A retailer in Coimbatore runs a busy WhatsApp Business account. Every day, customers send their names, addresses, and phone numbers to place orders. He stores all of it in a spreadsheet. He has no privacy policy on his website. His contact form has no consent checkbox. His delivery partner has access to the same customer database.
He's never thought about data privacy because no one ever asked him to. But from November 2026, they will. India's Digital Personal Data Protection Act (DPDP Act) is no longer a future regulation — it's here, it has hard deadlines, and it applies to his business. It probably applies to yours too.
This isn't about being a large corporation. The Act has no exemption based on turnover or employee count. If you collect, store, or process digital personal data from customers in India, you're covered. Here's what that means and what you need to do.
The core issue in plain English: If a customer gives you their name, phone number, email address, or any other information — even just by filling a form or messaging you on WhatsApp — that's personal data under DPDP. You now have legal obligations around how you collect, store, use, and protect it.
What Is the DPDP Act and Who Does It Apply To?
The Digital Personal Data Protection Act was passed by Parliament in 2023. The rules were finalised in late 2025, and enforcement is now rolling out through 2026 into 2027. Think of it as India's answer to Europe's GDPR — a comprehensive law that gives citizens rights over their personal data and puts obligations on every business that handles it.
"Personal data" under DPDP means anything by which a person can be identified: name, phone number, email address, Aadhaar number, location data, IP address, biometrics, purchase history — the list is broad. If you run a contact form, a loyalty programme, a booking system, a WhatsApp Business account, or a customer database of any kind, you are processing personal data.
The Act calls businesses that collect and use this data Data Fiduciaries. That's you. Your obligations as a Data Fiduciary include obtaining valid consent before collecting data, telling people clearly what you'll use it for, keeping it secure, allowing customers to access or delete their data on request, and notifying authorities quickly if there's a data breach.
No turnover threshold. No employee count minimum. No blanket exemption for small businesses has been notified. If you're operating, you're covered.
The Deadlines You Need to Know
The Act doesn't flip on in a single day. It rolls out in phases, with two key dates every Indian business should have marked:
| Deadline | What Happens | Priority |
|---|---|---|
| 13th Nov, 2026 | Consent Manager Framework becomes operational. Businesses must have lawful consent flows in place for data collection. Active regulatory supervision begins. | Urgent |
| 13th May, 2027 | Full compliance required — consent standards, security safeguards, breach notification timelines, and all data principal rights must be fully operational. | Plan Now |
November 2026 is roughly three months away. Building compliant consent flows, auditing your data, updating your privacy policy, and training your team takes months of work — which is exactly why businesses that haven't started are already behind.
What the Penalties Look Like
These are not token fines. The Data Protection Board of India has real enforcement teeth:
The Board is expected to move from awareness-building into active enforcement mode starting in late 2026. Early complaints and high-profile cases will set the tone. You don't want to be an example.
What You Actually Need to Do — Step by Step
Most small businesses in India need to complete six foundational steps. None of these require a large legal team — they require clarity about what data you hold and a willingness to put proper processes in place.
-
Map every place you collect personal data
Start by listing every touchpoint where you receive customer information — website contact forms, WhatsApp messages, booking systems, loyalty apps, email newsletters, CRM databases, delivery records. You can't protect data you haven't found. This data audit is the foundation of everything else.
-
Update your privacy policy — and actually display it
Your privacy policy must clearly state what data you collect, why you collect it, how long you keep it, who you share it with (delivery partners, payment gateways, marketing tools), and how customers can access or delete their information. It needs to be in plain language — not legalese — and linked visibly on your website and contact forms.
-
Add consent notices to every data collection point
Before collecting personal data, you need a clear, specific consent notice — not a buried checkbox in tiny text. The notice must tell the person what data you're collecting and what you'll do with it, in language they can actually understand. This applies to website forms, WhatsApp opt-ins, app sign-ups, and any other channel where you capture customer information.
-
Create a process for data principal rights
Under DPDP, every customer has the right to access the data you hold on them, correct inaccuracies, withdraw consent, and request deletion. You need a way to handle these requests — a dedicated email address, a response workflow, and a timeline (the Act expects prompt action). This doesn't need to be automated software; a clear internal process is enough to start.
-
Implement data security safeguards
This is where IT matters directly. Reasonable security safeguards include encrypted storage for customer data, access controls so only authorised staff can view sensitive records, regular backups, and a documented process for responding to data breaches. If you're storing customer data on an unencrypted laptop or in a shared Google Sheet with no access restrictions, that's a problem under DPDP — and a security risk regardless of the law.
-
Set up a breach notification process
If your customer data is compromised — through a cyberattack, a stolen device, or a third-party vendor's security failure — you are required to notify the Data Protection Board and affected individuals promptly. Serious breaches have a 72-hour reporting window. You need to know who to contact, what to report, and how to communicate with affected customers before the incident happens, not during the chaos of it.
Where TekyTec comes in: Steps 5 and 6 are where most businesses need technical help. Encrypted storage, access control systems, breach monitoring, and incident response planning are core parts of what we do in managed IT and IT consulting. We can audit your current data security posture and help you close the gaps before the November deadline.
A Word on Third-Party Vendors
One thing that trips businesses up: DPDP doesn't just govern how you handle data directly. It also makes you accountable for how your vendors and partners handle data on your behalf. Your payment gateway, your delivery partner, your email marketing tool, your accounting software — if they're processing personal data of your Indian customers, you need to have data processing agreements in place with them and ensure they meet appropriate security standards.
This isn't optional. If a third-party vendor you've hired suffers a breach that exposes your customer data, you bear regulatory responsibility. Review your vendor agreements now.
Common Questions About DPDP Compliance
Does the DPDP Act apply to small businesses in India?
Yes. It applies to every organisation that processes digital personal data in India — including startups, SMEs, freelancers, and sole proprietors. No exemption based on turnover or employee count has been notified. If you collect names, phone numbers, email addresses, or any personal data from customers, the Act applies to you.
What counts as "personal data" under DPDP?
Any data by which a person can be identified — name, phone number, email, Aadhaar number, location data, biometrics, IP address, and more. If you run a contact form, WhatsApp Business account, loyalty programme, or any booking system, you are almost certainly collecting personal data.
What is the first hard DPDP deadline?
November 13, 2026, when the Consent Manager Framework becomes operational. This marks the end of the "soft enforcement" phase — the Data Protection Board moves into active regulatory supervision from that point. Full compliance with all obligations is required by May 13, 2027.
What are the penalties for not complying?
Up to ₹250 crore for failing to implement security safeguards. Up to ₹200 crore for processing data without valid consent. Up to ₹200 crore for failing to notify a data breach. These are not theoretical maximums — the Board is expected to pursue significant cases in late 2026 to establish enforcement precedent.
Where do I start if I haven't done anything yet?
Start with a data audit — map every place you collect, store, or process customer data. Then update your privacy policy, add consent notices, implement basic security safeguards, and create a process for breach notification. If you need help with the technical side — secure storage, access controls, or breach monitoring — that's exactly what TekyTec handles for businesses across India.