---
title: "DPDP Readiness Checklist for Small Business"
description: "Explains ten practical DPDP readiness controls for small businesses — data mapping, notices, consent, breach response and vendor terms. Information only."
url: "https://advaslam.com/guides/dpdp-readiness-checklist-small-business/"
image: "https://advaslam.com/og/guides/dpdp-readiness-checklist-small-business.png"
---

[Data protection & DPDP compliance](https://advaslam.com/practice/data-protection/) · Guide

# DPDP Readiness Checklist for Kerala Small Businesses

By [**Adv. K J Muhammed Aslam**](https://advaslam.com/profile/) · Advocate, Ernakulam (Bar Council of Kerala)

Published 22 September 2026

A small business that decides why customer or employee data is collected is a Data Fiduciary under the DPDP Act, 2023. With the DPDP Rules notified on 13 November 2025 and commencement phased into 2027, readiness means ten controls: a data map, notice and consent, purpose limitation, access control, retention, a breach playbook, vendor terms, a cross-border record, a rights tracker and a children’s-data flow.

## What is the DPDP Act’s core bargain for a small business?

**Short answer:** Collect only what is needed, on clear consent with notice, use it only for the stated purpose, keep it accurate and secure, retain it only as long as required, and honour grievance and deletion requests. The Data Fiduciary bears the accountability; processors and vendors act only on documented instructions. Small businesses are fiduciaries whenever they decide purposes — billing, marketing, HR, support logs. Even a contact form plus WhatsApp marketing creates fiduciary duties. Mapping what data exists, where it sits, and why it is kept is therefore step zero; everything else follows the map.

## How should consent and notice be fixed first?

**Short answer:** Consent must be free, specific, informed, unconditional, and withdrawable, preceded by a notice stating what is collected, why, and how to withdraw or complain. Pre-ticked boxes, bundled consents, and dark patterns do not qualify, and consent managers become available under the phased Rules. Practical fix: rewrite each collection point — forms, checkout, app permissions — with purpose-specific checkboxes, a linked notice in plain language, and a logged timestamp. Store the consent artefact; it is the first document the Board or a complainant will ask for.

## What security, breach, and retention controls are expected?

**Short answer:** Reasonable security safeguards, breach notification to affected principals and the Data Protection Board within the Rule 7 timelines, and deletion on purpose-fulfilment or withdrawal are the operational core, sitting alongside the CERT-In 6-hour incident-reporting clock where it applies. Retention schedules and access controls evidence the control. Small-team implementation means MFA on admin accounts, least-privilege access, encrypted backups, a one-page breach playbook with owner and phone numbers, and a retention table (data → purpose → period → deletion method). Logs of access and deletion close the loop; undocumented controls are treated as absent.

## How should vendors, processors, and cross-border storage be handled?

**Short answer:** Vendors processing data on the business’s behalf need written DPDP-aligned instructions covering purpose, categories, security, sub-processors, breach notice, audit, and exit deletion, with cross-border transfers assessed under Section 16 and Rule 15. The fiduciary remains answerable for vendor failures. Inventory every sub-processor — payment gateway, CRM, email, analytics, cloud region — record hosting locations, and add the DPA schedule to renewals. Where children’s data or high-volume sensitive data is involved, reassess necessity first; avoidance beats paperwork.

## What rights and grievance workflow must work?

**Short answer:** Data principals hold rights to access, correction, erasure, nomination, and grievance redressal, and the fiduciary must publish grievance means and resolve complaints within prescribed timelines before Board escalation. A working email, tracker, and template replies constitute the minimum viable workflow. Assign one owner, acknowledge promptly, verify identity proportionately, act or reason refusal in writing, and log the outcome. Children’s data and verifiable parental consent need a separate documented flow under Section 9 and Rules 10/12 where applicable.

## How should HR and employee data be brought into scope?

**Short answer:** HR data — resumes, salary, attendance, health-adjacent records, and exit files — needs the same map, purpose, access, and retention discipline as customer data, with narrower access and clearer deletion on exit. Offer letters and HR policies should state purposes, retention, and grievance means in plain language. Practical steps include segregating HR folders from shared drives, limiting payroll access, documenting background-verification consent, and fixing an exit checklist that revokes access and schedules deletion. Employee grievances about data misuse follow the same tracker as customer requests, with identity verification proportionate to sensitivity.

## What marketing, cookies, and analytics hygiene is required?

**Short answer:** Marketing lists, cookies, pixels, and analytics need purpose-specific consent, opt-out paths, and vendor records — purchased databases and silent tracking contradict the consent bargain. Each campaign should trace to a consent source, each cookie to a disclosed purpose, and each analytics vendor to the sub-processor register. Fixes include consent-mode banners with reject-as-easy-as-accept, UTM-to-consent linkage for lead forms, suppression lists honoured across tools, and periodic purging of stale contacts. Children’s or student audiences trigger the higher Section 9 parental-consent flow; where age cannot be assured, avoid targeting that segment.

## Readiness checklist (10 controls)

| #   | Control | Evidence of compliance |
| --- | --- | --- |
| 1   | Data map (what/where/why) | Inventory sheet |
| 2   | Notice + consent artefacts | Logged consent records |
| 3   | Purpose limitation | Collection-point audit |
| 4   | Access control + MFA | Access matrix, MFA log |
| 5   | Retention + deletion schedule | Retention table, deletion certs |
| 6   | Breach playbook (DPDP + CERT-In clocks) | One-page playbook, drill date |
| 7   | Vendor DPAs + sub-processor list | Signed schedules |
| 8   | Cross-border record (s.16/R.15) | Hosting-region register |
| 9   | Rights + grievance tracker | Ticket log, templates |
| 10  | Children’s-data flow (if any) | Parental-consent SOP |

## How should incidents be drilled and documented before the Board acts?

**Short answer:** Incident readiness means a named owner, a contact sheet, a containment checklist, and a practice drill, so that breach assessment, principal notification, Board notification, and CERT-In reporting each trigger on time with logged decisions. Undrilled teams discover missing passwords, access, and vendor contacts during the incident itself. Run a tabletop exercise: simulate a leaked spreadsheet or compromised inbox, walk through containment, assessment, and notification decisions, and record lessons with assigned fixes. File the drill date, attendees, and action items alongside the breach playbook; that file evidences reasonable safeguards and accountability far better than a policy nobody has opened. Re-drill when vendors, systems, or team members change, and keep the contact sheet current.

## Primary sources

-   [DPDP Act 2023](https://indiacode.gov.in/handle/123456789/496508); DPDP Rules 2025, [G.S.R. 846(E) 13.11.2025](https://egazette.gov.in/WriteReadData/2025/267650.pdf) ([MeitY](https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf)/Gazette); commencement [G.S.R. 843(E) 13.11.2025](https://egazette.gov.in/WriteReadData/2025/267647.pdf).
-   [CERT-In Directions 28.04.2022](https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf) + FAQs 18.05.2022; DPDP ss.9/10/16; Rules 7/10/12/13/15.

FAQ

## Common questions

**Does DPDP apply to offline registers?**

Yes, where personal data is digitised or processed digitally. The map should include registers later entered into systems.

**What is the CERT-In vs DPDP clock confusion?**

CERT-In Directions impose a 6-hour incident report for covered entities; DPDP Rule 7 imposes Board and principal notification on its own timeline. Assess both; neither excuses the other.

**Do small businesses need a Data Protection Officer?**

Only Significant Data Fiduciaries carry the DPO/DPIA/audit load under Section 10. Small businesses need the ten controls above, scaled sensibly.

**What penalties apply?**

Graded penalties under the Act's schedule apply after commencement of the penalty provisions. Preparation now reduces exposure later.

**Where do we start this month?**

Data map, consent-notice rewrite, MFA plus backups, and the breach playbook — in that order.

**Related matters.** The matter entries this guide draws on:

-   [S.5 notice drafting — Malayalam + English](https://advaslam.com/practice/data-protection/matters/applicability-fiduciary-notices-consent/#section-5-notice-drafting-malayalam-english-item-by-item)
-   [Consent-flow design — five tests](https://advaslam.com/practice/data-protection/matters/applicability-fiduciary-notices-consent/#consent-flow-design-free-specific-informed-unconditional-unambiguous)
-   [Grievance-first rule before the Board](https://advaslam.com/practice/data-protection/matters/rights-children-employee-cctv-retention/#grievance-first-rule-board-will-not-hear-you-before-the-fiduciary-does)
-   [72-hour breach notices](https://advaslam.com/practice/data-protection/matters/vendor-security-breach-grievance/#72-hour-without-delay-notices-board-and-each-affected-principal)

**A note on this guide.** It is general legal information, not legal advice. The law may have changed since the date shown; before acting on anything here, take advice on your specific situation from an advocate of your choice.

Keep reading

Data protection & DPDP compliance

### The DPDP countdown: what Indian businesses must do before 14 May 2027

DPDP Act compliance explained: the DPDP Rules 2025 timeline, the 14 November 2026 Consent Manager date, and obligations and penalties from 14 May 2027.

16 Aug 2026

[The DPDP countdown: what Indian businesses must do before 14 May 2027](https://advaslam.com/writing/dpdp-act-deadline-businesses/)

Data protection & DPDP compliance

### DPDP Compliance Guide for Kerala Businesses to May 2027

DPDP readiness for Kerala SMEs: phased timeline to May 2027, notices, safeguards, breach response, rights, children, SDF, transfer, contracts, penalties.

25 Sept 2026

[DPDP Compliance Guide for Kerala Businesses to May 2027](https://advaslam.com/writing/dpdp-compliance-guide-kerala-businesses/)

Data protection & DPDP compliance

### CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?

India has two breach clocks that both apply: CERT-In's 6 hours and DPDP Rule 7's 72 hours. Who reports to whom, when each starts, and one playbook for both.

1 Sept 2026

[CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?](https://advaslam.com/writing/cert-in-6-hour-vs-dpdp-72-hour-breach-reporting/)

Contact

[WhatsApp](https://wa.me/919497240215?text=Hello%2C%20I%20found%20advaslam.com%20and%20would%20like%20to%20discuss%20a%20matter.) [contact@advaslam.com](mailto:contact@advaslam.com) [+91 94972 40215](tel:+919497240215)

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

```json
{"@context":"https://schema.org","@graph":[{"@type":"WebSite","@id":"https://advaslam.com/#website","url":"https://advaslam.com","name":"Adv. K J Muhammed Aslam","alternateName":"advaslam.com","publisher":{"@id":"https://advaslam.com/#person"},"inLanguage":"en-IN"},{"@type":"Person","@id":"https://advaslam.com/#person","name":"K J Muhammed Aslam","alternateName":["Adv. K J Muhammed Aslam","Advocate K J Muhammed Aslam","Muhammed Aslam K J","Adv. Aslam"],"honorificPrefix":"Adv.","jobTitle":"Advocate","description":"Advocate enrolled with the Bar Council of Kerala, practising from High Court Junction, Ernakulam: cyber and technology law, data protection (DPDP), business, banking and IPR, and litigation before the High Court of Kerala and the courts at Ernakulam.","url":"https://advaslam.com/profile/","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"alumniOf":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"memberOf":[{"@type":"Organization","name":"Bar Council of Kerala","url":"https://barcouncilkerala.org/lawyer-registry-list"},{"@type":"Organization","name":"Kerala High Court Advocates' Association","url":"https://khcaa.com/"}],"identifier":[{"@type":"PropertyValue","propertyID":"Bar Council of Kerala Enrolment No.","value":"K/001823/2026"},{"@type":"PropertyValue","propertyID":"KHCAA Membership No.","value":"OAJ 358"}],"knowsAbout":["Information Technology Act 2000","Cyber crime law","Technology law and technology contracts","Digital Personal Data Protection Act 2023","DPDP compliance","Data protection and privacy law","Business and commercial law","Contract drafting and negotiation","Banking and finance law","Negotiable Instruments Act cheque dishonour","SARFAESI Act","Intellectual property law","Copyright and trademark law","Patent infringement","GST and income-tax law","Blockchain and cryptocurrency technology","Web3 wallets and NFTs","Drone regulation and DigitalSky framework","Writ petitions under Article 226","Criminal law","Civil and consumer litigation","Family and succession law","Service and labour law","Legal drafting","Mediation and dispute resolution"],"knowsLanguage":["en","ml"],"workLocation":{"@id":"https://advaslam.com/#practice"},"hasCredential":[{"@type":"EducationalOccupationalCredential","credentialCategory":"Enrolment as an advocate","identifier":"K/001823/2026","recognizedBy":{"@type":"Organization","name":"Bar Council of Kerala"},"description":"Enrolled as an advocate with the Bar Council of Kerala (K/001823/2026), 2026"},{"@type":"EducationalOccupationalCredential","credentialCategory":"degree","educationalLevel":"Bachelor","recognizedBy":{"@type":"CollegeOrUniversity","name":"Bharata Mata School of Legal Studies"},"description":"BBA LLB (Hons.), Bharata Mata School of Legal Studies (2025)"},{"@type":"EducationalOccupationalCredential","credentialCategory":"Remote Pilot Certificate","recognizedBy":{"@type":"Organization","name":"Directorate General of Civil Aviation, India"},"description":"DGCA Remote Pilot Certificate, issued 2022"}],"subjectOf":[{"@type":"CreativeWork","name":"Govind Babu v. State of Kerala (Crl.M.C. No. 5640 of 2026, 2026:KER:69496)","url":"https://indiankanoon.org/doc/151180872/","datePublished":"2026-09-10","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Viji Sagar v. State of Kerala (Crl.M.C. No. 1603 of 2026, 2026:KER:20803)","url":"https://indiankanoon.org/doc/193042273/","datePublished":"2026-03-09","publisher":{"@type":"Organization","name":"High Court of Kerala"}},{"@type":"CreativeWork","name":"Anjana v. Manoharan A.P. (C.R.P. No. 442 of 2025, 2026:KER:10054)","url":"https://indiankanoon.org/doc/68585852/","datePublished":"2026-02-05","publisher":{"@type":"Organization","name":"High Court of Kerala"}}],"sameAs":["https://www.linkedin.com/in/azlubro","https://portal.khcaa.com/advocate?id=10480","https://lexosys.com"]},{"@type":"LegalService","@id":"https://advaslam.com/#practice","name":"Adv. K J Muhammed Aslam — Advocate, Ernakulam","url":"https://advaslam.com","image":"https://advaslam.com/og.png","telephone":"+919497240215","email":"contact@advaslam.com","address":{"@type":"PostalAddress","streetAddress":"3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction","addressLocality":"Ernakulam","addressRegion":"Kerala","postalCode":"682031","addressCountry":"IN"},"geo":{"@type":"GeoCoordinates","latitude":9.9889,"longitude":76.2748},"hasMap":"https://www.google.com/maps/search/?api=1&query=Lalan+Towers+High+Court+Junction+Ernakulam","areaServed":[{"@type":"City","name":"Ernakulam"},{"@type":"City","name":"Kochi"},{"@type":"State","name":"Kerala"},{"@type":"Country","name":"India"}],"openingHoursSpecification":{"@type":"OpeningHoursSpecification","dayOfWeek":["Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"opens":"10:00","closes":"18:30"},"founder":{"@id":"https://advaslam.com/#person"},"knowsAbout":["Cyber crime and IT Act matters","Data protection and DPDP Act compliance","Business, banking, intellectual property and tax","Legal drafting","Criminal law: bail, quash and appeals","Writ petitions before the High Court of Kerala","Civil, property and consumer matters","Family and succession matters","Service and labour matters"]},{"@type":"BlogPosting","@id":"https://advaslam.com/guides/dpdp-readiness-checklist-small-business/#article","isPartOf":{"@id":"https://advaslam.com/#website"},"headline":"DPDP Readiness Checklist for Small Business","description":"Explains ten practical DPDP readiness controls for small businesses — data mapping, notices, consent, breach response and vendor terms. Information only.","url":"https://advaslam.com/guides/dpdp-readiness-checklist-small-business/","mainEntityOfPage":"https://advaslam.com/guides/dpdp-readiness-checklist-small-business/","datePublished":"2026-09-22T00:00:00.000Z","dateModified":"2026-09-22T00:00:00.000Z","keywords":"DPDP readiness checklist, DPDP small business Kerala, consent notice DPDP, breach reporting DPDP, data mapping SME, DPDP vendor terms","inLanguage":"en-IN","author":{"@id":"https://advaslam.com/#person"},"publisher":{"@id":"https://advaslam.com/#person"},"image":"https://advaslam.com/og/guides/dpdp-readiness-checklist-small-business.png","about":{"@type":"Service","@id":"https://advaslam.com/practice/data-protection/#service","name":"Data protection & DPDP compliance","url":"https://advaslam.com/practice/data-protection/","provider":{"@id":"https://advaslam.com/#practice"}}},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://advaslam.com/"},{"@type":"ListItem","position":2,"name":"Guides","item":"https://advaslam.com/guides/"},{"@type":"ListItem","position":3,"name":"DPDP Readiness Checklist for Kerala Small Businesses","item":"https://advaslam.com/guides/dpdp-readiness-checklist-small-business/"}]},{"@type":"FAQPage","mainEntity":[{"@type":"Question","name":"Does DPDP apply to offline registers?","acceptedAnswer":{"@type":"Answer","text":"Yes, where personal data is digitised or processed digitally. The map should include registers later entered into systems."}},{"@type":"Question","name":"What is the CERT-In vs DPDP clock confusion?","acceptedAnswer":{"@type":"Answer","text":"CERT-In Directions impose a 6-hour incident report for covered entities; DPDP Rule 7 imposes Board and principal notification on its own timeline. Assess both; neither excuses the other."}},{"@type":"Question","name":"Do small businesses need a Data Protection Officer?","acceptedAnswer":{"@type":"Answer","text":"Only Significant Data Fiduciaries carry the DPO/DPIA/audit load under Section 10. Small businesses need the ten controls above, scaled sensibly."}},{"@type":"Question","name":"What penalties apply?","acceptedAnswer":{"@type":"Answer","text":"Graded penalties under the Act's schedule apply after commencement of the penalty provisions. Preparation now reduces exposure later."}},{"@type":"Question","name":"Where do we start this month?","acceptedAnswer":{"@type":"Answer","text":"Data map, consent-notice rewrite, MFA plus backups, and the breach playbook — in that order."}}]}]}
```
