For businesses

DPDP Act website security checklist for small businesses

The DPDP Act 2023 and the DPDP Rules 2025 require any business that collects personal data, including through website forms, to protect it with reasonable security safeguards, show a clear notice when asking for consent, and report data breaches to the Data Protection Board and affected people. Most of these duties apply from 13 May 2027, so small businesses should use the time now to fix the basics: HTTPS, collecting less data, access control, logs, backups and vendor contracts.

By the Secuvexa team, I.T. Experts, Gujarat · Updated

If your website collects names, phone numbers, email addresses or any other personal data, India's Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025 apply to you. In simple terms, you must tell people why you collect their data, keep it secure with "reasonable security safeguards", and report breaches to the Data Protection Board and to the people affected. Most of these duties apply from 13 May 2027. Below is a practical checklist for small business websites.

Not legal advice. This guide is written by security practitioners to help you with the technical side of DPDP. It is not legal advice. For your privacy notice, consent wording, contracts and sector-specific rules, consult a qualified lawyer.

DPDP Act and Rules: the key dates

DateWhat happens
11 August 2023DPDP Act, 2023 becomes law (receives Presidential assent).
13 November 2025DPDP Rules, 2025 notified (G.S.R. 846(E)). Rules on setting up the Data Protection Board take effect immediately.
13 November 2026Consent Manager registration rules (Rule 4) take effect.
13 May 2027Main obligations for businesses apply: notice and consent, security safeguards, breach intimation, data retention and erasure, children's data and people's rights.

Sources: the phased timeline as summarised by Legal 500 and MirvoLegal. MeitY announced the Rules publicly on 14 November 2025, so you may see that date too. In January 2026, Business Standard reported that MeitY proposed shortening some timelines, mainly for large "Significant Data Fiduciaries". We have not seen an amendment notified as of this update, but keep an eye on MeitY announcements.

What "reasonable security safeguards" means (Rule 6)

Under Rule 6 of the DPDP Rules, the minimum safeguards include:

  • protecting personal data through encryption, masking, obfuscation or tokenisation;
  • access control over the systems that hold personal data;
  • logs and monitoring so unauthorised access can be detected and investigated;
  • backups and continuity measures so data stays available if something goes wrong;
  • keeping those logs for at least one year (unless another law requires longer);
  • security clauses in contracts with anyone who processes data for you (your hosting company, web developer, CRM or email marketing tool);
  • appropriate technical and organisational measures to make sure the safeguards are actually followed.

The penalties in the Act are serious. Failing to take reasonable security safeguards can attract a penalty of up to ₹250 crore, and failing to report a breach up to ₹200 crore (summary of the Act's Schedule). The Board decides the actual amount based on factors such as the nature of the breach and the steps the business took, which is why documenting what you did matters.

Breach notification: Board, users and CERT-In

Under Rule 7, once the obligations apply, if personal data you hold is breached you must:

  1. inform each affected person without delay, in plain language: what happened, the likely impact, what you're doing and what they can do to protect themselves, plus a contact person;
  2. inform the Data Protection Board without delay, and send a detailed report within 72 hours of becoming aware of it (or longer if the Board allows), covering facts, cause, steps taken and people informed.

Separately, the CERT-In directions of 28 April 2022 already require service providers, intermediaries, data centres, body corporates and government organisations to report listed cyber incidents, including data breaches, website defacement and unauthorised access, to CERT-In within 6 hours of noticing them (incident@cert-in.org.in). The same directions require ICT system logs to be kept for a rolling 180 days within India, and system clocks to be synchronised with NIC or NPL time servers (or servers traceable to them). These rules are in force now, not in 2027.

Write your breach plan now. When something goes wrong, six hours goes very quickly. Keep a one-page plan: who decides, who calls the developer or hosting company, who drafts the user message, and the CERT-In email address.

Consent and notice on website forms

Every enquiry form, sign-up, order or job application form collects personal data. Before the main obligations apply:

  • Show a short notice next to the form (with a link to your full privacy notice) explaining what you collect, why, and how people can withdraw consent or complain. The Rules expect it to be clear and understandable on its own.
  • Don't pre-tick consent boxes, and keep marketing consent separate from consent needed to answer the enquiry.
  • Make withdrawal as easy as giving consent: an unsubscribe link, a simple email address or a form.
  • Collect less. A contact form usually needs a name, phone or email, and a message. Asking for date of birth, Aadhaar or full address "just in case" adds risk without benefit.
  • Children: schools, coaching institutes and anyone serving under-18s need verifiable parental consent under the Rules. Get legal advice on how to do this for your setup.

Practical DPDP website security checklist

Use this as a to-do list with your developer or hosting company. Our free scanner checks several of these from the outside.

Website and server

  • ☐ HTTPS everywhere, with HTTP redirected to HTTPS and a valid certificate (TLS 1.2 or higher).
  • ☐ Security headers set: HSTS, Content-Security-Policy, X-Frame-Options or frame-ancestors, X-Content-Type-Options, Referrer-Policy.
  • ☐ CMS, plugins and themes up to date; unused ones removed.
  • ☐ No exposed files: .env, .git, database dumps, backup.zip, directory listing.
  • ☐ Form data protected: form submissions not emailed in plain text to many inboxes; stored entries deleted when no longer needed.

Access control

  • ☐ Every admin has their own login (no shared "admin" account), with strong passwords and two-factor authentication.
  • ☐ Staff have only the access they need; ex-employees and old agencies removed the day they leave.
  • ☐ Hosting, domain registrar and email admin accounts protected with two-factor authentication.

Logging, backups and retention

  • ☐ Admin logins and changes logged; web server logs kept for at least one year (DPDP Rules) and kept in a way that satisfies CERT-In's 180-day requirement where it applies.
  • ☐ Automatic off-site backups, encrypted, and a test restore done at least once.
  • ☐ A retention rule: delete old enquiries and applications you no longer need.

Vendors and email

  • ☐ Written contracts with your web developer, hosting company and SaaS tools that cover security, confidentiality and breach notification to you.
  • ☐ Know where your data is: list every tool that receives form data (CRM, Google Sheets, WhatsApp integrations, email marketing).
  • ☐ SPF, DKIM and DMARC set up, so criminals can't easily send fake emails from your domain to your customers.

People and process

  • ☐ A named person responsible for data protection questions and complaints, shown on the website.
  • ☐ A one-page breach response plan (see above).
  • ☐ A periodic security audit, at least yearly and after big changes. See audit and VAPT costs.

Where to start this week

Run the free scan and fix anything marked critical. Then remove form fields you don't need, turn on two-factor login for every admin, and confirm your backups work. If your site has already been compromised, follow our hacked-website steps. If you'd like an expert review of your site against this checklist, get in touch.

Frequently asked questions

Does the DPDP Act apply to a small business website?

Yes, if you collect digital personal data such as names, phone numbers or email addresses through forms, orders or accounts. There is no general exemption just for being small, though the government can notify exemptions for certain classes of businesses.

When do DPDP obligations start for businesses?

The DPDP Rules were notified on 13 November 2025. Most business obligations, including notice, consent, security safeguards and breach reporting, apply from 13 May 2027. In January 2026 MeitY proposed bringing some timelines forward, so check for any amendment.

What should I do if my website leaks customer data?

Contain the problem, keep evidence, inform affected users without delay, and inform the Data Protection Board, with a detailed report within 72 hours once the DPDP Rules apply. If the CERT-In directions apply to you, report to CERT-In within 6 hours of noticing the incident.

Is a cookie banner enough for DPDP compliance?

No. DPDP is about all personal data you process, not only cookies. You need a clear notice, valid consent where required, security safeguards, a way for people to withdraw consent or ask for deletion, and a breach response plan.

Do I need a lawyer for DPDP compliance?

For the security steps in this checklist you usually need a technical person, not a lawyer. For your privacy notice, consent wording, contracts and any sector-specific rules, it is sensible to get advice from a qualified legal professional.

This guide is general information, not legal advice. If you have lost money to fraud, call 1930 immediately or report at cybercrime.gov.in.