DPDP Compliance for Your Website: A Plain-English Guide for Business Owners
If you run a business with a website, a new Indian law now applies to you — and most owners I speak to have not heard of it yet. India's Digital Personal Data Protection (DPDP) Rules were notified in November 2025, giving full effect to the DPDP Act, 2023. In plain terms: if your website collects a name, phone number, or email from people in India, you now have legal duties over that data.
This is not a big-tech-only law. It reaches the corner shop with an enquiry form, the coaching centre storing student numbers, the freelancer with a contact page, and the SaaS startup with a signup box. Here is what it means and, more usefully, what to actually do about it.
Does DPDP really apply to a small business?
Yes. Under the law, any business that decides how and why personal data is handled is a "Data Fiduciary," and the individuals whose data you hold are "Data Principals." There is no size test that lets a small business ignore the law — being tiny does not put you outside it.
The government has said it will provide a "facilitative compliance regime for startups and smaller enterprises," so some obligations may be eased for certain notified startups. That is welcome, but it is a softer on-ramp, not an exemption. You are still covered.
One more point that surprises founders: the law can also reach businesses located outside India if they offer goods or services to people in India. So a small agency abroad serving Indian customers is not automatically in the clear either.
What the law actually asks you to do
Strip away the legal language and the core duties are practical. According to the Ministry of Electronics and IT (MeitY), a Data Fiduciary must:
- Ask for clear consent. Give people a standalone, simple notice that plainly states what data you collect and the specific purpose you collect it for — before or when you collect it.
- Name a contact for data questions. Display the contact details of a designated officer (or Data Protection Officer) so people can raise queries about how their data is handled.
- Honour data rights. Let people access, correct, update, or erase their data — and respond to such requests within a maximum of 90 days.
- Report breaches. If personal data is exposed, inform the affected individuals promptly and in plain language — what happened, the likely impact, what you have done, and where to get help.
- Protect children's data. Get verifiable parental consent before processing a child's data, with limited exemptions for essentials like healthcare, education, and real-time safety.
Larger, high-volume operators (classified as "Significant Data Fiduciaries") carry heavier duties such as independent audits and impact assessments. Most MSMEs will not fall into that bracket — but the basic duties above still apply to everyone.
How much time do you have?
The rules roll out on an 18-month phased timeline. The Data Protection Board — a fully digital body where citizens can file and track complaints — is being set up first. The bulk of the day-to-day obligations for businesses (consent notices, data rights, breach reporting, security safeguards, retention limits) are expected to become enforceable around May 2027.
That sounds far away. It isn't. Retro-fitting consent, a privacy policy, a grievance contact, and a data-deletion process into an existing website — cleanly — takes planning, not a panicked weekend before the deadline. Starting now is the cheap option.
What are the penalties?
The DPDP Act sets financial penalties for non-compliance. At the highest end, these are reported to run up to ₹250 crore — for example, for failing to take reasonable security safeguards that lead to a breach. Treat that figure as a ceiling for serious failures, not a routine fine for a small shop. The realistic risk for most small businesses is a complaint, an order to fix things, and reputational damage — which is reason enough to get the basics right.
A copied privacy policy will not save you
Here is a common mistake: pasting a GDPR privacy policy from another website and assuming you are covered. You are not. India's DPDP framework has its own consent and notice requirements, built around seven principles — consent and transparency, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, and accountability. A generic overseas policy rarely matches these, and a policy that misstates how you actually handle data can be worse than none at all.
Your DPDP website checklist
Most of the fix lives on your website. Here is a practical starting checklist:
- Write a DPDP-fit privacy policy that describes the data you really collect and why — not a copied template.
- Add a clear consent step at every point you collect data: contact forms, enquiry buttons, newsletter signups, WhatsApp click-throughs.
- Publish the name and contact of a person responsible for data queries.
- Build a simple data-request process so people can ask to see, correct, or delete their data — and you can respond within 90 days.
- Decide how long you keep data and delete it when the purpose is over (don't hoard old leads forever).
- Tighten basic security: HTTPS, restricted access to your database and CRM, and a plan for what to do if data leaks.
- If you serve children, add verifiable parental consent where required.
None of this is exotic. It is mostly website and process work — the kind of thing a good web team folds into a build or a focused upgrade.
A note for smaller and Tier-2/3 businesses
You don't need an enterprise privacy department. You need three things done properly: a real privacy policy, honest consent where you collect data, and a working way to handle deletion requests. Get those in place and you have cleared the bar that most small businesses will be judged against. Everything else can be layered on over time.
Is your website DPDP-ready?
We build data-privacy compliance into websites for Indian businesses — a proper privacy policy, consent, a data-request flow, and the security basics. Book a free 15-minute readiness check and we'll tell you exactly where your site stands.
WhatsApp us: +91 91026 01040 · See our web development service · Book a free consultation
Handling data inside custom software, a CRM, or an ERP too? The same principles apply beyond the website — see our custom software work.
Frequently asked questions
Does DPDP apply if my website only has a contact form?
Yes. A contact form collects personal data (name, phone, email), so you are a Data Fiduciary for that data and the basic duties — consent, a privacy notice, and honouring deletion requests — apply.
I already have a privacy policy. Is that enough?
Not necessarily. If it's a copied GDPR or generic template that doesn't reflect how you actually collect and use data under India's rules, it may not meet DPDP's consent and notice requirements. It should be reviewed and rewritten to fit.
When do I have to be compliant?
The rules are phased over roughly 18 months, with most business obligations expected to be enforceable around May 2027. The sensible approach is to start now, because the fixes take planning.
Does DPDP apply to my business if I'm based outside India?
It can. The law can reach businesses outside India that offer goods or services to people in India, so serving Indian customers may bring you within scope.
What is the maximum penalty under DPDP?
Penalties are reported to go up to ₹250 crore at the highest end for the most serious failures, such as not taking reasonable security safeguards. For most small businesses the practical risk is a complaint and an order to fix things — but the reputational damage of a breach is real.
This article is general information for business owners, not legal advice. For your specific situation, consult a qualified professional.