Skip to content
Mounteyes
All guides

DPDP Act basics for Indian businesses

10 min readUpdated: Small Business

The Digital Personal Data Protection Act reaches almost any Indian business that collects a name and a phone number, which is almost all of them. Most of what it asks for is unglamorous and cheap. The expensive part is discovering, during an incident, that you never did it.

The short version

  • If you hold a customer's name, phone number or email, you are processing personal data.
  • Consent has to be specific, informed and withdrawable. A pre-ticked box is not consent.
  • You must be able to state what you hold, why, and for how long. Most businesses cannot.
  • Breach notification is not optional, and the clock starts when you become aware.
  • This guide is general information, not legal advice — have a lawyer review your actual position.

Who this reaches

India's Digital Personal Data Protection Act applies to the processing of digital personal data within India, and to processing outside India that relates to offering goods or services to people in India. There is no small-business exemption that removes the core obligations.

In practical terms: if you run an online store, a clinic with digital records, a school, a gym with a membership database, a restaurant that keeps reservation details, or a website with a contact form, you are in scope.

The Act uses "data fiduciary" for the organisation deciding how data is used, and "data principal" for the person the data is about. Vendors who process on your instructions are data processors — and using one does not transfer your responsibility to them.

What counts as personal data

Any data about an identifiable individual. That is broader than most people assume: a name, a phone number, an email address, a delivery address, an order history, an IP address in your logs, a photograph, a CCTV recording, an employee record, a job applicant's CV.

It does not have to be sensitive to be personal. A list of phone numbers with no other detail is personal data, and it is also exactly the kind of file that gets copied when a system is compromised.

The practical consequence is that the inventory is larger than the CRM. Spreadsheets on someone's laptop, WhatsApp exports, an old backup on a spare drive and the mailbox holding ten years of enquiries are all in scope.

Notice and consent, in practice

Before or at the point of collection, you have to tell people what you are collecting, the specific purpose, how they can withdraw consent, and how they can complain. That notice has to be in plain language and available in English and the Eighth Schedule languages.

Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the stated purpose. Bundling everything into one acceptance of a long policy does not meet that, and neither does a pre-ticked box.

Withdrawal has to be as easy as giving consent was. If someone can subscribe in one click and needs to send an email to leave, that asymmetry is the problem.

There are also legitimate uses that do not require consent — for example, where a person voluntarily provides data for a purpose and has not objected, or specified legal and emergency situations. Do not assume your case fits one; that is a question for a lawyer.

The rights you must be able to honour

People can ask for a summary of the personal data you hold and how it is processed, ask for correction of inaccurate or incomplete data, ask for erasure where the purpose is finished and no law requires retention, nominate someone to exercise their rights, and complain.

Each of those is only answerable if you know where the data is. This is the point at which the inventory stops being paperwork: a request to erase everything about one customer is unanswerable if their details are also in three spreadsheets and an old backup nobody has mapped.

So build the register first. Every system holding personal data, what it holds, why, who can access it, and how long it is kept.

Security obligations and breach reporting

You are required to take reasonable security safeguards to prevent a breach — and "reasonable" is judged after an incident, against what was available and normal for a business of your size.

If a breach occurs, you must notify the Data Protection Board and each affected person. The obligation is not conditional on the breach being large or on you being certain of the impact, and the clock starts when you become aware rather than when the investigation concludes.

That single fact should shape your incident planning. If you cannot establish what was accessed and whose data it was, you cannot notify accurately — which is why logging, retention and knowing what you hold are compliance controls and not just technical hygiene.

Penalties under the Act are substantial and are set against the failure rather than the size of the business.

A practical readiness sequence

**Inventory.** List every place personal data lives, including spreadsheets, mailboxes, messaging exports and backups.

**Minimise.** Stop collecting fields you never use, and delete data whose purpose has finished. This is the cheapest step and it reduces every other obligation at once.

**Retention.** Set a period per data type and enforce it with something automatic, because a policy nobody executes is worse than no policy — it documents an intention you are visibly not meeting.

**Notice and consent.** Rewrite your collection points so the purpose is specific and withdrawal is easy.

**Access control.** Restrict who can reach personal data to those who need it, and log access.

**Vendors.** List your processors, check what each one actually does with the data, and get the contractual terms in place.

**Incident plan.** Write down who decides, who notifies, and where the evidence comes from — before you need it.

Where CCTV and employee data fit

Camera footage of identifiable people is personal data, so a CCTV installation brings the same obligations: a stated purpose, notice before someone is recorded, a retention period, restricted access, and the ability to respond to a request about it.

Employee and applicant data is personal data too. Recruitment records, attendance, performance notes and monitoring output are all in scope, and monitoring staff without telling them is difficult to defend under any reading of the Act.

Both are covered in more detail in our guide on CCTV monitoring rules.

This is not legal advice

This guide is a plain-language orientation so you can ask better questions. It is not legal advice, it does not cover every provision or exemption, and rules issued under the Act continue to develop.

Where the answer affects a real decision — whether a legitimate use applies to you, what your notice must say, how to handle a specific breach — get advice from a lawyer on your actual facts. We help with the security and technical side of readiness, and we will tell you plainly when a question is a legal one rather than a technical one.

Nothing on this site will ever ask for your password, OTP or recovery codes.

Related guides

Want this handled for you?

Our engineers do this work for businesses every day, on monitoring platforms built to catch it earlier. Describe your situation and we will tell you what would actually help.

Talk to Our Security Team