Samaniz

Data protection

DPDP Act: a plain-English checklist for small businesses

8 min read · Samaniz Insights

India's Digital Personal Data Protection Act applies to any business handling the personal data of people in India. For a small business the practical work falls into six areas: knowing what data you hold, recording why you hold it, controlling who else touches it, setting how long you keep it, handling deletion requests, and preparing for a breach.

General information for orientation. Legal interpretation belongs with your counsel.

Who this applies to

The Act reaches businesses that process the digital personal data of individuals in India. Size offers little shelter: a twelve-person company holding customer contact details, employee records and vendor information falls within scope as surely as a large enterprise. The obligations scale with what you hold and how sensitive it is.

Personal data means anything identifying a living individual: names, phone numbers, email addresses, payment details, identity numbers, location, employment records. Most small businesses hold far more of it than they realise, spread across a CRM, a payroll system, a shared drive and several inboxes.

1. Know what personal data you hold

Everything else depends on this. Build an inventory covering each system that stores personal data, the categories held, roughly how many records, and who has access.

Start with the obvious systems, then chase the informal ones: spreadsheets on laptops, exports somebody produced for a report last year, attachments in shared mailboxes, backups of systems you retired. Informal copies are where exposure concentrates, because they sit outside whatever controls the main systems carry.

2. Record why you hold it

Each category of data needs a purpose you can state in a sentence. "Customer phone numbers, held to deliver orders and handle support queries." Where the basis is consent, you need a record of that consent: what the person agreed to, when, and in what terms.

This exercise usually reveals data held out of habit. Sales enquiries from four years ago. Applicant CVs from filled positions. Where a purpose fails to materialise, deletion is the cleanest answer available.

3. Refresh consent, and make withdrawal work

Consent captured once and left to age is among the most common weaknesses. The Act expects consent to be free, specific, informed and unambiguous, with withdrawal as straightforward as granting it.

Practically: review what your forms actually say, verify that a marketing opt-in is separate from a service agreement, and confirm that somebody in the business can action a withdrawal request within a day or two. A withdrawal mechanism that routes to an unmonitored inbox counts for very little.

4. Put vendor terms in writing

Your payroll provider, CRM, email platform, accountant and cloud host all process personal data on your behalf. Each relationship needs written terms covering what they may do with the data, how they secure it, how they notify you of a breach, and what happens at the end of the contract.

Many small businesses operate on informal arrangements with long-standing vendors. Converting those to written terms is unglamorous and among the highest-value work available, because responsibility for your data follows it wherever it travels.

5. Set retention by policy

Retention driven by habit means everything is kept forever, which maximises exposure with every passing year. Set a period for each data category, tied to the purpose: order records for the statutory accounting period, unsuccessful applicant CVs for six months, marketing contacts until withdrawal.

Then automate deletion where you can, and diarise it where you must. A policy that lives only in a document tends to be a policy everybody forgets.

6. Prepare for requests and breaches

Individuals may ask what you hold about them, ask for corrections, and ask for erasure. Decide now who owns those requests, where they arrive, and how quickly you respond. A named owner turns a scramble into a routine.

Breach preparation follows the same logic. Establish who is called, how you assess scope, how you notify the Data Protection Board and affected individuals, and where you record the whole sequence. Rehearse it once. The rehearsal reveals the gaps while the stakes remain low.

Where most small businesses stand today

The pattern is consistent: reasonable security on the main systems, an unmapped sprawl of informal copies, consent captured years ago in terms that would struggle today, and vendor relationships built on trust rather than paper. The technical posture is often better than the governance posture.

That is encouraging, because governance work is largely a matter of method rather than expenditure. An inventory, a purpose register, refreshed consent language, vendor terms, a retention schedule and a request process take effort rather than heavy investment.

A sensible order of work

  1. Inventory what you hold, including the informal copies
  2. Delete whatever lacks a current purpose
  3. Record the purpose and basis for what remains
  4. Fix consent language and the withdrawal path
  5. Paper the vendor relationships
  6. Set retention, and automate it where possible
  7. Assign ownership of requests and breach response

Working in that order means each step shrinks the work in the next one. Deleting early is the single highest-leverage move available, because data you have released stops being a liability entirely.