Skip to main content
A Rigorous Business Assessment & Advisory Platform for High-Growth Markets

Data Privacy Compliance Guide 2026

DPDP Act 2023 Compliance
for Small Businesses — Complete Checklist

India's Digital Personal Data Protection Act 2023 applies to every business that processes personal data. Penalties reach ₹250 crore. This guide gives you the complete compliance checklist and a 5-step implementation plan.

₹250 Cr

Max penalty for security breach

72 hrs

Breach notification window

Every

Indian business processes personal data

Need Expert Help?

Talk to an IBEAN specialist about applying these insights to your business — personalised advisory, not just information.

WhatsApp Us

Direct line to our advisory team

Fixed-fee diagnostic first. No commitment required.

The Law Explained

What Is the DPDP Act 2023 — and Does It Apply to You?

The Digital Personal Data Protection Act 2023 is India's first comprehensive data protection law. It was passed by Parliament in August 2023 and is being implemented in phases. The Act applies to any entity that processes personal data of individuals in India — regardless of size, sector, or turnover.

If your business has customer records, employee data, vendor contact details, or website analytics — you process personal data, and the DPDP Act applies to you.

Common Misconception

Many Indian SMEs believe data protection laws only apply to large tech companies or businesses with customer portals. The DPDP Act applies to any business that collects personal data — including a standalone shop with a WhatsApp contact list, a manufacturer with an HR database, or a service firm with client email records.

Penalty Structure

DPDP Act 2023 — Penalty Schedule

Penalties are per violation and multiply across incidents

ViolationMaximum Penalty
Failure to implement adequate security safeguards (resulting in breach)Up to ₹250 crore
Failure to notify Data Protection Board of a data breachUp to ₹200 crore
Non-compliance with obligations related to children's dataUp to ₹200 crore
Failure to respond to Data Protection Board's directionsUp to ₹150 crore
Breach of any other provision of the ActUp to ₹50 crore
Repeated non-compliancePenalties multiply per incident

Compliance Checklist

DPDP Act 2023 — Complete Compliance Checklist for Small Businesses

25 compliance requirements across 7 categories. "Required" items are mandatory obligations for most Data Fiduciaries under the current provisions.

Consent

Obtain free, informed, specific, and unambiguous consent before collecting personal data

Required

Consent request is separate from other terms — not buried in T&C

Required

Provide an easy mechanism for users to withdraw consent at any time

Required

Keep records of consent — who consented, when, and for what purpose

Required

Notice

Privacy notice updated to describe: what data is collected, why, how long it is kept, and who it is shared with

Required

Notice provided in language the data principal (person) understands

Required

Contact details of Data Protection Officer (if applicable) or grievance officer in notice

Required

Data Security

Reasonable security safeguards implemented — encryption at rest and in transit

Required

Access controls — personal data accessible only to employees who need it

Required

Audit logs maintained for access to personal data

Required

Vendor/processor agreements updated to include data security requirements

Required

Data Rights

Process to respond to data access requests (individuals requesting their own data) within 48 hours

Required

Process to respond to data correction requests

Required

Process to respond to data erasure requests ("right to be forgotten")

Required

Grievance redressal mechanism in place with a named contact

Required

Data Breach Notification

Incident response plan covers personal data breaches specifically

Required

Notification to CERT-In / Data Protection Board within 72 hours of breach discovery

Required

Notification to affected data principals (individuals) in the event of a significant breach

Required

Breach register maintained documenting all incidents and response actions

Required

Data Retention & Deletion

Retention policy defined — data not kept longer than necessary for the stated purpose

Required

Deletion process in place — personal data erased when purpose is fulfilled or consent withdrawn

Required

Retention schedule documented and reviewed annually

Cross-Border Data Transfers

Identify if personal data is transferred outside India (e.g., cloud providers, SaaS tools, analytics)

Required

Ensure transfers comply with permitted country list (to be notified by Government)

Data processing agreements with international processors include DPDP Act obligations

Implementation Guide

5-Step DPDP Act Compliance Plan for Indian SMEs

01

Week 1–2

Data Mapping

Create a personal data inventory. For every category of personal data: What data? Why collected? Where stored? Who has access? How long kept? Who is it shared with? This map is the foundation of everything else.

02

Week 3–4

Consent Audit

Review every data collection point — website forms, app registration, physical intake forms, email marketing lists, employment contracts. Ensure DPDP-compliant consent is obtained at each point. Update forms and mechanisms where they fall short.

03

Month 2

Privacy Notice Update

Rewrite your privacy policy and any data notices to meet DPDP Act requirements. Describe: what data is collected, purpose, retention period, sharing with third parties, individual rights (access, correction, erasure), and grievance officer contact details.

04

Month 2

Breach Response Protocol

Define and document your incident response procedure for personal data breaches. Who is notified internally? Who contacts CERT-In / the Data Protection Board? Who contacts affected individuals? The 72-hour clock starts from breach discovery — not breach investigation.

05

Month 3

Vendor & Security Controls

Update contracts with all vendors who process personal data on your behalf (cloud providers, HR software, CRM, accounting tools, marketing platforms). Add DPDP Act obligations. Implement security safeguards: encryption, MFA, access logs, regular security reviews.

Frequently Asked Questions

DPDP Act 2023 — Common Questions from Indian SMEs

Frequently Asked Questions

DPDP Act 2023 — Common Questions from Indian SMEs

7 Questions
help_outline

Additional questions? Contact the advisory team

Is Your Business DPDP Act Compliant?

IBEAN's Cybersecurity & DPDP Readiness Assessment maps your current compliance posture — consent mechanisms, security safeguards, breach response, and data rights processes — and builds the gap closure plan.