data in digital form. A small business must have a clear purpose, give notice, get valid consent where needed, protect data with reasonable security, report breaches as the rules require, delete data when no longer needed and respect people's data rights.
Key takeaways
- The DPDP Act covers digital personal data of people in India.
- Businesses that decide why and how data is used are called Data Fiduciaries.
- Notice and consent, security, breach reporting and deletion are core duties.
- People can ask to access, correct or erase their data.
- Security work such as access control, backups and logs supports compliance.
- This guide is general information; get legal advice for your case.
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's main law on how organisations handle digital personal data. DPDP Act compliance means building your data habits and systems around its rules.
The law applies to personal data collected in digital form, and to data collected on paper that is later made digital. It also applies to some processing outside India when it is linked to offering goods or services to people in India. The government has also notified rules under the Act, which give more detail on notices, consent, breach reporting and timelines, and some parts come into force in stages.
Key DPDP Act terms in simple words
The Act uses a few new terms. Knowing them makes the rest of the law easier to follow.
| Term | Simple meaning | Example |
|---|---|---|
| Data Principal | The person the data is about | Your customer, patient, student or employee |
| Data Fiduciary | The business that decides why and how data is used | Your shop, clinic, school or company |
| Data Processor | A vendor that handles data for you | Your CRM, hosting, payroll or SMS provider |
| Consent Manager | A registered platform people can use to manage consent | Defined under the rules |
| Personal data breach | Any unauthorised access, sharing, loss or change of personal data | A hacked database or a lost laptop with customer data |
| Data Protection Board | The body that handles complaints and penalties | Set up under the Act |
Most small businesses are Data Fiduciaries for their own customers and staff, and use several Data Processors such as hosting, email and CRM providers.
Does the DPDP Act apply to my small business?
If you collect personal data of people in India in digital form for business, the Act most likely applies to you. Size alone does not remove the duty.
- Your website has a contact, enquiry or booking form
- You keep customer phone numbers in a CRM, Excel or WhatsApp Business
- You run an online store with customer accounts or orders
- You hold staff records, salary data or ID copies
- You send marketing SMS, emails or WhatsApp messages
- You run a clinic, school, coaching centre or CA office with client files
If you ticked any of these, it is worth reviewing your data practices. Some exemptions and lighter rules may apply in certain cases, so check with a legal advisor.
What are the main duties under the DPDP Act?
The main duties are notice, consent or another lawful reason, accuracy, security, breach reporting, deletion when no longer needed, and a way for people to raise requests and complaints.
Core duties for a Data Fiduciary
- Use personal data only for a lawful purpose
- Give a clear notice that says what data you collect and why
- Get free, specific, informed and clear consent where consent is the basis, and let people withdraw it easily
- Keep data accurate when it is used for decisions
- Take reasonable security safeguards to prevent breaches
- Inform the Data Protection Board and affected people of a breach, as the rules require
- Erase data when the purpose is over, unless law requires you to keep it
- Publish contact details for data questions and handle complaints
- Make sure your Data Processors work under a contract and protect data
Extra care for children's data
Processing data of children (under 18) needs verifiable consent from a parent or guardian, and some tracking and targeted advertising aimed at children is not allowed. Schools, coaching centres and apps for young users should pay special attention to this.
What rights do people have under the DPDP Act?
People can ask what data you hold, ask you to correct or erase it, raise a complaint with you, and nominate someone to act for them. You need a simple way to receive and answer these requests.
- Right to get a summary of their data and how it is used
- Right to correct, complete, update or erase their data
- Right to grievance redressal from your business
- Right to nominate another person in case of death or incapacity
In practice, this means you should know where each person's data is stored. If customer data sits in five places (website forms, CRM, Excel, email and WhatsApp), answering a request becomes hard. Reducing copies makes both compliance and security easier.
How does security support DPDP Act compliance?
The Act asks for reasonable security safeguards to prevent personal data breaches. Good security work is the practical base for compliance.
| Security step | What it protects | Related SI Cyber service |
|---|---|---|
| Access control and two-factor login | Stops misuse and stolen password attacks | Data security |
| Encryption in transit (HTTPS) and at rest | Protects data on the website and in storage | Website security |
| Backups and restore tests | Prevents data loss | Backup and disaster recovery |
| Logs and monitoring | Helps detect and investigate breaches | Security monitoring |
| Regular audits and fixes | Finds gaps before attackers do | Security audit |
| Vendor checks | Makes sure processors protect data | Cybersecurity consulting |
Logs matter more than many owners think. Without them, you cannot tell what data was affected in a breach, which makes reporting and fixing harder.
DPDP Act compliance basics: a starter plan
Start by mapping your data, cutting what you do not need, fixing notices and consent, and securing the systems that hold personal data.
- 1
Map your data
List what personal data you collect, where it is stored, who can access it and which vendors handle it.
- 2
Collect less
Remove form fields and copies you do not need. Less data means less risk.
- 3
Update notices and consent
Write a clear, simple notice and consent wording for forms and sign-ups, with legal help.
- 4
Secure key systems
Website, CRM, email and shared drives get two-factor login, updates, backups and access limits.
- 5
Set retention and deletion
Decide how long each type of data is kept and how it is deleted.
- 6
Prepare a breach plan
Write who does what if data leaks, including reporting steps and timelines under the rules.
- 7
Check vendors
Review contracts and security of hosting, CRM, payroll and messaging vendors.
- 8
Train staff
Teach staff simple rules for handling customer data, sharing files and spotting phishing.
How SI Cyber helps with the security side
We handle the technical security work that supports DPDP Act compliance. For legal wording and interpretation, work with your legal advisor; we coordinate with them where needed.
Data and risk mapping
Find where personal data lives in your website, apps and tools.
Security hardening
Access control, two-factor login, HTTPS, backups and logs.
Breach readiness
Response plan and monitoring so you can act fast. Read our ransomware protection guide too.
Regular reviews
Ongoing checks through our security maintenance plans.
Cost depends on how many systems, vendors and locations hold personal data. You get a clear quote after a free call. SI Cyber is powered by Shivah Web Tech, an MSME registered and Startup India recognised company. Contact us to start.
Frequently Asked Questions
What is the DPDP Act in simple words?
The Digital Personal Data Protection Act, 2023 is India's law on how organisations collect, use, store and share digital personal data. It gives people rights over their data and gives businesses duties, such as giving clear notice, getting valid consent where needed, keeping data secure, reporting breaches as the rules require and deleting data when it is no longer needed.
Does the DPDP Act apply to small businesses?
In most cases, yes. If a small business collects personal data of people in India in digital form, such as website enquiries, customer phone numbers or staff records, the Act is likely to apply. The government can exempt or relax rules for some types of businesses, so check the notified rules or ask a legal advisor about your exact position.
What is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is the person or business that decides why and how personal data is processed. For example, a shop that collects customer numbers for billing is a Data Fiduciary. The vendors who process data on its behalf, such as a hosting or CRM provider, are Data Processors. The Data Fiduciary stays responsible for compliance, including the work done by its processors.
What should I do if there is a data breach under the DPDP Act?
Contain the breach quickly, find what data and which people are affected, and keep records. The Act and rules require informing the Data Protection Board and affected people in the manner and time set by the rules. Cyber incidents may also need reporting to CERT-In. A written breach plan and good logs make these steps much easier.
What are the penalties under the DPDP Act?
The Act sets financial penalties for failures such as not taking reasonable security safeguards or not reporting a breach. The amounts depend on the type of failure and are decided by the Data Protection Board after an inquiry. The highest penalties are large, so it is worth taking basic steps early. Check the Act or a legal advisor for exact figures.
Do I need a privacy policy on my website for the DPDP Act?
You need to give a clear notice to people when you collect their data, explaining what you collect, why, and how they can use their rights or complain. Many businesses do this through a privacy notice on the website and short notices near forms. The exact content should follow the rules, so get legal help with the wording.
Can SI Cyber make my business DPDP compliant?
We help with the technical security part, such as finding where data is stored, access control, encryption, backups, logs, monitoring and breach readiness. Compliance also needs legal steps like notices, consent wording and contracts, which a legal advisor should handle. We are happy to work alongside your legal advisor so both parts fit together.
Talk to our team today
Call or WhatsApp +91 85808 92163. We reply fast, Monday to Friday.