BorderAstra
← All guides

Guide · DPDP

DPDP, Explained: what it means for SMEs

India now has a comprehensive data protection law, and for the first time it applies to almost every business that touches a customer's name, phone number, or email. The Digital Personal Data Protection Act, 2023 sat dormant for two years while the country waited on the operational detail. That detail arrived in November 2025, when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 and constituted the Data Protection Board of India. The regime is now live, and the clock on compliance is running.

This is a plain-English brief on what the law is, when its deadlines land, and why small and mid-sized businesses in particular cannot afford to treat it as a problem for "the big companies."

What the law actually does

The DPDP Act governs the processing of digital personal data — any information about an identifiable person, held or processed digitally, including data collected on paper and later digitised. If your systems hold names, contact details, online identifiers, or behavioural data, you are a Data Fiduciary under the Act: the entity that decides why and how that data is processed. The individuals whose data you hold are Data Principals, and the Act gives them enforceable rights over it.

In practice, the law asks four things of a business:

The timeline that matters

The Rules use a staggered, roughly 18-month runway. Three dates define it:

Eighteen months sounds generous. For a business without a privacy function, mapping every data flow, rebuilding consent, and standing up breach procedures will consume most of it.

Why "we're too small to matter" is the costly mistake

This is where SMEs get caught. Indian regulation usually comes with size-based relief — turnover floors, user thresholds, small-business carve-outs. The DPDP Act does not. It is built around the individual whose data is processed, not the size of the company processing it. A business collecting even a single customer's email is a Data Fiduciary and must comply.

There is a widely repeated myth that startups are exempt. The Act does contain a provision — Section 17(3) — that lets the government exempt certain classes of data fiduciaries, including recognised startups, from some obligations such as notice and retention limits. But that is a power the government may use, not one it has used. No such notification has been issued. Until one is, planning your compliance around a hypothetical future exemption is a gamble, not a strategy — every startup and small business remains subject to the full Act.

The one genuine relief for smaller players: unless the government designates you a Significant Data Fiduciary (a status reserved for high-volume or high-risk processors), you are not required to appoint a Data Protection Officer or run formal data-protection impact assessments. You do, however, need a published point of contact and a working grievance-redressal mechanism.

The cost of getting it wrong

The penalties are not calibrated to company size, and they are steep. The Schedule to the Act sets fixed-rupee ceilings, assessed per instance:

Two features make this sharper than the numbers first suggest. Penalties are fixed ceilings rather than a percentage of turnover, so there is no "small company, small fine" cushion — a modest business can face a disproportionate number. And they are cumulative: one incident that reveals inadequate safeguards and a missed notification and processing without consent can draw penalties across each category at once. The Board does weigh mitigating factors — self-disclosure, prompt remediation, a documented compliance record — so a real, evidenced compliance programme directly reduces exposure. Orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal.

The bottom line

DPDP is not a big-company problem with a long fuse. It is a whole-market obligation with a hard 2027 deadline, an already-operational regulator, and penalties indifferent to your size. The businesses that come through it cleanly will be the ones that started early — mapping what data they hold, rebuilding consent and notice, tightening security, and documenting the whole effort so that, if the Board ever asks, the answer is on file.

The first step is the cheapest: find out where you actually stand today. Knowing your specific gaps — before enforcement, before a complaint, before a breach — is what turns an abstract fear of ₹250 crore into a concrete, prioritised, and very manageable to-do list.

This brief is general information on the DPDP Act, 2023 and DPDP Rules, 2025, not legal advice. For obligations specific to your business, consult a qualified data-protection practitioner.

Your site

Where does your site stand?

BorderAstra runs 41 automated DPDP readiness checks against your live site — notice, consent, trackers, security, and breach readiness — and shows you exactly where the gaps are. Free, no card, about 30 seconds.

Scan my site →
A readiness & gap tool — not a compliance certificate.