Whatever your size or sector, if you process personal data, a common baseline of responsibility applies. Here’s what sits inside that baseline.
1. A lawful basis for every category of personal data you process — consent, or a legitimate use, never assumed.
2. A notice that actually meets the Rules’ content requirements, not a generic privacy-policy paragraph.
3. Reasonable security safeguards, applied continuously — not a one-time setup exercise.
4. A working process for the rights people can exercise — access, correction, erasure, grievance, nomination.
5. A breach response plan that’s been thought through before it’s needed, not improvised afterward.
2. A notice that actually meets the Rules’ content requirements, not a generic privacy-policy paragraph.
3. Reasonable security safeguards, applied continuously — not a one-time setup exercise.
4. A working process for the rights people can exercise — access, correction, erasure, grievance, nomination.
5. A breach response plan that’s been thought through before it’s needed, not improvised afterward.
None of this scales down for small organisations the way some other compliance regimes do. The DPDP Act’s core obligations apply whether you’re a two-person startup or a national bank — what changes with size is how much infrastructure you need to meet them, not whether you have to.
There’s no small-business exemption from the basics. Only a difference in how much work meeting them takes.
NEXT —
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf  ·  The DPDP Rules, 2025 — official text, MeitY — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdfÂ