DPDP Act Checklist for Small Businesses

Free tool: answer a few questions to get a personalised Digital Personal Data Protection Act checklist and a draft privacy notice for your shop, startup or website.

India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 apply to any business that handles customers' digital personal data, including small shops, freelancers, clinics, coaching centres and online sellers. Most obligations are due to apply from 13 May 2027, so there is time to prepare, but the work is easier if you start early.

This is a self-help tool and not legal advice. The Act, the Rules and any exemptions can change, so confirm details on the MeitY website or with a lawyer.

Step 1: Which of these describe your business?

Step 2: Draft a privacy notice

The Act expects you to tell people, in plain language, what data you collect, why, and how they can exercise their rights. Fill this in to get a starting draft you can adapt.

What the law asks of a small business

These are the main duties for a "Data Fiduciary", which is the Act's term for any business deciding why and how personal data is used. Details are summaries of the Act and Rules as published, so verify them before relying on them.

Small business or not, start here

You do not need expensive software to begin. A one-page list of what data you hold and where, a clear notice on your forms, a named contact for complaints, strong passwords with two-step login on key accounts, and a simple plan for what to do if something leaks will put you ahead of most small firms.

Running a business also means GST. Our GST calculator adds or removes GST from any price.

Frequently asked questions

Does the DPDP Act apply to a small shop or freelancer?

The Act covers anyone who processes digital personal data in India, and there is no general exemption for small businesses. The government can notify exemptions or relaxed rules for some classes such as startups, so check the latest notifications.

When do I need to comply?

Most obligations are due to apply from 13 May 2027, 18 months after the Rules were notified in November 2025. Confirm the dates on the official MeitY site.

Do I need a Data Protection Officer?

A DPO is mandatory only for Significant Data Fiduciaries, a category the government designates based on factors such as the volume and sensitivity of data. Most small businesses will not be one, but you should still name a contact for complaints.

Does paper-only data count?

The Act applies to digital personal data, and to non-digital data that is later digitised. If you keep a paper register and later type it into a computer, it is covered.

Is the generated notice enough to be compliant?

No. It is a starting draft. Compliance also needs safeguards, breach handling, retention and rights processes, and a lawyer should review the notice for your situation.

Last reviewed: October 2026. General information, not legal advice.