If your business collects customer names, phone numbers, emails, PAN or any personal information — and almost every business does — the Digital Personal Data Protection (DPDP) Act, 2023 matters to you. It sets rules for how personal data must be collected, used and protected.
The core idea: consent
You can collect personal data only for a clear, lawful purpose, and generally only with the person's consent. That consent must be informed — the customer should know what you're collecting and why. You can't quietly repurpose their data for something they didn't agree to.
A practical checklist for small businesses
- Publish a clear, honest privacy policy on your website and forms.
- Collect only the data you actually need — don't hoard.
- Get explicit consent (a ticked checkbox, not a pre-ticked one) before collecting.
- Store data securely and limit who can access it.
- Have a way for customers to ask what you hold and request deletion.
- Delete data you no longer need.
Why it's worth taking seriously
Non-compliance can attract significant penalties, and customers increasingly expect their data to be respected. For a young brand, being visibly careful with data is a trust advantage over bigger, sloppier competitors.
Start simple
You don't need enterprise software on day one. Start with a proper privacy policy, consent checkboxes on your forms, and basic access controls on where customer data lives. Build from there as you grow.
Get started with GovYapar →
This article is for general information based on rules current at the time of writing and is not professional advice. Rules change — confirm specifics with a GovYapar expert before acting.
← Back to all articles