DPDP Act for SMEs: what to do before 13 May 2027
Under India’s Digital Personal Data Protection Act, 2023, your business is the data fiduciary for customer and employee data, and your software vendors are processors. Most obligations apply from 13 May 2027. Here is what a small business and its CA should put in place.
By the rung1 team · Published · Updated · 8 min read
Fiduciary and processor, in plain words
The data fiduciary decides why and how personal data is used: that is your business. A data processor handles data on the fiduciary’s behalf: that is your software vendor. You stay responsible for what your processors do, which is why the contract with them matters.
What an SME should do now
- List where personal data lives: ERP customer masters, payroll, CRM, WhatsApp, spreadsheets.
- Give a clear notice and take consent where you rely on consent.
- Sign a data processing agreement with each vendor.
- Set up a way to answer access, correction and erasure requests.
- Decide who is responsible for a breach, and practise the notification.
What to ask each software vendor
- A signed DPA before any real data is loaded.
- A published sub-processor list, with notice before changes.
- Where data is stored, including backups and logs.
- How fast they erase data on request.
- A named person for incidents, and their notification timeline.
- Whether your data is ever used to train AI models.
Where rung1 stands
rung1 is your processor. Data stays in Mumbai (AWS ap-south-1), including backups and logs; a DPA is signed before the first real record; sub-processors are published; erasure is done within 72 hours; and your data is never used to train a model. We build to the DPDP obligations now, ahead of 13 May 2027.
Questions people ask
The DPDP Rules, 2025 phase the Act in; most obligations for data fiduciaries apply from 13 May 2027.
Usually a data processor: it processes personal data on your instructions. Your business is the data fiduciary and remains responsible.
Purpose and instructions, security safeguards, sub-processors, data location, breach notification, and deletion or return of data at the end of the contract.