If your business collects customer names, phone numbers, emails, PAN or any personal information, and almost every business does, the Digital Personal Data Protection (DPDP) Act, 2023 matters to you. It sets rules for how personal data must be collected, used and protected.
The core idea: consent
You can collect personal data only for a clear, lawful purpose, and generally only with the person's consent. That consent must be informed, the customer should know what you're collecting and why. You can't quietly repurpose their data for something they didn't agree to.
A practical checklist for small businesses
- Publish a clear, honest privacy policy on your website and forms.
- Collect only the data you actually need — don't hoard.
- Get explicit consent (a ticked checkbox, not a pre-ticked one) before collecting.
- Store data securely and limit who can access it.
- Have a way for customers to ask what you hold and request deletion.
- Delete data you no longer need.
Why it's worth taking seriously
Non-compliance can attract significant penalties, and customers increasingly expect their data to be respected. For a young brand, being visibly careful with data is a trust advantage over bigger, sloppier competitors.
Start simple
You don't need enterprise software on day one. Start with a proper privacy policy, consent checkboxes on your forms, and basic access controls on where customer data lives. Build from there as you grow.
Get started with Govyapar →
This article is for general information based on rules current at the time of writing and is not professional advice. Rules change — confirm specifics with a Govyapar expert before acting.
← Back to all articles