Most of what Indian businesses believe about data privacy was true in about 2018, in a different country. The law here has changed, the definitions have changed, and a lot of confident advice still circulating in offices is now simply wrong.
India passed the Digital Personal Data Protection Act in 2023. It is the country's first dedicated personal data law, and it covers any organisation that handles the digital personal data of people in India. It reaches companies based outside India too, if they offer goods or services to people here.
If you hold a customer list, run a lead form, or keep staff records on a computer, you are what the Act calls a Data Fiduciary. The person whose data you hold is a Data Principal. That is the starting point for everything below.
Here are the beliefs we hear most often from clients, and what is actually true. Each one ends with the practical step to take, because a myth corrected and then ignored is not much of an improvement.
Myths About Who the Rules Apply To
"We are too small to be a target."
Small businesses get attacked more often, not less, precisely because the defences are thinner. Most attacks are not chosen by a person studying your company. They are automated scans hunting for an unpatched plugin, a reused password or an exposed database, and they do not check your turnover first.
Size affects the consequences, not the odds. A large company survives a breach. A small one often cannot absorb the loss of customer trust that follows.
Do this Turn on two-factor authentication for email, hosting and banking this week. It blocks the overwhelming majority of automated attacks and costs nothing.
"We only collect names and phone numbers, so it does not really count."
A name and a phone number are personal data. So is an email address, a delivery address, a photograph, and in many contexts an IP address. There is no minimum amount of data below which the rules stop applying.
In practice the name and number pair is one of the most damaging things to lose in India, because it is exactly what a phone scammer needs to sound credible when they ring your customer claiming to be you.
Do this Count the places a customer phone number currently lives: CRM, spreadsheets, WhatsApp, the accounts software, somebody's personal contacts. Most businesses are surprised by the number.
"The DPDP Act is for big tech companies, not businesses like ours."
The Act applies by activity, not by size. Handling digital personal data of people in India brings you inside it. The heavier obligations, such as appointing a Data Protection Officer and running independent audits, attach to a category called Significant Data Fiduciary, which is reserved for larger processors. The baseline duties are not.
Those baseline duties include taking reasonable security safeguards, honouring correction and erasure requests, reporting breaches, and running a grievance channel customers can actually use. The Act does let the government notify certain classes of business, including startups, for relief from some provisions, so watch for that if it ever applies to you.
Do this Publish a named contact for data questions on your website. It is the cheapest obligation to meet and one of the most visible when it is missing.
Myths About What Compliance Means
"Data privacy and data security are the same thing."
They are different problems, and you can fail at one while doing the other perfectly. Security is about keeping data away from people who should not have it. Privacy is about what you and your own staff are entitled to do with it in the first place.
A company with encrypted servers, locked laptops and a clean breach record can still be in the wrong if it collected the data without consent, or is using it for something it never disclosed. Encryption does not create permission.
Do this For each data set you hold, write one line saying why you have it and what you use it for. If you cannot write that line, you probably should not be holding it.
"We have a privacy policy on the website, so we are compliant."
A privacy policy is a disclosure, not a defence. Most Indian business websites carry one copied from another site, describing data practices the company does not follow, occasionally still naming the company it was copied from.
The obligation is to do what you say and be able to show it. A policy that does not match reality is worse than having none, because it is documentary evidence of the gap.
Do this Read your own privacy policy end to end. Mark every sentence that is not true today. That list is your real compliance backlog.
"Consent means a pre-ticked box, or them carrying on using the site."
Under the DPDP Act, consent has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. A pre-ticked box is not an affirmative action, and neither is failing to object.
It also has to be as easy to withdraw as it was to give. A business that takes consent in one tap but requires an email to a support address to withdraw it has not met the standard. The request must be tied to a stated purpose too, so one blanket tick cannot cover marketing, profiling and sharing with partners all at once.
Do this Untick every pre-ticked box on your forms. Put a plain-language line next to the submit button saying what you will do with the data.
Myths About Where Data Lives and How Long You Keep It
"Our data is on the cloud, so the provider is responsible for it."
Cloud providers run a shared responsibility model. They secure the infrastructure. You stay responsible for who you grant access to, how you configure it, and what you choose to put in there.
Most cloud data exposures are not provider failures. They are storage buckets left public, permissions granted to a former employee and never revoked, and databases put online without a password.
Do this List everyone with access to your customer data. Remove anyone who has left or changed role. Repeat every quarter, because this list only ever grows on its own.
"We can keep customer data as long as we like."
Personal data should be kept only as long as it serves the purpose you collected it for, or as long as another law requires you to keep it. Indian tax and company law set their own retention periods, and those are legitimate reasons to hold records.
"We might need it one day" is not a purpose. A lead list from 2016 that nobody has contacted since is not an asset. It is a liability sitting on a server waiting to be stolen.
Do this Pick a retention period for each data type, write it down, and delete what is past it. Start with old lead lists and former employee records.
"When we delete a record from the CRM, it is gone."
It is gone from one place. The same record usually also sits in email attachments, exported spreadsheets, an accounts package, a marketing tool, WhatsApp chats, and every backup taken since the day it was created.
If a customer asks you to erase their data and you delete the CRM row only, you have not honoured the request. You will find that out when their name turns up in the next mailing.
Do this Draw a one-page map of where customer data flows and where copies land. Deletion cannot be done properly without it.
"Sharing customer details on WhatsApp is fine, everyone does it."
Everyone does do it, and it is the largest uncontrolled copy of customer data in most Indian small businesses. Once a spreadsheet of names and numbers is forwarded into a staff group, it exists on personal phones you do not control, backed up to personal cloud accounts you cannot reach.
When that employee leaves, the data leaves with them, and there is no delete button that reaches their handset.
Do this Stop sending customer lists as attachments in personal chats. Share a link to a controlled system where access can be switched off instead.
What the Law Actually Asks of a Small Business
Stripped of the legal vocabulary, the baseline duties are short and mostly unglamorous.
| Duty | What it means in practice | Effort |
|---|---|---|
| Lawful basis | Collect data with clear consent, or for a defined legitimate use | Form and notice rewrite |
| Purpose limitation | Use it only for what you told people you would use it for | Policy and habit |
| Data minimisation | Stop asking for fields nobody ever looks at | One afternoon |
| Security safeguards | Passwords, two-factor, access control, updates, encryption | Ongoing |
| Retention limits | Delete what is past its purpose and its legal retention period | Quarterly |
| Individual rights | Let people see, correct and erase their data, and act when they ask | Process, not software |
| Grievance channel | A named contact who answers data questions | One page |
| Breach reporting | Report a breach rather than quietly hoping | Plan it in advance |
The Schedule to the DPDP Act sets penalties in crores of rupees. The heaviest, up to ₹250 crore, attaches to failing to take reasonable security safeguards to prevent a personal data breach. Failing to report a breach, and failures around children's data, carry their own tiers below that.
Enforcement has been phased in stages rather than switched on overnight, so the immediate practical risk varies by obligation and by date. The direction is settled even where the timing is not, and the cheap fixes are worth doing either way.
An Eight-Step Starting Point
If none of this exists at your company yet, this is the order that removes the most risk for the least work.
- List every place customer data is stored, including spreadsheets and chat apps.
- List everyone who can reach it, and remove anyone who should not.
- Turn on two-factor authentication for email, hosting, banking and your CRM.
- Delete data that is past its purpose, starting with old lead lists.
- Remove form fields you collect but never use.
- Rewrite the privacy policy so it describes what you actually do.
- Publish a named contact for data questions and grievances.
- Write a one-page plan for the first 24 hours after a breach.
Steps one, two and three take a single working day between them and remove more risk than everything else on the list combined. Most businesses never get to them because they are waiting to do privacy properly later.
Frequently Asked Questions
What is the difference between data privacy and data security?
Security is keeping data away from people who should not have it. Privacy is about what you are entitled to do with it in the first place, and whether the person it belongs to agreed. You can have excellent security and still be in the wrong on privacy, because encryption does not create permission.
Does the DPDP Act apply to small businesses in India?
Yes. The Act applies by activity rather than size, so any organisation handling the digital personal data of people in India falls under it. The heavier duties, such as appointing a Data Protection Officer, apply only to larger processors classed as Significant Data Fiduciaries. The Act does allow the government to notify certain classes of business, including startups, for relief from some provisions.
Is a privacy policy enough to be compliant?
No. A privacy policy is a disclosure, not a defence. What matters is whether you actually do what it says and can show it. A copied policy describing practices you do not follow is worse than having none, because it documents the gap.
Are names and phone numbers really personal data?
Yes. So are email addresses, delivery addresses, photographs and in many contexts IP addresses. There is no minimum amount of data below which the rules stop applying. In India a name and number pair is among the most damaging things to lose, because it is what a phone scammer needs to sound convincing.
If our data is on the cloud, is the provider responsible?
Only for the infrastructure. Cloud providers use a shared responsibility model, so access control, configuration and what you choose to store stay yours. Most cloud exposures are misconfigured storage or permissions never revoked from a former employee, not provider failures.
How long can we keep customer data?
As long as it serves the purpose you collected it for, or as long as another law such as tax or company law requires. "We might need it one day" is not a purpose. Old lead lists nobody has contacted are a liability rather than an asset.
What counts as valid consent under the DPDP Act?
It must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Pre-ticked boxes and continued use of a website do not qualify. It must be tied to a stated purpose, and withdrawing it has to be as easy as giving it was.
What are the penalties under the DPDP Act?
The Schedule to the Act sets them in crores of rupees, with the heaviest tier of up to ₹250 crore attached to failing to take reasonable security safeguards against a breach. Lower tiers cover breach reporting and children's data. Enforcement has been phased in stages, so the immediate risk varies by obligation.
What should we do first if we have done nothing so far?
Three things, in one day. List every place customer data lives, including spreadsheets and chat apps. List everyone who can reach it and remove those who should not. Turn on two-factor authentication for email, hosting, banking and your CRM. That removes more risk than everything else combined.