{"id":1368,"date":"2026-09-03T10:00:27","date_gmt":"2026-09-03T04:30:27","guid":{"rendered":"https:\/\/www.cnc-system.com\/blog\/?p=1368"},"modified":"2026-09-02T22:06:19","modified_gmt":"2026-09-02T16:36:19","slug":"dpdp-act-compliance-checklist-small-business-india","status":"publish","type":"post","link":"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/","title":{"rendered":"DPDP Act Compliance Checklist for Small Businesses in India \u2014 What&#8217;s Actually Required in 2026"},"content":{"rendered":"<p>If you run a small business in India and collect any digital personal data \u2014 customer phone numbers, employee Aadhaar copies, a WhatsApp lead list, a CCTV feed of your reception \u2014 the Digital Personal Data Protection Act now applies to you. Not &#8220;will apply someday&#8221;: the Rules were notified on 13 November 2025, the Data Protection Board is already operational, and the phase that switches on penalties begins on <strong>13 November 2026<\/strong>. Full compliance is due <strong>13 May 2027<\/strong>.<\/p>\n<p>Most of what is written about DPDP is aimed at banks and unicorns. This checklist is for the 20-person trading firm, the clinic, the CA office, the school, the manufacturer with 60 staff \u2014 businesses that have real personal data and no compliance department. CNC has helped Delhi SMEs secure their IT since 1996, and we&#8217;ve built this from the questions they actually ask.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_three_DPDP_dates_every_Indian_SME_should_know\"><\/span>The three DPDP dates every Indian SME should know<span class=\"ez-toc-section-end\"><\/span><\/h2><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_87 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#The_three_DPDP_dates_every_Indian_SME_should_know\" >The three DPDP dates every Indian SME should know<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#First_does_DPDP_even_apply_to_you\" >First: does DPDP even apply to you?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#The_DPDP_compliance_checklist_for_small_businesses\" >The DPDP compliance checklist for small businesses<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#1_Know_what_personal_data_you_hold_%E2%80%94_and_where\" >1. Know what personal data you hold \u2014 and where<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#2_Publish_a_plain-language_privacy_notice\" >2. Publish a plain-language privacy notice<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#3_Fix_your_consent_mechanism\" >3. Fix your consent mechanism<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#4_Understand_%E2%80%9Clegitimate_uses%E2%80%9D_%E2%80%94_you_dont_need_consent_for_everything\" >4. Understand &#8220;legitimate uses&#8221; \u2014 you don&#8217;t need consent for everything<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#5_Put_reasonable_security_safeguards_in_place\" >5. Put reasonable security safeguards in place<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#6_Build_a_breach_response_procedure_%E2%80%94_before_you_need_it\" >6. Build a breach response procedure \u2014 before you need it<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#7_Set_retention_periods_and_actually_delete_data\" >7. Set retention periods and actually delete data<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#8_Handle_data_principal_rights_requests\" >8. Handle data principal rights requests<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#9_Check_childrens_data_if_it_touches_your_business\" >9. Check children&#8217;s data if it touches your business<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#10_Get_your_vendor_contracts_right\" >10. Get your vendor contracts right<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#What_you_do_NOT_need_yet\" >What you do NOT need (yet)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#A_realistic_90-day_plan_for_an_SME\" >A realistic 90-day plan for an SME<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#Frequently_asked_questions\" >Frequently asked questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#Is_there_a_small-business_exemption_under_the_DPDP_Act\" >Is there a small-business exemption under the DPDP Act?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#Does_DPDP_require_me_to_store_data_on_servers_in_India\" >Does DPDP require me to store data on servers in India?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#Is_Windows_10_a_DPDP_problem\" >Is Windows 10 a DPDP problem?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#What_should_I_do_first_if_I_only_have_one_week\" >What should I do first if I only have one week?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.cnc-system.com\/blog\/dpdp-act-compliance-checklist-small-business-india\/#Can_CNC_help_with_DPDP_compliance\" >Can CNC help with DPDP compliance?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n\n<table>\n<thead>\n<tr>\n<th>Date<\/th>\n<th>What happens<\/th>\n<th>What it means for you<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>13 Nov 2025<\/td>\n<td>Rules notified; Data Protection Board established<\/td>\n<td>Complaints can already be filed against you<\/td>\n<\/tr>\n<tr>\n<td>13 Nov 2026<\/td>\n<td>Penalty and appeal provisions become operative; Consent Manager registration opens<\/td>\n<td>Enforcement teeth arrive \u2014 10 weeks from now<\/td>\n<\/tr>\n<tr>\n<td>13 May 2027<\/td>\n<td>Full compliance: consent, notices, rights, security safeguards, breach reporting, retention<\/td>\n<td>Every obligation below must be live<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The penalty ceilings are designed to get attention: up to \u20b9250 crore per instance for failing to maintain reasonable security safeguards, and \u20b9200 crore for failing to report a breach. The Board scales penalties to the size and nature of the violation, so a small business isn&#8217;t facing \u20b9250 crore \u2014 but it is facing a formal, digital complaint process that any customer or employee can trigger.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"First_does_DPDP_even_apply_to_you\"><\/span>First: does DPDP even apply to you?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Almost certainly yes. The Act covers digital personal data \u2014 any data about an identifiable individual that is collected digitally or digitised later. That includes a paper visitor register you photograph, a customer list in Excel, biometric attendance records, and your website contact form. There is no turnover threshold that exempts you. The only real carve-out is personal data an individual has made publicly available themselves, and processing for purely personal or domestic use.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"The_DPDP_compliance_checklist_for_small_businesses\"><\/span>The DPDP compliance checklist for small businesses<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_Know_what_personal_data_you_hold_%E2%80%94_and_where\"><\/span>1. Know what personal data you hold \u2014 and where<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>You cannot protect what you haven&#8217;t mapped. List every place personal data lives: Tally customer masters, HR files, email, WhatsApp Business, CCTV DVRs, the website database, Google Drive, engineers&#8217; laptops. For each, note what data, why you collect it, who can access it, and how long you keep it. For most SMEs this is a two-hour exercise with a spreadsheet \u2014 and it drives every other item below.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Publish_a_plain-language_privacy_notice\"><\/span>2. Publish a plain-language privacy notice<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Under the Rules, a notice must be standalone and understandable, listing the specific personal data collected and the itemised purpose for each. &#8220;We may use your data to improve services&#8221; no longer qualifies. It must also tell people how to withdraw consent, exercise their rights, and complain to the Board. One notice on your website plus a short version at the point of collection (forms, onboarding) is the practical minimum.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_Fix_your_consent_mechanism\"><\/span>3. Fix your consent mechanism<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Consent must be free, specific, informed, unconditional and unambiguous \u2014 a clear affirmative action. Pre-ticked boxes, bundled consent (&#8220;by continuing you agree to everything&#8221;), and silence do not count. Withdrawal must be as easy as giving consent. For a small business this usually means: a real checkbox on web forms, a documented verbal-consent line for phone enquiries, and a way to record that an employee agreed to the HR data policy.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"4_Understand_%E2%80%9Clegitimate_uses%E2%80%9D_%E2%80%94_you_dont_need_consent_for_everything\"><\/span>4. Understand &#8220;legitimate uses&#8221; \u2014 you don&#8217;t need consent for everything<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The Act lets you process data without fresh consent for certain purposes: employment-related processing, responding to a request the person made voluntarily (a customer asking for a quote), legal obligations, medical emergencies. Knowing this stops you from drowning your customers in consent pop-ups for things that are already lawful.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"5_Put_reasonable_security_safeguards_in_place\"><\/span>5. Put reasonable security safeguards in place<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This is the item that carries the \u20b9250 crore ceiling, and it&#8217;s where an IT partner earns its keep. The Rules expect encryption or masking of personal data, access controls, logging and monitoring to detect unauthorised access, backups to restore data after a breach, and contractual security obligations on your vendors. In practice for an SME: patched operating systems (Windows 10 without extended updates fails this test), endpoint protection on every machine, a properly configured firewall, role-based access in Tally and shared drives, encrypted backups with a tested restore, and log retention of at least one year.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"6_Build_a_breach_response_procedure_%E2%80%94_before_you_need_it\"><\/span>6. Build a breach response procedure \u2014 before you need it<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A personal data breach must be reported to the Data Protection Board and to every affected individual. The notification must describe the breach, the likely consequences, and what you are doing about it. Write the procedure now: who declares a breach, who contacts the Board, how you reach affected customers, what your IT partner does in the first hour. A one-page plan drafted calmly beats improvising after a ransomware note appears.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"7_Set_retention_periods_and_actually_delete_data\"><\/span>7. Set retention periods and actually delete data<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Personal data must be erased once its purpose is served or consent is withdrawn \u2014 unless retention is required by another law (GST, income tax, labour records). Attach a retention period to every row in your data map, then set a quarterly calendar reminder to purge. Old CCTV footage, ex-employee files, and lapsed-lead lists are the usual offenders.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"8_Handle_data_principal_rights_requests\"><\/span>8. Handle data principal rights requests<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Individuals can ask what data you hold, request correction or erasure, nominate someone to act for them, and have a grievance addressed. The Rules set a maximum 90-day resolution timeline, so publish a contact point (an email address is fine) and keep a simple log of requests and responses.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"9_Check_childrens_data_if_it_touches_your_business\"><\/span>9. Check children&#8217;s data if it touches your business<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Schools, coaching centres, paediatric clinics and any business with under-18 customers need verifiable parental consent before processing a child&#8217;s data, and cannot track or target advertising at children. If this applies, it is a priority item, not a footnote.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"10_Get_your_vendor_contracts_right\"><\/span>10. Get your vendor contracts right<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If a third party processes personal data for you \u2014 a payroll service, a cloud CRM, a marketing agency, your IT AMC provider \u2014 you remain responsible as the Data Fiduciary. Contracts should require them to protect the data and delete it when the engagement ends. Ask your vendors one question: &#8220;Are you DPDP-ready?&#8221; and keep the answer in writing.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_you_do_NOT_need_yet\"><\/span>What you do NOT need (yet)<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Small businesses are not automatically &#8220;Significant Data Fiduciaries&#8221; \u2014 that designation, with its Data Protection Officer, annual audit and impact assessment requirements, is for large-scale or sensitive processors named by the government. You do not need a certified DPO, a data localisation server, or a lakh-rupee consulting engagement to be compliant. You need the ten items above, done properly and documented.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"A_realistic_90-day_plan_for_an_SME\"><\/span>A realistic 90-day plan for an SME<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<table>\n<thead>\n<tr>\n<th>Weeks<\/th>\n<th>Action<\/th>\n<th>Who<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>1\u20132<\/td>\n<td>Data mapping spreadsheet; vendor list<\/td>\n<td>Owner + office manager<\/td>\n<\/tr>\n<tr>\n<td>3\u20134<\/td>\n<td>Privacy notice; consent fixes on forms<\/td>\n<td>Owner + web\/IT partner<\/td>\n<\/tr>\n<tr>\n<td>5\u20138<\/td>\n<td>Security safeguards: patching, endpoint protection, access control, encrypted backup, log retention<\/td>\n<td>IT partner<\/td>\n<\/tr>\n<tr>\n<td>9\u201310<\/td>\n<td>Breach procedure; retention schedule; rights-request contact<\/td>\n<td>Owner + IT partner<\/td>\n<\/tr>\n<tr>\n<td>11\u201312<\/td>\n<td>Staff briefing; vendor letters; file everything in one folder<\/td>\n<td>Owner<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Started in September 2026, this lands you fully prepared before penalties go live in November \u2014 with months of buffer before the May 2027 deadline.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_asked_questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Is_there_a_small-business_exemption_under_the_DPDP_Act\"><\/span>Is there a small-business exemption under the DPDP Act?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>No general exemption. The government can notify relaxations for specific classes such as startups, but as of September 2026 nothing exempts ordinary SMEs from the core obligations. Small size affects how penalties are scaled, not whether the law applies.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Does_DPDP_require_me_to_store_data_on_servers_in_India\"><\/span>Does DPDP require me to store data on servers in India?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>No. The final Rules use a restriction-list model \u2014 transfers are allowed except to countries the government specifically restricts \u2014 rather than mandatory localisation. Using a reputable cloud service is fine if your contract covers security and deletion.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Is_Windows_10_a_DPDP_problem\"><\/span>Is Windows 10 a DPDP problem?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Potentially, yes. &#8220;Reasonable security safeguards&#8221; is judged against current good practice, and an operating system without security updates is hard to defend after a breach. Machines still on Windows 10 need either commercial Extended Security Updates or an upgrade path.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_should_I_do_first_if_I_only_have_one_week\"><\/span>What should I do first if I only have one week?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Map your data, fix the security basics (patching, backup, access control), and write the breach procedure. Those three protect you against the highest-penalty failures and the most likely real-world incident.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Can_CNC_help_with_DPDP_compliance\"><\/span>Can CNC help with DPDP compliance?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>We handle the technical safeguards \u2014 patching, endpoint security, firewall, access control, encrypted backup, log retention and breach-response readiness \u2014 and can point you to a legal advisor for the policy documents. See our <a href=\"https:\/\/www.cnc-system.com\/dpdp-compliance\">DPDP compliance service for Delhi businesses<\/a>.<\/p>\n<div style=\"margin: 32px 0; padding: 24px; background: #f0f6ff; border: 1px solid #c7ddff; border-radius: 12px;\">\n<p style=\"margin: 0 0 8px; font-size: 18px;\"><strong>Get the technical safeguards done before 13 November<\/strong><\/p>\n<p style=\"margin: 0 0 14px;\">CNC has secured Delhi small-business IT since 1996 \u2014 8 certified engineers, 4.9\u2605 from 983 Google reviews. We&#8217;ll run a DPDP safeguards assessment on your office and give you a fixed-price plan for whatever is missing.<\/p>\n<p style=\"margin: 0;\">\ud83d\udcde <a href=\"tel:+919810130131\"><strong>+91-98101-30131<\/strong><\/a> \u00a0\u00b7\u00a0 \ud83d\udcac <a href=\"https:\/\/wa.me\/918130992267?text=Hi%20CNC%2C%20I%20need%20a%20DPDP%20safeguards%20assessment%20for%20my%20office.%20My%20name%20is%20___%20and%20my%20office%20is%20in%20___.\" target=\"_blank\" rel=\"noopener\"><strong>WhatsApp us<\/strong><\/a> \u00a0\u00b7\u00a0 <a href=\"https:\/\/www.cnc-system.com\/dpdp-compliance\">DPDP service details \u2192<\/a><\/p>\n<\/div>\n<p><em>This article is general information based on the DPDP Act 2023 and DPDP Rules 2025 as notified on 13 November 2025. It is not legal advice. Consult a qualified advisor for your specific compliance position.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you run a small business in India and collect any digital personal data \u2014 customer phone numbers, employee Aadhaar copies, a WhatsApp lead list, a CCTV feed of your reception \u2014 the Digital Personal Data Protection Act now applies to you. Not &#8220;will apply someday&#8221;: the Rules were notified on 13 November 2025, the&#8230;<\/p>\n","protected":false},"author":100,"featured_media":1369,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[217],"tags":[478,21,477,411,480,479],"class_list":["post-1368","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security-solutions","tag-compliance","tag-cyber-security","tag-data-protection","tag-dpdp-act","tag-india","tag-small-business-it"],"_links":{"self":[{"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/posts\/1368","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/users\/100"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/comments?post=1368"}],"version-history":[{"count":1,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/posts\/1368\/revisions"}],"predecessor-version":[{"id":1370,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/posts\/1368\/revisions\/1370"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/media\/1369"}],"wp:attachment":[{"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/media?parent=1368"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/categories?post=1368"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cnc-system.com\/blog\/wp-json\/wp\/v2\/tags?post=1368"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}