DPDP Compliance for MSMEs & Small Business
Small does not mean exempt. The DPDP Act has no turnover or size threshold — if you handle customers’, employees’ or vendors’ data, it applies to you from day one.
The personal data you handle
A quick reality check. If any of this looks familiar, the DPDP Act applies to you.
Why DPDP applies to MSMEs & Small Business
Many small businesses assume the law works like GST — below a threshold, you’re out. It doesn’t. There is no small-business exemption, and the discretionary startup relief (Section 17(3)) has not been notified. The good news: for an MSME the core duties are simple to set up — notice, consent, a grievance contact and basic security.
Sector note: Beyond DPDP: no size exemption; the startup carve-out in Section 17(3) is not yet in force.
What to keep in mind
The points that cause most of the DPDP exposure in MSMEs & Small Business.
No ‘too small to comply’
Turnover buys no exemption. If you collect a name and phone number digitally, you’re a Data Fiduciary.
Start with the basics
A clear notice, real consent, a published grievance contact and reasonable security get you most of the way — without enterprise complexity.
WhatsApp & marketing lists
Broadcasting offers to numbers collected for billing needs consent. Build a simple opt-in and honour opt-outs.
Keep only what you need
Don’t hoard customer data or ID copies. Minimise and set a simple retention rule.
How dpflo helps MSMEs & Small Business
An India-resident DPDP platform that turns these obligations into a small set of guided workflows.
- A right-sized starter setup: notice, consent, grievance contact and retention — quick to deploy.
- Simple opt-in/opt-out for WhatsApp and marketing lists.
- Automated discovery & classification of personal data across your databases, cloud storage and SaaS apps.
- Consent capture, consent receipts and easy withdrawal — web, app, QR and a hosted preference centre.
- A resident/customer request (DSR) & grievance portal with SLA tracking and audit-ready evidence.
- Retention schedules, data-minimisation flags and a 72-hour breach-notification workflow.
- A vendor/processor register with data-processing-agreement (DPA) tracking.
Get MSMEs & Small Business DPDP-ready
Book a short call and we'll map your data, show you where the gaps are, and give you a tailored plan for the DPDP Act.