Home / Sectors / MSME
MSME · Startups, small business, mid-market

DPDP for MSMEs and startups

There is no MSME exemption in the DPDP Act. No revenue floor. No headcount threshold. A two-person startup carries the same duty as Reliance Retail. What you do get is a phased enforcement runway ending 14 May 2027. Use it well.

No MSME exemption DPDP Act Sec. 3 + Rule 3 6 min read Verified 8 Sep 2026

01The uncomfortable answer: MSMEs are not exempt

Section 3 of the DPDP Act applies to any processing of digital personal data. No size threshold. No revenue floor. No headcount trigger.

The policy reasoning: personal data harm to an Indian Data Principal does not scale with the size of the Data Fiduciary. A small startup losing 10,000 records can cause identical harm to a large enterprise losing the same 10,000 records. So the duty is the same.

What varies is the penalty within a cap. Section 33(2) tells the Data Protection Board to weigh proportionality. A small MSME with a first-time breach and cooperative posture is likely to face a materially smaller number than a large enterprise with a repeat pattern. The cap is the same. The number chosen inside the cap will not be.

Sec. 3, Sec. 33(2) DPDP Act. Storyboard18 reporting on MSME compliance stress test, November 2025.

02What the phased runway gives you

13 Nov 2025

Nothing that binds you

Rules 1, 2, 17 to 21 in force. These are definitions and Board-related. No operational obligation on you yet.

14 Nov 2026

Consent Manager registration

Only matters if you plan to be a Consent Manager. Most MSMEs do not. Skip.

14 May 2027

Everything binds

Rules 3, 5 to 16, 22, 23 in force. Consent notice, security safeguards, breach notification, retention, DPO publication, grievance. This is your line.

Proposed

13 Nov 2026 (if MeitY shortens)

MeitY has floated shortening 18 months to 12 months. If notified, your line moves to 13 November 2026. Watch the Updates feed.

03The version of "MSME DPDP compliance" that actually fits a 20-person team

You do not need a compliance department. You need six things done reasonably well by someone in the team wearing a compliance hat two hours a week.

  1. A Rule 3 consent notice on your website and app

    Standalone, plain language, itemised data categories, specific withdrawal link. Free tools exist for the drafting; ours is one of them.

  2. A published grievance officer contact

    Section 8(9) obliges you to name a person, publish their email (phone optional), and put it on the website footer and the app "About" screen. Rule 3(b)(iii) requires the specific link on the consent notice too.

  3. Basic security controls that any managed database gives you

    Rule 6 wants encryption at rest, access controls, and one-year log retention. If you are on AWS RDS, Google Cloud SQL, Azure SQL, or any of the modern managed Postgres or MySQL services, all three are already on by default. Turn on the ones that aren't. Do not roll your own crypto.

  4. A one-page breach playbook that names who does what

    Who calls whom in the first hour. Who drafts the Board notification. Who drafts the Data Principal notice. Where the letter templates live. Timing: without delay for the initial alert, comprehensive report to the Board within 72 hours. Store it where the on-call person can find it at 2am. Rehearse it once. Half a day, done.

  5. A retention schedule that fits on a napkin

    Early-stage startup version: customer records for the life of the contract plus GST retention (8 years under the Companies Act if you're a private limited), marketing preferences until withdrawal, analytics 90 days, support tickets 3 years. That's it. Add rows only when a new personal-data category enters your system.

  6. A DSR handling process

    Rule 14 gives you 7 days to acknowledge, 90 days to complete an erasure. A shared email inbox and a checklist do the job. You do not need an enterprise DSR platform for the first 12 months.

04Two things not to do

First, do not buy a Rs. 5 lakh enterprise compliance platform on day one. You do not need it.

Off-the-shelf Rule 3 notice generators, consent widgets, and DSR tools exist as free or low-cost SaaS. Use those first. Upgrade only when you can articulate a specific gap.

Second, do not skip because "the Board will not come for a small company like ours."

The Board is expected to enforce broadly, both to build case law and because Data Principal complaints will drive its docket. A single unhappy customer with a valid grievance can put you in front of the Board. Better to have a defensible posture on day one.

Industry commentary on Board enforcement patterns; SFLC assessment, 2026.

05What if you become an SDF later

A fast-growing MSME can cross into Significant Data Fiduciary territory quickly. Design your data architecture assuming this may happen.

Section 10 designation is a Central Government notice based on the six-factor test. Volume of personal data processed is one factor. A B2C fintech that goes from 10,000 to 10 million users in two years can plausibly be designated.

Practical: even if you are not yet an SDF, adopt Rule 12 obligations one at a time as you scale. Appoint someone as DPO. Run a DPIA on any new high-risk processing feature. This is cheaper as a habit than as a scramble on the day the notice arrives.

Sec. 10 DPDP Act. Rules 12, 13 DPDP Rules 2025 (effective 14 May 2027).
Free minimum viable compliance for MSMEs. dcomply's MSME Starter covers the six items above for Rs. 1,499 per month. Grow into more modules as you scale. Or use our free tools to draft your notice and check your gap.