What the India DPDP Act Means for Your Business Data in 2026
Compliance

What the India DPDP Act Means for Your Business Data in 2026

Home/Blog/What the India DPDP Act Means for Your Business Data in 2026
A

Aarav Mehta

Tax & Compliance Specialist

December 12, 20257 min read4 sections

India's Digital Personal Data Protection (DPDP) Act 2023 became enforceable in 2025, and its implementation rules are now creating real compliance obligations for businesses that collect, store, or process personal data of Indian citizens. For most Indian SMBs, the Act's requirements are manageable — but only if you understand what they actually require, as opposed to the alarmist interpretations circulating in business circles.

1What Data Is Covered Under the DPDP Act

The Act covers 'personal data' — any data that can identify a natural person, including names, phone numbers, email addresses, Aadhaar numbers, PAN details, purchase history, and location data. It does not cover data about companies or anonymised data. For a typical retail SMB, the personal data you collect includes customer names, addresses, phone numbers, and transaction records. This is the scope you need to manage.


2Consent Requirements: What You Must Tell Customers

The Act requires 'free, specific, informed, unconditional, and unambiguous' consent before collecting personal data. In practice: your sign-up form, checkout page, or loyalty card enrolment must have a clear consent checkbox linking to your privacy policy — not buried in terms and conditions. The privacy policy must specify exactly what data you collect, why, for how long, and with whom it is shared.


3Data Residency and Storage Rules

The Act mandates that personal data of Indian citizens be stored on servers located in India. For SMBs using cloud software, this means verifying that your SaaS vendor stores data in India — specifically in an Indian AWS, Google Cloud, or Azure region. Vendors like Zoroflex store all data in AWS Mumbai (ap-south-1) by default. Verify this with any vendor that handles your customer data before signing up.


4Penalties Under the DPDP Act

The maximum penalty for a data breach due to inadequate security measures is ₹250 crore. For failure to notify users or the Data Protection Board of a breach, penalties reach ₹200 crore. These numbers sound alarming, but the Act's enforcement philosophy is proportionate — first-time, good-faith violations from SMBs are expected to attract much lower penalties.

Key Takeaway

DPDP compliance for most Indian SMBs reduces to four practical steps: (1) audit what personal data you collect and why, (2) add a proper consent mechanism to every data collection touchpoint, (3) verify that your software vendors store data in India, and (4) draft a simple privacy policy. This is a weekend project, not a compliance transformation.

Share:WhatsAppXLinkedIn
A

Aarav Mehta

Tax & Compliance Specialist

Aarav has 11 years of experience in indirect taxation and GST advisory for Indian SMBs. He previously worked with a Big 4 firm and now leads compliance product design at Zoroflex.

Comments2

Leave a comment

H
Harish MenonEdTech Startup, Bangalore

December 14, 2025

We store student data including minors' information. The DPDP Act has stricter rules for children's data — would love a follow-up article specifically on that section.

A
Aarav MehtaAuthorDecember 14, 2025

Great suggestion, Harish. Children's data under DPDP requires verifiable parental consent and prohibits behavioural tracking — it's a significantly higher compliance bar. Working on a dedicated piece for EdTech.

D
Divya KrishnanHealthcare Clinic, Coimbatore

December 17, 2025

Patient health records — are these covered under DPDP or under a separate health data regulation? Getting conflicting advice from our consultants.

A
Aarav MehtaAuthorDecember 17, 2025

Health data is classified as 'sensitive personal data' under DPDP and has additional processing restrictions. The Digital Health Data Management Policy (under NHP) will add another layer — recommend consulting a healthcare-specific compliance advisor for clinical data.

Related Articles