DPDP Rules 2025: A Plain-Language Checklist for Small Businesses Before May 2027
Published: 10/9/2026
Category: Data & Security
India's DPDP Rules were notified on 13 November 2025, with most obligations taking effect around May 2027. There is no small-business exemption. A plain-language checklist of what to do and when.
The Digital Personal Data Protection (DPDP) Rules were notified on 13 November 2025, starting a phased rollout. Most practical obligations, such as notice and consent, security safeguards, breach notification, retention limits and people's rights over their data, take effect around May 2027. There is no blanket exemption for small businesses: if you collect customers' names, phone numbers or other personal data digitally, the law applies to you.
What counts as personal data in a small business
- Customer names, phone numbers and addresses in your billing or CRM
- WhatsApp contacts used for business
- Patient or student records
- Staff details, ID copies and bank details
- CCTV footage that identifies people
The checklist
1. Know what you collect (do now)
List every place personal data lives: billing software, WhatsApp, Excel sheets, paper registers scanned to phones, email. For each, note what data, why you need it and who can see it.
2. Collect only what you need
If you only need a phone number for the bill and delivery, do not also collect date of birth "just in case". Less data means less risk.
3. Give a clear notice and take consent
When you collect data, tell people in simple words what you collect, why and how to contact you. For uses like marketing messages, take clear consent and keep a record of it.
4. Make it easy to say no or ask for deletion
People can withdraw consent and ask for their data to be corrected or erased. Decide who in your business handles these requests and how quickly.
5. Protect the data
- Individual logins for staff, with access limited by role
- Strong passwords and two-step verification on email and business apps
- No customer lists on personal phones or pen drives
- Regular backups, stored securely
6. Do not keep data forever
Decide how long you keep each type of data, based on business and legal needs (tax records have their own retention periods). Delete what you no longer need.
7. Plan for a breach
If a phone with customer data is lost, or an account is hacked, the Rules require you to inform affected people and the Data Protection Board. Write down now who does what.
8. Check your vendors
Your billing software, WhatsApp provider and cloud storage process data for you. Ask them how they protect it and whether their contracts cover DPDP obligations.
A realistic timeline for a small business
| By | Do |
|---|
| December 2026 | Data list, minimise collection, staff logins and passwords |
| March 2027 | Notices and consent records for marketing; vendor check |
| May 2027 | Request handling, retention rules and breach plan in place |
Where BizFlow fits
BizFlow supports individual staff logins with role-based access, records marketing consent against customers and keeps data in one system instead of scattered sheets and phones.
This is general information, not legal advice. For your specific obligations, consult a qualified professional.
Frequently asked questions
Q: Does the DPDP Act apply to small shops?
A: Yes. There is no blanket exemption by size. If you process customers' personal data digitally, the obligations apply.
Q: When do the DPDP obligations take effect?
A: The Rules were notified on 13 November 2025 with a phased rollout; most substantive obligations apply around May 2027.
Sources
Home | Blog