Skip to content
Back to Blog
·10 min read·compliance

Understanding the DPDP Act 2023: A Complete Guide for Small Businesses

What the Digital Personal Data Protection Act requires from your business, the penalties for non-compliance, and practical steps to get compliant.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder, Bachao.AI

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

What Is the DPDP Act?

The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first comprehensive data privacy law. If you run a business in India that collects, stores, or processes digital personal data — this law applies to you.

🎯Key Takeaway
If your business has a website with a contact form, an e-commerce store, a SaaS product, or even a simple app that collects names and email addresses — you are a "Data Fiduciary" under this law and you must comply.

Who Does It Apply To?

The short answer: almost every business.

If your business does this...You are a...DPDP applies?
Collects customer names & emailsData Fiduciary✅ Yes
Runs an e-commerce storeData Fiduciary✅ Yes
Has employee HR recordsData Fiduciary✅ Yes
Processes paymentsData Fiduciary✅ Yes
Uses analytics (Google Analytics etc.)Data Fiduciary✅ Yes
Only handles anonymized data❌ No

The 7 Core Obligations

graph TD A[🏢 Your Business
Data Fiduciary] --> B[📋 1. Lawful Purpose] A --> C[✅ 2. Explicit Consent] A --> D[🔒 3. Security Safeguards] A --> E[🗑️ 4. Data Deletion] A --> F[📢 5. Breach Notification] A --> G[👤 6. Data Principal Rights] A --> H[📝 7. Grievance Redressal] style A fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style D fill:#1e5f3a,stroke:#10B981,color:#e2e8f0 style F fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0

1. Lawful Purpose

You can only collect data for a clear, specific, legitimate purpose. "We might use it later" is not a valid reason.

Users must give free, specific, informed, and unambiguous consent. Pre-ticked checkboxes don't count. Consent buried in terms and conditions doesn't count.

⚠️
WARNING
The DPDP Act requires consent to be as easy to withdraw as it is to give. If you make users click through 5 screens to unsubscribe but only 1 to subscribe, you're non-compliant.

3. Reasonable Security Safeguards

This is deliberately broad — the Act doesn't prescribe specific technologies. But regulators will look at whether you've done due diligence: encryption, access controls, vulnerability assessments, employee training.

🛡️
SECURITY
A VAPT scan is the single most effective way to demonstrate "reasonable security safeguards" to the Data Protection Board. It's documented proof that you've assessed and addressed your vulnerabilities.

4. Data Deletion

Once the purpose for collecting data is fulfilled, you must delete it. Keeping customer data "just in case" is now illegal.

5. Breach Notification

If a breach occurs, you must notify the Data Protection Board without delay. CERT-In additionally mandates notification within 6 hours.

6. Data Principal Rights

Users (called "Data Principals") have the right to:

    1. Access their data
    2. Correct inaccurate data
    3. Erase their data
    4. Nominate someone to act on their behalf

7. Grievance Redressal

You must appoint a Data Protection Officer (or a designated contact for smaller businesses) and provide a working grievance mechanism.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The Penalty Structure

🚨
DANGER
These are not theoretical numbers. The Data Protection Board has been constituted and is actively processing complaints.
₹250 CrFailure to implement security safeguards
₹200 CrFailure to notify Board of breach
₹150 CrNon-compliance with provisions for children's data
₹50 CrFailure to honour data deletion requests
₹10,000Penalty per instance for Data Principals who provide false info

The Board considers the size and nature of the business when determining penalty amounts — but relying on leniency is not a compliance strategy.

Practical Compliance Roadmap

Here's a 4-step plan any SMB can follow:

Step 1: Data Audit

Map every piece of personal data your business collects. Most SMBs are surprised to find data scattered across:

    1. Spreadsheets (customer lists, sales reports)
    2. Email inboxes (customer correspondence)
    3. Third-party tools (CRM, analytics, marketing platforms)
    4. Databases (application data, user accounts)
    5. Cloud storage (Google Drive, Dropbox backups)
graph LR A[📊 Spreadsheets] --> E[📋 Data Inventory] B[📧 Email Inboxes] --> E C[🔧 Third-party SaaS] --> E D[🗄️ Databases] --> E E --> F[🔍 Classify by Sensitivity] F --> G[📝 Compliance Map] style E fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 style G fill:#1e5f3a,stroke:#10B981,color:#e2e8f0

Update your privacy policy and consent forms. Here's what good consent looks like in code:

html
<!-- ❌ BAD: Pre-ticked, bundled consent -->
<label>
  <input type="checkbox" checked />
  I agree to the terms, privacy policy, and marketing emails
</label>

<!-- ✅ GOOD: Separate, unticked, specific consent -->
<label>
  <input type="checkbox" required />
  I consent to Acme Corp collecting my name and email to process my order.
  <a href="/privacy-policy">Read our privacy policy</a>
</label>

<label>
  <input type="checkbox" />
  I'd also like to receive product updates via email (optional).
</label>
💡
TIP
Add a consent withdrawal button that's just as prominent as your sign-up form. A simple "Delete My Data" link in your footer or account settings page satisfies this requirement.

Step 3: Run a Security Assessment

Identify vulnerabilities that could lead to a data breach — because the fastest path to a DPDP penalty is a breach you could have prevented.

bash
# Quick security headers check
curl -sI https://yourdomain.com | grep -iE "strict-transport|content-security|x-frame|x-content-type"

# If you see nothing, your headers are missing — that's a finding.

Step 4: Set Up Breach Response

Have a plan before you need one:

TimelineAction
0–1 hoursDetect breach (requires monitoring!)
1–4 hoursContain & assess scope
4–6 hoursNotify CERT-In (mandatory)
6–24 hoursNotify Data Protection Board
24–72 hoursNotify affected Data Principals
1–2 weeksPublish incident report & remediation
ℹ️
INFO
Most SMBs fail at step 1 — they don't have monitoring to even detect a breach. Setting up basic logging and alerting is the highest-ROI security investment you can make.

How Bachao.AI Helps

Our platform maps directly to DPDP compliance requirements:

DPDP RequirementBachao.AI ProductWhat It Does
Reasonable security safeguardsVAPT Scan (Free)Identifies all vulnerabilities in your web presence
Breach notification readinessDark Web MonitoringAlerts you if credentials or data appear on the dark web
Data audit & classificationDPDP Compliance ScoreMaps your data handling against DPDP requirements
Employee awarenessSecurity TrainingPhishing simulation + compliance training
Incident responseIncident Response24/7 breach response with CERT-In notification
🎯Key Takeaway
Start free, upgrade when ready. Our free VAPT scan + DPDP readiness score gives you a concrete starting point for compliance. No credit card required.

Book Your Free Scan


Written by Shouvik Mukherjee, Founder of Bachao.AI. Follow me on LinkedIn for daily cybersecurity insights for Indian businesses.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See where your business stands against the DPDP Act 2023

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →