There is no small-business carve-out in the Digital Personal Data Protection Act today, and that surprises almost every founder who hears it for the first time. Here is what actually applies if you run a small operation, and where the genuine relief sits amidst the compliance noise.
The startup exemption myth
Section 17(3) lets the Central Government notify certain Data Fiduciaries, including startups, as exempt from specific obligations like the Section 5 notice requirement or parts of Section 8. As things stand, no such notification has been issued, so this relief is not yet operative. Building a compliance plan around a hypothetical future exemption is a gamble rather than a strategy. Every business processing personal data in India today, regardless of size or revenue, has to comply with the Act as it currently stands.
Proportionate safeguards
What that means in practice is proportionate. A five-person shop with a customer spreadsheet does not need an enterprise security operations centre, but it does need basic access control, a backup plan, and a lawful basis for every category of personal data it collects. Most small operations will not be designated a Significant Data Fiduciary under Section 10, meaning you will avoid the heavy Data Protection Impact Assessment and audit obligations reserved for high-volume, high-risk organisations.
The minimal viable compliance stack
You do not need a massive legal department to get the foundations right. Focus on these practical steps.
- List every place personal data enters your business: signup forms, payment gateways, support tickets, vendor tools.
- Write one standalone notice that actually describes what you collect and why, in language a customer would understand.
- Set up one inbox or contact point for grievances and consent withdrawal requests under Section 13.
- Check your vendors. Section 8 makes you liable for your Data Processors, so ensure your SaaS tools are DPDP-compliant.
- Write down, even briefly, what you would do in the first 72 hours of a suspected breach to meet the Rule 7 clock.
None of this requires a massive budget. It requires deciding, once, what data you actually need and being honest with yourself about where it goes afterwards.