top of page

DPDP Act Website Compliance: What Every Indian Small Business Must Do Before 2027

20 hours ago
4 min read

DPDP Act website compliance means making sure every form, checkout page, and WhatsApp opt-in on your site collects, stores, and deletes visitor data the way India's Digital Personal Data Protection Act, 2023 requires. The Act's rules were notified in 2025, with obligations phasing in through 2026 and 2027, and enforcement carries real financial penalties — this isn't a law businesses can quietly ignore the way some earlier privacy guidance was. If your website has a contact form, an online store, or a WhatsApp chat button, you're already collecting personal data covered by the Act.


What the DPDP Act Actually Covers

The Act treats any business that collects personal data — a name, phone number, email, or even a WhatsApp number — as a 'Data Fiduciary,' and the person the data belongs to as a 'Data Principal.' Data Fiduciaries have specific obligations: consent must be free, specific, informed, and given for a clear purpose, not buried in a pre-ticked checkbox. A Data Principal must be able to withdraw consent as easily as they gave it, request their data be corrected, and ask for it to be deleted. Larger businesses that process data at scale get extra obligations as 'Significant Data Fiduciaries,' including appointing a Data Protection Officer — most small and mid-sized businesses won't fall into that category, but the base obligations apply to everyone.


The Website Compliance Checklist

  1. Publish a clear, plain-language privacy notice before you collect any data — not a legal-only document buried three clicks deep in the footer.

  2. Redesign every form on your site (contact, quote request, newsletter signup, WhatsApp opt-in) so consent is an active, unticked checkbox with a specific stated purpose.

  3. Give visitors an easy way to withdraw consent or request their data be deleted — a monitored email address or a simple form is enough for most small businesses.

  4. Audit every third-party script running on your site — Meta Pixel, Google Analytics, email marketing tools, chat widgets — because data those scripts collect is still your legal responsibility as the Data Fiduciary.

  5. Keep a written record of what personal data you collect, why you collect it, and how long you keep it. A spreadsheet is a legitimate starting point.

  6. If you run WhatsApp marketing or automation, document that opt-in separately — the same consent rules that apply to an email list apply to a WhatsApp broadcast list, and this is easy to overlook when a chatbot is set up quickly.

  7. Put a basic data-breach response process in writing: who gets notified internally, how fast, and what gets communicated externally if customer data is ever exposed.

  8. Review how your site handles data from anyone under 18 separately — the DPDP Act sets stricter consent requirements, including verifiable parental consent, for children's data.


Penalties Make "We'll Get to It Later" an Expensive Plan

Unlike some earlier Indian data-protection guidance that carried little real enforcement, the DPDP Act sets out financial penalties that can run into hundreds of crores of rupees for serious or repeated violations, decided case by case by the Data Protection Board of India. A small business is unlikely to face the largest penalties reserved for major data breaches, but the direction of travel is clear: data-handling practices treated as a formality for years are now a compliance obligation with a real enforcement body behind them.


Building Compliance In From the Start

Retrofitting consent flows onto an existing website after the fact is possible but messy — every form, every WhatsApp opt-in, every stored customer record needs to be found and fixed individually. It's far cleaner to build compliant consent capture, a proper privacy notice, and clean data-handling practices into a website from day one, which is how Arcknet approaches every website development project now, not as an afterthought. The same applies to WhatsApp Business API setups, where consent documentation needs to be part of the automation build rather than bolted on later.


Frequently Asked Questions

Does the DPDP Act apply to a small business with just a contact form on its website?

Yes. The Act doesn't set a business-size exemption for the core consent and notice obligations — a single contact form that collects a name and phone number is enough to make you a Data Fiduciary under the law.

Do I need a Data Protection Officer?

Only if you qualify as a Significant Data Fiduciary, a category the government designates based on the volume and sensitivity of data you process. Most local service businesses, small e-commerce stores, and B2B websites won't meet that threshold, but the base consent and notice obligations still apply.

Is a generic privacy policy template enough?

A generic template is a starting point, not a finish line — it needs to accurately describe what your specific site actually collects (forms, cookies, WhatsApp opt-ins, payment data) and how long you keep it, or it creates a paper trail that contradicts your real practices.


This is a practical starting point, not legal advice — for a final compliance sign-off, pair it with a lawyer's review. If you're not sure where your website currently stands, get in touch with Arcknet for a straightforward website and data-collection review.

Recent Posts

See All

Comments


Black_And_White_Modern_Simple_Minimalist_Logo_With_Name-removebg-preview.png
bottom of page