India's Digital Personal Data Protection Act applies to far more businesses than realise it. Here is what it requires, in plain language.
India's Digital Personal Data Protection Act 2023 is the first law to place real, enforceable duties on ordinary Indian businesses handling personal data. Most Kerala SMEs we speak to have not yet assessed what it means for them.
Does it apply to you?
If you hold personal data about identifiable people in India — customers, staff, students, patients, suppliers — it applies. There is no small-business exemption of the kind people assume.
A twelve-person trading firm with a customer database is in scope. So is a clinic, a school, a jeweller with a loyalty list, and a business that only keeps employee records.
The duties, in plain terms
Collect only the personal data you actually need for a stated purpose
Tell people what you are collecting and why, in clear language
Secure it with reasonable safeguards
Delete it when the purpose ends, rather than keeping it indefinitely
Report a breach to the Data Protection Board and to affected individuals
Respond when someone asks what you hold about them, or asks you to correct it
Children's data carries a higher bar
Data concerning anyone under eighteen requires verifiable parental consent, and tracking or behavioural advertising directed at children is prohibited outright.
For Kerala's schools, coaching centres and paediatric clinics this is the most consequential part of the Act, and the one least often assessed.
The penalties are not nominal
Financial penalties under the Act run to substantial amounts, with the largest tied to failure to take reasonable security safeguards to prevent a breach. The exact figure is less important than the direction: this is no longer a matter of best practice.
The practical exposure for most SMEs is not a regulator arriving unannounced. It is a breach that forces disclosure, at which point the question becomes what safeguards you had in place beforehand.
Where to start, in order
Compliance is not a product you buy. Start with the unglamorous work and most of the exposure closes.
Write down what personal data you hold, where it lives, and who can reach it. Most businesses have never done this.
Remove access nobody needs — former staff accounts are the most common finding
Turn on multi-factor authentication everywhere it is available
Make sure backups exist, are offline, and have actually been restored in a test
Stop staff sharing customer or student data through personal messaging accounts
What technology can and cannot do
Technical controls close part of the gap. The rest is documented process and staff awareness, and no vendor can sell you those.
Be sceptical of anyone offering DPDP compliance as a product. What is genuinely available is an assessment of where you stand and a prioritised plan — which is what our cybersecurity service in Kerala.
Most of the work is knowing what personal data you hold and who can reach it, which is unglamorous and the part that gets deferred. Our cybersecurity services in Kerala page covers the controls, and Microsoft 365 covers the retention and access settings most businesses already own and have not configured.

