The Digital Personal Data Protection Act applies to shops, clinics, coaching centres and startups, not just large companies. Here are five practical first steps.
The Digital Personal Data Protection Act, 2023 applies to anyone who processes personal data of individuals in digital form in India — which includes most shops, clinics, coaching centres, agencies and startups that keep customer records on a computer or phone. Its rules were notified in 2025 with a phased start, so obligations are arriving in stages.
Five first steps
- Know what you collect. List the personal data you hold — customer names and numbers, patient records, employee files — where it is kept, and who can see it.
- Say why, clearly. Customers must be told what data you collect and why, in plain language. A clear privacy notice on your website and at the counter is the starting point.
- Collect less. Do not collect data you do not need, and delete what you no longer need.
- Check your vendors. Billing software, CRM tools and cloud storage providers process data for you. You remain responsible for what they do, so you need a written contract with them.
- Plan for a breach. Personal data breaches must be reported to the Data Protection Board and to affected people. Decide now who in your business will do that.
Children’s data
Under the Act a child is anyone under eighteen, and processing children’s data needs verifiable parental consent. Tracking and targeted advertising directed at children is prohibited. Schools, coaching centres and apps used by teenagers need to take particular care.
Our DPDP privacy policy guide explains the Act in detail, and our SaaS agreement guide explains the contracts you need with software vendors.
News on this page is general information, not legal advice. For your own matter, talk to our team, or find an advocate for court work — the advocate’s fee is engaged and paid by you directly.