← Back to CNC Website  |  Classic Network and Computers
IT Services, Laptop Repair & CCTV — Delhi Since 1996 📞 +91-9810130131
Skip to content
Our Updated Blogs & Articles

Our Updated Blogs & Articles

CNC System

Menu
  • Home
  • About Us
  • Our Clients
  • Contact Us
Menu
Compliance manager and IT engineer reviewing a DPDP Act checklist at a small business office in India

DPDP Act Compliance Checklist for Small Businesses in India — What’s Actually Required in 2026

Posted on September 3, 2026September 2, 2026 by Raju Manocha

If you run a small business in India and collect any digital personal data — customer phone numbers, employee Aadhaar copies, a WhatsApp lead list, a CCTV feed of your reception — the Digital Personal Data Protection Act now applies to you. Not “will apply someday”: the Rules were notified on 13 November 2025, the Data Protection Board is already operational, and the phase that switches on penalties begins on 13 November 2026. Full compliance is due 13 May 2027.

Most of what is written about DPDP is aimed at banks and unicorns. This checklist is for the 20-person trading firm, the clinic, the CA office, the school, the manufacturer with 60 staff — businesses that have real personal data and no compliance department. CNC has helped Delhi SMEs secure their IT since 1996, and we’ve built this from the questions they actually ask.

Quick help from CNC — West Patel Nagar, Delhi

Need laptop repair or data recovery help?

CNC is at West Patel Nagar, Delhi — same-day service, free diagnosis, No Fix No Charge.

📞 Call CNC — 9810130131 💬 WhatsApp CNC →

⭐ 4.9★ · 981 Google reviews · Since 1996 · GST invoice · Learn more →

The three DPDP dates every Indian SME should know

Table of Contents

Toggle
  • The three DPDP dates every Indian SME should know
  • First: does DPDP even apply to you?
  • The DPDP compliance checklist for small businesses
    • 1. Know what personal data you hold — and where
    • 2. Publish a plain-language privacy notice
    • 3. Fix your consent mechanism
    • 4. Understand “legitimate uses” — you don’t need consent for everything
    • 5. Put reasonable security safeguards in place
    • 6. Build a breach response procedure — before you need it
    • 7. Set retention periods and actually delete data
    • 8. Handle data principal rights requests
    • 9. Check children’s data if it touches your business
    • 10. Get your vendor contracts right
  • What you do NOT need (yet)
  • A realistic 90-day plan for an SME
  • Frequently asked questions
    • Is there a small-business exemption under the DPDP Act?
    • Does DPDP require me to store data on servers in India?
    • Is Windows 10 a DPDP problem?
    • What should I do first if I only have one week?
    • Can CNC help with DPDP compliance?
Date What happens What it means for you
13 Nov 2025 Rules notified; Data Protection Board established Complaints can already be filed against you
13 Nov 2026 Penalty and appeal provisions become operative; Consent Manager registration opens Enforcement teeth arrive — 10 weeks from now
13 May 2027 Full compliance: consent, notices, rights, security safeguards, breach reporting, retention Every obligation below must be live

The penalty ceilings are designed to get attention: up to ₹250 crore per instance for failing to maintain reasonable security safeguards, and ₹200 crore for failing to report a breach. The Board scales penalties to the size and nature of the violation, so a small business isn’t facing ₹250 crore — but it is facing a formal, digital complaint process that any customer or employee can trigger.

First: does DPDP even apply to you?

Almost certainly yes. The Act covers digital personal data — any data about an identifiable individual that is collected digitally or digitised later. That includes a paper visitor register you photograph, a customer list in Excel, biometric attendance records, and your website contact form. There is no turnover threshold that exempts you. The only real carve-out is personal data an individual has made publicly available themselves, and processing for purely personal or domestic use.

The DPDP compliance checklist for small businesses

1. Know what personal data you hold — and where

You cannot protect what you haven’t mapped. List every place personal data lives: Tally customer masters, HR files, email, WhatsApp Business, CCTV DVRs, the website database, Google Drive, engineers’ laptops. For each, note what data, why you collect it, who can access it, and how long you keep it. For most SMEs this is a two-hour exercise with a spreadsheet — and it drives every other item below.

2. Publish a plain-language privacy notice

Under the Rules, a notice must be standalone and understandable, listing the specific personal data collected and the itemised purpose for each. “We may use your data to improve services” no longer qualifies. It must also tell people how to withdraw consent, exercise their rights, and complain to the Board. One notice on your website plus a short version at the point of collection (forms, onboarding) is the practical minimum.

3. Fix your consent mechanism

Consent must be free, specific, informed, unconditional and unambiguous — a clear affirmative action. Pre-ticked boxes, bundled consent (“by continuing you agree to everything”), and silence do not count. Withdrawal must be as easy as giving consent. For a small business this usually means: a real checkbox on web forms, a documented verbal-consent line for phone enquiries, and a way to record that an employee agreed to the HR data policy.

4. Understand “legitimate uses” — you don’t need consent for everything

The Act lets you process data without fresh consent for certain purposes: employment-related processing, responding to a request the person made voluntarily (a customer asking for a quote), legal obligations, medical emergencies. Knowing this stops you from drowning your customers in consent pop-ups for things that are already lawful.

5. Put reasonable security safeguards in place

This is the item that carries the ₹250 crore ceiling, and it’s where an IT partner earns its keep. The Rules expect encryption or masking of personal data, access controls, logging and monitoring to detect unauthorised access, backups to restore data after a breach, and contractual security obligations on your vendors. In practice for an SME: patched operating systems (Windows 10 without extended updates fails this test), endpoint protection on every machine, a properly configured firewall, role-based access in Tally and shared drives, encrypted backups with a tested restore, and log retention of at least one year.

6. Build a breach response procedure — before you need it

A personal data breach must be reported to the Data Protection Board and to every affected individual. The notification must describe the breach, the likely consequences, and what you are doing about it. Write the procedure now: who declares a breach, who contacts the Board, how you reach affected customers, what your IT partner does in the first hour. A one-page plan drafted calmly beats improvising after a ransomware note appears.

7. Set retention periods and actually delete data

Personal data must be erased once its purpose is served or consent is withdrawn — unless retention is required by another law (GST, income tax, labour records). Attach a retention period to every row in your data map, then set a quarterly calendar reminder to purge. Old CCTV footage, ex-employee files, and lapsed-lead lists are the usual offenders.

8. Handle data principal rights requests

Individuals can ask what data you hold, request correction or erasure, nominate someone to act for them, and have a grievance addressed. The Rules set a maximum 90-day resolution timeline, so publish a contact point (an email address is fine) and keep a simple log of requests and responses.

9. Check children’s data if it touches your business

Schools, coaching centres, paediatric clinics and any business with under-18 customers need verifiable parental consent before processing a child’s data, and cannot track or target advertising at children. If this applies, it is a priority item, not a footnote.

10. Get your vendor contracts right

If a third party processes personal data for you — a payroll service, a cloud CRM, a marketing agency, your IT AMC provider — you remain responsible as the Data Fiduciary. Contracts should require them to protect the data and delete it when the engagement ends. Ask your vendors one question: “Are you DPDP-ready?” and keep the answer in writing.

What you do NOT need (yet)

Small businesses are not automatically “Significant Data Fiduciaries” — that designation, with its Data Protection Officer, annual audit and impact assessment requirements, is for large-scale or sensitive processors named by the government. You do not need a certified DPO, a data localisation server, or a lakh-rupee consulting engagement to be compliant. You need the ten items above, done properly and documented.

A realistic 90-day plan for an SME

Weeks Action Who
1–2 Data mapping spreadsheet; vendor list Owner + office manager
3–4 Privacy notice; consent fixes on forms Owner + web/IT partner
5–8 Security safeguards: patching, endpoint protection, access control, encrypted backup, log retention IT partner
9–10 Breach procedure; retention schedule; rights-request contact Owner + IT partner
11–12 Staff briefing; vendor letters; file everything in one folder Owner

Started in September 2026, this lands you fully prepared before penalties go live in November — with months of buffer before the May 2027 deadline.

Frequently asked questions

Is there a small-business exemption under the DPDP Act?

No general exemption. The government can notify relaxations for specific classes such as startups, but as of September 2026 nothing exempts ordinary SMEs from the core obligations. Small size affects how penalties are scaled, not whether the law applies.

Does DPDP require me to store data on servers in India?

No. The final Rules use a restriction-list model — transfers are allowed except to countries the government specifically restricts — rather than mandatory localisation. Using a reputable cloud service is fine if your contract covers security and deletion.

Is Windows 10 a DPDP problem?

Potentially, yes. “Reasonable security safeguards” is judged against current good practice, and an operating system without security updates is hard to defend after a breach. Machines still on Windows 10 need either commercial Extended Security Updates or an upgrade path.

What should I do first if I only have one week?

Map your data, fix the security basics (patching, backup, access control), and write the breach procedure. Those three protect you against the highest-penalty failures and the most likely real-world incident.

Can CNC help with DPDP compliance?

We handle the technical safeguards — patching, endpoint security, firewall, access control, encrypted backup, log retention and breach-response readiness — and can point you to a legal advisor for the policy documents. See our DPDP compliance service for Delhi businesses.

Get the technical safeguards done before 13 November

CNC has secured Delhi small-business IT since 1996 — 8 certified engineers, 4.9★ from 983 Google reviews. We’ll run a DPDP safeguards assessment on your office and give you a fixed-price plan for whatever is missing.

📞 +91-98101-30131  ·  💬 WhatsApp us  ·  DPDP service details →

This article is general information based on the DPDP Act 2023 and DPDP Rules 2025 as notified on 13 November 2025. It is not legal advice. Consult a qualified advisor for your specific compliance position.

📍 O-41 West Patel Nagar · Mon–Sat 10 AM–7 PM

Need laptop repair or data recovery help?

CNC is at West Patel Nagar, Delhi — same-day service, free diagnosis, No Fix No Charge.

📞 Call CNC — 9810130131 💬 WhatsApp CNC →

⭐ 4.9★ · 981 Google reviews · Since 1996 · GST invoice · Learn more →

Prices and rates mentioned in this article are indicative estimates as of September 2026, exclusive of GST unless stated, and may change without notice due to exchange-rate movements, supply constraints and market demand. Please confirm current pricing and availability with CNC before making any decision.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Send Query

    Recent Posts

    • DPDP Act Compliance Checklist for Small Businesses in India — What’s Actually Required in 2026
    • Free Data Recovery Software vs Professional Data Recovery in Delhi: When DIY Works — and When It Destroys Your Data
    • Outsourced IT Engineer vs In-House IT Staff: Real Cost Comparison for Delhi Offices (2026)
    • Network Slowdowns Are Costing You: How a Network Solutions Provider Can Help
    • Slow, Crashing or Freezing? How Computer Repair and Services Can Help

    Recent Comments

    1. Understanding Computer AMC Price: What Factors Affect the Cost? on IT AMC Price List Delhi 2026 — Per Desktop, Laptop, Printer, Server & CCTV Camera (+ Calculator)
    2. IT AMC and CCTV Installation Cost in Delhi: Complete Pricing Guide on IT AMC Price List Delhi 2026 — Per Desktop, Laptop, Printer, Server & CCTV Camera (+ Calculator)
    3. IT AMC in Delhi: Cost, Benefits & Complete Business Guide on Comprehensive vs Non-Comprehensive AMC: Which One Do You Need?
    4. IT AMC Cost in Delhi — Real 2026 Pricing | CNC on IT AMC Price List Delhi 2026 — Per Desktop, Laptop, Printer, Server & CCTV Camera (+ Calculator)
    5. IT AMC Price List Delhi 2026 — Per Device Rates + Cost Calculator | CNC on Comprehensive vs Non-Comprehensive AMC: Which One Do You Need?

    Categories

    • amc services
    • Best Firewall Protection
    • Careers & Jobs at CNC
    • CCTV solutions
    • Classic Network & Computers
    • Cloud Security Solutions
    • Computer
    • Computer Hardware Maintenance
    • Computer Hardware Networking
    • Computer Hardware Repair Services
    • Computer Integration
    • Computer Repair
    • Computer Solution Services
    • Cyber Security Companies
    • Cyber Security Solutions
    • data recovery
    • Data Recovery Software
    • Hardware Solution for Computer
    • IT Computer Services
    • IT Solution
    • Laptop Repair
    • Laptop Repair Service
    • Network Security
    • Networking
    • Power Conditioners
    • Power Conditioning Equipment
    • Power Conditioning Systems
    • Refurbished Computers
    • Resident Engineer
    • Software Solutions
    • Storage and data recovery
    ©2026 Our Updated Blogs & Articles | Built using WordPress and Responsive Blogily theme by Superb

    Table of Contents

    ×
    • The three DPDP dates every Indian SME should know
    • First: does DPDP even apply to you?
    • The DPDP compliance checklist for small businesses
      • 1. Know what personal data you hold — and where
      • 2. Publish a plain-language privacy notice
      • 3. Fix your consent mechanism
      • 4. Understand “legitimate uses” — you don’t need consent for everything
      • 5. Put reasonable security safeguards in place
      • 6. Build a breach response procedure — before you need it
      • 7. Set retention periods and actually delete data
      • 8. Handle data principal rights requests
      • 9. Check children’s data if it touches your business
      • 10. Get your vendor contracts right
    • What you do NOT need (yet)
    • A realistic 90-day plan for an SME
    • Frequently asked questions
      • Is there a small-business exemption under the DPDP Act?
      • Does DPDP require me to store data on servers in India?
      • Is Windows 10 a DPDP problem?
      • What should I do first if I only have one week?
      • Can CNC help with DPDP compliance?
    → Index