Fourteen steps that take an Indian business from unprepared to DPDP-ready — each one tied to the exact section of the DPDP Act 2023 or DPDP Rules 2025 it satisfies. Tick items off as you go; your progress is saved on this device.
Take the free EasyDP DPDP Checker — it takes 2 minutes and tells you exactly which section of the Act applies to you and what your penalty exposure is. As a rule of thumb: the Act applies to personal data collected in digital form, or collected on paper and then digitised (Section 3). If you store customer details in any software — billing, WhatsApp, a spreadsheet — you're likely covered, but the details depend on what you collect and how. Read our guide on whether the DPDP Act applies to your business for the edge cases, including the exemption for purely personal or household use.
Before you can protect data, you need to know where it lives — it's the first-month job in our 90-day DPDP implementation plan. Create a simple inventory:
A simple spreadsheet is fine. This becomes your Data Register — keep it updated.
List every third-party tool or service that handles customer data: Razorpay, Shiprocket, Google Analytics, Mailchimp, Tally, your billing software. Under DPDP, you are the Data Fiduciary and they are your Data Processors — you are responsible for their compliance. Check if they have a privacy policy and data processing terms.
Draft a privacy notice that covers: what data you collect, why, who you share it with, how long you keep it, and how customers can exercise their rights. Keep it simple — one A4 page in plain language. Publish it on your website footer, Instagram bio link, or WhatsApp pinned message.
Define how you'll get consent from customers before collecting their data. For a WhatsApp business, this might be a standard message you send to all new customers. For a Shopify store, it's a checkbox at checkout. For a physical store, it could be a QR code at the counter that opens a digital consent form.
Consent must be explicit, specific, and documented. "They gave me their number so it's fine" is not consent under the DPDP Act.
Create a way for customers to ask about their data, request corrections, or ask for deletion. Minimum viable: a dedicated email address (privacy@yourbusiness.in) and a documented process for what to do when a request arrives. The DPDP Rules don't fix a single statutory deadline for responding — instead, they require you to publish how customers can exercise their rights and the time period within which you'll respond (Rule 14). Pick a target you can actually meet — many businesses commit to 30 days — and state it in your privacy notice.
"Reasonable security safeguards" is the legal standard — one of the core responsibilities every business carries. For an SMB, this means:
Every person who handles customer data needs to know the basics: what data you collect, why, how to handle customer requests, and what to do if there's a potential breach. A one-hour team session with a written summary is sufficient for most SMBs. Document that you did it. Our staff training guide includes a ready-made session plan.
Your contracts with Data Processors (delivery partners, payment gateways) should include data protection clauses. These are often called Data Processing Agreements (DPAs) — our guide to what your contracts must say covers them in detail. Most large providers (Google, Meta, Razorpay) already offer these. Review and sign them.
If any of your customers might be under 18 — schools, coaching centres, apps, gaming, children's products — you must implement parental consent verification. This is non-negotiable and carries the highest penalty (₹200 Crore). If you're in this category, contact EasyDP specifically about the parental consent flow.
Write down: what you'll do if customer data is compromised. Who to call, what to tell customers, how to notify the Data Protection Board. Keep this document somewhere everyone on your team can find it. Under Rule 7 of the DPDP Rules 2025, you must inform affected customers and the Board without delay on becoming aware of a breach, and then file the detailed breach information with the Board within 72 hours. Our guide to breach notification timelines under the DPDP Rules explains exactly what each notification must contain — you don't have time to figure out the process after a breach happens.
For customers whose data you collected before the law takes effect, the Act requires you to send them a DPDP-compliant notice as soon as reasonably practicable (Section 5(2)) — covering what data you hold, why, and how they can exercise their rights or withdraw consent. Their earlier consent continues to be valid until they withdraw it, so this is a notification exercise rather than a fresh consent drive — but you need a plan to reach your existing database before enforcement begins in May 2027. EasyDP's multilingual notices can run that re-noticing batch in each customer's own language.
Decide how long you'll keep different types of data and when you'll delete it. The DPDP Act's principle is simple: keep personal data only as long as it's needed for the purpose you collected it for, or as long as another law requires you to keep it (Section 8(7)). The fixed three-year erasure timelines in the Rules apply only to very large platforms — e-commerce, social media, and gaming companies above user thresholds set in the Third Schedule — not to typical SMBs.
In practice, that means writing your own retention policy and being able to justify it. For example: tax and transaction records stay as long as GST and income-tax law require (roughly six years); marketing contacts stay until the person opts out; inactive customer accounts get deleted after a period you set and state in your privacy notice. Then actually implement deletion — if you're using Shopify, use their built-in anonymization feature. If it's a spreadsheet, set a calendar reminder to clean it annually.
The DPB can ask for evidence of your compliance efforts. Keep records of: when you updated your privacy notice, consent records for customers, DSRs received and resolved, breach incidents (even minor ones), staff training sessions, and third-party DPAs signed. EasyDP's audit logs build this evidence file automatically. This documentation is your defence if a complaint is ever filed against you.
This checklist is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Verify obligations and deadlines against the current notified text for your specific business.
The free DPDP checker asks six questions about your business and tells you which obligations — and which penalties — apply to you. It's the fastest way to complete Step 1.
Take the 2-minute checkerDownload the one-page PDF companion to this checklist — the same 14 steps in four quadrants, with a QR code back to this page. Pin it up next to the billing desk.
Download the PDF ↓Yes — the core obligations of the DPDP Rules 2025 apply from May 13, 2027, and each step maps to an obligation that will be enforceable from that date. Start with the Map & Document phase now: consent processes, staff training, and re-noticing your existing customer base take months, not days.
Want the reasoning behind each step? Read the long-form guides linked inside every step above, or start with the whole DPDP Act in plain English.