DPDPA compliance is not an enterprise-only exercise — if your SMB collects customer, employee, or vendor personal data in digital form, the Act’s baseline obligations apply to you now, with substantive duties sharpening ahead of 13 May 2027.

TL;DR

  • DPDPA compliance is not just for large enterprises — Section 3 of the Digital Personal Data Protection Act, 2023 applies to any entity processing personal data of individuals in India, including SMBs with 10–500 employees.
  • Consent under Section 6 must be free, specific, informed, unconditional, and unambiguous, backed by clear affirmative action — pre-ticked boxes and bundled consent clauses will not hold up.
  • Breach notification runs on a dual-clock: CERT-In within 6 hours and the Data Protection Board within 72 hours, once obligations under the DPDP Rules, 2025 come into force.
  • Mandatory audits and DPO appointment under Rule 13 apply only to Significant Data Fiduciaries (SDFs) — most SMBs will not be SDFs, but still carry full baseline obligations.
  • Penalties can reach up to ₹250 crore per instance for non-compliance, decided by the Data Protection Board.
  • The practical working deadline for SMBs to be readiness-tested against is 13 May 2027.

What Does DPDPA Compliance Actually Require from an Indian SMB?

DPDPA compliance for a typical Indian SMB comes down to four operational pillars: lawful collection (consent or a permitted legitimate use), secure storage, timely breach response, and the ability to honour Data Principal rights like access, correction, and erasure. Unlike older Indian frameworks, DPDPA does not classify data into legacy “sensitive” categories requiring extra safeguards — every category of personal data carries the same baseline obligations under the Act, which simplifies classification but raises the bar on default hygiene.

For most SMBs, this means treating customer phone numbers, employee Aadhaar copies, and vendor emails with the same rigour, rather than triaging by perceived sensitivity.

Section 6 requires consent to be free, specific, informed, unconditional, and unambiguous, given through clear affirmative action. A notice must accompany or precede the consent request, in English or any language listed in the Eighth Schedule of the Constitution, itemising the personal data collected and the specified purpose.

Consent elementWhat it means in practiceCommon SMB mistake
SpecificOne purpose per consent artefactBundling marketing + service consent into one checkbox
InformedNotice must precede or accompany the requestBurying data use in a 40-page ToS
UnconditionalService can’t be denied for withholding non-essential consentMaking app usage mandatory-gated on marketing opt-in
WithdrawableAs easy to withdraw as to give (Sec 6(4))No self-serve withdrawal mechanism

Where consent isn’t practical — such as employee data — the Act provides legitimate uses under Section 7, including the Employment ground for HR-related processing like payroll and attendance. We cover this in detail for HR teams in DPDPA for Employers: When Is an Employer a Data Fiduciary?.

The consent lifecycle for a typical SMB should look like this:

Fig. 1 SMB consent and lawful-ground flow DPDPA · illustrative
flowchart TD A[SMB collects personal data] --> B[Purpose-specific notice served] B --> C{Lawful ground under DPDPA?} C -->|Consent Sec 6| D[Free, specific, informed consent captured] C -->|Legitimate use Sec 7| E[Employment / statutory / other permitted ground] D --> F[Consent event logged — timestamp, version, purpose] E --> G[Retention SOP applied] F --> G G --> H[Withdrawal & Data Principal rights honoured]

The flowchart above shows two parallel paths through SMB data processing: customer and marketing data typically routes through Section 6 consent with a logged consent event, while employee payroll and statutory filings may proceed under Section 7 legitimate use without a separate consent artefact. Every path terminates at retention and rights handling — meaning an access, correction, or erasure request must be serviceable regardless of which lawful ground was used.

What Are the Breach Notification Timelines SMBs Must Plan For?

DPDPA compliance readiness hinges heavily on breach response, because the timelines are unforgiving. Once a Data Fiduciary becomes aware of a personal data breach, a dual-clock applies:

  1. CERT-In notification within 6 hours of becoming aware of the incident, per existing CERT-In directions on cybersecurity incidents.
  2. Data Protection Board notification within 72 hours, per the intimation requirements set out in the DPDP Rules, 2025, including a description of the breach, data categories affected, and remedial measures taken.

Most SMBs do not have a documented breach playbook today. Building one — with a named owner, a communication template, and a rehearsed escalation path — is one of the highest-leverage DPDPA compliance steps an SMB can take before 2027.

DPDPA breach dual-clock timeline for Indian SMBs

Does Every SMB Need a DPO and Annual Audits?

No. Rule 13’s obligations — appointing a Data Protection Officer, conducting periodic Data Protection Impact Assessments, and independent audits — apply only to entities notified as Significant Data Fiduciaries (SDFs) under Section 10, based on factors like data volume, sensitivity, and risk to Data Principals or India’s sovereignty.

Most SMBs will not be classified as SDFs. But every Data Fiduciary, SDF or not, must still designate a contact person under Section 8(9) to handle grievances and Data Principal requests — a lighter-weight but still mandatory obligation.

This distinction matters a great deal for sector-specific SMBs. NBFCs handling KYC and loan data, for instance, face a higher likelihood of SDF classification given data sensitivity — see our breakdown in DPDP Consent for NBFCs & Wealth: Across the Stack. Hospitals and clinics face similar exposure due to health data volumes; see DPDP Consent for Hospitals: Beyond the HIS. Schools handling children’s data under Section 9 face a distinct consent regime altogether — see Parental Consent & School Admissions Under DPDPA.

What Does a Data Fiduciary Actually Own Under DPDPA?

Every SMB processing personal data is, by definition, a Data Fiduciary under Section 2(i) — the entity that determines the purpose and means of processing. This role carries non-delegable accountability: even when a vendor (a Data Processor) is contracted to handle data, the Data Fiduciary remains responsible for breach notification, consent validity, and security safeguards. For how this classification lands in practice for companies that hold employee data, see If You Have Employees, You’re Already a Data Fiduciary Under DPDPA.

What Data Categories Create the Most SMB Exposure?

Data categoryTypical sourceLawful basisRetention risk
Customer contact & transaction dataCRM, billing systemsConsent (Sec 6)High — often kept indefinitely
Employee recordsHRMS, payrollEmployment (Sec 7)Medium — needs defined retention
Vendor/partner dataContracts, onboarding formsConsent or legitimate useLow-medium
Website/app user dataAnalytics, marketing toolsConsent (Sec 6)High — third-party sharing risk

Why Does Architecture Matter More Than Policy Documents for DPDPA Readiness?

A consent policy PDF does not survive a Data Protection Board inquiry — evidence does. This is where most SMB compliance efforts fall short: they draft a privacy policy but cannot produce a verifiable record of which consent was given, when, for what purpose, and whether it was later withdrawn.

Privigo’s approach centres on architecture rather than paperwork: a sealed PII vault that isolates personal data from operational systems, cryptographically immutable consent records that timestamp and hash every consent event so it cannot be silently altered, and an evidentiary-grade audit trail built to withstand DPB scrutiny — not just internal review. This is the difference between claiming compliance and being able to prove it on demand.

SMB DPDPA Readiness — Governance Table

AreaOwnerStatus
Consent notices & capture flowsProduct/Marketing lead
Employee data & HR processing basisHR/People lead
Vendor/Data Processor contractsLegal/Ops lead
Breach response playbook & dual-clock ownersCompliance/IT lead
Data Principal request handling (access, correction, erasure)Compliance lead
Section 8(9) grievance contact designationFounder/Compliance lead
SDF classification assessmentCompliance/Legal lead
Retention & deletion policyOps/IT lead

Closing

DPDPA compliance for Indian SMBs is achievable without an enterprise-sized legal team, but it requires starting now, not in early 2027. Three concrete next steps:

  1. Audit your consent surfaces — every form, checkout flow, and signup screen that collects personal data.
  2. Assign breach-response ownership — name who calls CERT-In within 6 hours and who files with the DPB within 72.
  3. Move from policy to proof — ensure your consent and audit records are structured to survive a real regulatory inquiry, not just a website footer.

If your team wants a structured walkthrough of how these obligations apply to your specific data flows and vendor relationships, Book a demo with Privigo — we map your consent architecture, processor agreements, and breach posture against the DPDPA in a single 30-minute session.

Frequently Asked Questions

Does DPDPA compliance apply to small businesses, or only large companies?

Yes — DPDPA applies to any Data Fiduciary processing personal data of individuals in India, regardless of size. Section 3 sets no employee or revenue threshold; only the additional Rule 13 obligations (audits, DPO appointment) are limited to Significant Data Fiduciaries.

What is the deadline for DPDPA compliance in India?

No single hard deadline exists yet, but the government has indicated phased commencement with substantive obligations, including breach notification and consent requirements, expected to be in force by 13 May 2027. SMBs should treat this as the working target date.

Do SMBs need to appoint a Data Protection Officer (DPO)?

No — not unless notified as a Significant Data Fiduciary under Section 10 and Rule 13. Most SMBs instead need a designated internal contact person under Section 8(9) who can respond to grievances and Data Principal requests.

What happens if an SMB suffers a data breach under DPDPA?

All Data Fiduciaries, including SMBs, must follow the dual-clock breach notification rule: CERT-In within 6 hours under CERT-In directions, and the Data Protection Board within 72 hours, per the intimation requirements under the DPDP Rules, 2025.

Sources

This article provides operational compliance guidance and does not constitute legal advice. SMBs should obtain institution-specific legal counsel for their particular circumstances and data processing activities.