The Digital Personal Data Protection Act 2023 applies to every Indian business that handles personal data — employee records, customer lists, patient files, student information. That is essentially every business in Delhi, from a 5-person CA firm to a hospital. With penalties reaching ₹250 crore and enforcement machinery taking shape, “we’ll deal with it later” is becoming an expensive strategy. Here is the practical 10-point checklist Classic Network and Computers (CNC) uses to take Delhi SMBs from zero to baseline compliance — typically in 4–8 weeks.
First: Understand Your Role as a “Data Fiduciary”
Under DPDP, any organisation that decides why and how personal data is processed is a Data Fiduciary — with obligations around consent, security, breach notification, and individual rights (access, correction, erasure). The people whose data you hold are Data Principals, and they can complain directly to the Data Protection Board. Size does not exempt you; smaller businesses simply have simpler data maps to work through.
The 10-Point DPDP Compliance Checklist
1. Map every place personal data lives
HR files, Tally, CRM and customer lists, email, WhatsApp groups, CCTV recordings, website forms, vendor systems, and old backups. You cannot protect what you have not listed — this inventory is the foundation of everything else.
2. Establish a lawful basis and take real consent
For most SMB processing, this means clear, specific, opt-in consent notices — not pre-ticked boxes or clauses buried in terms. Keep records of when and how consent was given.
3. Publish a DPDP-compliant privacy policy
Plain language: what you collect, why, how long you keep it, who you share it with, and how a person can exercise their rights. Your website form and offline intake forms should link to it.
4. Minimise — collect only what the purpose needs
Photocopying Aadhaar “just in case” is exactly the habit DPDP targets. Less data held equals less to secure and less liability.
5. Restrict internal access
Salary data should not be on a shared drive that everyone can open. Role-based access on folders, Tally, and cloud drives is a technical control CNC implements in days.
6. Secure the systems holding data
Licensed, patched software; endpoint security on every PC; MFA on email and cloud accounts; encrypted laptops for anyone taking data outside the office. “Reasonable security safeguards” is the DPDP obligation that carries the ₹250-crore ceiling — and it overlaps heavily with ordinary good IT practice. See our cyber security services for the technical layer.
7. Build a 72-hour breach response playbook
Who detects the breach, who decides on notification, who informs the Data Protection Board and affected individuals, and in what format — written down before an incident happens, not improvised during one.
8. Handle rights requests
A simple documented process for access, correction, and erasure requests — with one named owner and a response timeline that meets the Act’s requirements.
9. Put contracts around your processors
Payroll vendors, marketing agencies, cloud tools — anyone processing personal data on your behalf needs proper data-processing terms. Their breach becomes your problem under DPDP.
10. Train the team and review annually
Most breaches start with a person, not a system. Short annual training plus a yearly review as DPDP rules evolve keeps the programme live rather than on paper.
What DPDP Compliance Costs a Delhi SMB in 2026
| Engagement | Scope | Indicative Price |
|---|---|---|
| Audit and gap analysis | Data mapping, assessment against DPDP obligations, prioritised remediation plan | from ₹15,000 |
| Full implementation package | Audit + policies, consent framework, technical controls, breach workflow, staff training | ₹35,000 – ₹1,00,000 |
| Virtual DPO and monitoring | Ongoing oversight, rights-request handling, quarterly health checks, rule updates | from ₹5,000 / month |
Indicative pricing; a fixed quotation is given after a free readiness assessment. Full details on the CNC DPDP compliance services page.
The Mistakes That Attract Trouble
- Treating DPDP as a legal-document exercise — a policy PDF with no technical controls behind it fails the “reasonable safeguards” test that carries the biggest penalty
- Ignoring WhatsApp and personal devices where customer data actually moves day-to-day
- Keeping everything forever — retention without purpose is a violation waiting to be found
- Assuming “we’re too small to matter” — complaints are free for any individual to file with the Data Protection Board
Frequently Asked Questions — DPDP Compliance 2026
Does DPDP apply to a business with only 10 employees?
Yes. The Act applies based on whether you process personal data, not on company size. Ten employees means employee data as a minimum, plus customer data if applicable — both are covered.
What should a small business do first for DPDP?
Start with the data inventory (point 1 above). Every other control depends on knowing what you hold and where it lives. A structured audit takes 1–2 weeks and immediately shows your real exposure.
How long does DPDP compliance take?
A typical Delhi SMB reaches baseline compliance in 4–8 weeks with structured help: audit weeks 1–2, policies and technical controls weeks 3–5, training and documentation weeks 6–8. Larger multi-system organisations take 3–6 months.
Is a Data Protection Officer mandatory for small businesses?
A formal DPO is mandated for Significant Data Fiduciaries (a category to be notified by government). Smaller businesses still need someone accountable — which is why many Delhi SMBs use a virtual DPO service rather than hiring a full-time officer.
Who provides DPDP compliance services in Delhi?
CNC provides end-to-end DPDP compliance in Delhi — audit, policies, and critically the technical implementation (access control, data loss prevention, breach detection) — because we are an IT company first. We implement compliance on the systems, not just on paper. Free readiness assessment for Delhi NCR businesses.
Classic Network and Computers (CNC) is an IT services company at O-41, West Patel Nagar, New Delhi 110008, providing DPDP compliance, cyber security, and IT services since 1996. Call +91-9810130131 or WhatsApp +91-8130992267. Office hours: Monday–Saturday, 10 AM–7 PM. See the full DPDP Act compliance services page.
This article was published by Classic Network and Computers (CNC), an IT services company at O-41, West Patel Nagar, New Delhi – 110008, India. Founded in April 1996, CNC provides laptop repair, computer hardware service, data recovery, IT AMC (Annual Maintenance Contracts), DPDP compliance, cyber security, cloud services, office network setup, CCTV installation, and Tally Prime software to businesses across Delhi NCR.
📞 +91-9810130131
· 💬 WhatsApp 8130992267
· 🌐 cnc-system.com
· ★ 4.9 Google rating · 981+ reviews · Since 1996
This article was published by Classic Network and Computers (CNC), an IT services company at O-41, West Patel Nagar, New Delhi – 110008, India. Founded in April 1996, CNC provides laptop repair, computer hardware service, data recovery, IT AMC (Annual Maintenance Contracts), CCTV installation, cyber security, cloud services, and Tally Prime software to businesses and individuals across Delhi NCR.
📞 +91-9810130131 · 💬 WhatsApp 8130992267 · 🌐 cnc-system.com · ★ 4.9 Google rating · 981+ reviews · Since 1996
