Skip to main content

Sources last verified on 20 August 2026. Methodology

DPDP compliance checklist for small businesses: 10 steps (2026)

Compliance

By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 3 min read

The short answer

Work ten steps before the main obligations commence on the computed date of 13 May 2027: check the Act applies to you under section 3, map what personal data you hold and why, assign each purpose a ground under section 4 (consent or a section 7 legitimate use), build the Rule 3 notice, make consent meet section 6, set security safeguards per Rule 6, prepare the Rule 7 breach workflow, set retention and erasure under section 8(7) and Rule 8, stand up rights handling and grievance redressal within the ninety day ceiling, and put contracts behind every vendor that touches personal data under section 8(2). There is no small business exemption in the Act's application section, though section 17(3) lets the Central Government notify certain classes including startups as exempt from specified provisions only.

Small businesses ask the DPDP question differently: not "what does the law say" but "what is the shortest honest list of things to do". Here is that list, ten steps, each cited to the provision it answers. Print this page if you want it on paper; every step keeps its citation.

First, the threshold facts. There is no small business exemption in the Act's application section: section 3 applies the framework to digital personal data with no organisation size test. Section 17(3) does let the Central Government, having regard to the volume and nature of personal data processed, notify certain classes of Data Fiduciaries, including startups, as exempt from specified provisions only: the section 5 notice, subsections (3) and (7) of section 8, and sections 10 and 11. Consent, security safeguards and breach intimation stay in force even for an exempted class, so watch for notifications, but do not plan on one. The main obligations sit in the commencement group computed to 13 May 2027, interpretation until officially confirmed, which makes this a preparation window.

The ten steps

  1. Confirm the Act applies to you. If you process digital personal data in India, or process abroad in connection with offering goods or services to people in India, it does (section 3). The applicability checker walks the criteria in two minutes.

  2. Map your personal data. List every place personal data lives: customer records, orders, support tickets, marketing lists, employee files, vendor tools. For each, note what data, why you hold it, and where it flows. Every later step depends on this map.

  3. Assign each purpose a ground. Section 4 allows exactly two: consent, or a certain legitimate use under section 7 (employment, voluntary provision for a specified purpose, medical emergencies and the other listed uses). Tag every purpose in your map with its ground; anything untagged has to stop or get consent.

  4. Build the notice. Rule 3 requires a standalone notice in clear and plain language that itemises the personal data, states each purpose and the goods or services it enables, and gives working links to withdraw consent, exercise rights and complain to the Board. The privacy notice generator assembles a starting draft from your inputs.

  5. Make consent real. Where consent is your ground, section 6 sets the standard: free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and as easy to withdraw as it was to give. Prefilled boxes and bundled agreements do not survive that sentence.

  6. Set security safeguards. Rule 6 lists minimum measures for protecting personal data, including techniques of the encryption or masking class, access control, logs and backups. For a small business this is mostly configuration discipline in the tools you already use, written down.

  7. Prepare for a breach before one happens. Rule 7 starts two clocks at the moment of awareness: intimation to every affected person and to the Board without delay, and detailed Board information within seventy two hours. Name an owner, keep the two intimation drafts ready, and rehearse once. The breach response playbook is the working version of this step.

  8. Decide retention and erasure. Section 8(7) requires erasure when consent is withdrawn or the purpose is no longer served, unless a law requires retention. Rule 8 adds timed erasure mechanics for the large platform classes listed in its Third Schedule, which most small businesses will not meet, and Rule 8(3) requires personal data and logs of processing to be retained for at least one year before erasure. Give every data category in your map an end of life.

  9. Stand up rights and grievances. Individuals get access, correction, erasure, nomination and grievance redressal. Rule 14 caps your published grievance response period at ninety days. A shared inbox with an owner and a tracked deadline is a legitimate small business implementation.

  10. Put contracts behind your vendors. Section 8(2) permits engaging a Data Processor only under a valid contract, and section 8 keeps you responsible for what they do with your data. List every tool that touches personal data and check its contract covers instructions, breach support and erasure. The processor contract checklist covers the clauses.

Where to go from here

Steps 2 through 10 are exactly what the company compliance plan tool generates as a tracked, exportable action list ordered for your role, with the official source behind every action. Run it after the applicability check, and revisit the plan when the Central Government notifies anything under section 17(3).

Downloadable starter templatesDoes the DPDP Act apply to startups?

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 3, p. 3. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 3: the Act applies to digital personal data processed within India and to processing abroad connected with offering goods or services to Data Principals in India, with no organisation size threshold.
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 4, p. 4. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 4: processing only for a lawful purpose, on consent or a certain legitimate use under section 7.
  3. [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 6, p. 5. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 6: consent must be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and as easy to withdraw as to give.
  4. [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 8: the Data Fiduciary's general obligations, including engaging processors only under a valid contract (8(2)), security safeguards (8(5)), breach intimation (8(6)) and erasure (8(7)).
  5. [5]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 17(3), p. 12. Published 11 August 2023. Official source ↗ · Official requirement · Verified 21 August 2026Section 17(3): the Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or classes of Data Fiduciaries, including startups, as exempt from specified provisions.
  6. [6]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 3, p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026Rule 3: the notice must stand alone, use clear and plain language, itemise the personal data, state the purposes and goods or services, and give working paths to withdraw consent, exercise rights and complain to the Board.
  7. [7]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 6, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026Rule 6: reasonable security safeguards, including at minimum the measures it lists such as encryption or masking class techniques, access control, logs and backups.
  8. [8]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 7, p. 26. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026Rule 7: breach intimation to every affected Data Principal and to the Board, with detailed Board information within seventy two hours of awareness.
  9. [9]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 8, p. 27. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026Rule 8: timed erasure clocks for the classes of Data Fiduciaries specified in the Third Schedule, with at least forty eight hours notice to the Data Principal before erasure, and a minimum one year retention of personal data and logs of processing under Rule 8(3).
  10. [10]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 14, p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026Rule 14: rights handling and grievance redressal, with the published response period not exceeding ninety days. Rule 14 begins on Gazette page 29 and its response period provision appears on page 30.
  11. [11]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 21 August 2026The checklist obligations sit in the eighteen month commencement groups of G.S.R. 843(E) paragraph (c) and Rule 1(4).
  12. [12]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 21 August 2026The calendar date 13 May 2027 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.

checklistsmall businesscompliancestartups

Share this: