Small business

DPDP Act for small businesses: there is no size test

A man at his desk looking at his phone, a laptop open beside a model of a building.

The DPDP Act has no size test, so a small business that keeps customer or lead data digitally is covered. From 13 May 2027 you need consent notices, security safeguards, a detailed breach report to the Board within 72 hours of becoming aware, erasure when the purpose ends, and a published contact and grievance period of at most 90 days.

Last checked against the official text: Updated 5 min read

On this page
  1. What the law says about size
  2. Our view: what these businesses typically hold
  3. The duties that start on 13 May 2027
  4. Lead data and enquiries
  5. Our view: first steps
  6. Common questions
  7. In the news
  8. Sources

If your business keeps the names, phone numbers and addresses of customers or enquirers in digital form, the DPDP Act covers you, whatever your size. This page sets out what the law says about small businesses, then the duties that start on 13 May 2027, then our own view of where to begin. The sections on the law are cited in the Sources box. The two sections marked Our view are our opinion and carry no citation.

What the law says about size

The Act has no turnover or headcount test. It applies to the processing of digital personal data in India, including data collected on paper and digitised afterwards. Personal data is any data about an individual who can be identified by or in relation to that data, so a name with a phone number in a customer list or an enquiry sheet is personal data. An individual who uses personal data only for a personal or domestic purpose is outside the Act.

The Central Government may notify certain Data Fiduciaries, including startups, based on the volume and nature of the data they process, so that some duties do not apply to them. Those duties are notice, accuracy of data, erasure, the extra duties of Significant Data Fiduciaries and the right of access. The Rules name no startup or class, so check the Gazette for a notification before you assume you are exempt.

How an online shop fills in its data protection documents · 56 s
What the video shows
  • How Sample Store fills in its DPDPA documents.
  • An online shop that sells its own products. Made-up names and data.
  • Consent notice
  • With or before a consent request, say what you collect and why.
  • Say how to withdraw. Make withdrawing about as easy as giving consent.
  • Withdrawing stops the offers. An order already paid for is still delivered.
  • Vendor risk assessment
  • A courier and a payment gateway both handle customer data. List each one.
  • Mark how sensitive the data is.
  • A processor serving your customers needs a valid contract. You stay responsible.
  • Data retention schedule
  • Erase data when consent is withdrawn or its purpose is served, unless a law says keep it.
  • Keep data and processing logs at least a year, for uses by the State that the Rules list. Then erase, unless another law requires longer.
  • Rights request form
  • A customer makes a request. Tick which right it is.
  • Write down the date it arrives.
  • For a grievance, reply within the period you publish. The Rules cap it at 90 days.

Our view: what these businesses typically hold

Our view. The table lists the personal data we would expect each kind of business to be holding. It is a prompt for your own list and makes no claim about the law.

A property broker in a bright flat noting down details while talking to a young couple.
BusinessPersonal data it typically holds
Dairy delivery appName, phone number, delivery address and pin, subscription and delivery history, payment records
Kirana ordering appName, phone number, address, order lists, payment references, rider contact details
Coaching instituteNames and phone numbers of students and parents, fee and attendance records, marks, enquiry forms. Some students may be children.
SalonName, phone number, appointment history, service preferences and notes, payment records, enquiries from social media

Where the data lives matters as much as what it is. Check each place you keep it: an app, a messaging account, a spreadsheet, a payment dashboard.

The duties that start on 13 May 2027

DutyWhat it asks of you
NoticeEvery request for consent is accompanied or preceded by a notice that describes the data, each purpose, how to withdraw consent, how to use rights and how to complain to the Board.
ConsentConsent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to the data that is necessary for the purpose. Withdrawing must be as easy as giving it. If this is questioned in a proceeding, you must prove that notice was given and consent obtained.
AccuracyWhere data is used to decide something about a person or is disclosed to another Data Fiduciary, make sure it is complete, accurate and consistent.
SecurityTake reasonable safeguards: encryption, masking or tokens, access controls, logs and monitoring, backups, and, wherever applicable, a contract provision with each Data Processor.
BreachTell each affected person without delay, tell the Board without delay, then send a detailed report within 72 hours of becoming aware of the breach.
ErasureErase data when a person withdraws consent or the purpose is no longer served, unless a law requires you to keep it, and have each Data Processor erase the data you gave it. Separately, keep logs of the processing, with the personal data and traffic data they cover, for at least one year for the purposes the Rules list, then erase them unless another law requires longer.
Contact and grievancesPublish a business contact for questions, how people can make requests, and a grievance response period of no more than 90 days.
VendorsYou are responsible for processing done on your behalf. Engage a processor for offering goods or services only under a valid contract.
ChildrenGet a parent’s verifiable consent before processing a child’s data, and do not track, behaviourally monitor or target ads at children, unless an exemption applies.

Lead data and enquiries

You may use details a person voluntarily gave you for the purpose she gave them, unless she has told you she does not consent to that use. The Act gives an example: a person messages a real estate broker, shares her details to find rented accommodation, and later says she no longer needs help. The broker must stop processing her data. Any other use needs her consent or another use the Act lists. Read how long you can keep customer data before you keep a lead list for years.

Our view: first steps

Our view. This is the order we would work in. The steps follow the duties above.

  1. Write down every place customer and lead data sits: app, WhatsApp, spreadsheets, payment tools, paper.
  2. Cut fields you do not use. Every field you drop is one less to protect, notify about and erase.
  3. Write one notice for each purpose you ask consent for. What a notice must contain.
  4. Publish a contact and a grievance period. What to publish on your site or app.
  5. List the vendors that touch the data, such as the app developer, SMS and payment providers, and cloud storage, and put a contract in place with each one that processes the data on your behalf. Processors and vendors.
  6. Set a deletion date for each kind of data, and write down who to call and what to send if data leaks. The breach duties.
  7. If you serve children, read children’s data under the Act first.

The applicability article covers scope in detail, and the timeline shows every date.

Common questions

Does the DPDP Act apply to a small business?

Yes. The Act sets no turnover or headcount test for coverage. It applies to digital personal data, including data collected on paper and digitised afterwards. The duties start on 13 May 2027.

Is a name and phone number in a lead list personal data?

Yes. The Act defines personal data as any data about an individual who is identifiable by or in relation to that data, and a name with a phone number is such data.

Can I keep using a lead’s phone number after the enquiry?

You may use details a person voluntarily gave you for the purpose she gave them, unless she has told you she does not consent to that use. The Act’s own example is a broker who must stop processing a person’s details once she says she no longer needs help. Any other use needs her consent or another use the Act lists.

What must a small business have in place by 13 May 2027?

A notice with each request for consent, consent limited to the data you need, reasonable security safeguards, breach reports to the Board and affected people, erasure when the purpose ends, a published business contact, published ways to make requests, and a grievance response period of no more than 90 days.

Are startups or small businesses exempt?

Not by size. The Central Government may notify certain Data Fiduciaries, including startups, based on the volume and nature of the data they process, so that the notice, accuracy, erasure, Significant Data Fiduciary and access duties do not apply to them. The Rules name none. Check the Gazette before assuming you are exempt.

Next steps

In the news

Sources

Every section, rule and date above was checked against the official text on 6 Oct 2026.

Digital Personal Data Protection Act, 2023 (No. 22 of 2023)

Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)

  • Section 2(t)Personal data
  • Section 3Digital personal data, including data collected on paper and digitised afterwards; personal or domestic use excluded; no size test
  • Section 4(1)Processing only with consent or for a certain legitimate use
  • Section 5(1)Notice with or before every consent request
  • Section 6(1)Consent: free, specific, informed, unconditional, unambiguous; limited to the data necessary
  • Section 6(4)Withdrawal as easy as giving consent
  • Section 6(10)Data Fiduciary must prove notice and consent
  • Section 7(a)Use for the specified purpose for which the person voluntarily provided her data; the real estate broker illustration
  • Section 8(2)Processor engaged for offering goods or services: only under a valid contract
  • Section 8(3)Completeness, accuracy and consistency where data decides something about a person or is disclosed
  • Section 8(5)Reasonable security safeguards
  • Section 8(6)Intimation of a personal data breach
  • Section 8(7)Erase on withdrawal of consent or when the purpose is no longer served; cause the processor to erase
  • Section 8(9)Publish a business contact
  • Section 8(10)Grievance redressal mechanism
  • Section 9Children: verifiable parental consent; no tracking or targeted advertising
  • Section 17(3)Notified Data Fiduciaries, including startups, may be excused certain duties

DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)

  • Rule 1(4)Rules 3, 5 to 16 in force eighteen months from publication
  • Rule 3Notice: itemised data, specific purposes, link, withdrawal, rights, complaint
  • Rule 6Reasonable security safeguards, including logs kept for one year and a contract provision with each processor
  • Rule 7Breach: tell each affected person and the Board without delay; detailed report within 72 hours of becoming aware
  • Rule 8One-year minimum for personal data, traffic data and logs
  • Rule 9Publish the contact; mention it in every response to a rights communication
  • Rule 14Publish how to make requests; grievance period of not more than ninety days

Notifications

Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)

  • G.S.R. 843(E), clause (c)Sections 3 to 5, 6 (except 6(9)), 7 to 17 in force eighteen months from 13 November 2025

A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.