If you run a small business in India and collect any digital personal data — customer phone numbers, employee Aadhaar copies, a WhatsApp lead list, a CCTV feed of your reception — the Digital Personal Data Protection Act now applies to you. Not “will apply someday”: the Rules were notified on 13 November 2025, the Data Protection Board is already operational, and the phase that switches on penalties begins on 13 November 2026. Full compliance is due 13 May 2027.
Most of what is written about DPDP is aimed at banks and unicorns. This checklist is for the 20-person trading firm, the clinic, the CA office, the school, the manufacturer with 60 staff — businesses that have real personal data and no compliance department. CNC has helped Delhi SMEs secure their IT since 1996, and we’ve built this from the questions they actually ask.
Quick help from CNC — West Patel Nagar, Delhi
Need laptop repair or data recovery help?
CNC is at West Patel Nagar, Delhi — same-day service, free diagnosis, No Fix No Charge.
⭐ 4.9★ · 981 Google reviews · Since 1996 · GST invoice · Learn more →
The three DPDP dates every Indian SME should know
| Date | What happens | What it means for you |
|---|---|---|
| 13 Nov 2025 | Rules notified; Data Protection Board established | Complaints can already be filed against you |
| 13 Nov 2026 | Penalty and appeal provisions become operative; Consent Manager registration opens | Enforcement teeth arrive — 10 weeks from now |
| 13 May 2027 | Full compliance: consent, notices, rights, security safeguards, breach reporting, retention | Every obligation below must be live |
The penalty ceilings are designed to get attention: up to ₹250 crore per instance for failing to maintain reasonable security safeguards, and ₹200 crore for failing to report a breach. The Board scales penalties to the size and nature of the violation, so a small business isn’t facing ₹250 crore — but it is facing a formal, digital complaint process that any customer or employee can trigger.
First: does DPDP even apply to you?
Almost certainly yes. The Act covers digital personal data — any data about an identifiable individual that is collected digitally or digitised later. That includes a paper visitor register you photograph, a customer list in Excel, biometric attendance records, and your website contact form. There is no turnover threshold that exempts you. The only real carve-out is personal data an individual has made publicly available themselves, and processing for purely personal or domestic use.
The DPDP compliance checklist for small businesses
1. Know what personal data you hold — and where
You cannot protect what you haven’t mapped. List every place personal data lives: Tally customer masters, HR files, email, WhatsApp Business, CCTV DVRs, the website database, Google Drive, engineers’ laptops. For each, note what data, why you collect it, who can access it, and how long you keep it. For most SMEs this is a two-hour exercise with a spreadsheet — and it drives every other item below.
2. Publish a plain-language privacy notice
Under the Rules, a notice must be standalone and understandable, listing the specific personal data collected and the itemised purpose for each. “We may use your data to improve services” no longer qualifies. It must also tell people how to withdraw consent, exercise their rights, and complain to the Board. One notice on your website plus a short version at the point of collection (forms, onboarding) is the practical minimum.
3. Fix your consent mechanism
Consent must be free, specific, informed, unconditional and unambiguous — a clear affirmative action. Pre-ticked boxes, bundled consent (“by continuing you agree to everything”), and silence do not count. Withdrawal must be as easy as giving consent. For a small business this usually means: a real checkbox on web forms, a documented verbal-consent line for phone enquiries, and a way to record that an employee agreed to the HR data policy.
4. Understand “legitimate uses” — you don’t need consent for everything
The Act lets you process data without fresh consent for certain purposes: employment-related processing, responding to a request the person made voluntarily (a customer asking for a quote), legal obligations, medical emergencies. Knowing this stops you from drowning your customers in consent pop-ups for things that are already lawful.
5. Put reasonable security safeguards in place
This is the item that carries the ₹250 crore ceiling, and it’s where an IT partner earns its keep. The Rules expect encryption or masking of personal data, access controls, logging and monitoring to detect unauthorised access, backups to restore data after a breach, and contractual security obligations on your vendors. In practice for an SME: patched operating systems (Windows 10 without extended updates fails this test), endpoint protection on every machine, a properly configured firewall, role-based access in Tally and shared drives, encrypted backups with a tested restore, and log retention of at least one year.
6. Build a breach response procedure — before you need it
A personal data breach must be reported to the Data Protection Board and to every affected individual. The notification must describe the breach, the likely consequences, and what you are doing about it. Write the procedure now: who declares a breach, who contacts the Board, how you reach affected customers, what your IT partner does in the first hour. A one-page plan drafted calmly beats improvising after a ransomware note appears.
7. Set retention periods and actually delete data
Personal data must be erased once its purpose is served or consent is withdrawn — unless retention is required by another law (GST, income tax, labour records). Attach a retention period to every row in your data map, then set a quarterly calendar reminder to purge. Old CCTV footage, ex-employee files, and lapsed-lead lists are the usual offenders.
8. Handle data principal rights requests
Individuals can ask what data you hold, request correction or erasure, nominate someone to act for them, and have a grievance addressed. The Rules set a maximum 90-day resolution timeline, so publish a contact point (an email address is fine) and keep a simple log of requests and responses.
9. Check children’s data if it touches your business
Schools, coaching centres, paediatric clinics and any business with under-18 customers need verifiable parental consent before processing a child’s data, and cannot track or target advertising at children. If this applies, it is a priority item, not a footnote.
10. Get your vendor contracts right
If a third party processes personal data for you — a payroll service, a cloud CRM, a marketing agency, your IT AMC provider — you remain responsible as the Data Fiduciary. Contracts should require them to protect the data and delete it when the engagement ends. Ask your vendors one question: “Are you DPDP-ready?” and keep the answer in writing.
What you do NOT need (yet)
Small businesses are not automatically “Significant Data Fiduciaries” — that designation, with its Data Protection Officer, annual audit and impact assessment requirements, is for large-scale or sensitive processors named by the government. You do not need a certified DPO, a data localisation server, or a lakh-rupee consulting engagement to be compliant. You need the ten items above, done properly and documented.
A realistic 90-day plan for an SME
| Weeks | Action | Who |
|---|---|---|
| 1–2 | Data mapping spreadsheet; vendor list | Owner + office manager |
| 3–4 | Privacy notice; consent fixes on forms | Owner + web/IT partner |
| 5–8 | Security safeguards: patching, endpoint protection, access control, encrypted backup, log retention | IT partner |
| 9–10 | Breach procedure; retention schedule; rights-request contact | Owner + IT partner |
| 11–12 | Staff briefing; vendor letters; file everything in one folder | Owner |
Started in September 2026, this lands you fully prepared before penalties go live in November — with months of buffer before the May 2027 deadline.
Frequently asked questions
Is there a small-business exemption under the DPDP Act?
No general exemption. The government can notify relaxations for specific classes such as startups, but as of September 2026 nothing exempts ordinary SMEs from the core obligations. Small size affects how penalties are scaled, not whether the law applies.
Does DPDP require me to store data on servers in India?
No. The final Rules use a restriction-list model — transfers are allowed except to countries the government specifically restricts — rather than mandatory localisation. Using a reputable cloud service is fine if your contract covers security and deletion.
Is Windows 10 a DPDP problem?
Potentially, yes. “Reasonable security safeguards” is judged against current good practice, and an operating system without security updates is hard to defend after a breach. Machines still on Windows 10 need either commercial Extended Security Updates or an upgrade path.
What should I do first if I only have one week?
Map your data, fix the security basics (patching, backup, access control), and write the breach procedure. Those three protect you against the highest-penalty failures and the most likely real-world incident.
Can CNC help with DPDP compliance?
We handle the technical safeguards — patching, endpoint security, firewall, access control, encrypted backup, log retention and breach-response readiness — and can point you to a legal advisor for the policy documents. See our DPDP compliance service for Delhi businesses.
Get the technical safeguards done before 13 November
CNC has secured Delhi small-business IT since 1996 — 8 certified engineers, 4.9★ from 983 Google reviews. We’ll run a DPDP safeguards assessment on your office and give you a fixed-price plan for whatever is missing.
This article is general information based on the DPDP Act 2023 and DPDP Rules 2025 as notified on 13 November 2025. It is not legal advice. Consult a qualified advisor for your specific compliance position.
📍 O-41 West Patel Nagar · Mon–Sat 10 AM–7 PM
Need laptop repair or data recovery help?
CNC is at West Patel Nagar, Delhi — same-day service, free diagnosis, No Fix No Charge.
⭐ 4.9★ · 981 Google reviews · Since 1996 · GST invoice · Learn more →
Prices and rates mentioned in this article are indicative estimates as of September 2026, exclusive of GST unless stated, and may change without notice due to exchange-rate movements, supply constraints and market demand. Please confirm current pricing and availability with CNC before making any decision.
