India's Digital Personal Data Protection Act, 2023 was a law without teeth until the DPDP Rules, 2025 were notified on 14 November 2025. Most obligations take effect 18 months later — around May 2027, with consent-manager registration and the Data Protection Board set up earlier. That runway is why "DPDP compliance for small business" is trending now rather than later: the work takes months, not days.
Does it apply to you?
Yes, if you process personal data digitally in India — which includes:
- An online store, booking site or app collecting names, phones, emails, addresses
- A WhatsApp Business account with saved customer contacts and order histories
- A clinic, salon or gym keeping client records in software or a spreadsheet
- A payroll file with employee details
There is no turnover threshold. Only purely personal/household use and certain publicly available data are excluded. Small businesses are not "significant data fiduciaries" (no audits, no DPO), but the core duties apply.
The seven core duties
1. Notice before consent
Before collecting personal data, tell the person what you collect, why, and how they can withdraw consent or complain. The Rules require the notice to be standalone, in plain language, and available in English or any Eighth Schedule language. A privacy policy on your site fulfils this if it is specific — generate a DPDP-aware one with the privacy policy generator.
2. Consent that is free, specific and informed
Pre-ticked boxes and bundled consent are invalid. "By continuing you agree" does not work for marketing messages. For WhatsApp promotions, an explicit opt-in is required — and this dovetails with Meta's own opt-in rules.
3. Purpose limitation and data minimisation
Collect only what the purpose needs. A pincode is needed for delivery; date of birth is not. Delete data when the purpose ends — the Rules set retention triggers (e.g. e-commerce and gaming platforms with 20 lakh+ users must erase data after 3 years of inactivity; smaller businesses should set their own reasonable period and state it).
4. Security safeguards
Encryption or masking, access control, logs retained for a year, backups. For a small business this means: HTTPS, strong unique passwords with 2FA on your Shopify/WordPress/Google accounts, no customer lists in open WhatsApp groups, and a laptop that locks.
5. Breach notification
Notify affected users promptly and the Data Protection Board within 72 hours of becoming aware of a breach — describing what happened, the risk, and what you are doing. Have a template ready.
6. Data principal rights
Provide a way (email is fine) to access, correct and erase data, and to nominate someone. Respond within a reasonable period; the Rules nudge toward 90 days for erasure.
7. Children's data
For users under 18, obtain verifiable parental consent before processing, and never do behavioural tracking or targeted ads. If your product is for adults, say so and do not knowingly onboard minors.
Penalties
Up to ₹250 crore for security failures and ₹200 crore for breach-notification failures per instance. Realistically, the Board will scale penalties to the size and intent of the business — but "we are small" is not a defence.
A practical 8-week plan
| Week | Action |
|---|---|
| 1 | Map what personal data you hold and where (forms, WhatsApp, spreadsheets, software) |
| 2 | Publish a specific privacy notice; add consent checkboxes to forms |
| 3 | Enable 2FA everywhere; remove shared passwords |
| 4 | Set a retention rule and delete stale records |
| 5 | Create a "privacy@" email and a one-page rights-request procedure |
| 6 | Draft a breach-response template |
| 7 | Re-check your WhatsApp marketing opt-ins; stop messaging anyone who hasn't opted in |
| 8 | Update terms and refund policies to reference the privacy notice — the T&C generator and refund policy generator cross-link automatically |
FAQ
I only use WhatsApp and a notebook. Does DPDP apply?
The digital part does — WhatsApp contacts and chats are digital personal data. Paper notebooks are outside the Act unless digitised.
Do I need a Data Protection Officer?
No. DPOs are required only for Significant Data Fiduciaries notified by the government.
Can I still send offers to old customers?
Only with consent for marketing. Transactional messages (order updates, invoices) are permitted under the original purpose.
Do I need consent to store an invoice with a customer's name?
Processing required by law — GST invoicing, tax records — is a legitimate use without separate consent. State it in your notice.