Regulatory7 min read18 Mar 2026

DPDP Act compliance: the 90-day playbook for SMEs

You don't need a privacy department. You need a data map, six documents and a habit. Here's the sequence.

With the DPDP Act's rules in force and enforcement machinery taking shape, 'we'll deal with it when it's enforced' has quietly become the riskiest position an SME can take. The good news: for most SMEs, credible compliance is a 90-day project, not a transformation program.

Days 1–30: know your data

  • Map what personal data you collect, where it sits, who touches it: one workshop, one spreadsheet
  • Classify: employee data, customer data, vendor data; digital vs paper
  • Kill what you don't need. Retention is a legal position, not a server setting

Days 31–60: paper the basics

  • Privacy notice that says, in plain language, what you collect and why
  • Consent capture where consent is your basis, logged, not assumed
  • Grievance channel with a named officer and a response clock
  • Vendor clauses: your processors sign up to your obligations

Days 61–90: build the habit

  • A breach response one-pager: who calls whom, in what order, within what time
  • Access-request procedure: you have to be able to find a person's data to honour their rights
  • One hour of training for everyone who touches personal data
The takeaway. Ninety days, six documents, one owner. The firms that struggle are the ones that treat DPDP as an IT project. It's a governance project with an IT component.

Want the gap list for your company? A DPDP readiness check is a fixed-fee package.

Begin a conversation

General information, not legal, financial, tax or regulatory advice. Law and regulation change; verify against primary sources before acting. See our Disclaimer. Read it here.

WhatsApp