DPDP Act explained in plain English: the full guide for Indian MSMEs

SaralPrivacy editorial team28 min read7,269 words

Most small business owners in India think the DPDP Act is a law for Infosys, Zomato and the banks. It is not. If you keep customer phone numbers in a WhatsApp group, candidate CVs in a Google Drive folder, or client PAN numbers in a Tally backup, this law is about you.

Here is the short answer. The Digital Personal Data Protection Act, 2023 says you may collect and use a person's data only for a clear reason, only with their permission or one of nine listed exceptions, only for as long as you need it, and only if you keep it safe. You must tell people what you are doing. You must let them ask what you hold, fix it, and delete it. The full set of these duties starts on 13 May 2027.

This guide walks through the whole law in plain words. No section is skipped. Every rule comes with an example from a real Indian business — a recruitment agency, a CA firm, a coaching class, a D2C brand, a clinic, a broker.

Most MSME owners are reading this as a law for large companies. It is a law for anyone with a customer list.


What is the DPDP Act, and who does it cover?

The Digital Personal Data Protection Act, 2023 is India's first full law on personal data. Parliament passed it in August 2023. The rules that make it work — the Digital Personal Data Protection Rules, 2025 — were notified on 13 November 2025.

The law covers digital personal data. That means data that was born digital, and also paper data that you later typed or scanned into a computer. A visitor register lying in a drawer is outside the law. The same register once you photograph it and save it to Drive is inside it.

It applies to businesses inside India. It also applies to businesses outside India if they offer goods or services to people in India.

There is no size cut-off. A two-person recruitment agency in Indore and a 5,000-person IT firm in Bengaluru are both covered. The size of your business changes how much you have to do, not whether you have to do it.

The law came into force in stages:

When the DPDP Act takes effect
  1. 13 November 2025

    Definitions and the Board

    The definitions and the machinery of the Data Protection Board came into effect.

  2. 13 November 2026

    Consent Managers

    The rules for Consent Managers begin.

  3. 13 May 2027

    Everything that bites

    Notice, consent, security, breach reporting, deletion, people's rights, extra duties for large companies, cross-border rules.

So you have time. You do not have spare time. Most of the work below is record-keeping and habit change, and that takes months, not weeks.


The seven words you need to know

The law uses a small set of terms. Learn these seven and the rest of the Act reads easily.

The seven terms the Act runs on
Personal data
Any data that identifies a person, alone or combined with what else you hold.
Processing
Almost anything you do with data — collect, store, change, share, delete.
Data Fiduciary
The business deciding why and how data is used. That is you.
Data Principal
The person the data is about. For a child, their parent or guardian.
Data Processor
Anyone handling data for you, on your instructions.
Consent
Permission given freely, for a clearly stated purpose.
Legitimate use
Nine specific situations where the law lets you skip consent.

Personal data

Any data about a person who can be identified from it — alone, or when joined with something else you hold.

That is wider than a name. It includes:

  • A mobile number saved next to a purchase history
  • An email address saved next to a service preference
  • Location data that shows someone visiting a clinic every Tuesday
  • A fingerprint or face scan used to mark attendance
  • Bank details saved next to a spending pattern

The test is simple. Can you work out who this is? If yes, it is personal data.

Processing

Almost anything you do with data. The law lists it out: collecting, recording, organising, storing, changing, retrieving, using, sharing, and deleting.

If a computer touches the data at any step, processing has happened. Saving a CV is processing. Emailing it to a client is processing. Deleting it is processing too.

Data Fiduciary

The business that decides why the data is collected and how it will be used. That is you.

"Fiduciary" is a trust word. It is used for a trustee — someone who holds another person's property and must act in their interest. The law chose it on purpose. You do not own the data. You hold it.

Data Principal

The person the data is about. Your customer, your employee, your candidate, your patient, your student, your vendor's staff.

For a child — anyone under 18 — the Data Principal includes the parent or lawful guardian. For a person with a disability who has a lawful guardian, it includes that guardian.

Data Processor

Anyone who handles the data for you, on your instructions. Your cloud host. Your payroll agency. Your SMS gateway. Your CRM vendor. Your accountant, if you send them staff data.

This one matters more than owners expect. If your processor leaks the data, the Data Protection Board comes to you.

A vendor's mistake is your penalty. Read the contract before you read the pitch deck.

Permission from the person, given freely, for a clearly stated purpose. Not a pre-ticked box. Not a line buried on page four of your terms.

Legitimate use

Nine specific situations where the law lets you use data without asking. They are listed later in this guide. They are narrow. They are not a general excuse.


When are you allowed to use someone's personal data?

Section 4 sets the base rule, and it is a short one. You may process personal data only for a lawful purpose, and only on one of two grounds:

Section 4 — the only two grounds

Consent

The person's permission, meeting all five tests. Can be withdrawn at any time.

Fits things people choose — marketing, loyalty programmes, optional features.

One of nine legitimate uses

A closed list in Section 7. Narrow, and not a general excuse.

Fits things you must do anyway — payroll, court orders, medical emergencies.

There is no third option.

That is the whole menu. There is no third option.

This is the single most useful thing to internalise. For every set of data you hold, you should be able to point at one of these two and say which one it is. A recruitment agency that cannot say why it is allowed to hold a four-year-old CV has already found its first gap.

The law is not trying to stop you from running your business. It is asking you to be deliberate. Consent fits things people choose — marketing messages, a loyalty programme, an optional feature. Legitimate use fits things you must do anyway — paying your staff, replying to a court order, treating an emergency patient.


Section 6 sets five tests. Consent must pass all five.

Section 6 — consent must pass all five
  1. Free

    Given without pressure. If saying no means losing a service the person is otherwise entitled to, the consent is not free.

  2. Specific

    Tied to a clearly named purpose.

    FailsWe may use your data for business purposes

    PassesWe will use your mobile number to send you your order status

  3. Informed

    The person knew what they were agreeing to, because you told them clearly first.

  4. Unconditional

    Not bundled with something unrelated. You cannot make consent for marketing a condition of getting the invoice.

  5. Unambiguous

    Shown by a clear positive action — a tick, a tap, a signature. Silence is not consent. A pre-ticked box is not consent. Someone not replying is not consent.

The Act gives its own example. A telemedicine app asks for consent to use your health data to treat you, and in the same request asks for access to your phone contacts. Your consent covers the health data only. Contacts are not needed to run a video consultation, so the permission for contacts is not valid.

Now put that in an Indian MSME frame:

  • Recruitment agency. A candidate sends a CV for one job opening. That is consent for that opening. It is not consent to keep the CV in your database for three years and forward it to forty clients. If you want that, ask for it separately and say so plainly.
  • D2C brand. A checkout page with a pre-ticked "Send me offers on WhatsApp" box fails the unambiguous test. Untick it by default.
  • Coaching institute. Making a parent agree to marketing photos of their child on Instagram as a condition of admission fails the unconditional test.
  • CA firm. A client shares bank statements for filing returns. That is consent for filing. It is not consent to pitch them an insurance product.

Consent is not a document you collect. It is a purpose you can point to.

What must your notice say before you ask?

Section 5, read with Rule 3, says you must give a notice before you ask for consent. The notice has to contain four things:

  • An itemised list of the data you want. "Contact details" is not enough. "Name, mobile number, email address, PAN" is.
  • The exact purpose. Say what goods, services or use this enables. "To improve our services" is not a purpose.
  • How the person can exercise their rights, including how to withdraw consent.
  • How to complain to the Data Protection Board.

The notice also has to be:

  • Given on its own, not buried inside a long terms-and-conditions document
  • Written in clear, plain language
  • Available in English or any of the 22 languages in the Eighth Schedule to the Constitution, at the person's choice
  • Accompanied by contact details for your Data Protection Officer, or for whoever answers data questions in your business

Example. A person opens a savings account through a bank's app. The bank must say which documents and details it is taking, why it needs them — KYC rules, running the account, processing transactions — and how the customer can raise a request or a complaint.

MSME version. A gym in Pune signing up a member should have a short notice next to the form: we take your name, mobile, date of birth and emergency contact; we use them to manage your membership, send class reminders and call your emergency contact if something happens on the floor; you can email privacy@ourgym.in to see, correct or delete your details, or to withdraw consent. That is a compliant notice. It fits on half a page.

People can withdraw consent at any time. The law says withdrawal must be as easy as giving it. If one tap gave consent, one tap must take it back. A form that requires a signed letter by post fails.

Withdrawal has consequences the person has to accept. If a customer withdraws consent for an e-commerce platform to process their data for order fulfilment, the platform can stop letting them place orders. But it must still finish the orders already paid for.

When someone withdraws, you must:

  • Stop processing that data, unless another lawful ground applies
  • Make your processors stop too
  • Do both within a reasonable time

MSME version. A candidate emails your recruitment agency and says "please remove me from your database". You stop sending their profile to clients. You also tell your ATS vendor and any client who still holds the CV. Then you delete it, unless a law makes you keep it.

A Consent Manager is a new kind of company created by this law. Think of it as a single dashboard where a person can see every consent they have given across many businesses, and grant or withdraw them from one place.

Consent Managers must register with the Data Protection Board. They answer to the person, not to the businesses. They are not allowed to have conflicts of interest.

For an MSME, this is mostly good news. Over time, you may be able to plug into a Consent Manager instead of building consent tracking yourself. These rules start on 13 November 2026. Watch which Consent Managers register, and ask your software vendors whether they plan to connect.

You do. Section 6(10) puts the burden of proof on the Data Fiduciary. If a question comes up, you must show that the notice was given properly and the consent was taken properly.

This is the quiet rule that catches small businesses. A tick box that does not log the date, the version of the notice shown, and the action taken is a tick box you cannot defend later.

Consent you cannot prove is consent you did not take.


Section 7 lists nine legitimate uses. Nothing outside this list counts. Read them once carefully — several of them will cover a large part of what your business does every day.

Section 7 — the nine legitimate uses
  • Voluntarily givenAny business
  • Government benefitsThe State
  • State functionsThe State
  • Legal duty to discloseAny business
  • Court orders and claimsAny business
  • Medical emergenciesHealth providers
  • Public health eventsHealth providers
  • DisastersAny business
  • EmploymentAny employer

Numbers 1 and 9 cover most of what a small business does day to day.

1. The person gave it voluntarily and did not object. If someone hands you their data for a clear purpose and shows no sign of objecting, you may use it for that purpose.

The Act's own examples: a customer at a pharmacy gives their number and asks for the receipt by SMS — the pharmacy may use it to send the receipt. A person contacts a property broker for help finding a rental and shares their details — the broker may use them to find and share options, and must stop once the person says they no longer need help.

MSME note. This is the ground most small businesses actually operate on. A walk-in customer who gives their number for a delivery update is a Section 7(a) case, not a consent case. But it is narrow. It covers the purpose the person had in mind, and nothing more. The number given for a delivery update is not a number you may add to a Diwali offers blast.

2. Government benefits and services. The State can process data to give out subsidies, benefits, services, certificates, licences or permits, where the person has already consented to the State for such a purpose, or where the data already sits in a notified government database. The Second Schedule sets standards that still apply — lawfulness, necessity, accuracy, security, accountability.

Example. A woman enrols in a maternity benefit scheme and consents. The government may then use that data to check whether she qualifies for a child nutrition scheme, without asking again.

3. The State performing its functions. Processing needed for the State to carry out a function under law, or in the interest of India's sovereignty and integrity or the security of the State.

4. Meeting a legal duty to disclose. Where a law requires you to give information to the State. A bank reporting a suspicious transaction, or a business reporting under tax law, does not need consent.

5. Court orders and civil claims. Processing to comply with an Indian court judgment, decree or order, or a foreign judgment on a contract or civil claim.

6. Medical emergencies. Where there is a threat to life or an immediate threat to health, of the person or anyone else. A hospital treating an unconscious accident victim does not stop to collect a consent form.

7. Public health events. Providing treatment or health services during an epidemic, a disease outbreak, or another threat to public health. Covid-era vaccination drives and contact tracing sit here.

8. Disasters and breakdown of public order. Keeping people safe or giving them help during a disaster. "Disaster" carries the meaning given in the Disaster Management Act, 2005.

9. Employment. Processing for employment purposes, or to protect the employer from loss or liability. This includes preventing corporate espionage, protecting trade secrets and confidential information, and providing a service or benefit the employee asked for.

MSME note. Number nine covers a lot of a small business's HR life. Payroll, attendance, PF and ESI filings, appraisal records, a laptop issued to a staff member — these sit under employment purposes, not consent. That is deliberate. Consent between a boss and an employee is rarely free.

But it is not unlimited. Tracking a field sales executive's phone location on a Sunday is hard to defend as an employment purpose. And it does not remove your other duties — you still owe employees notice, security, accuracy and the right to correct their records.

Legitimate use is a door, not a corridor. It opens for one purpose and closes behind you.

Five mistakes to avoid when choosing your ground

  • Assuming consent covers everything. It does not. Consent is one of two grounds, and it is the weaker one, because it can be withdrawn.
  • Claiming a legitimate use when consent was actually needed. Each of the nine has specific conditions. "It helps my business" is not one of them.
  • Taking consent where a legitimate use already applied. This is the mistake nobody warns you about. If you ask for consent to run payroll, you have handed the employee a right to withdraw it — and then you cannot run payroll. Use the right ground, not the safest-feeling one.
  • Treating legitimate use as a blanket permission. It is nine named situations, not a category of convenience.
  • Not writing the ground down. If it is not in your register, you will not remember it in 2028, and you cannot prove it in a grievance.

What rights do your customers, employees and candidates have?

Four rights. You have to make each one actually usable.

The right to know what you hold (Section 11)

A person who gave you consent — including under the voluntary-provision ground in Section 7(a) — can ask you for:

  • A summary of the personal data you are processing about them, and what you are doing with it
  • The names of every other Data Fiduciary and Data Processor you shared it with, and a description of what you shared
  • Anything else that may be prescribed later

There is one carve-out. This right does not extend to data you shared with an authority legally entitled to ask for it, where the sharing was for preventing, detecting or investigating an offence or a cyber incident, or for prosecution. Telling a suspect that the police asked for their data would defeat the investigation.

MSME note. This right is the reason your data map matters. If a candidate asks "which of your clients has my CV?", the honest answer has to be a list. If your answer is "I would have to check forty email threads", you have found a gap.

The right to correct, complete, update and erase (Section 12)

If someone asks you to fix wrong data, fill in missing data or update stale data, you must do it.

If someone asks you to delete their data, you must delete it — unless you need it for the stated purpose or a law requires you to keep it.

That last clause matters. A CA firm cannot delete a client's records just because the client asks, when the Income Tax Act requires those records to be preserved. The honest reply is: we have deleted your marketing preferences and contact list entry; we are required to retain your filing records until [date], after which they will be deleted.

The right to complain to you first (Section 13)

Every business must give people an easy way to raise a grievance about how their data was handled, or about their rights not being honoured. You must respond within the period the Rules set, which is up to ninety days.

Here is the part worth knowing: a person must use your grievance process before going to the Data Protection Board. A working complaints inbox is not a nicety. It is your first line of defence.

The right to nominate someone (Section 14)

A person can nominate someone to exercise their rights if they die or become incapable of doing it themselves. "Incapacity" means unsoundness of mind or bodily infirmity.

Nomination follows your terms of service and any applicable law. For most MSMEs, this means adding a nominee field to your account settings and knowing what to do when a family member writes in.

You must publish how all of this works

The Rules require you to prominently publish on your website or app:

  • How a person can make a rights request
  • What details you need to identify them — customer ID, registered mobile, username
  • How your grievance system works, and how long you take to respond

The test is not whether the page exists. The test is whether a customer can find it in thirty seconds and use it without calling you.


What does the DPDP Act ask every business to do?

Section 8 is the core duty list. These apply whether you run on consent or on legitimate use.

1. You stay responsible. You are answerable for all processing you do, and for all processing done on your behalf. No contract can shift that. Even if the Data Principal failed to do something they were supposed to do, your duties stand.

2. Use processors only under a contract. You may engage a Data Processor only under a valid contract. Rule 6(1)(f) requires that contract to include proper security terms. Before you sign one, check their technical ability, their security setup, their track record, their stability, and whether they can help you meet your own duties.

3. Keep data accurate. Where the data is likely to be used to make a decision about the person, or shared with another Data Fiduciary, you must make sure it is complete, accurate and consistent. Wrong data causes real harm — a rejected loan, a wrong medical note, a candidate marked as blacklisted by mistake.

4. Put technical and organisational measures in place. "Technical" means systems, software, encryption, access controls. "Organisational" means policies, training, who-does-what, and management oversight. They must be appropriate — sized to how much data you hold, how sensitive it is, and what could go wrong.

5. Apply reasonable security safeguards. Rule 6 spells out the minimum:

  • Protect the data itself — encryption, obfuscation, masking, or virtual tokens that stand in for the real value
  • Control access to the systems where personal data lives
  • Log, monitor and review who touched what, so you can spot and investigate unauthorised access
  • Keep working after an incident — backups and a recovery plan
  • Retain logs and personal data for one year, so incidents can be detected and investigated, unless a law says otherwise
  • Put security terms in processor contracts
  • Back it with technical and organisational measures

MSME note. You do not need an enterprise security stack. You need: unique logins for each person instead of a shared password; a spreadsheet of who has access to what; encryption switched on where your tools offer it; a backup that has actually been tested; and logs that exist. Most small businesses fail on the shared-password point alone.

6. Report breaches on two clocks. A personal data breach means unauthorised processing, or accidental disclosure, sharing, use, change, destruction or loss of access to personal data. It covers hacking, a staff member snooping, a misconfigured folder, a misdirected email, a stolen laptop and a ransomware attack.

When one happens, Rule 7 requires two things:

Rule 7 — two clocks start at once

Without delay

To every affected person

Through their account or a registered channel: what happened, how wide it is, when it happened, what it means for them, what you have done and are doing about it, what they can do to protect themselves, and who to contact.

Without delay, then within 72 hours

To the Data Protection Board

First, a description — nature, extent, timing, location and likely impact. Then within 72 hours a fuller report: the facts and reasons, the steps you took, anything found about who caused it, what stops a repeat, and confirmation that you told the affected people.

The Board can allow longer on a written request.

The 72 hours run from when you became aware — and "aware" is judged objectively. It means when you should reasonably have known, if you were monitoring properly. Not knowing because nobody was looking is not a defence.

A breach you have rehearsed for is half its size. Run the drill before you need it.

7. Delete data when its purpose ends. You must erase personal data when the person withdraws consent, or as soon as it is reasonable to assume the stated purpose is no longer being served — whichever comes first — unless a law requires you to keep it. You must make your processors delete it too.

Rule 8 sets fixed periods for certain large businesses. E-commerce entities and social media intermediaries with at least two crore registered users in India, and online gaming intermediaries with at least fifty lakh, must erase a user's data three years after the user last approached them or last exercised a right. At least 48 hours before that deletion, they must tell the user, so the user can log in and keep the account alive.

Alongside this, the Rules require personal data, related traffic data and processing logs to be kept for at least one year from processing, for purposes such as investigating offences and cyber incidents, enforcing legal claims, following court or regulatory orders, handling grievances, and keeping data secure.

Read those two together and the shape is clear: keep for at least a year, then delete when the purpose is done.

MSME note. The three-year rule targets giants, and your business is almost certainly below the thresholds. The principle still applies to you through Section 8(7). A coaching institute holding the phone numbers of students who finished in 2019 has no purpose left. That data is pure risk with no upside.

Default retention is the most expensive retention policy in India.

8. Publish a point of contact. You must prominently publish the business contact details of your Data Protection Officer, if you must have one, or of a person who can answer questions about how you process personal data. That person needs enough knowledge and enough authority to give a real answer.

For a 12-person firm this is usually the founder or the ops lead. Put a name and an email on the website. Not a contact form.

9. Run a grievance mechanism. You must have an effective way for people to raise grievances, with technical and organisational measures behind it so it actually works. The Rules set an outer limit of ninety days to respond.

An effective mechanism has: a clear way to file, an acknowledgement, an investigation, a communicated outcome, an escalation path, and a record of what happened.


What extra rules apply to children's data?

A child is anyone under 18. The bar here is high, and the penalty band is the second highest in the Act.

Verifiable parental consent is mandatory. Before processing any child's data, you must get consent from a parent or lawful guardian, and you must take real steps to check that person is an adult who could be identified if the law required it.

Rule 10 gives you two routes. Either use reliable identity and age details you already hold about that adult. Or use identity and age details the adult provides voluntarily, or virtual tokens issued by an authorised entity — for example through a DigiLocker service provider.

The Act's example: a child tries to create an account on a platform. If the parent is already a registered user whose identity and age the platform holds reliably, the platform checks against that. If the parent is new, the platform must verify adult status using government-issued identity and age details, or a virtual token the parent supplies.

You are not being asked to run a background check. You are being asked to take reasonable steps.

No processing that harms a child. You must not process a child's data in a way likely to have a harmful effect on their well-being. "Harmful effect" is deliberately left undefined so it can flex — think physical safety, mental and emotional health, education, social development, and financial interests.

No tracking, no behavioural monitoring, no targeted ads. You may not track a child's online activity, monitor their behaviour, or direct targeted advertising at them. This does not ban all advertising on services children use. It bans advertising aimed at a child based on their data or behaviour.

The exemptions. Rule 12 lists who is let off some of these duties, and for what.

Exempt classes of business, each limited to a specific purpose:

  • Clinical establishments, mental health establishments and healthcare professionals — only to provide health services to the child, only as far as needed to protect their health
  • Allied healthcare professionals — only to carry out treatment and referral plans, only as far as needed
  • Educational institutions — only for tracking and monitoring tied to educational activities or child safety
  • Crèches and child day care centres — only for tracking and monitoring for child safety
  • Transport providers for schools, crèches and child care centres — only for location tracking during travel, for safety

Exempt purposes, whoever is doing it:

  • Exercising a power or duty under law in the child's interests
  • Providing a government subsidy, benefit, service, certificate, licence or permit to the child
  • Creating an email account, limited to that
  • Finding a child's real-time location for safety or security
  • Blocking content, services or ads that would be harmful to the child
  • Checking that a user is not a child in the first place

The Central Government may also notify ages above which certain businesses are freed from the parental consent and tracking rules, where it is satisfied that their processing is verifiably safe.

MSME note. This section lands hardest on coaching classes, play schools, school bus operators, paediatric clinics, kids' apparel brands and youth sports academies. If you run a coaching institute, the exemption lets you track attendance and safety. It does not let you retarget a 15-year-old with fee offers on Instagram. Those are different activities and the law treats them differently.


What is a Significant Data Fiduciary, and are you one?

Almost certainly not — but you should know what the category is, because your larger clients will be in it and will push their duties down to you.

The Central Government may notify any business, or a class of businesses, as a Significant Data Fiduciary. It weighs the volume and sensitivity of data processed, the risk to people's rights, the impact on India's sovereignty and integrity, risk to electoral democracy, security of the State, and public order.

If you are notified as one, five extra duties apply:

  • Appoint a Data Protection Officer based in India, who represents you under the Act, reports to your board or equivalent, and is the contact point for grievances
  • Appoint an independent data auditor to check how you are doing, free of conflicts of interest
  • Run a Data Protection Impact Assessment and an audit at least once every 12 months. The impact assessment describes people's rights and your purpose, then assesses and manages the risk to those rights
  • Send the Board a report with the significant observations from that assessment and audit
  • Do due diligence on your algorithms. Rule 13(3) requires you to verify that technical measures, including algorithmic software used to host, display, upload, change, publish, transmit, store, update or share personal data, are not likely to put people's rights at risk
  • Keep specified data in India. Rule 13(4) says data the Central Government specifies, on a committee's recommendation, may not be transferred outside India. No such list has been published yet, so this duty is not yet live

MSME note. Here is where this touches you. When an enterprise client is notified as an SDF, their auditor will ask them to prove that their vendors are handling data properly. That question lands in your inbox as a security questionnaire or a data protection addendum. Small firms that can answer it quickly win work from small firms that cannot.


Can you store or send data outside India?

Section 16 takes a blacklist approach, not a whitelist. Transfers out of India are allowed unless the Central Government notifies a specific country or territory as restricted.

As things stand, no country has been notified. So a D2C brand on Shopify, a recruitment firm on a US-hosted ATS, or a CA firm using a foreign cloud drive is not breaking this rule today.

Two cautions.

Rule 15 allows the Central Government to set requirements for making personal data available to a foreign State, or to any person or agency under a foreign State's control. Those requirements have not been specified yet. Keep a simple list of where your data goes so you can respond when they are.

Section 16(2) says nothing in Section 16 cuts down any other law that gives higher protection or a stricter transfer rule. If RBI rules on payment data, or sector rules in health or finance, say the data must stay in India, those rules win. The DPDP Act is a floor, not a ceiling.


When does the DPDP Act not apply?

The Act carves out several situations. Read these carefully — most of them are narrower than people hope.

Personal or household use. The Act does not apply to an individual processing personal data for a purely personal or domestic purpose. Your family photo album and your personal contact list are outside it.

The exemption is narrow. It covers individuals, not businesses. The moment you run a business from home and start processing customer data, it stops applying.

Data the person made public themselves. The Act does not apply to personal data made publicly available by the person it belongs to, or by someone under a legal duty to publish it. The Act's example: someone blogging their views has made that data public.

Two limits. First, the exemption covers the data in the form it was published. If you scrape public profiles and combine them with private data to build detailed profiles, that combined processing can fall back inside the Act. Second, "publicly available" means the person chose to publish it — not that you found it somewhere.

Research, archiving and statistics. The Act does not apply to processing needed for research, archiving or statistical purposes, if the data is not used to make decisions about a specific person, and the processing follows the standards in the Second Schedule. Those standards are: lawful processing, necessity and proportionality, reasonable efforts at accuracy, limited retention, reasonable security safeguards, appropriate technical and organisational measures, and accountability.

Certain businesses, including startups. Section 17(3) lets the Central Government notify certain Data Fiduciaries — including startups — as exempt from Section 5 (notice), Section 8(3) and 8(7) (data accuracy for decisions and disclosures, and retention and erasure), Section 10 (Significant Data Fiduciary duties) and Section 11 (the right to access information).

A "startup" here means a private limited company, partnership firm or LLP incorporated in India and recognised as a startup by the department that handles startups in the Central Government.

Read that carefully. The Government may notify such classes. Until it does, nobody is exempt. Do not build your plan on an exemption that has not been granted. And note what stays even if it is granted: consent, security safeguards, correction and erasure rights, and grievance redressal all remain.

Processing by the State. For the State and its instrumentalities, Section 8(7) (retention and erasure) and Section 12(3) (the right to erasure) do not apply. Where the processing is not for making decisions about the person, Section 12(2) (correction, completion, updating) does not apply either.

Specific contexts. Chapters II and III and Section 16 do not apply where processing is:

  • Necessary to enforce a legal right or claim
  • By a court, tribunal or a body carrying out judicial, quasi-judicial, regulatory or supervisory functions, where necessary for that work
  • In the interest of preventing, detecting, investigating or prosecuting an offence or a breach of law
  • About people outside India, done under a contract with a person outside India, by someone based in India
  • Necessary for a court-approved merger, demerger, amalgamation, reconstruction, transfer of undertaking or division of companies
  • To find out the financial information, assets and liabilities of a loan defaulter, subject to disclosure rules in other laws

Time-limited exemptions. Within five years of the Act commencing, the Central Government may declare that a provision will not apply to specified businesses for a specified period. This lets it phase in duties sector by sector.

National security. The Act does not apply to processing by State instrumentalities the Central Government notifies, in the interests of India's sovereignty and integrity, security of the State, friendly relations with foreign States, public order, or preventing incitement to related offences. It also covers data those bodies pass to the Central Government. It applies only to notified bodies, and only for those purposes.


Who enforces this, and what are the penalties?

The Data Protection Board of India, set up under Section 18, is the enforcer. It receives breach reports, complaints from people, references from governments and directions from courts. It can inquire into breaches and impose penalties.

The Board is designed as a digital office — proceedings run online from complaint to disposal. For inquiries it has the powers of a civil court: summoning people, taking evidence, requiring documents, and inspecting data and records.

One current fact worth knowing. The Board exists in law from 13 November 2025, but as of August 2026 its Chairperson and Members have not been appointed. MeitY issued notices in May and June 2026 to fill the posts. So enforcement machinery is not yet running.

Do not misread that as breathing room. The duties still commence on 13 May 2027. And your customers, your enterprise clients and your prospects are already asking privacy questions in procurement, long before any regulator does.

The Board is not staffed yet. Your buyers are already asking.

The penalty bands

The Schedule to the Act sets maximums:

The Schedule — maximum penalties
  • ₹250 crFailure to take reasonable security safeguards to prevent a breach
  • ₹200 crFailure to notify the Board or affected people of a breach; and breach of the children's data duties
  • ₹150 crBreach of the extra duties of a Significant Data Fiduciary
  • ₹50 crBreach of any other provision of the Act or the Rules
  • ₹10,000Breach of the duties of a Data Principal

Breaking a voluntary undertaking accepted by the Board attracts the penalty applicable to the original breach. These are ceilings, not tickets.

These are ceilings, not tickets. Nobody expects a ₹250 crore penalty on a ten-person firm.

How the Board decides the amount

Section 33(2) lists what the Board weighs:

  • The nature, gravity and duration of the breach
  • The type and nature of the personal data affected — health, financial and children's data attract more
  • Whether the breach is repetitive
  • Whether the business gained, or avoided a loss, because of it
  • Whether it acted to reduce the damage, and how quickly and effectively
  • Whether the penalty is proportionate and effective at securing compliance and deterring repeats
  • The likely impact of the penalty on the business

Notice how many of these you control after something goes wrong. Fast, documented, honest action is a penalty-reducing act, in writing, in the statute.

The voluntary undertaking

Section 32 lets the Board accept a voluntary undertaking at any stage of a proceeding. You commit to do something by a date, or to stop doing something, and possibly to publicise the undertaking. With your consent, the Board can vary the terms.

Once accepted, the undertaking bars further proceedings on the matters it covers — unless you fail to keep to it, in which case that failure is itself treated as a breach and the Board may proceed with the original penalty.

This is a real route for a small business that finds and fixes a problem itself. Self-reporting and cooperation have a defined pay-off here.


What should an MSME do first?

Start with a register, not a policy. Policies written before you know what you hold are fiction.

The Six-Column Data Register

One spreadsheet. Six columns. One row for every set of personal data your business touches.

The Six-Column Data Register
1What data?2Whose?3Why?4On what ground?5Who else sees it?6When do we delete it?
Name, mobile, email, PAN, Aadhaar, bank details, CV, photo, biometric, locationCustomer, employee, candidate, vendor contact, student, patientOne clear purpose in one sentenceConsent, or which of the nine legitimate usesEvery tool, vendor and person — CRM, WhatsApp, accountant, cloud drive, courierA number, not “when needed”

Columns 4 and 6 are where the gaps live. That is not a failure — it is the output of the exercise.

A ten-person business usually finds between 15 and 30 rows. Half of them will be surprises — the old Google Sheet, the WhatsApp broadcast list, the intern's laptop, the shared Gmail nobody has closed.

Three of the columns will be easy. Columns 4 and 6 are where the gaps live. That is not a failure. That is the output of the exercise.

Do these now

  • Build the register. Half a day with the two or three people who actually touch data.
  • Map the flows. Draw where data enters, where it sits, and where it leaves.
  • Find the gaps. Compare what you do against what this guide describes.
  • Brief your team. Everyone who touches customer data should know these seven words.
  • Review your vendors. Which of them are Data Processors? Do your contracts say anything about security?
  • Name an owner. One person accountable, with a published email address.

Do these by 13 November 2026

That is when the Consent Manager rules begin. Before then:

  • Decide whether a Consent Manager will be useful to you, and ask your software vendors about their plans
  • Fix your consent mechanisms regardless — clear notice, free and specific consent, one-tap withdrawal

Do these by 13 May 2027

This is the real deadline. By then you need:

  • Notices that meet Rule 3, given before every consent request
  • Consent flows that pass all five tests, with logs that prove it
  • Security safeguards under Rule 6 — access control, logging, backups, encryption where available, one-year retention of logs
  • A breach process under Rule 7 that can notify people and the Board on time, tested at least once
  • A retention and deletion process under Rule 8, so data actually goes away
  • A published contact point under Rule 9
  • A working rights and grievance process under Rule 14, answering within ninety days
  • Parental consent machinery under Rule 10, if you touch children's data
  • A record of cross-border flows, ready for whatever Rule 15 requires

Then keep it running

Watch your processing as it changes. Review controls periodically. Rehearse the breach drill. Train new staff. Keep the register current — a register updated once is a museum piece.


What each part of a small business should do

Most MSMEs do not have separate legal, IT and marketing departments. But the work still splits along these lines, and it helps to name who owns what.

The owner or ops lead. Understand the consent-versus-legitimate-use split. Decide the ground for each row of the register. Approve notices and privacy pages. Set vendor contract standards. Define who does what when a breach happens. Track new notifications from MeitY and the Board.

Whoever handles IT. Turn on access controls and unique logins. Keep logs. Set up and test backups. Make sure data can actually be found and deleted when someone asks. Configure systems to collect only what is needed. Know where personal data physically lives. Check your vendors' security, not just their price.

Whoever handles HR. Decide which employee processing sits under employment purposes and which needs consent. Give employees a notice about what you hold and why. Give them a way to correct their records. Fold data questions into the grievance process. Check background verification practices. If you monitor email, systems or location, make sure the ground is sound and the staff have been told.

Whoever handles sales and marketing. Unless the voluntary-provision ground clearly covers it, marketing needs consent. Keep marketing consent separate from service consent. Honour withdrawals fast. Keep children out of marketing data sets entirely. Collect only what you will use. Keep proof of every marketing consent.

Whoever handles customer support or the front desk. This is where rights requests actually arrive — usually as a casual WhatsApp message, not a formal letter. Train the team to recognise one. Give them an escalation path. Track requests and grievances with dates. When a customer reports wrong data, make sure the fix reaches every system, and tell anyone you shared it with.


The bottom line

The DPDP Act does not ask you to become a law firm. It asks you to know what personal data you hold, why you hold it, who else sees it, and when it goes away. Everything else in the Act follows from those four answers.

Large companies will solve this with consultants and platforms. MSMEs will solve it with a register, a few habits and a named owner. The second route is cheaper and, done honestly, just as defensible.

You will not be punished for starting early. You will be punished for starting late.

You are not being asked to become a law firm. You are being asked to keep a register.

Sources

Reviewed 22 August 2026. Government notifications on Significant Data Fiduciaries, restricted countries and startup exemptions were awaited at the time of writing. Check for newer notifications before acting on the dates here.

Reference material, not legal advice.