Data Privacy Compliance for Indian MSMEs: A DPDPA 2023 Field Guide
Most owner-led firms in India are treating the Digital Personal Data Protection Act as a large-company problem. It is not. The Act has no revenue threshold, no headcount threshold and no exemption for small businesses. If you hold a spreadsheet of customer phone numbers, run a WhatsApp broadcast list, collect resumes through a careers form, or store employee Aadhaar copies in a shared drive, you are a Data Fiduciary and the law already applies to you.
What changed is that the obligations now have a date attached. The DPDP Rules were notified on 13 November 2025, and the substantive rules take effect 18 months later, on 13 May 2027. That sounds distant. It is not, because the work is not a document you write in a weekend. It is a discovery exercise, a set of process changes, and a habit that has to survive staff turnover. Firms that start in the last quarter usually discover they cannot locate half the personal data they hold, which is exactly the problem the law is trying to fix.
This guide is written for a business with somewhere between five and two hundred people, no in-house legal team, and no appetite for a six-figure consulting engagement. It covers what the law actually requires of you, what it does not, what it costs, and the order to do it in.
What the law is, in one section
The DPDP Act 2023 governs digital personal data: any data about an identifiable individual that is either collected digitally or digitised afterwards. Paper records that stay on paper are outside scope. The moment you photograph a form and file the image, they are inside it.
Three roles matter, and mixing them up is the source of most confusion.
| Role | Who it is | Typical MSME example | Who carries the liability |
|---|---|---|---|
| Data Principal | The individual whose data it is | Your customer, employee, job applicant, vendor's staff | Holds rights, not duties |
| Data Fiduciary | Whoever decides why and how the data is processed | You, in almost every case | Everything. Liability does not transfer. |
| Data Processor | A vendor processing on your instructions | Your payroll bureau, CRM, cloud host, calling agency | Answerable to you by contract, not to the Board |
That last row is the one founders miss. If your outsourced telecalling agency leaks a customer list, the Data Protection Board of India does not pursue the agency. It pursues you. The only protection is a written processing contract and evidence that you did some diligence before handing the data over.
The timeline you are actually working against
The Act received assent in August 2023 but sat dormant without rules. The Rules, notified in November 2025, brought it to life on a staged schedule. Some parts are already live, most bite in 2027.
One live proposal is worth tracking rather than acting on. In a January 2026 stakeholder consultation, MeitY floated compressing parts of the timeline, potentially pulling some obligations forward to November 2026 for the largest platforms. Nothing has been gazetted. Treat 13 May 2027 as the operative date and treat any acceleration as a risk that argues for starting earlier, not as a reason to panic.
Does it apply to you? A five-question test
| Question | If yes |
|---|---|
| Do you store any customer, employee or applicant details in digital form? | You are a Data Fiduciary. There is no volume threshold. |
| Do you run marketing to a list you collected yourself? | You need a lawful basis and a record of it for every contact. |
| Do you use third-party tools (CRM, payroll, analytics, cloud storage)? | Each one is a Processor. Each needs a written contract clause. |
| Do you serve customers in India from outside India? | The Act applies extraterritorially to offering goods or services in India. |
| Do you knowingly collect data about anyone under 18? | Verifiable parental consent applies, with narrow carve-outs. |
The only genuinely useful exemption for a small firm is the one nobody mentions: processing for a purely personal or domestic purpose is out of scope, and so is publicly available data that the individual themselves made public. Neither helps a business with a customer database. Section 17(3) of the Act does allow the government to notify classes of low-risk Data Fiduciaries with lighter obligations, and MeitY has signalled sympathy for MSMEs, but no such notification exists today. Planning around a hypothetical exemption is not a plan.
The seven obligations, translated
Strip away the drafting and there are seven things a non-Significant Data Fiduciary has to do. This is the whole job.
| # | Obligation | What it means in practice | Effort for a 30-person firm |
|---|---|---|---|
| 1 | Notice and consent | Tell people, in clear language and in the language of their choice from the Eighth Schedule, exactly what you collect and why. Get an affirmative yes. No pre-ticked boxes. | 2 to 3 weeks |
| 2 | Purpose limitation | Use the data only for the purpose you stated. A support enquiry list is not a marketing list. | Process change, ongoing |
| 3 | Data minimisation and retention | Collect only what the purpose needs. Delete once the purpose is served and no legal retention applies. | 1 to 2 weeks to define, then automate |
| 4 | Reasonable security safeguards | Encryption, access control, logging, backups. Rule 6 is explicit that logs must be retained for at least one year. | 4 to 8 weeks with IT support |
| 5 | Breach notification | Tell affected individuals without delay and file a detailed report with the Board within 72 hours. No materiality threshold. | 1 week to write the plan, then drill it |
| 6 | Data principal rights | Publish a contact point and honour access, correction, erasure and grievance requests within your published timeline. | 1 week plus a mailbox owner |
| 7 | Processor contracts | Written contract with every vendor that touches personal data on your behalf. | 2 to 4 weeks of vendor chasing |
Obligation four is where most small firms are genuinely exposed, and it is rarely a software problem. It is a habit problem: shared logins, customer lists on personal WhatsApp, spreadsheets emailed to a Gmail address, an ex-employee who still has drive access. Fixing that is closer to the process discipline we describe in the documentation hierarchy guide than to anything a compliance vendor sells you.
The consent notice most firms get wrong
A compliant notice under Rule 3 is not your existing privacy policy with a date changed. It has to stand on its own, be understandable independently of anything else, and be itemised. That means listing each category of data and the specific purpose beside it, rather than a paragraph saying you collect information to improve your services.
It also has to carry three things that older Indian privacy policies almost never include: a plain description of how to withdraw consent (and withdrawal must be as easy as giving it), how to exercise rights, and how to complain to the Board. If your current policy ends with a support email address and nothing else, it fails on all three.
One practical trap: bundling. You cannot make consent for marketing a condition of delivering the product. If the customer must tick one box to buy and that box also signs them up for promotional messaging, the consent is not free and does not count.
The 72-hour clock
Breach response is the obligation with the sharpest teeth and the shortest fuse. The Schedule to the Act sets a penalty of up to Rs 250 crore for failing to implement reasonable security safeguards and up to Rs 200 crore for failing to notify. Those are ceilings, and the Board is directed to consider the nature and gravity of the breach and mitigation efforts when fixing the amount, so an MSME is not realistically facing Rs 250 crore. But the notification failure is entirely within your control, and failing at it converts a bad day into an avoidable second offence.
Write the breach plan before you need it, and put one name against it. The plan should fit on a single page: who declares a breach, who contains it, who drafts the individual notice, who files with the Board, and where the log lives. Then run it once as a tabletop exercise. A plan nobody has rehearsed will not survive a Friday evening.
What you can safely ignore
The heaviest obligations in the Rules attach to Significant Data Fiduciaries, a class the government notifies based on data volume, sensitivity and risk to sovereignty. Unless you are a large platform, a major bank or an insurer, you will not be one. Knowing the difference saves real money, because a lot of consulting is sold on obligations that do not apply to you.
| Obligation | Ordinary Data Fiduciary (you) | Significant Data Fiduciary |
|---|---|---|
| Data Protection Officer based in India | Not required. Name a contact person and publish the details. | Mandatory, reporting to the board |
| Annual Data Protection Impact Assessment | Not required | Mandatory, every year |
| Independent data audit | Not required | Mandatory, every year |
| Algorithmic fairness and due diligence review | Not required | Mandatory |
| Third Schedule fixed erasure (3 years of inactivity) | Applies only above the user thresholds (2 crore for e-commerce and social media, 50 lakh for online gaming) | Typically applies |
| Notice, consent, security, breach reporting, rights | All apply in full | All apply in full |
The bottom row is the point. Being small removes the governance overhead. It does not remove the core duties, and the core duties are the ones a customer complaint will be about.
Children's data: the trap for education, health and D2C
If your business knowingly deals with anyone under 18, verifiable parental consent applies, and the Rules contemplate identity verification through means such as a Digital Locker service. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited outright.
There is meaningful relief in the Fourth Schedule. Clinical establishments, healthcare professionals, educational institutions, creches and child transport services can process children's data for narrowly defined purposes, such as delivering health services or monitoring location in the interests of the child's safety, without the full verifiable-consent machinery. That relief is purpose-bound and conditional. A school can track a bus. A school cannot use the same data to sell a holiday programme.
What it actually costs
Compliance vendors quote a wide range because the range is genuinely wide. Here is a realistic Year 1 picture for Indian firms without a dedicated privacy function.
| Firm profile | Consent and cookie tooling | Legal and policy work | Security uplift and internal time | Realistic Year 1 total |
|---|---|---|---|---|
| Under 20 people, under 10,000 records | Free tier to Rs 25,000 | Rs 40,000 to Rs 1.2 lakh (templates plus review) | Mostly internal, 60 to 100 hours | Rs 1 lakh to Rs 3 lakh |
| 20 to 100 people, under 1 lakh records | Rs 60,000 to Rs 2.5 lakh | Rs 1.5 lakh to Rs 4 lakh | Rs 1 lakh to Rs 3 lakh | Rs 4 lakh to Rs 10 lakh |
| 100 to 500 people, multi-system, some customer scale | Rs 2 lakh to Rs 5 lakh | Rs 4 lakh to Rs 8 lakh | Rs 4 lakh to Rs 12 lakh | Rs 10 lakh to Rs 25 lakh |
Two observations. First, the tooling line is the smallest one, which is why buying a consent platform first is almost always the wrong move. Second, the internal-time column is the one that gets underestimated, exactly as it does with process documentation. Data discovery across a messy stack is slow work, and nobody outside the business can do it for you.
Treat the numbers as planning ranges rather than quotes. Pricing in this market moved fast through 2026 and per-record models scale very differently from flat subscriptions once you cross a few lakh records.
A 90-day readiness plan
You do not need 18 months of effort. You need 90 focused days now, then maintenance. This sequence puts the cheap, high-value work first.
| Phase | What you do | Output that proves it |
|---|---|---|
| Days 1-20: Discover | List every place personal data lives: CRM, accounting, HR files, drives, WhatsApp, spreadsheets, forms, the sales team's laptops. Record what, why, who can see it, where it is stored. | A one-page data inventory. This is the single most valuable artefact you will produce. |
| Days 21-35: Decide lawful basis | For each purpose, decide whether you rely on consent or on a legitimate use such as employment. Kill any purpose you cannot justify. | Purpose register with a basis against each row |
| Days 36-50: Fix collection points | Rewrite notices at every point of capture. Unbundle marketing consent. Remove pre-ticked boxes. Add a withdrawal route. | Updated forms, website notice, and a consent log |
| Days 51-65: Close the security gaps | Individual logins, role-based access, encryption at rest for the core stores, offboarding checklist, one year of access logs. | Access matrix plus a documented offboarding SOP |
| Days 66-80: Contract the vendors | Identify every Processor. Get a data processing clause signed. Ask where they store data and for how long. | Vendor register with contract status per row |
| Days 81-90: Stand up the response machinery | Publish the rights and grievance contact, set a response service level, write the one-page breach plan, run one tabletop drill. | Published contact point, breach playbook, drill notes |
| Ongoing | Quarterly review of the inventory and vendor register. Annual refresh of notices. Privacy on the induction checklist. | A standing agenda item in the monthly ops review |
The pattern should look familiar if you have read our work on business process improvement: discover, decide, standardise, then maintain. Privacy compliance behaves like any other operating system component. It fails for the same reason SOPs fail, which is that nobody owns it after the launch push, and it succeeds for the same reason, which is a named owner and a review cadence. The SOP Blueprint sets out that ownership model in detail.
Five mistakes that keep recurring
Buying tooling before doing discovery. A consent platform records consent for the data flows you tell it about. If you have not mapped the flows, you have bought an expensive banner.
Assuming the vendor carries the risk. Liability sits with the Data Fiduciary. A cloud provider's compliance certificate is evidence for your diligence file, not a transfer of your obligation.
Treating an updated privacy policy as the deliverable. The policy is the visible tip. The obligations that get enforced are collection practice, security and breach response.
Ignoring employee and applicant data. HR is usually the messiest personal data estate in a small firm, and it is fully in scope. Old resumes nobody deleted are pure liability with zero business value.
Waiting for a small-business exemption. Section 17(3) permits one. None has been notified. If it arrives it will reduce work you have already done, which is a good outcome. Betting on it is not a strategy.
Key takeaways
- The DPDP Act has no size threshold. If you hold digital personal data in India, you are a Data Fiduciary and the obligations apply to you in full.
- The operative deadline is 13 May 2027, 18 months after the Rules were notified on 13 November 2025. A proposal to compress parts of that timeline has been floated but not gazetted.
- Seven obligations cover the whole job for a non-Significant Data Fiduciary: notice and consent, purpose limitation, minimisation and retention, security, breach reporting, rights handling, and processor contracts.
- Being small exempts you from DPOs, annual DPIAs, audits and algorithmic reviews. It does not exempt you from anything a customer would actually complain about.
- Breach response is the highest-risk obligation: tell affected people without delay, file with the Board within 72 hours, and keep access logs for at least a year.
- Realistic Year 1 cost sits between roughly Rs 1 lakh and Rs 10 lakh for most MSMEs, and the tooling line is the smallest part of it.
- Start with a data inventory, not a purchase. Ninety focused days now beats a panicked quarter in early 2027.
This guide is general information about Indian data protection law as it stands in September 2026, not legal advice. Obligations turn on your specific data flows, and you should take qualified counsel before relying on any of it.
---
This guide is part of the Stratisian Vault. Not sure where your personal data actually lives? Book a strategy call and we will map your data estate and hand you the inventory as a working document.