The DPDP Act 2023 — What a Small Indian Business Actually Has to Do
By Kiran · Founder, Combifer Technologies
General information, not legal advice. The DPDP Act and the rules made under it continue to evolve, and how they apply depends on your specific circumstances. Confirm the current position with a qualified lawyer before relying on this.
Most writing about the Digital Personal Data Protection Act, 2023 is aimed at companies with a legal department. If you run a 20-person business in Bengaluru or Pune, that writing is not for you — and the practical version, the one that tells you what to actually do on Monday morning, is surprisingly hard to find.
Here is that version.
Does it apply to you?
Almost certainly yes. The Act governs digital personal data — any data about an identifiable individual, held in digital form. It does not have a turnover threshold or an employee-count exemption. A ten-person company with a customer list in a spreadsheet is in scope.
Two things commonly surprise people. First, it applies to processing outside India if you are offering goods or services to people in India. Second, employee data is personal data. Your HR records, attendance logs, salary information and the CVs sitting in an inbox are all covered. Most small businesses think about their customers and forget their own staff.
The three roles, and which one you are
The Act names three parties. The Data Principal is the individual the data is about. The Data Fiduciary is whoever decides why and how the data gets processed. The Data Processor handles data on a Fiduciary's behalf.
You are almost certainly a Data Fiduciary for your customer and employee data. Your software vendors are usually Processors acting for you. That distinction matters because the obligations sit mostly with the Fiduciary — you cannot outsource accountability by putting data in someone else's product.
What you are actually obliged to do
Strip away the drafting and it reduces to a handful of duties.
Give notice. Before or at the time you collect personal data, tell the person what you are collecting, why, how they can exercise their rights, and how they can complain. Plain language, not a wall of legalese.
Obtain consent, where consent is your basis. Consent has to be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. Bundling it into a general terms acceptance is the most common failure.
Use it only for the stated purpose. If you collected an email address to send an invoice, that is what it is for.
Keep it accurate, and keep it secure. Reasonable security safeguards are an explicit obligation, and the penalties for failing to take them are the largest in the Act.
Delete it when you are done. When the purpose is served or consent is withdrawn, the data goes — including from your processors.
Publish a way to complain. A named contact, reachable, who responds within a defined time.
Report breaches. If personal data is compromised, both the affected individuals and the Data Protection Board have to be told.
Consent is where most small companies fail
The most common gap is not encryption or retention schedules. It is that consent was never really obtained.
A pre-ticked box is not consent. A line in your terms of service saying "by using this site you agree" is not consent — that is browsewrap, and it fails the "clear affirmative action" test. Neither is a cookie banner whose only button is Accept.
If you are relying on consent, the person must have done something deliberate, for a purpose you named, and be able to withdraw it as easily as they gave it. Withdrawal is the part people forget to build.
Employee data deserves its own pass
Run the exercise for your own team, not just your customers. Where do CVs live after a hire is made? Who can see salary data? How long do you keep records for someone who left two years ago? Is attendance data visible to people who have no business seeing it?
Access control is doing real compliance work here. "Everyone in the company can open the HR folder" is a finding waiting to happen, and it is also just bad practice.
Where to start this week
Do not begin with policy documents. Begin with an inventory.
List every place personal data sits: your CRM, your accounting software, your HR files, the shared drive, that one spreadsheet, the WhatsApp group where someone posted a customer's address. For each, write down what it holds, why you have it, who can see it, and how long you keep it.
That inventory takes an afternoon and it will tell you more about your exposure than any template policy. Most of what follows — a notice, a retention rule, tightening access — is obvious once you can see the list.
Then name a person who owns data requests and complaints, publish how to reach them, and make sure they will actually respond.
None of this requires a legal department. It requires knowing what you hold and being able to say why.