Home / Guide
A plain guide to data protection for Indian small and medium businesses.
No section numbers, no legal argument, and nothing you need a lawyer to decode. This is what the law asks of an ordinary business, when it starts to matter, and what to do about it in a sensible order.
The vocabulary, without the circling.
Data protection writing is full of words that sound interchangeable and are not. Here is what we mean when we use them, so nothing in a report needs decoding.
| Term | What it means in practice |
|---|---|
| Personal data | Any information about a person who can be identified from it. A name, a phone number, an order history, a photograph, a device identifier, a CCTV recording. It does not have to be sensitive to count. |
| Data Fiduciary | The organisation that decides why personal data is collected and how it will be used. In almost every engagement, this is you. |
| Data Principal | The individual the data is about. Your customers, your employees, your members, the people who fill in your forms. |
| Processing | Anything you do with personal data. Collecting, storing, sorting, sharing, exporting, backing up and deleting all count. Simply holding a file is processing. |
| Processor | A vendor that handles personal data on your instructions, such as your payroll provider, support tool or courier. You stay responsible for what they do with it. |
| Consent | A clear, specific agreement given freely by the person, which they can withdraw as easily as they gave it. A pre-ticked box, a bundled checkbox or silence does not qualify. |
| Privacy notice | What you tell someone, at the point you collect their data, about what you are taking and why. It is separate from your terms of service and has to stand on its own. |
| Personal data breach | Any event where personal data is lost, exposed, altered or accessed by someone who should not have it. A misdirected email and a lost laptop both count, not only a hack. |
| Retention | How long you keep something before deleting it, and what triggers that deletion. Keeping data because deleting it never came up is not a retention position. |
| Evidence pack | The dated, indexed set of documents showing what you assessed, what you decided and what you built. The thing you reach for if anyone asks. |
1. What the law actually asks for
Strip away the vocabulary and India's data protection law asks an organisation four things.
- Know what you hold. Be able to say what personal data the business has, where it sits, why you have it and who else sees it.
- Have a reason for holding it. Either the person agreed, in a way you can evidence, or you fall within one of a short list of permitted uses.
- Tell people, in language they understand. At the point you collect something, say what you are taking and why.
- Look after it, and let go of it. Keep it reasonably secure, let people see, correct or delete it, and stop holding it when you no longer need it.
Everything else is detail hanging off those four. A business that can genuinely do all four is in a good position, whatever its paperwork looks like. A business with excellent paperwork and no idea what it holds is not.
2. Whether it applies to you
It almost certainly does. The obligations follow the personal data rather than your size, your turnover or whether you have a website. If you hold customer phone numbers, employee records or a list of enquiries, you are in scope.
Size changes proportion, not application. A fifteen person business is not expected to build what a bank builds. It is expected to do something sensible and be able to show that it thought about it. That distinction is the single most useful thing to understand, because it is what stops this becoming either a panic or a pointless expense.
Two situations add requirements rather than changing the basics. If you hold data about people under eighteen, you need verified permission from a parent or guardian and you cannot track or target them. If you serve customers outside India, another framework may apply to the same systems alongside this one.
3. When you need to be ready
The law passed in 2023. The rules under it commence in stages rather than all at once, which has caused a lot of confusion and a certain amount of opportunistic marketing.
The practical position for an ordinary business is this. The regulator and the definitions are already in force. The machinery around consent managers comes into effect earlier than the rest. The substantive obligations on organisations are expected to apply from May 2027.
That sounds comfortable but it might not be so in reality. The work is not paperwork, it is discovery followed by change. Finding every place personal data sits takes weeks. Fixing what you find takes developer time, vendor conversations and habit change across a team. Businesses that start three months before a deadline do not finish.
The sensible reading is that 2026 is for finding out where you stand and fixing the serious things, and 2027 is for being able to demonstrate it. If you do nothing until the deadline is visible, you will be buying whatever is available rather than what you need.
4. The six things every business needs
Regardless of sector or size, these six come up every time.
A record of what you hold
One sheet, one row per activity. What data, about whom, why, where it lives, who else gets it, how long you keep it, who owns it. This is dull, it takes the longest, and it is the thing everything else depends on. Do not skip it and start with a privacy policy.
A privacy notice that is true
Written from the record above rather than copied. If your notice does not mention the courier, the marketing platform and the support tool, it does not describe your business.
Consent you can evidence
Where you rely on agreement, it has to be specific, freely given, recorded, and as easy to withdraw as it was to give. One checkbox covering terms, marketing and data sharing at once does not meet that. Neither does a pre-ticked box.
Data terms with your vendors
Your payroll provider, courier, marketing platform and support tool all handle personal data for you. You remain answerable for what they do with it, so the contract needs to say something about it.
A rule that deletes things
Decide how long each category is kept and what triggers deletion, then make deletion actually happen. Most businesses have never deleted anything, which means every old record is still exposure you are carrying for no benefit.
A plan for the bad day
Who to call, what to check, what to write down, who has to be told and how quickly. Written before you need it, and walked through once so you know it works.
5. Five things people get wrong
"We are too small for this"
Size changes what is proportionate, not whether the law applies.
"We bought a consent tool, so we are covered"
A tool records consent. It does not know which of your activities need consent, which rest on something else, what your vendors do afterwards, or when anything should be deleted. Bought before the map exists, it gets configured around guesses, and a confident record of the wrong consent is worse than no record.
"Our privacy policy covers it"
A privacy policy is a description. If it does not match what the business actually does, it is a description of a different company, and it will be the first document anyone asks for.
"We will deal with it when the rules bite"
The work is discovery and change, not drafting. Drafting is the fast part. Finding out what you hold and getting your team and vendors to change behaviour is what takes the time.
"It is a legal problem"
No, it is a techno-legal problem. For small businesses, facts change what legal advice could be. How many systems hold customer data, which tools did the team start using, who still has access to the drive/cloud storage. Those are answered by looking at the data, design and infrastructure, and then supported by legal advice.
6. What to do in the next thirty days
If you do nothing else this quarter, do these. None of them need a consultant.
- Week one. List every tool the business pays for or uses, including the free ones. Ask each team which systems they personally use, because the list from finance and the list from the team will not match.
- Week two. For each one, write down what personal data is in it and who has access. Mark the ones holding identity documents, financial details or anything about children.
- Week three. Check who still has access who should not. Former staff, former agencies, former freelancers. This usually produces the fastest risk reduction of anything on this list, and it costs nothing.
- Week four. Read your privacy policy against your list. Note everything it does not mention. Do not rewrite it yet, just record the gap.
At the end of that month you will have something most businesses of your size do not: a factual picture. Whether you then do the work internally, hire us, or hire someone else, you will be making an informed decision instead of buying a solution to a problem nobody has defined.
If you want a quicker read on where you stand, the ten question readiness check takes about three minutes and sends nothing to us.
7. The words you will keep meeting
These turn up in every document on this subject. A fuller list sits on our about page.
- Personal data. Anything about a person who can be identified from it. A phone number, an order history, a photograph, a CCTV recording. It does not have to be sensitive to count.
- Data Fiduciary. The organisation deciding why data is collected and how it is used. In nearly every case, that is you.
- Data Principal. The individual the data is about. Your customers, staff and members.
- Processing. Anything you do with it, including simply storing it.
- Processor. A vendor handling data on your instructions. You stay responsible for them.
- Privacy notice. What you tell someone when you collect their data. Separate from your terms of service.
- Personal data breach. Any loss, exposure or unauthorised access. A misdirected email counts, not just a hack.
Find out where your business actually stands.
Three minutes in your browser, or thirty minutes with us. Both are free and neither commits you to anything.