In your business
A first-ninety-days sequence for a small business: confirm the Act applies, write the notice, settle consent, publish a contact and grievance route, set retention, prepare for a breach, then check your readiness.
Questions this module answers
- Who needs to comply with the DPDP Act?
- What must be included in a consent notice under the DPDP Act and Rules 2025?
- What is a Consent Manager under the DPDP Act?
- What are the breach notification timelines under the DPDP Act and Rules 2025?
- How long can companies store personal data under the DPDP Act?
Figures use one colour per role, throughout the course:
- Data Principal
- Data Fiduciary
- Data Processor
- Consent Manager
- Government and Board
The first five modules explained the law. This one turns it into a sequence for a small business over its first ninety days, in the order that each step makes the next one easier. Each lesson cites the provision it rests on and ends with one line on what SaralPrivacy provides for that step.
Days 1 to 10: Confirm the Act applies and map what you hold
Section 3 decides whether the Act applies: digital personal data processed in India, including paper records digitised later, and processing abroad linked to offering goods or services to people in India. Once it does, your first output is an inventory of every place personal data sits, and every later step is built on it.
- Days 1 to 3
Apply the Section 3 tests
Is it digital, or collected on paper and digitised later? Is it processed in India, or abroad in connection with offering goods or services to people in India? Is it outside the exclusions for personal or domestic use and for data made public by the person herself or under a legal duty?
Section 3 - Days 3 to 8
List every place personal data sits
CRM, billing, payroll, appointment book, shared drive, customer chat groups, website forms, and each vendor holding any of it. Include employees: their records are digital personal data too.
Section 3(a) - Days 8 to 10
For each row, record the data and the purpose
Whose data, which fields, why you collect it, where it is stored and who can see it. The notice in the next stage must name the personal data and the purpose.
Section 5(1)
Output of this stage: a data inventory, one row per place personal data sits, with one person responsible for keeping it current.
Read the full lesson, with every provision it rests on (1 min)
Start with Section 3. The Act applies to the processing of digital personal data within India where the personal data is collected in digital form, or collected on paper and digitised subsequently (Section 3(a)). It also applies to processing outside India "in connection with any activity related to offering of goods or services to Data Principals within the territory of India" (Section 3(b)). There is no turnover threshold and no headcount threshold; a two-person firm with a customer spreadsheet is in.
Section 3(c) sets out what is not covered: personal data processed by an individual for a personal or domestic purpose, and personal data made publicly available by the Data Principal herself or by someone under a legal obligation to publish it. The Act's own illustration is a person blogging her views on social media.
With that settled, make the inventory. List every place personal data sits: the CRM, the billing system, payroll, the appointment book, the shared drive, the WhatsApp groups you use with customers, the forms on your website, and the vendors that hold any of it. For each, note whose personal data it is, what fields you hold, why you collect it, where it is stored, and who can see it. Include employees; their personal data is digital personal data like anyone else's.
This map is the foundation for everything that follows. The notice in the next lesson is written from it, the consent decisions in lesson three are made purpose by purpose from it, and the retention schedule in lesson five is attached to it. Keep it as a living document rather than a one-time exercise, and give one person the job of keeping it current.
SaralPrivacy's readiness assessment opens with this inventory and scores the gaps against the Act.
Days 10 to 25: Write the notice
Section 5(1) requires a notice with, or before, every consent request, telling the person what data is processed and why, how to withdraw consent and seek redress, and how to complain to the Board. From 13 May 2027, Rule 3applies from 13 May 2027 requires it to stand on its own and itemise the data and purposes.
It stands on its own.
Presented and understandable independently of any other information you provide.
Rule 3(a)An itemised description of the personal data.
Rule 3(b)The specified purpose, and the goods, services or uses it enables.
Rule 3(b)A link, and any other means, to withdraw consent as easily as it was given.
Rule 3(c)How to exercise her rights and how to complain to the Board.
Rule 3(c)Available in English or in a language listed in the Constitution's Eighth Schedule.
Section 5(3)Existing customers get a notice too, as soon as reasonably practicable.
You may keep processing until she withdraws consent.
Section 5(2)
Output of this stage: one notice per purpose or product flow, written from the inventory. Rule 3 applies from 13 May 2027.
Read the full lesson, with every provision it rests on (2 min)
Section 5(1) requires that every request for consent be accompanied or preceded by a notice telling the Data Principal three things: the personal data and the purpose for which it will be processed; how she can exercise her right to withdraw consent under Section 6(4) and her right of grievance redressal under Section 13; and how she can make a complaint to the Board. Section 5(3) requires the option to read the notice in English or in any language listed in the Eighth Schedule to the Constitution.
Rule 3 turns that into a specification. The notice must be "presented and be understandable independently of any other information" the business provides (Rule 3(a)), so a line buried in a long policy does not qualify. It must give, in clear and plain language, an itemised description of the personal data and the specified purpose or purposes, with a specific description of the goods or services being provided (Rule 3(b)). And it must give the link to the website or app, and any other means, through which the Data Principal can withdraw consent as easily as she gave it, exercise her rights, and complain to the Board (Rule 3(c)). Rule 3 applies from 13 May 2027, but there is no reason to write a notice that will need rewriting then.
Section 5(2) deals with the customers you already have. Where consent was given before the Act commenced, give the notice "as soon as it is reasonably practicable", by email, in-app notification or another effective method, and you may continue processing until the Data Principal withdraws consent.
Write one notice per purpose or per product flow rather than one document for the whole business. Use the inventory: each row that relies on consent needs a notice that names its data items and its purpose.
SaralPrivacy's privacy notice generator at https://saralprivacy.com/tools/dpdpa-privacy-notice-generator produces a notice structured to Rule 3 from your inventory.
Days 25 to 40: Consent, legitimate uses, and children
For each purpose in the inventory, record whether you rely on consent under Section 6 or a legitimate use under Section 7, because Section 6(10) puts the burden of proving notice and consent on you. A child's data needs a parent's verifiable consent first under Section 9, with the Rule 10applies from 13 May 2027 checks from 13 May 2027.
Is it a child's personal data?
Section 9(1)If yesFirst obtain the parent's verifiable consent, checking that the person identifying as the parent is an identifiable adult (Rule 10). No tracking, behavioural monitoring or targeted advertising directed at children (Section 9(3)).If no, go to the next test.
Did she voluntarily give this personal data for this specified purpose, without indicating that she does not consent to its use?
Section 7(a)If yesA legitimate use: no consent request is needed, but stay within that purpose.If no, go to the next test.
Is it for employment, or another use Section 7 lists, such as complying with a court order or responding to a medical emergency?
Section 7If yesA legitimate use under that clause.If no, you need consent.
Ask for consent that is free, specific, informed, unconditional and unambiguous, limited to the data the purpose needs, and record it.
Section 6(1)
Output of this stage: for each purpose, the ground relied on; for each consent, when it was given, the notice shown and how it can be withdrawn. Rule 10 applies from 13 May 2027.
Read the full lesson, with every provision it rests on (2 min)
Go back to the inventory and, for each purpose, decide which of two grounds you are relying on.
The first is consent. Section 6(1) requires it to be "free, specific, informed, unconditional and unambiguous with a clear affirmative action", and limits it to the personal data necessary for the specified purpose. Section 6(3) requires the request to be in clear and plain language, available in English or an Eighth Schedule language, and to carry the contact details of the Data Protection Officer or another person authorised to respond to the Data Principal. Section 6(4) gives her the right to withdraw at any time with ease comparable to giving it, and Section 6(6) requires you, within a reasonable time, to stop processing and to cause your Data Processors to stop, unless the law otherwise requires the processing. Section 6(10) puts the burden on you: in any proceeding you must prove that notice was given and consent obtained. So record, for each consent, when it was given, what the notice said, and how it can be withdrawn.
The second ground is a legitimate use under Section 7. The most useful for a small business is Section 7(a): personal data the Data Principal voluntarily provided for a specified purpose, where she has not indicated that she does not consent to its use. The Act's illustration is a pharmacy customer who asks for a receipt by phone message. Section 7(i) covers processing for the purposes of employment and for protecting the employer from loss or liability. Other clauses cover compliance with a court order, medical emergencies, epidemics and disasters. Legitimate use needs no consent request, but it is bounded by the purpose the Data Principal had in mind.
If you process children's personal data, Section 9(1) requires the verifiable consent of the parent or lawful guardian first, Section 9(2) forbids processing likely to cause a detrimental effect on a child's well-being, and Section 9(3) forbids tracking, behavioural monitoring and targeted advertising directed at children. Rule 10, which applies from 13 May 2027, requires due diligence that the person identifying as the parent is an identifiable adult, using identity and age details you already hold, details she provides voluntarily, or a virtual token from an authorised entity such as a Digital Locker service provider.
SaralPrivacy's assessment records the ground for each purpose and flags where a consent record is missing.
Days 40 to 50: Publish a contact person and open a grievance route
Section 8(9) and Rule 9applies from 13 May 2027 require you to publish a contact who can answer questions about your processing, prominently on your website or app and in every reply to a rights request. Section 8(10) requires a grievance route that works, and Section 13(3) makes a person use it before she approaches the Board.
- Publish
Name a contact person and publish her business contact information
Prominently on your website or app, and in every response to a communication exercising a Data Principal's rights.
Rule 9 - Receive
A Data Principal raises a grievance through your route
She has a right to readily available means of grievance redressal.
Section 13(1) - Respond
Respond within the period the Rules prescribe
Section 13(2) - Only then
If still unhappy, she may approach the Board
She must exhaust your grievance route first.
Section 13(3)
Output of this stage: a published contact, a grievance email or form, a register of each grievance from receipt to closure, and a named person on duty. Rule 9 applies from 13 May 2027.
Read the full lesson, with every provision it rests on (2 min)
Two short obligations sit in Section 8, and both are visible to every customer.
Section 8(9) requires a Data Fiduciary to publish the business contact information of its Data Protection Officer, where one is required, or otherwise of "a person who is able to answer on behalf of the Data Fiduciary" the questions a Data Principal raises about the processing of her personal data. Rule 9 says where: prominently on the website or app, and in every response to a communication in which a Data Principal exercises her rights. Rule 9 applies from 13 May 2027. A small business does not need a Data Protection Officer unless it is notified as a Significant Data Fiduciary (module 4); it does need a named person and a working address.
Section 8(10) requires "an effective mechanism to redress the grievances of Data Principals". Section 13(1) states the same thing from the Data Principal's side as a right to readily available means of grievance redressal, and Section 13(2) requires a response within the period the Rules prescribe. Section 13(3) is the part that protects you: a Data Principal must exhaust your grievance route before approaching the Board. A route that works is your first and best line, because a matter that is resolved there never becomes a complaint.
The mechanism can be simple. A dedicated email address or form, a register that logs the date received, the request, the person handling it and the date closed, and a template reply that names the contact person as Rule 9 requires. Decide who is on duty for it and who covers when they are away. Test it by sending yourself a request and timing the response.
Put the contact and the grievance route in the notice from lesson two, since Section 5(1) requires the notice to explain how rights and grievances are exercised.
SaralPrivacy's assessment checks that the contact person and grievance route are published where Rule 9 and Section 8 require them.
Days 50 to 65: Set retention and erasure
Section 8(7) requires you to erase personal data once consent is withdrawn or the purpose is no longer served, whichever is earlier, unless a law requires you to keep it, and to make your Data Processors erase it too. Rule 8(3)applies from 13 May 2027 also requires you to keep processing logs and related personal data for at least one year.
The erasure trigger.
Consent withdrawn, or when it is reasonable to assume the purpose is no longer served, whichever is earlier.
Section 8(7)Any law that requires you to keep it.
Retention needed to comply with a law in force overrides erasure, as with a bank keeping identity records after an account closes.
Section 8(7)The one-year minimum for logs.
Personal data, associated traffic data and other logs of processing are kept for at least one year from the date of processing, then erased unless another law requires longer.
Rule 8(3)If you are in a class the Rules list: the inactivity period and a warning.
Tell the Data Principal at least forty-eight hours before erasure, so she can log in or make contact and keep her data.
Rule 8(2)Your Data Processors erase what you gave them.
Section 8(7)
Output of this stage: a retention schedule attached to the inventory, and systems and vendor contracts that can actually delete. Rule 8 applies from 13 May 2027.
Read the full lesson, with every provision it rests on (2 min)
Section 8(7) is the retention rule. Unless retention is necessary to comply with a law in force, a Data Fiduciary must erase personal data when the Data Principal withdraws consent, or "as soon as it is reasonable to assume that the specified purpose is no longer being served", whichever is earlier, and must cause its Data Processors to erase what it gave them. The Act's illustrations are a used-car listing that is erased once the sale concludes, and a closed bank account whose records are kept because banking law requires it.
Section 8(8) adds a deeming rule: the purpose is treated as no longer served if the Data Principal neither approaches you for the purpose nor exercises any of her rights for a prescribed period. Rule 8(1) sets those periods for the classes of Data Fiduciary listed in the Rules; if you are not in a listed class, the general test in Section 8(7) governs. Rule 8(2) requires, for those classes, at least forty-eight hours' notice to the Data Principal before erasure so she can log in or make contact and keep her account.
Rule 8(3) runs the other way and applies to every Data Fiduciary. Personal data, associated traffic data and other logs of processing must be retained for a minimum of one year from the date of processing, for the purposes the Rules specify, and erased after that unless another law requires longer. The Rule's own illustration is an e-book purchase: the order, payment and delivery records stay for a year even if the buyer deletes her account. Rule 8 applies from 13 May 2027.
Build the schedule from the inventory. For each purpose, write down the trigger for erasure (consent withdrawn, order fulfilled, employee left), the legal hold that overrides it (tax, labour, sectoral rules), and the one-year log retention under Rule 8(3). Then check that each system can actually delete, and that each vendor contract obliges the Data Processor to delete on your instruction.
SaralPrivacy's assessment produces a retention schedule against this inventory.
Days 65 to 85: Security safeguards and a breach playbook
Section 8(5) requires reasonable security safeguards, and Rule 6applies from 13 May 2027 sets the minimum: encryption or masking, access control, logs and monitoring, backups, and a safeguards clause in each Data Processor contract. If a breach happens, Rule 7applies from 13 May 2027 requires notice to each affected person without delay and detailed information to the Board within seventy-two hours.
- Before any breach
Put the minimum safeguards in place
Encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review; backups; logs kept for one year; and a safeguards clause in every Data Processor contract.
Rule 6(1) - On becoming aware
Tell each affected Data Principal, without delay
What happened, the likely consequences for her, what you are doing, what she can do to protect herself, and whom to contact; through her user account or registered contact.
Rule 7(1) - Without delay
Tell the Board: a description of the breach
Its nature, extent, timing, location and likely impact.
Rule 7(2)(a) - Within 72 hours
Send the Board the detailed information
Updated details, the facts and reasons, mitigation, any findings on who caused it, steps to prevent recurrence, and a report of the notices sent to Data Principals. The Board may allow longer on a written request.
Rule 7(2)(b)
Output of this stage: the Rule 6 safeguards in place, and a written playbook naming who declares a breach, who drafts both notices and who speaks to the Board. Rules 6 and 7 apply from 13 May 2027.
Read the full lesson, with every provision it rests on (2 min)
Section 8(5) requires a Data Fiduciary to protect personal data in its possession or under its control, including processing done on its behalf by a Data Processor, "by taking reasonable security safeguards to prevent personal data breach". Section 8(2) requires any Data Processor to be engaged under a valid contract, and Section 8(1) keeps you responsible for what that Data Processor does with your personal data.
Rule 6(1) lists the minimum safeguards: securing personal data through encryption, obfuscation, masking or virtual tokens; controlling access to the computer resources involved; keeping logs and monitoring so unauthorised access can be detected, investigated and remedied; backups or other measures so processing can continue after a loss; retaining those logs and the personal data for one year for that purpose; a provision in the Data Processor contract requiring safeguards; and technical and organisational measures to make all of it stick. Rule 6 applies from 13 May 2027. For a small business this is a checklist: strong passwords and two-factor login, role-based access, encrypted backups, audit logs turned on, and a clause in every vendor agreement.
Section 8(6) requires that, in the event of a personal data breach, you intimate both the Board and each affected Data Principal. Rule 7 gives the form and the clock. Rule 7(1): tell each affected Data Principal, without delay and in plain language, through her account or a registered mode of contact, what happened, what it likely means for her, what you are doing about it, what she can do to protect herself, and whom to contact. Rule 7(2): tell the Board without delay a description of the breach, and within seventy-two hours of becoming aware of it, or a longer period the Board allows on written request, send the detailed facts, causes, mitigation, findings on who caused it, steps to prevent recurrence, and a report of the intimations sent to Data Principals. Rule 7 applies from 13 May 2027.
Write the playbook before it is needed: who declares a breach, who drafts the two notices, where the templates live, and who speaks to the Board.
SaralPrivacy's assessment includes breach-readiness questions and template notices for Rule 7.
Day 90: Check your readiness
By day ninety you should hold six outputs, each resting on a provision: the inventory, the notices, a recorded ground per purpose, a published contact and grievance route, a retention schedule, and safeguards with a breach playbook. What remains is to test them against the whole law and keep them current as the Rules come into force.
A recorded ground for every purpose.
Consent under Section 6 or a legitimate use under Section 7, with parental consent under Section 9 and Rule 10 where a child is involved.
Section 6A published contact and a working grievance route.
As Section 8(9), Section 8(10) and Section 13 require.
Rule 9Safeguards and a breach playbook.
The Rule 6 minimum, and the Rule 7 notices to Data Principals and the Board.
Rule 6
Every rule named here applies from 13 May 2027. Check each output against the whole of the law, not lesson by lesson.
Read the full lesson, with every provision it rests on (2 min)
If you have followed the sequence, you now have an inventory that shows where the Act applies (Section 3), a notice for each consent-based purpose written to Rule 3applies from 13 May 2027 and Section 5, a recorded ground for every purpose under Section 6 or Section 7 with parental consent handled under Section 9 and Rule 10applies from 13 May 2027 where it arises, a published contact person and a grievance route that satisfy Section 8, Rule 9applies from 13 May 2027 and Section 13, a retention schedule built on Section 8(7) and Rule 8applies from 13 May 2027, and safeguards and a breach playbook that answer Section 8(5), Rule 6applies from 13 May 2027 and Rule 7applies from 13 May 2027.
What remains is to test it against the whole of the law rather than lesson by lesson, and to keep it current as the Rules come into force through 13 May 2027 and as your business changes. That is the point at which this course hands over.
SaralPrivacy's readiness assessment at https://saralprivacy.com/assessment takes the inventory you built in these ninety days, scores it against the Act and the Rules provision by provision, and returns a prioritised list of what to fix next. The privacy notice generator at https://saralprivacy.com/tools/dpdpa-privacy-notice-generator turns the inventory into notices. Both are built on the same provision text that this course cites, so a finding in the assessment links back to the section or rule that requires it.
This is the last module. If a term is unfamiliar, the glossary and the provision pages on this site carry the gazette text and the plain-language notes; if a step above is unclear, the module that teaches it is linked from each citation.