India's Digital Personal Data Protection regime has moved from legislation to active enforcement, and there is no small-business exemption. Penalties reach ₹250 crore. Here is a plain-language compliance checklist for Indian SMEs.
India's data protection regime is no longer a future concern. With the DPDP Rules notified in November 2025, the 2026–27 period marks the shift from preparation to active enforcement and operational accountability — and the law deliberately contains no small-business exemption. If you store customer phone numbers in a spreadsheet, the Act applies to you.
Key takeaways
- There is no turnover threshold and no SME carve-out — the obligations scale with the data you hold, not your revenue.
- Penalties reach ₹250 crore, with the largest category tied to failing to take reasonable security safeguards.
- The Consent Manager framework has been operationalised through mid-2026, giving individuals interoperable control over consent.
- A data inventory is the prerequisite for everything else. Start there, not with policy documents.
Who does the DPDP Act actually cover?
The Act governs any organisation that determines the purpose and means of processing personal digital data belonging to people in India. In the law's language that organisation is a Data Fiduciary, and the individual is a Data Principal.
In practical terms, you are almost certainly a Data Fiduciary if you run any of the following:
- A retail or distribution business storing customer names, numbers or addresses
- A clinic or hospital holding patient records
- A school holding student and parent information
- Any business with employee payroll and HR records
- A website with a contact form, newsletter or login
What obligations does this create?
Lawful, purpose-limited consent
Consent must be free, specific, informed, unconditional and unambiguous, and it must be requested for a stated purpose. Bundled consent — the single checkbox covering everything a business might ever want to do — no longer satisfies the standard. Notices must be available in English and the languages listed in the Eighth Schedule of the Constitution.
Purpose limitation and deletion
You may keep personal data only while the stated purpose remains live. Once it lapses, and once no legal retention duty applies, the data must be erased. This is where most Indian SMEs are furthest from compliance: the default habit is to keep everything forever.
Reasonable security safeguards
The Act requires reasonable safeguards against breaches, and this is the obligation carrying the heaviest penalty exposure. It is an outcome standard rather than a prescribed checklist — "we did not know" is not a defence.
Breach notification
Personal data breaches must be reported to the Data Protection Board and to affected individuals. You need a defined internal process for this before an incident occurs, because timelines are short and improvisation under pressure produces incomplete disclosures.
Honouring data principal rights
Individuals can request access to a summary of their data, correction, completion, updating, erasure, and grievance redressal. You must publish a contact point for these requests and actually answer them.
A step-by-step readiness checklist
- Build a data inventory. For every system — billing software, WhatsApp exports, HR sheets, CCTV, website database — record what personal data it holds, why, who can access it, and how long it is kept.
- Delete what you cannot justify. The cheapest compliance win available is reducing the data you hold. Data you do not have cannot be breached or mishandled.
- Rewrite consent notices. One purpose per consent, in plain language, with a genuine ability to decline.
- Fix access control. Shared logins and blanket admin rights are the most common finding in Indian SME audits. Give each employee a named account with least-privilege access.
- Encrypt data at rest and in transit. HTTPS everywhere, encrypted database volumes, encrypted backups.
- Write a breach response plan. Who is called, who assesses scope, who notifies the Board, who informs customers, and in what order.
- Set retention schedules. Define a deletion timeline per data category and automate it where your software allows.
- Vet your processors. Vendors handling data for you must be bound by contract to equivalent standards. Ask your software suppliers where their servers are and what they do with your data.
- Appoint an accountable person. Even where a formal Data Protection Officer is not mandated, name someone responsible internally.
- Train the team. Most breaches at SMEs begin with an employee action, not a technical exploit.
| Common SME practice | Risk under DPDP | Fix |
|---|---|---|
| Customer list on a personal phone | Uncontrolled, unauditable copy | Move to access-controlled system |
| Shared admin login | No accountability trail | Individual named accounts |
| Unencrypted local backups | Safeguard failure exposure | Encrypted, access-limited backups |
| Keeping records indefinitely | Purpose limitation breach | Documented retention schedule |
| Single blanket consent checkbox | Invalid consent | Purpose-specific consent |
Compliance is not a document you produce once. It is a property of how your systems are built — which is why retrofitting it is always more expensive than designing for it.
The business case beyond avoiding penalties
Treating DPDP purely as a cost misses the commercial upside. Enterprise and government buyers in India now routinely ask about data handling during procurement. An SME that can answer those questions credibly wins contracts that a competitor with a spreadsheet full of customer numbers cannot.
Conclusion
The obligations are demanding but they are finite, and they reward the same disciplines as good engineering: know what you hold, keep less of it, control who touches it, and plan for the bad day. Shwastik Tech builds its hospital, school and billing platforms with access control, encryption and retention rules built in rather than added later. If you would like a readiness review of your current systems, our security team can walk you through the checklist above — reach out here.
This article is general information, not legal advice. Consult a qualified data-protection lawyer for advice specific to your organisation.
Frequently asked questions
Does the DPDP Act apply to small businesses in India?
Yes. The Act contains no minimum turnover threshold, no employee-count exemption and no general SME carve-out. If you digitally process the personal data of people in India — including customer phone numbers, employee records or patient details — you are covered.
What are the penalties for non-compliance with the DPDP Act?
Financial penalties run up to ₹250 crore for the most serious categories of breach, most notably failure to take reasonable security safeguards against a personal data breach. Penalties are assessed per instance and consider the nature, gravity and duration of the failure.
What is a Consent Manager under the DPDP framework?
A Consent Manager is a registered intermediary platform through which individuals can give, review, manage and withdraw consent across multiple digital services in an interoperable way. The central government has been operationalising this framework through 2026.
What is the single most important first step for an SME?
Build a data inventory. You cannot protect, minimise or delete personal data you have not catalogued. Listing what personal data you hold, where it lives, why you collected it and who can access it is the foundation every other DPDP obligation rests on.