By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
A small business that decides why customer or employee data is collected is a Data Fiduciary under the DPDP Act, 2023. With the DPDP Rules notified on 13 November 2025 and commencement phased into 2027, readiness means ten controls: a data map, notice and consent, purpose limitation, access control, retention, a breach playbook, vendor terms, a cross-border record, a rights tracker and a children’s-data flow.
What is the DPDP Act’s core bargain for a small business?
Short answer: Collect only what is needed, on clear consent with notice, use it only for the stated purpose, keep it accurate and secure, retain it only as long as required, and honour grievance and deletion requests. The Data Fiduciary bears the accountability; processors and vendors act only on documented instructions. Small businesses are fiduciaries whenever they decide purposes — billing, marketing, HR, support logs. Even a contact form plus WhatsApp marketing creates fiduciary duties. Mapping what data exists, where it sits, and why it is kept is therefore step zero; everything else follows the map.
How should consent and notice be fixed first?
Short answer: Consent must be free, specific, informed, unconditional, and withdrawable, preceded by a notice stating what is collected, why, and how to withdraw or complain. Pre-ticked boxes, bundled consents, and dark patterns do not qualify, and consent managers become available under the phased Rules. Practical fix: rewrite each collection point — forms, checkout, app permissions — with purpose-specific checkboxes, a linked notice in plain language, and a logged timestamp. Store the consent artefact; it is the first document the Board or a complainant will ask for.
What security, breach, and retention controls are expected?
Short answer: Reasonable security safeguards, breach notification to affected principals and the Data Protection Board within the Rule 7 timelines, and deletion on purpose-fulfilment or withdrawal are the operational core, sitting alongside the CERT-In 6-hour incident-reporting clock where it applies. Retention schedules and access controls evidence the control. Small-team implementation means MFA on admin accounts, least-privilege access, encrypted backups, a one-page breach playbook with owner and phone numbers, and a retention table (data → purpose → period → deletion method). Logs of access and deletion close the loop; undocumented controls are treated as absent.
How should vendors, processors, and cross-border storage be handled?
Short answer: Vendors processing data on the business’s behalf need written DPDP-aligned instructions covering purpose, categories, security, sub-processors, breach notice, audit, and exit deletion, with cross-border transfers assessed under Section 16 and Rule 15. The fiduciary remains answerable for vendor failures. Inventory every sub-processor — payment gateway, CRM, email, analytics, cloud region — record hosting locations, and add the DPA schedule to renewals. Where children’s data or high-volume sensitive data is involved, reassess necessity first; avoidance beats paperwork.
What rights and grievance workflow must work?
Short answer: Data principals hold rights to access, correction, erasure, nomination, and grievance redressal, and the fiduciary must publish grievance means and resolve complaints within prescribed timelines before Board escalation. A working email, tracker, and template replies constitute the minimum viable workflow. Assign one owner, acknowledge promptly, verify identity proportionately, act or reason refusal in writing, and log the outcome. Children’s data and verifiable parental consent need a separate documented flow under Section 9 and Rules 10/12 where applicable.
How should HR and employee data be brought into scope?
Short answer: HR data — resumes, salary, attendance, health-adjacent records, and exit files — needs the same map, purpose, access, and retention discipline as customer data, with narrower access and clearer deletion on exit. Offer letters and HR policies should state purposes, retention, and grievance means in plain language. Practical steps include segregating HR folders from shared drives, limiting payroll access, documenting background-verification consent, and fixing an exit checklist that revokes access and schedules deletion. Employee grievances about data misuse follow the same tracker as customer requests, with identity verification proportionate to sensitivity.
What marketing, cookies, and analytics hygiene is required?
Short answer: Marketing lists, cookies, pixels, and analytics need purpose-specific consent, opt-out paths, and vendor records — purchased databases and silent tracking contradict the consent bargain. Each campaign should trace to a consent source, each cookie to a disclosed purpose, and each analytics vendor to the sub-processor register. Fixes include consent-mode banners with reject-as-easy-as-accept, UTM-to-consent linkage for lead forms, suppression lists honoured across tools, and periodic purging of stale contacts. Children’s or student audiences trigger the higher Section 9 parental-consent flow; where age cannot be assured, avoid targeting that segment.
Readiness checklist (10 controls)
| # | Control | Evidence of compliance |
|---|---|---|
| 1 | Data map (what/where/why) | Inventory sheet |
| 2 | Notice + consent artefacts | Logged consent records |
| 3 | Purpose limitation | Collection-point audit |
| 4 | Access control + MFA | Access matrix, MFA log |
| 5 | Retention + deletion schedule | Retention table, deletion certs |
| 6 | Breach playbook (DPDP + CERT-In clocks) | One-page playbook, drill date |
| 7 | Vendor DPAs + sub-processor list | Signed schedules |
| 8 | Cross-border record (s.16/R.15) | Hosting-region register |
| 9 | Rights + grievance tracker | Ticket log, templates |
| 10 | Children’s-data flow (if any) | Parental-consent SOP |
How should incidents be drilled and documented before the Board acts?
Short answer: Incident readiness means a named owner, a contact sheet, a containment checklist, and a practice drill, so that breach assessment, principal notification, Board notification, and CERT-In reporting each trigger on time with logged decisions. Undrilled teams discover missing passwords, access, and vendor contacts during the incident itself. Run a tabletop exercise: simulate a leaked spreadsheet or compromised inbox, walk through containment, assessment, and notification decisions, and record lessons with assigned fixes. File the drill date, attendees, and action items alongside the breach playbook; that file evidences reasonable safeguards and accountability far better than a policy nobody has opened. Re-drill when vendors, systems, or team members change, and keep the contact sheet current.
Primary sources
- DPDP Act 2023; DPDP Rules 2025, G.S.R. 846(E) 13.11.2025 (MeitY/Gazette); commencement G.S.R. 843(E) 13.11.2025.
- CERT-In Directions 28.04.2022 + FAQs 18.05.2022; DPDP ss.9/10/16; Rules 7/10/12/13/15.
FAQ
