DPDP for small business

No legal department? The law still applies to you — and it is more manageable than it sounds.

The DPDP Act has no turnover threshold and no small-business exemption. A clinic with two hundred patients carries the same duties as a bank with two crore customers. The good news is that for an organisation of your size, roughly ten decisions cover most of the real risk — and eight of them cost nothing but an afternoon.

This is educational material written by practitioners who run security and compliance programmes, not by lawyers. It will make you a better-informed client of legal advice — it does not replace it.

Clear the air

Five things we hear that are simply not true.

We are too small for this law.

There is no size threshold. Enforcement is complaint-driven and free for the complainant, so it takes one annoyed customer, parent or resident — and small organisations are easier to investigate, not harder.

We do not really collect data.

Names, phone numbers, addresses, ID photocopies, patient notes, WhatsApp groups, CCTV footage and delivery lists are all personal data. Almost every business collects more than it thinks.

Our data is on paper.

The moment a register is typed into a computer or photographed on a phone, it is digital and it is covered. In 2026 that happens to nearly everything.

Our software vendor handles compliance.

Your vendor is a Data Processor. The duty and the penalty stay with you. What the vendor can give you is a contract and technical controls, if you ask for them.

We will deal with it if we get a notice.

The evidence a Board proceeding asks for — consent records, notice versions, access logs, retention rules — can only be created before the incident. After it, the gap is permanent.

The plan

Ten steps, starting with the one that costs nothing.

Do them in order. Steps one and two alone remove more risk than any product you could buy, because data you no longer hold cannot be leaked, subpoenaed or complained about.

01

One page, every place

Write down each place personal data sits: billing app, Excel, Google Drive, Gmail, WhatsApp, CCTV recorder, the folder of Aadhaar photocopies, the ex-employee's laptop. Half an hour, and it changes the conversation.

02

Delete what you should never have kept

Old customer lists, ID copies you took 'just in case', ex-employee records past their statutory period. Deletion is free, immediate, and removes risk permanently.

03

Stop collecting extras

If you do not need date of birth or an Aadhaar copy to deliver the service, remove the field. Every unnecessary field is a liability you volunteered for.

04

Fix the form

Add a short, honest notice above the submit button: what you take, why, how to ask you to delete it, and who to contact. Two sentences beat two pages nobody reads.

05

Lock the accounts

Individual logins instead of one shared password, multi-factor authentication on email and cloud storage, and staff access limited to what their job needs.

06

Get the WhatsApp problem under control

Member photos, patient reports and resident directories circulating in group chats are the single most common exposure in small organisations. Move them into one controlled system.

07

Ask your vendors for two things

A data processing agreement, and confirmation of where the data is stored. Any serious vendor already has both ready to send.

08

Name a person and publish them

One named contact for privacy grievances, with a working email or phone number on your website and on your forms. It satisfies a duty and it de-escalates complaints before they reach the Board.

09

Write the retention rule down

How long you keep each type of record, and why. Then set a recurring reminder to actually delete.

10

Decide who you call at 2 a.m.

A single page: who declares an incident, who notifies the Board within 72 hours, who tells affected people, who speaks publicly. Print it and put it where it will be found.

By sector

Where your particular risk actually sits.

  • Clinics and diagnostic labs

    Patient names beside test results are the most sensitive combination you can hold, and reports routinely travel over personal WhatsApp accounts. Fix the sharing channel first; it is the single biggest exposure in Indian healthcare of this size.

  • Coaching classes and playschools

    Your students are mostly under 18, which puts you under the strictest part of the Act: verifiable parental consent, no behavioural tracking, no advertising targeted at children. Photographs on social media need consent too.

  • Housing societies and RWAs

    Resident directories, vehicle numbers, staff Aadhaar copies, visitor registers and CCTV footage. Committees change annually and data leaves with the outgoing secretary's phone — write down who holds what before the next handover.

  • Retail, gyms and salons

    Loyalty and billing apps quietly accumulate phone numbers used for promotional messaging that was never consented to. Separate 'service' from 'marketing' at the point of collection and the problem disappears.

Score yourself

Ten statements. Count the ones you could defend today.

  • 01We can list every system and file holding personal data, on demand.
  • 02Our notice is standalone, specific, and readable by a first-time reader.
  • 03Consent is unticked by default and recorded with the exact text shown.
  • 04Withdrawing consent is as easy as giving it, and it reaches our vendors.
  • 05Retention periods exist per data type and deletion actually runs.
  • 06Every processor is covered by a signed data processing agreement.
  • 07Access is least-privilege, with MFA on email and cloud storage.
  • 08We would detect a breach in hours, not from a customer's phone call.
  • 09A grievance contact is published and answered within a defined SLA.
  • 10Someone has rehearsed the 72-hour notification in the last twelve months.

Seven or more and you are in decent shape. Four or fewer and one complaint would be uncomfortable. Either way, the fastest improvements are the first two steps above.

Get help

You should not have to become a privacy expert to run your business.

Tell us what you run and what you collect. We will tell you plainly which of these ten steps you already pass, which two matter most this month, and whether you need us at all. Plenty of small organisations leave that call with a checklist and no invoice.