Compliance

The DPDP Act, 2023: what an Indian SMB actually has to do

Not a GDPR summary with the numbers changed. What the Act actually requires, in the order a small business runs into it.

Check your DPDP readiness — free More on the blog

The DPDP Act, 2023: what an Indian SMB actually has to do

Most compliance content written for Indian SMBs about the Digital Personal Data Protection Act, 2023 is a GDPR explainer with the section numbers swapped out. That gets the shape of the law right and almost everything else wrong — the DPDP Act is a shorter, differently structured statute, and a business that prepares for GDPR-in-India ends up compliant with a law that does not exist and exposed under the one that does.

The one word that decides everything: "consent"

The Act turns on a single mechanism. Before you collect personal data — a name, a phone number, an email address, anything that identifies a person — you show a Consent Notice in clear language, in English or any language in the Eighth Schedule, that says what data you are collecting and why. No notice, no lawful collection, regardless of how the data is later used. This is the gap that shows up first in almost every DPDP readiness check: a signup form, a WhatsApp order flow, a delivery address field, none of them carrying a notice at all. It costs nothing to fix and it is the duty most businesses have never heard of.

Three duties that actually get enforced

  • Consent Notice before collection — s.5, read with s.6. Silence here is the single most common finding on a first scan.
  • Reasonable security safeguards to prevent a personal data breach — Schedule, read with s.8(5). "Reasonable" is undefined by design, which means a court decides after the fact, not you in advance.
  • Report a breach to the Data Protection Board and to every affected person — s.8(6). There is no size exemption and no de minimis threshold in the text.

What it actually costs to get wrong

The Schedule to the Act sets a statutory maximum of ₹250 crore per breach of a duty, and it stacks — three separate lapses can each engage their own ceiling. That is a maximum, not an amount owed automatically, and the Data Protection Board sets the real figure per case. But it is the number that turns "we should get to this eventually" into a board-meeting agenda item. A ceiling is not a bill. It is what a single bad quarter can turn into if nobody in the room can say what the business actually does with a customer’s phone number.

Where to actually start

Not with a policy document. Start with an inventory: every place the business collects a name, a phone number, a photo, a health record, or anything else that identifies a real person — a signup form, a delivery address, a CCTV feed, an HR file. For each one, ask whether a notice exists at the point of collection. That single question, answered honestly across every collection point, is most of what a DPDP readiness check is actually scoring. The free check on this site does exactly that in about five minutes, and returns a score with the section number attached to every gap — the same twenty-odd questions a lawyer would ask, without the retainer.

Common questions

Does the DPDP Act apply to small businesses in India?

Yes. The Digital Personal Data Protection Act, 2023 applies to any business that processes digital personal data in India, with no turnover or headcount threshold. A two-person shop taking phone numbers on a signup form is a Data Fiduciary under the Act exactly as a large company is. Some obligations, such as appointing a Data Protection Officer, attach only to Significant Data Fiduciaries, but the core duties of notice, purpose limitation and security apply to everyone.

What is the penalty under the DPDP Act 2023?

The Schedule to the Act sets penalties per violation, with the highest at up to Rs 250 crore for failing to take reasonable security safeguards to prevent a personal data breach. Failure to notify the Data Protection Board and affected users of a breach carries up to Rs 200 crore. These are ceilings, not fixed fines: the Board sets the amount considering the nature, gravity and duration of the breach.

What is a consent notice under the DPDP Act?

A notice given at or before the point you collect personal data, stating what data you are collecting, the specific purpose you will use it for, how the person can withdraw consent, and how they can complain to the Data Protection Board. It must be available in English and the Eighth Schedule languages. In practice this is the duty most Indian small businesses have never implemented, because it applies to ordinary signup forms and order flows, not just formal privacy policies.

Related reading

  • The DPDP Rules, 2025: the dates your business is actually working to — The Act has been law since 2023 and enforced almost nothing. The Rules notified on 13 November 2025 set the clock — one year for consent managers, eighteen months for everything that touches you.
  • The 45-day rule: what it actually costs to pay an MSME supplier late — Section 16 of the MSMED Act does not ask nicely. Compound interest, three times the bank rate, and a clause in your contract cannot waive it.
  • POSH compliance at 10 employees: what actually becomes mandatory — Not a policy you write once and file away. A constituted committee, a real annual report, and a headcount nobody is tracking.

Written by Swaraj Layek

Founder & CEO at VidhiSar. I have watched four companies pay for the same mistake, and it was never the mistake anyone expected. VidhiSar is software, not a law firm: every answer names the section it relies on so you can check it, and anything turning on your specific facts is worth putting to a professional. More about who builds this