New user? Start your first legal consultation for just ₹99. Get started →
Startup Services

DPDP Act Compliance for Startups and Small Businesses: What Delhi NCR Founders Need to Know Before 2027

7 min read
DPDP Act Compliance for Startups and Small Businesses: What Delhi NCR Founders Need to Know Before 2027

If your business collects names, phone numbers, emails, or any other personal details from customers, through a website form, a WhatsApp enquiry, an app sign-up, or even a spreadsheet, India's data protection law applies to you. It isn't limited to large technology companies, and the compliance clock has already started.

This piece explains who is covered, what the law actually requires, the dates that matter, and where small businesses most often get it wrong.

The Law in Brief

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first dedicated data protection statute. It became operational through the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, which set out the detailed mechanics: how notice must be given, how consent is recorded, how breaches are reported, and how the new regulator, the Data Protection Board of India, functions.

The Act uses its own vocabulary, and it helps to know three terms:

  • Data Principal: the individual whose personal data is being collected (your customer, user, or employee).
  • Data Fiduciary: the business or person that decides why and how that data is processed. If you run a business that collects customer details, this is you.
  • Data Processor: a third party that handles data on your behalf, such as a cloud provider, CRM, or payment tool.

A key point many small businesses miss: the Act places responsibility on the Data Fiduciary even when a vendor does the actual processing. Outsourcing your CRM does not outsource your liability.

The Dates That Matter

The Rules phase in over 18 months rather than taking effect all at once:

  • 13 November 2025: the Rules were notified, and the provisions setting up the Data Protection Board took effect.
  • 13 November 2026: the framework for registered "Consent Managers" (platforms that help individuals manage consent) becomes operational.
  • 13 May 2027: the core obligations on businesses become enforceable, including notice, consent, security safeguards, breach reporting, individual rights, and retention limits.

One caution: in January 2026, the Ministry of Electronics and Information Technology held stakeholder consultations proposing to shorten the compliance window for certain larger data processors. As of the latest information available, that proposal had not been confirmed by gazette notification, so 13 May 2027 remains the operative date for businesses generally. Because this is an area where dates can move, confirm the current position with a lawyer before you build a compliance plan around a specific deadline.

What the Law Actually Requires

1. A clear notice before you collect data. When you ask for personal data, you must tell the person, in plain language, what data you are collecting and why, how they can withdraw consent or exercise their rights, and how to complain to the Board. A buried clause in a long privacy policy is not the standard the law is aiming for.

2. Consent that is free, specific, informed, and withdrawable. Pre-ticked boxes, bundled consents ("agree to everything or you can't use the service"), and consent that is difficult to withdraw all create risk. Withdrawing consent should be as easy as giving it.

3. Using data only for the purpose you stated. Data collected for a consultation booking cannot quietly be repurposed for unrelated marketing without a proper basis. The Act does allow processing without consent in limited "legitimate use" situations, such as responding to a medical emergency or complying with a legal obligation, but these are narrow and should not be treated as a loophole.

4. Reasonable security safeguards. You are expected to protect the data you hold, including access controls, encryption where appropriate, and sensible vendor practices.

5. Breach reporting. If a personal data breach occurs, you must notify both the Data Protection Board and the affected individuals. The Rules require a detailed report to the Board, with an initial intimation made promptly and a fuller report to follow within a prescribed period.

6. Respecting individual rights. People can ask what data you hold about them, request correction or erasure, and raise grievances. You need a working process and a named point of contact to handle these.

7. Extra care for children's data. For anyone under 18, the Act requires verifiable parental consent, and bans tracking, behavioural monitoring, and targeted advertising aimed at children. Businesses in education, gaming, and consumer apps need to pay particular attention here.

8. Deleting data when it is no longer needed. Holding personal data indefinitely "just in case" is itself a compliance problem.

The Penalties Are Not Symbolic

The Act sets maximum penalties by type of breach. Failure to maintain reasonable security safeguards can attract a penalty of up to ₹250 crore, and failures such as not notifying a breach, or breaching the children's data obligations, carry maximums of up to ₹200 crore. These are ceilings, not fixed fines, and the Board is expected to weigh factors such as the nature and gravity of the breach, the steps taken to mitigate it, and the conduct of the business. But the scale makes clear that this is a serious regime, and the Board has been functioning since late 2025, so complaints can already be filed with it.

Does This Apply to a Small Business or Early-Stage Startup?

Yes, in principle. The Act applies based on whether you process digital personal data, not on the size of your company. The Central Government has the power to notify relaxations for certain classes of data fiduciaries, including startups, but you should not assume a blanket exemption exists for your business. Planning as though the full obligations apply is the safer course.

Where Small Businesses Commonly Go Wrong

  • Copying a privacy policy from another website. It rarely matches what your business actually does with data, and an inaccurate policy is worse than a basic accurate one.
  • Collecting more data than needed. Asking for address, date of birth, or ID details when the service doesn't require them increases both risk and obligation.
  • No record of consent. If you cannot show when and how someone agreed, you will struggle to defend a complaint.
  • Informal data sharing. Customer lists shared over WhatsApp groups, personal email accounts, or shared spreadsheets are a frequent source of breaches.
  • Vendor blind spots. Not knowing what your CRM, ad platform, or payment tools do with the data you pass them.
  • No breach plan. When a breach happens, the first 72 hours matter, and that is a bad time to start deciding who is responsible for what.

A Practical Starting Point

Without turning this into a full compliance programme, most small businesses can begin with a few steps: map what personal data you collect and where it is stored; remove data fields you don't need; rewrite your consent language and privacy notice in plain terms; list your vendors and what they access; decide who internally handles data requests and breaches; and set a retention period after which old data is deleted.

None of this requires a large budget, but the decisions involved, such as what your lawful basis is, how to word consent, and what your vendor contracts should say, are legal judgments that go wrong when guessed at.

Get Clarity Before the Deadline

Legal7 connects you instantly with Bar Council verified lawyers experienced in startup and corporate compliance matters, starting at just ₹99, so you can talk through how the DPDP Act applies to your specific business before it becomes a problem.

[ Talk Now — ₹99 ]

Frequently Asked Questions

Does the DPDP Act apply to offline or paper records? The Act covers personal data collected in digital form, and also data collected offline that is later digitised. A paper form that you type into a spreadsheet is within scope once digitised.

Do we need a Data Protection Officer? Appointing a Data Protection Officer is a requirement for "Significant Data Fiduciaries", a category the Central Government designates based on factors such as the volume and sensitivity of data processed. Most small businesses will not be designated, but every business should still have a clear internal point of contact for data requests and complaints.

Can we keep using our existing customer database? Existing data does not disappear from the law's reach. For data collected before the obligations take effect, you will generally need to give the required notice and be able to justify continued processing, so this is worth reviewing before May 2027 rather than after.

What should we do first if we suspect a data breach? Contain the incident, preserve records of what happened, and get legal advice quickly, because notification obligations to the Board and to affected individuals are time-sensitive.

This article is for general information only and is not legal advice. Laws and deadlines may change; consult a qualified advocate for guidance on your specific situation.