India’s data-protection regime has moved from policy discussion to an implementation countdown. The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, along with the establishment of the Data Protection Board of India and a phased enforcement schedule. The official commencement notification provides for different parts of the Act to take effect at different stages. Certain provisions became effective with the notification, another limited set is scheduled one year after publication, and the main operational obligations are scheduled 18 months after publication. This creates important milestones around 13 November 2026 and 13 May 2027 . For MSMEs, this transition period should not be interpreted as permission to postpone action. Data discovery, contract revision, system changes and employee training frequently take longer than expected. Why DPDP Compliance Is an MSME Issue Many business owners assume that data-protection laws apply only to technology companies, banks, hospitals or large e-commerce platforms. In reality, an ordinary MSME may process personal data through: Customer enquiry forms WhatsApp conversations Employee records Salary and attendance systems CCTV footage Vendor databases Loyalty programmes E-commerce orders Delivery records Email marketing Job applications Warranty registrations Customer-support systems Mobile applications Website cookies and analytics A company does not have to sell personal information to create a data-protection risk. Simply collecting, storing, sharing, analysing or retaining digital personal data can create responsibilities. What Is Personal Data? Personal data is information relating to an identifiable individual. Depending on the context, it may include a person’s: Name Mobile number Email address Residential address Identification details Photograph Location information Purchase history Employee records Bank details Device or account identifiers Health-related information Communication history The compliance question is not merely, “Do we collect Aadhaar or financial data?” The broader question is, “Can the information identify an individual, directly or when combined with other information?” Step One: Prepare a Data Inventory The first practical task is to identify what personal data the business holds. Each department should record: What information is collected From whom it is collected Why it is needed How it is collected Where it is stored Who can access it Which external vendors receive it How long it is retained How it is deleted Whether it relates to children Whether it is transferred outside India The data inventory should include information stored in laptops, spreadsheets, email accounts, cloud drives, accounting software, CRM platforms, HR systems , messaging applications and physical documents later digitised. This exercise often reveals duplicate databases, former-employee access, old customer lists and information retained without a continuing business purpose. Step Two: Define the Purpose of Collection MSMEs should avoid collecting personal data because it “may be useful later.” Every data field should serve a clear purpose. For example: An address may be needed to deliver a product. A bank account may be needed to process salary. A mobile number may be needed to provide order updates. An identity document may be needed to satisfy a legal obligation. The business should be able to explain why the information is necessary and how it will be used. Purpose clarity is also commercially useful. It reduces unnecessary storage, lowers cybersecurity exposure and improves the quality of customer databases. Step Three: Rewrite Consent and Privacy Notices The notified framework requires clear, standalone and understandable consent notices explaining the specific purpose for which personal data is collected and used. The Government has emphasised simple language, transparency, purpose limitation, data minimisation, security and accountability. A privacy notice should not be copied from another website without examining the actual practices of the business. The notice should accurately describe: Categories of personal data collected Purpose of processing Method of withdrawing consent Contact for privacy-related queries Rights available to the individual Relevant sharing with service providers Retention or deletion approach Complaint and grievance process Consent should not be hidden inside unrelated terms or obtained through misleading design. Step Four: Review Every Technology Vendor An MSME may rely on external providers for payroll , accounting, cloud storage, marketing, CRM, website hosting, payment processing, delivery, analytics and customer support. Outsourcing the activity does not eliminate business risk. Vendor contracts should address: Permitted use of personal data Confidentiality Security controls Subcontractors Data location Breach notification Return or deletion of information Audit and cooperation obligations Access control Contract termination Assistance with customer requests The lowest-priced software subscription may become expensive if it cannot support deletion, access requests, breach investigation or secure data export. Step Five: Create a Personal Data Breach Plan A personal data breach may involve unauthorised access, accidental disclosure, loss, alteration or destruction of personal data. The DPDP Rules require affected individuals to be informed promptly in plain language about the nature of a breach, its possible consequences, the measures taken and the contact available for assistance. An MSME breach-response plan should identify: Who receives the first internal alert Who can isolate affected systems Who evaluates the type of data involved Who communicates with customers Who coordinates with technology vendors Who preserves evidence Who obtains legal and cybersecurity advice Who maintains the incident record Employees should know that hiding a suspected incident can increase the damage. Step Six: Prepare for Individual Rights Requests The framework provides individuals with rights relating to access, correction, updating, erasure, grievance redressal and nomination. The notified Rules also provide a maximum response framework for relevant requests. MSMEs should create a simple workflow for receiving and verifying requests. A shared email inbox with no defined owner is not an adequate process. Responsibility should be assigned to a specific officer or senior employee, even where the business is not required to appoint a formal Data Protection Officer. Step Seven: Pay Special Attention to Children’s Data Businesses serving children through education, healthcare, gaming, retail, entertainment, sports or digital platforms must apply greater care. The notified framework requires verifiable consent before processing children’s personal data, subject to limited exemptions for specified purposes. An age-confirmation checkbox alone may not be sufficient in every situation. Businesses should review how age and parental or guardian authority are verified, while avoiding excessive collection of identification information. Step Eight: Strengthen Basic Cybersecurity Data protection cannot be achieved through paperwork alone. At a minimum, MSMEs should implement: Multi-factor authentication Strong password controls Role-based access Regular backups Updated operating systems Endpoint protection Encryption where appropriate Restricted administrator rights Former-employee access removal Vendor-access review Phishing awareness Incident logging Secure disposal of devices and records The business should maintain evidence of these controls. A security measure that cannot be demonstrated may be difficult to defend after an incident. Step Nine: Review Employee Data Practices Employee information is frequently overlooked. MSMEs should review: Recruitment records Background-verification reports Attendance and biometric systems Salary information Medical documents Performance records CCTV monitoring Official email monitoring Employee location tracking Former-employee files Access should be limited to people who genuinely need the information. Retention should be linked to employment, legal and business requirements rather than indefinite storage. A Practical DPDP Implementation Calendar August–October 2026 Appoint an internal compliance owner Complete data mapping Identify high-risk systems Review website and application notices List all data-processing vendors Remove unnecessary data Prepare an incident-response team November 2026–January 2027 Reassess the provisions becoming effective Finalise privacy and consent notices Amend priority vendor contracts Establish rights-request workflows Train customer-facing and HR employees Test the breach-response process February–April 2027 Conduct a mock data incident Test access and deletion procedures Review children’s-data practices Verify security evidence Close outstanding vendor gaps Obtain specialist legal advice for complex processing By 13 May 2027 The organisation should be able to demonstrate that its actual operating practices—not merely its policy documents—are aligned with the applicable obligations taking effect under the phased framework. Mistakes MSMEs Should Avoid Copying a foreign privacy policy Treating consent as a permanent permission Collecting more information than required Keeping former-customer data indefinitely Ignoring employee information Assuming the software vendor is solely responsible Having no breach-response owner Allowing shared passwords Failing to remove former-employee access Publishing a privacy notice that does not reflect actual practices SMEStreet Editorial Perspective DPDP compliance should not be presented to MSMEs merely as another legal burden. A company that knows what information it holds, limits unnecessary access, responds properly to customers and manages vendors carefully becomes more secure and professionally governed. Privacy readiness can improve customer confidence, enterprise procurement eligibility, investor due diligence and international business relationships. The objective is not to create hundreds of pages of policy. The objective is to build a business in which personal data is collected deliberately, protected responsibly and deleted when it is no longer required. Frequently Asked Questions Does the DPDP framework apply to small businesses? Business size alone does not determine whether data-protection obligations are relevant. An MSME processing digital personal data should evaluate the applicability of the Act, Rules, exemptions and phased provisions. Does an MSME need a Data Protection Officer? Not every enterprise is automatically required to appoint a formal Data Protection Officer. However, every business should assign responsibility for data-protection queries, incidents and individual requests. Is customer consent always required? The Act provides consent-based processing as well as specified legitimate uses. Businesses should obtain professional advice on the appropriate legal basis for each activity rather than assuming that one approach applies universally. Can personal data be stored on cloud servers outside India? The framework permits cross-border processing subject to restrictions that may be notified by the Government. Contractual, security and sector-specific requirements should also be reviewed. Is a privacy policy enough for compliance? No. Compliance also involves actual data practices, security, vendor management, consent, retention, breach response and rights-handling procedures. Research and Methodology Note This article is based primarily on the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the official commencement notification and Government explanations issued through MeitY and the Press Information Bureau. Author Note Dr Faiz Askari is Founder, Editor and CEO of SMEStreet and has extensively engaged with MSMEs, policymakers, technology providers and business leaders through editorial analysis, interviews and ecosystem initiatives. Legal Disclaimer: This article provides general editorial information and does not constitute legal advice. Applicability may vary according to the nature of the organisation, data processed, sectoral regulations and government notifications. Businesses should consult qualified legal and cybersecurity professionals. Tags : DPDP Act | DPDP compliance for MSMEs
Source: Read Full Article