Data Privacy Compliance Guide 2026
DPDP Act 2023 Compliance
for Small Businesses — Complete Checklist
India's Digital Personal Data Protection Act 2023 applies to every business that processes personal data. Penalties reach ₹250 crore. This guide gives you the complete compliance checklist and a 5-step implementation plan.
₹250 Cr
Max penalty for security breach
72 hrs
Breach notification window
Every
Indian business processes personal data
Talk to an IBEAN specialist about applying these insights to your business — personalised advisory, not just information.
WhatsApp Us
Direct line to our advisory team
Fixed-fee diagnostic first. No commitment required.
The Law Explained
What Is the DPDP Act 2023 — and Does It Apply to You?
The Digital Personal Data Protection Act 2023 is India's first comprehensive data protection law. It was passed by Parliament in August 2023 and is being implemented in phases. The Act applies to any entity that processes personal data of individuals in India — regardless of size, sector, or turnover.
If your business has customer records, employee data, vendor contact details, or website analytics — you process personal data, and the DPDP Act applies to you.
Common Misconception
Many Indian SMEs believe data protection laws only apply to large tech companies or businesses with customer portals. The DPDP Act applies to any business that collects personal data — including a standalone shop with a WhatsApp contact list, a manufacturer with an HR database, or a service firm with client email records.
Penalty Structure
DPDP Act 2023 — Penalty Schedule
Penalties are per violation and multiply across incidents
| Violation | Maximum Penalty |
|---|---|
| Failure to implement adequate security safeguards (resulting in breach) | Up to ₹250 crore |
| Failure to notify Data Protection Board of a data breach | Up to ₹200 crore |
| Non-compliance with obligations related to children's data | Up to ₹200 crore |
| Failure to respond to Data Protection Board's directions | Up to ₹150 crore |
| Breach of any other provision of the Act | Up to ₹50 crore |
| Repeated non-compliance | Penalties multiply per incident |
Compliance Checklist
DPDP Act 2023 — Complete Compliance Checklist for Small Businesses
25 compliance requirements across 7 categories. "Required" items are mandatory obligations for most Data Fiduciaries under the current provisions.
Consent
Obtain free, informed, specific, and unambiguous consent before collecting personal data
RequiredConsent request is separate from other terms — not buried in T&C
RequiredProvide an easy mechanism for users to withdraw consent at any time
RequiredKeep records of consent — who consented, when, and for what purpose
RequiredNotice
Privacy notice updated to describe: what data is collected, why, how long it is kept, and who it is shared with
RequiredNotice provided in language the data principal (person) understands
RequiredContact details of Data Protection Officer (if applicable) or grievance officer in notice
RequiredData Security
Reasonable security safeguards implemented — encryption at rest and in transit
RequiredAccess controls — personal data accessible only to employees who need it
RequiredAudit logs maintained for access to personal data
RequiredVendor/processor agreements updated to include data security requirements
RequiredData Rights
Process to respond to data access requests (individuals requesting their own data) within 48 hours
RequiredProcess to respond to data correction requests
RequiredProcess to respond to data erasure requests ("right to be forgotten")
RequiredGrievance redressal mechanism in place with a named contact
RequiredData Breach Notification
Incident response plan covers personal data breaches specifically
RequiredNotification to CERT-In / Data Protection Board within 72 hours of breach discovery
RequiredNotification to affected data principals (individuals) in the event of a significant breach
RequiredBreach register maintained documenting all incidents and response actions
RequiredData Retention & Deletion
Retention policy defined — data not kept longer than necessary for the stated purpose
RequiredDeletion process in place — personal data erased when purpose is fulfilled or consent withdrawn
RequiredRetention schedule documented and reviewed annually
Cross-Border Data Transfers
Identify if personal data is transferred outside India (e.g., cloud providers, SaaS tools, analytics)
RequiredEnsure transfers comply with permitted country list (to be notified by Government)
Data processing agreements with international processors include DPDP Act obligations
Implementation Guide
5-Step DPDP Act Compliance Plan for Indian SMEs
Week 1–2
Data Mapping
Create a personal data inventory. For every category of personal data: What data? Why collected? Where stored? Who has access? How long kept? Who is it shared with? This map is the foundation of everything else.
Week 3–4
Consent Audit
Review every data collection point — website forms, app registration, physical intake forms, email marketing lists, employment contracts. Ensure DPDP-compliant consent is obtained at each point. Update forms and mechanisms where they fall short.
Month 2
Privacy Notice Update
Rewrite your privacy policy and any data notices to meet DPDP Act requirements. Describe: what data is collected, purpose, retention period, sharing with third parties, individual rights (access, correction, erasure), and grievance officer contact details.
Month 2
Breach Response Protocol
Define and document your incident response procedure for personal data breaches. Who is notified internally? Who contacts CERT-In / the Data Protection Board? Who contacts affected individuals? The 72-hour clock starts from breach discovery — not breach investigation.
Month 3
Vendor & Security Controls
Update contracts with all vendors who process personal data on your behalf (cloud providers, HR software, CRM, accounting tools, marketing platforms). Add DPDP Act obligations. Implement security safeguards: encryption, MFA, access logs, regular security reviews.
Frequently Asked Questions
DPDP Act 2023 — Common Questions from Indian SMEs
DPDP Act 2023 — Common Questions from Indian SMEs
Additional questions? Contact the advisory team
Is Your Business DPDP Act Compliant?
IBEAN's Cybersecurity & DPDP Readiness Assessment maps your current compliance posture — consent mechanisms, security safeguards, breach response, and data rights processes — and builds the gap closure plan.