Compliance

DPDP Act Compliance for Indian Businesses — What You Actually Need to Do

· 7 min read

There is a particular kind of silence in a room when someone says "Are we DPDP compliant?" and nobody answers. Not because nobody cares, but because nobody knows what the question actually means for a business that runs a WhatsApp broadcast list, an email newsletter and a CRM full of phone numbers collected at a trade show three years ago.

India's Digital Personal Data Protection Act, 2023 is not a future problem. It is law. The rules are notified, the Data Protection Board is constituted, and the penalties run up to Rs 250 crore per breach. Yet most Indian SMBs are treating it like demonetisation — something that will definitely happen, just not today.

This guide is for the business owner who does not have a compliance officer, a legal team, or a budget line for "privacy infrastructure." It is for the person who runs the business and manages the customer data and sends the campaigns and now has to figure out what the DPDP Act means for all of that.

What the DPDP Act Actually Requires From You

Strip away the legalese and the Act asks five things of every business that handles personal data:

  1. Know what data you hold and why. You cannot protect what you have not inventoried. Every name, email, phone number, WhatsApp number and purchase history you store is "digital personal data" under the Act.
  2. Collect it with clear, informed consent. Not buried in a 4,000-word terms page nobody reads. The consent request must be in plain language, specific to the purpose, and withdrawable at any time.
  3. Let people see, correct and delete their data. The Act calls them "Data Principals." They have the right to know what you hold, correct inaccuracies, and request erasure — and you must respond within the prescribed timelines.
  4. Keep it only as long as needed. Data collected for a Diwali campaign in 2024 has no business sitting in your CRM in 2027 if the customer never bought anything and never opted in to future communication.
  5. Report breaches. If personal data is compromised, you must notify the Data Protection Board and the affected individuals. "We didn't know it happened" is not a defence.

Where Indian SMBs Typically Fail

Having worked with businesses across the spectrum — from solo consultants to 50-person agencies — the failure points are remarkably consistent:

Spreadsheet CRMs. Contact data lives in Google Sheets shared with six people, two of whom left the company. Nobody knows who has access. Nobody can tell you where a specific customer's data is or how to delete it. Responding to a deletion request means manually hunting through 14 tabs and hoping you found everything.

WhatsApp broadcasts from personal phones. Customer numbers stored in the phone's contact list, mixed with personal contacts. No export path, no deletion mechanism, no audit trail of who was contacted and when. The phone is the database, and if it breaks, the "database" is gone.

Email lists with no opt-out. A Mailchimp audience built from business cards collected at events. Half the people don't remember signing up. There is no consent record, no unsubscribe mechanism that actually removes the person from every list, and no way to prove when consent was given.

No data export capability. A customer asks "What data do you have on me?" and the business owner has to spend two hours pulling records from three different tools, copying them into a Word document, and emailing it. For one request. Now imagine fifty.

What "Being Compliant" Looks Like in Practice

Compliance is not a certificate you buy or a checkbox you tick. It is a set of operational capabilities your business either has or does not have. Here is what the practical setup looks like:

A single system of record for customer data. One place where every contact, every consent choice, every communication and every data request lives. Not five tools stitched together with manual processes — one source of truth.

Consent tracking per channel. Knowing that a customer opted in to WhatsApp marketing does not mean they consented to email. Consent is per-purpose and per-channel. Your system needs to record what each person agreed to, when they agreed, and let them withdraw any of those individually.

In LigiComms, the built-in CRM tracks consent per channel per contact. If someone unsubscribes from WhatsApp but wants to keep receiving email, that is exactly what happens — no manual juggling across tools.

Self-service data export. When a customer exercises their right to data portability, your response should not involve two hours and a Word document. It should be a button that generates a structured download of everything you hold on them — or, at the business level, everything your business holds across the platform.

LigiComms includes a self-service data export directly in the dashboard. One click packages your posts, contacts, templates, messages, analytics, invoices and settings into a downloadable ZIP. No support ticket required.

Self-service account deletion. The Act gives individuals the right to erasure. At the business level, that means the account owner must be able to permanently delete the workspace and all its data without needing to send an email and wait. LigiComms offers permanent account deletion from the profile — confirm with your email, and it is done. A reactivation link is emailed in case you change your mind; after the window, the data is gone.

Encrypted credential storage. Every channel token, SMTP password, SMS API key and WhatsApp credential must be encrypted at rest — not just "in the database" but with authenticated encryption where the keys are managed separately from the data. A breach of the database alone should not expose usable credentials.

The Consent Problem Nobody Talks About

Most Indian businesses collected their contact lists before the DPDP Act was notified. Trade show business cards from 2022. WhatsApp contacts added from walk-in customers in 2023. Email addresses from a website form that said "Subscribe to updates" without specifying what "updates" meant.

The Act does not retroactively invalidate all pre-existing data, but it does require that you can demonstrate a lawful basis for continuing to process it. For most SMBs, that means:

  • Sending a one-time re-consent campaign to your existing list — a clear, honest message asking people to confirm they want to keep hearing from you.
  • Honouring every opt-out immediately, across every channel — not "we'll remove you in 7-10 business days."
  • Deleting contacts who do not re-consent within a reasonable window. Yes, your list will shrink. But a list of 500 people who actually want your messages outperforms a list of 5,000 who don't — in deliverability, in engagement, and now in legal risk.

Breach Notification: The Clock You Cannot Stop

If personal data you hold is compromised — whether by a hack, a misconfigured server, a lost device or an employee mistake — the DPDP Act requires you to notify the Data Protection Board and the affected individuals. The rules prescribe timelines; "we'll get to it when we can" is not an option.

What this means operationally:

  • You need to know what data you hold — you cannot report a breach you cannot describe.
  • You need audit logs — who accessed what, when. Error logs, API interaction logs, login records.
  • You need encryption at rest — so a database breach does not automatically mean a data breach. If the credentials are encrypted with keys the attacker does not have, the exposure is mitigated.

This is where using a platform that handles security infrastructure for you matters. When your social-media tool, your CRM, your messaging and your wallet all live in one place with encryption, audit logging and access controls built in, you are not trying to secure five separate tools with five separate attack surfaces.

The Real Cost of Non-Compliance

The headline penalty is Rs 250 crore. That is not a realistic scenario for most SMBs — it is the ceiling for the largest enterprises. But the operational penalties are very real even at smaller scale:

  • Investigation costs. The Data Protection Board can investigate on complaint. Responding to an investigation — even one you survive — consumes weeks of management time.
  • Customer trust. One public data-handling complaint on social media does more damage to a local business than any fine.
  • Platform consequences. Meta, Google and telecom carriers are increasingly enforcing their own data-handling requirements. Non-compliant businesses get suspended from the platforms they depend on.

A Practical Checklist

If you take one thing from this article, take this checklist. Print it. Stick it on the wall behind your monitor.

  1. Do you know where all your customer data lives? Not "roughly" — exactly.
  2. Can you produce a complete export of any customer's data within hours, not days?
  3. Can a customer delete their relationship with you without sending an email and waiting?
  4. Do you track per-channel consent — WhatsApp separately from email separately from SMS?
  5. Are stored credentials encrypted at rest with keys managed separately from the data?
  6. Do you have audit logs that tell you who accessed what and when?
  7. Can you notify affected individuals within the prescribed timeframe if a breach occurs?

If you answered "no" to more than two of these, you are not ready. The good news is that every single one of these capabilities is a built-in feature of a modern platform, not a custom project. You do not need to build compliance infrastructure — you need to use a tool that already has it.

The DPDP Act does not ask you to become a data-protection expert. It asks you to handle personal data responsibly — which, if you think about it, is what your customers always expected. The law just gave them teeth.

Ready to simplify your social media?

Start your 14-day free trial of LigiComms. No credit card. No contracts. Just results.

Start free trial

Already using a tool you like? You can earn by recommending LigiComms instead → Affiliate Program