Skip to content
Kaagazo.
Trendinglegalprivacycompliance

DPDP Rules 2025: the compliance checklist for small websites, apps and WhatsApp businesses

The Digital Personal Data Protection Rules were notified in November 2025 with an 18-month runway. If you collect customer names, phone numbers or addresses — even on WhatsApp — here is what you must have in place before the deadline.

Published 3 September 2026 · 3 min read · Kaagazo editorial

DPDP Rules 2025: the compliance checklist for small websites, apps and WhatsApp businesses — illustration

India's Digital Personal Data Protection Act, 2023 was a law without teeth until the DPDP Rules, 2025 were notified on 14 November 2025. Most obligations take effect 18 months later — around May 2027, with consent-manager registration and the Data Protection Board set up earlier. That runway is why "DPDP compliance for small business" is trending now rather than later: the work takes months, not days.

Does it apply to you?

Yes, if you process personal data digitally in India — which includes:

  • An online store, booking site or app collecting names, phones, emails, addresses
  • A WhatsApp Business account with saved customer contacts and order histories
  • A clinic, salon or gym keeping client records in software or a spreadsheet
  • A payroll file with employee details

There is no turnover threshold. Only purely personal/household use and certain publicly available data are excluded. Small businesses are not "significant data fiduciaries" (no audits, no DPO), but the core duties apply.

The seven core duties

Before collecting personal data, tell the person what you collect, why, and how they can withdraw consent or complain. The Rules require the notice to be standalone, in plain language, and available in English or any Eighth Schedule language. A privacy policy on your site fulfils this if it is specific — generate a DPDP-aware one with the privacy policy generator.

Pre-ticked boxes and bundled consent are invalid. "By continuing you agree" does not work for marketing messages. For WhatsApp promotions, an explicit opt-in is required — and this dovetails with Meta's own opt-in rules.

3. Purpose limitation and data minimisation

Collect only what the purpose needs. A pincode is needed for delivery; date of birth is not. Delete data when the purpose ends — the Rules set retention triggers (e.g. e-commerce and gaming platforms with 20 lakh+ users must erase data after 3 years of inactivity; smaller businesses should set their own reasonable period and state it).

4. Security safeguards

Encryption or masking, access control, logs retained for a year, backups. For a small business this means: HTTPS, strong unique passwords with 2FA on your Shopify/WordPress/Google accounts, no customer lists in open WhatsApp groups, and a laptop that locks.

5. Breach notification

Notify affected users promptly and the Data Protection Board within 72 hours of becoming aware of a breach — describing what happened, the risk, and what you are doing. Have a template ready.

6. Data principal rights

Provide a way (email is fine) to access, correct and erase data, and to nominate someone. Respond within a reasonable period; the Rules nudge toward 90 days for erasure.

7. Children's data

For users under 18, obtain verifiable parental consent before processing, and never do behavioural tracking or targeted ads. If your product is for adults, say so and do not knowingly onboard minors.

Penalties

Up to ₹250 crore for security failures and ₹200 crore for breach-notification failures per instance. Realistically, the Board will scale penalties to the size and intent of the business — but "we are small" is not a defence.

A practical 8-week plan

WeekAction
1Map what personal data you hold and where (forms, WhatsApp, spreadsheets, software)
2Publish a specific privacy notice; add consent checkboxes to forms
3Enable 2FA everywhere; remove shared passwords
4Set a retention rule and delete stale records
5Create a "privacy@" email and a one-page rights-request procedure
6Draft a breach-response template
7Re-check your WhatsApp marketing opt-ins; stop messaging anyone who hasn't opted in
8Update terms and refund policies to reference the privacy notice — the T&C generator and refund policy generator cross-link automatically

FAQ

I only use WhatsApp and a notebook. Does DPDP apply?

The digital part does — WhatsApp contacts and chats are digital personal data. Paper notebooks are outside the Act unless digitised.

Do I need a Data Protection Officer?

No. DPOs are required only for Significant Data Fiduciaries notified by the government.

Can I still send offers to old customers?

Only with consent for marketing. Transactional messages (order updates, invoices) are permitted under the original purpose.

Processing required by law — GST invoicing, tax records — is a legitimate use without separate consent. State it in your notice.

Keep reading