If your business collects even an email address through a website form, the Digital Personal Data Protection (DPDP) Act, 2023 already applies to you. There is no small-business exemption, no revenue threshold, no employee-count carve-out. Penalties for getting it wrong run into hundreds of crores at the top end. Here is a practical checklist of what a startup or SME actually needs to have in place.
Do you need consent, and what makes it valid?
Yes, you need valid consent before processing anyone's personal data, and "valid" has a specific meaning under the Act: consent must be free, specific, informed, unambiguous, and as easy to withdraw as it was to give. A pre-checked consent box or a buried clause in your terms of service does not meet this bar.
Do you need a third-party consent manager?
No, not by default. The DPDP Act does not require every data fiduciary to route consent through a registered third-party consent manager. Startups and SMEs can request and record consent directly, provided the consent notice itself is clear, in plain language, and available in the languages your users actually need.
What rights do you need to be able to fulfil for users?
Data principals, the individuals whose data you hold, have the right to access their data, correct inaccuracies, request erasure, and nominate someone to act on their behalf. This means your systems, not just your privacy policy, need an actual process for handling these requests within a reasonable time.
What happens if you have a data breach?
You must notify the Data Protection Board of India promptly. Failing to report a breach carries a penalty of up to ₹200 crore, and failing to have had reasonable security safeguards in place to begin with carries the highest exposure under the Act, up to ₹250 crore. These are ceiling figures, not automatic fines, but they signal how seriously the Board is expected to treat security failures.
Do you need agreements with your vendors and processors?
Yes. If you use third-party vendors to process personal data on your behalf (email tools, analytics, payment processors, cloud storage), you need signed Data Processing Agreements with them that reflect your obligations under the Act, since you remain responsible for how your data is handled even when a vendor is doing the actual processing.
What is the compliance timeline?
Obligations are phasing in through 2027 under the DPDP Rules, 2025. Consent notices, security safeguards and breach reporting obligations land first; more involved obligations like formal consent-manager registration and Significant Data Fiduciary duties follow later. Getting the foundational pieces, consent, notices, a breach process, right now positions you well as the later phases take effect. It's one of several foundational legal steps worth sequencing early, alongside priorities like registering your startup's trademark.
Disclaimer: This article is for general information only and is not legal advice. DPDP Rules and phased timelines are still being notified and can change; consult a qualified advocate for your specific compliance programme.
Frequently asked questions
Does the DPDP Act apply to small startups, or only large companies?
It applies to every entity processing personal data of Indian residents, regardless of size, revenue, or employee count. There is no small-business exemption; a 3-person startup collecting email addresses through a website form is a data fiduciary under the Act.
Do I need to hire a third-party consent manager?
No, the DPDP Act does not require every data fiduciary to engage a third-party consent manager. Startups and SMEs can request consent directly and manage consent records internally, as long as the consent itself is free, specific, informed, unambiguous and easy to withdraw.
What are a data principal's rights I need to be able to fulfil?
Data principals (the individuals whose data you hold) have rights to access their data, correct it, have it erased, and nominate someone to exercise these rights on their behalf if they become incapacitated or die. Your systems and processes need to actually be able to fulfil these requests, not just state them in a policy.
What happens if we have a data breach and don't report it?
Failure to notify a data breach to the Data Protection Board of India carries a penalty of up to ₹200 crore. Failure to implement reasonable security safeguards in the first place carries the highest exposure, up to ₹250 crore, though actual penalties are assessed based on the nature and scale of the failure, not automatically at the maximum.
Is there special treatment for children's data?
Yes. Processing a child's personal data carries additional obligations, including verifiable parental consent, and non-compliance with these specific obligations attracts penalties of up to ₹200 crore, separate from the general penalty structure.
How much does DPDP compliance typically cost a small business?
For a startup or SME with basic data processing and no Significant Data Fiduciary obligations, a comprehensive compliance programme (policies, consent flows, vendor agreements, breach process) typically runs from roughly ₹3 lakh to ₹10 lakh, though this varies widely with the complexity of the data you handle.