Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

DPDP compliance checklist for small businesses: 10 steps (2026)

Compliance

By · Primary sources verified by dpdprules.orgPublished · Last reviewed 4 min read

How can a small business comply with the DPDP Act?

The short answer

Work 10 steps before the main obligations commence on the computed date of 13 May 2027, interpretation until officially confirmed: check the Act applies to you under section 3, map what personal data you hold and why, assign each purpose a ground under section 4 (consent or a section 7 legitimate use), build the Rule 3 notice, make consent meet section 6, set security safeguards per Rule 6, prepare the Rule 7 breach workflow, set retention and erasure under section 8(7) and Rule 8, stand up rights handling and grievance redressal, where Rule 14(3) names 90 days without stating what they cap, and put a valid contract behind every Data Processor that processes personal data on your behalf, under section 8(2). There is no small business exemption in the Act's application section, though section 17(3), in the group computed to commence 13 May 2027, interpretation until officially confirmed, lets the Central Government notify certain Data Fiduciaries or classes, including startups, to whom section 5, sections 8(3) and 8(7), and sections 10 and 11 shall not apply.

More answered questions →

Summary infographic headed 'Small business DPDP checklist'
The infographic states that section 3 contains no small business exemption, that a small business should confirm applicability and map its personal data, that it should set its lawful ground, notice, consent, security and breach workflow, and that retention, rights handling and vendor contracts come next. A shopfront beside a ticked DPDP checklist carries no further claim.

Small businesses ask the DPDP question differently: not "what does the law say" but "what is the shortest honest list of things to do". Here is that list, 10 steps, each cited to the provision it answers. Print this page if you want it on paper; every step keeps its citation.

First, the threshold facts. There is no small business exemption in the Act's application section: section 3 applies the framework to digital personal data with no organisation size test. Section 17(3) does let the Central Government, having regard to the volume and nature of personal data processed, notify certain classes of Data Fiduciaries, including startups, as exempt from specified provisions only: the section 5 notice, subsections (3) and (7) of section 8, and sections 10 and 11. Consent, security safeguards and breach intimation still apply even for an exempted class, so watch for notifications, but do not plan on one. The main obligations sit in the commencement group computed to 13 May 2027, interpretation until officially confirmed, which makes this a preparation window.

The 10 steps

  1. Confirm the Act applies to you. If you process digital personal data in India, or process abroad in connection with offering goods or services to people in India, it does (section 3). The applicability checker walks the criteria in two minutes.

  2. Map your personal data. List every place personal data lives: customer records, orders, support tickets, marketing lists, employee files, vendor tools. For each, note what data, why you hold it, and where it flows. Every later step depends on this map.

  3. Assign each purpose a ground. Section 4 allows exactly two: consent, or a certain legitimate use under section 7 (employment, voluntary provision for a specified purpose, medical emergencies and the other listed uses). Tag every purpose in your map with its ground; anything untagged has to stop or get consent.

  4. Build the notice. Rule 3 requires a standalone notice in clear and plain language that itemises the personal data, states each purpose and the goods or services it enables, and gives working links to withdraw consent, exercise rights and complain to the Board. The privacy notice generator assembles a starting draft from your inputs.

  5. Make consent real. Where consent is your ground, section 6 sets the standard: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and withdrawable with ease comparable to the ease of giving it. Prefilled boxes and bundled agreements do not survive that sentence.

  6. Set security safeguards. Rule 6 lists minimum measures for protecting personal data, including techniques of the encryption or masking class, access control, logs and backups. For a small business this is mostly configuration discipline in the tools you already use, written down.

  7. Prepare for a breach before one happens. Rule 7 starts 2 clocks at the moment of awareness: intimation to every affected person and to the Board without delay, and detailed Board information within 72 hours. Name an owner, keep the two intimation drafts ready, and rehearse once. The breach response playbook is the working version of this step.

  8. Decide retention and erasure. Section 8(7) requires erasure when consent is withdrawn or the purpose is no longer served, unless a law requires retention. Rule 8 adds timed erasure mechanics for the large platform classes listed in its Third Schedule, which most small businesses will not meet, and Rule 8(3) requires personal data and logs of processing to be retained for at least 1 year before erasure. Give every data category in your map an end of life.

  9. Stand up rights and grievances. Individuals get access, correction, erasure, nomination and grievance redressal. Rule 14(3) names 90 days in a sentence printed with no object for "publish", so what the 90 days caps is not stated on its face; this site reads it as the response period you must publish, which the grievance redressal guide sets out. A shared inbox with an owner and a tracked deadline is a legitimate small business implementation.

  10. Put contracts behind your vendors. Section 8(2) permits engaging a Data Processor only under a valid contract, and section 8 keeps you responsible for what they do with your data. List every tool that touches personal data and check its contract covers instructions, breach support and erasure. The processor contract checklist covers the clauses.

Where to go from here

Steps 2 through 10 are exactly what the company compliance plan tool generates as a tracked, exportable action list ordered for your role, with the official source behind every action. Run it after the applicability check, and revisit the plan when the Central Government notifies anything under section 17(3). If 1 person owns most of this work, the founders and small teams guide sets it out as 1 plan rather than rule by rule firefighting.

If you build software, the startup checklist orders the same duties for a product team spending its runway, and the CTO checklist is the engineering slice: safeguards, retention timers, breach detection and the product surfaces.

Downloadable starter templates →Does the DPDP Act apply to startups? →The startup checklist, in dependency order →The CTO checklist, the engineering slice →

ChecklistSmall businessComplianceStartups

Share this: