A customer’s mobile number in your CRM. An employee’s PAN and bank details in payroll records. A CV received through email. A delivery address stored in an order-management system.

MSMEs handle personal data every day, often without treating it as a formal data protection responsibility.

India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules 2025 create a framework for how personal data should be collected, used, stored, protected and deleted.

For MSMEs, DPDP compliance is not just about adding a privacy policy to a website. It starts with understanding what personal data the business collects, why it is required, where it is stored, who can access it and how long it should be retained.

The DPDP Rules 2025 were notified in November 2025, with major requirements becoming operational after prescribed transition periods.

What Are the Digital Personal Data Protection Rules 2025?

The Digital Personal Data Protection Rules 2025 explain how several provisions of the DPDP Act India framework will operate in practice.

Two terms are particularly important.

A Data Principal is the individual whose personal data is being processed. For an MSME, this may be a customer, employee, job applicant or individual vendor.

A Data Fiduciary is the person or organisation that determines why and how personal data is processed.

For example, if an MSME collects a customer’s details to fulfil an order or stores employee information for payroll, it may be acting as a Data Fiduciary.

The basic principle is simple: collect personal data for a legitimate purpose, protect it properly, avoid keeping it unnecessarily and allow individuals to exercise their rights.

Does the DPDP Act Apply to MSMEs?

There is no blanket exemption simply because a business is registered as an MSME. 

The DPDP Act for MSMEs becomes relevant when a business processes digital personal data that falls within the scope of the law. 

This could include: 

  • Customer names, phone numbers and email addresses 
  • Delivery addresses and transaction details 
  • Employee PAN and bank information 
  • Payroll and attendance records 
  • Job applications and CVs 
  • Website enquiry details 
  • Personal information relating to vendors or representatives 

Information collected offline and later converted into digital form may also fall within the framework. 

For data protection for MSMEs, the focus should therefore be on the type of personal data being handled rather than only the size of the business. 

Customer Data: Collect Only What You Need

Customer data protection is likely to become one of the most important parts of DPDP compliance for MSMEs. 

Consider a potential customer filling out a quotation form. 

The business may genuinely need the customer’s name, mobile number, email address and details about their requirement. But at that stage, does it also need their date of birth, complete residential address or identity document? 

Possibly not. 

This is an important mindset shift under the DPDP framework. Instead of asking what information a business can collect, MSMEs should ask what information is genuinely required for the specific purpose. 

For data privacy for small businesses, reducing unnecessary data collection can also reduce security and compliance risks. 
 

Consent and Privacy Notices

Where consent is being relied upon, individuals should clearly understand what information is being collected and why. 

Privacy notices should explain: 

  • What personal data is being collected 
  • Why the business needs the information 
  • How consent can be withdrawn where applicable 
  • How individuals can exercise their rights 
  • How grievances can be raised 

MSMEs should review every major point where personal data enters the business. 

This may include website forms, customer registrations, online checkouts, newsletter subscriptions, event registrations, marketing campaigns and digital onboarding journeys. 

A good test is simple: can a customer easily understand what will happen to their information? 

If not, the notice may need improvement. 

Employee Data Protection Matters Too

MSMEs also hold large amounts of employee information. 

This may include: 

  • PAN details 
  • Bank account information 
  • Salary records 
  • Attendance data 
  • Identity documents 
  • Employment history 
  • Contact details 

The DPDP Act recognises certain employment-related uses of personal data, so consent may not be required for every employee-data activity. 

However, employee data protection still requires proper controls. 

Businesses should know what employee data they hold, why it is required, who can access it, whether it is shared with payroll or HR vendors and how long it is retained. 

This responsibility may involve HR, accounts, management, IT and compliance teams. 

For many MSMEs, the first practical step is moving employee records out of scattered spreadsheets, inboxes and personal devices into one controlled system. A secure HRMS such as Zimyo, which is ISO 27001 certified and built with encryption, access controls and regular vulnerability testing, lets businesses decide exactly who can view salary, PAN or bank details, instead of leaving that information open to anyone with a shared folder link.

Security Measures for MSMEs

DPDP compliance for small businesses also requires reasonable security safeguards. 

MSMEs do not necessarily need expensive enterprise cybersecurity systems, but basic controls should be in place. 

These may include: 

  • Avoiding shared passwords 
  • Restricting access to payroll and customer databases 
  • Removing access when employees leave 
  • Maintaining backups 
  • Protecting sensitive documents 
  • Reviewing third-party security practices 

Businesses should also know exactly who can currently access customer and employee information. 

If that answer is unclear, access controls need attention. 

What Happens After a Personal Data Breach?

A data breach does not always involve a major cyberattack. 

It could involve a lost laptop, compromised email account, hacked CRM, customer spreadsheet sent to the wrong recipient or unauthorized access to payroll records. 

Under the DPDP Rules, affected individuals may need to be informed, and information may also need to be provided to the Data Protection Board within the prescribed timeline. 

MSMEs should therefore have a simple response process covering: 

  • Who receives the internal breach report? 
  • Who assesses whether personal data has been affected? 
  • Whether notification is required 
  • How affected individuals will be identified 
  • What immediate steps can contain the incident 

A documented process makes it easier to respond quickly if an incident occurs.

Data Retention: Do Not Keep Everything Forever

Personal data should not remain indefinitely across old laptops, inboxes, shared drives and software accounts. 

Once the original purpose for collecting information has ended, businesses should assess whether there is still a valid reason to retain it. 

However, MSMEs may also need to keep certain records because of GST, income-tax, labour, company law, banking, contractual or sector-specific requirements. 

A good retention policy should answer three questions: 

  • Why are we keeping this data? 
  • How long do we need it? 
  • What happens when that period ends? 

Customer and Employee Rights

The DPDP Act provides individuals with rights relating to access, correction, updating, completion, erasure, grievance redressal and nomination. For an MSME, this means someone inside the organisation should know what to do if a customer or employee asks: 

  • What information do you hold about me? 
  • Can you correct my details? 
  • Can my information be deleted? 

The business may not need a dedicated privacy department, but it should have a clear internal owner and response process. 

CRM, Payroll and SaaS Vendors Matter Too

Customer and employee information is often stored with external service providers. 

These may include: 

  • CRM platforms 
  • Payroll software 
  • Cloud storage 
  • Accounting systems 
  • Logistics platforms 
  • Email services 
  • Marketing tools 
  • SaaS applications 

Using an external provider does not automatically remove the MSME’s responsibility. 

Vendor review should therefore form part of a DPDP compliance checklist. 

Businesses should know what personal data is shared, why it is shared, what safeguards the provider uses and what happens to the data when the commercial relationship ends. 

DPDP Compliance Checklist for MSMEs

A simple checklist can help MSMEs get started: 

  • Identify the personal data your business collects. 
  • Record why each category of data is required. 
  • Review privacy notices and consent language. 
  • Restrict access to customer and employee information. 
  • Check passwords, backups and security controls. 
  • Review CRM, payroll, cloud and other vendors. 
  • Define data-retention periods. 
  • Create processes for access, correction and erasure requests. 
  • Prepare grievance and data-breach response procedures. 
  • Review data protection practices periodically. 

MSMEs reviewing their broader compliance readiness can also explore eMSME for business compliance tools, regulatory guidance and support. 

Penalties Under the DPDP Act

The penalties under the DPDP Act can be significant. 

The Schedule provides for penalties of up to ₹250 crore for failure to take reasonable security safeguards. 

Certain failures relating to personal data breach notification may attract penalties of up to ₹200 crore, while certain violations relating to children’s personal data may also attract penalties of up to ₹200 crore. 

These are maximum statutory limits and are not automatic penalties for every mistake or incident. 

The seriousness of the breach, duration, type of data involved and mitigation measures may also be relevant.

When Should MSMEs Start Preparing?

The best starting point is to answer six basic questions: 

  • What personal data do we collect? 
  • Why do we collect it? 
  • Where is it stored? 
  • Who can access it? 
  • Which vendors receive it? 
  • When should it be deleted? 

Once these answers are clear, reviewing consent, privacy notices, access controls, vendor contracts, retention, breach management and grievance handling becomes much easier. 

Conclusion

The DPDP framework makes personal data management an important compliance area for MSMEs. 

Businesses do not need to change everything overnight, but they should know what personal data they hold, why it is required, where it is stored and who can access it. 

Starting with data mapping, access controls, vendor reviews, proper retention practices and breach-response procedures can make DPDP compliance for MSMEs much more manageable. 

Preparing early can also help businesses avoid rushed compliance changes once the relevant requirements become fully operational. 

Frequently Asked Question

1. Is the DPDP Act applicable to MSMEs?

Yes. MSMEs processing digital personal data covered by the Act may have compliance obligations. Udyam registration itself does not provide a blanket exemption. 

2. What is DPDP compliance for MSMEs?

DPDP compliance covers how a business collects, uses, stores, protects, shares and deletes personal data. It may also include consent, privacy notices, individual rights, vendor management and breach response. 

3. Do small businesses need to comply with the DPDP Rules 2025?

Small businesses processing personal data covered by the framework should assess which obligations apply to them. Business size alone should not be treated as an automatic exemption. 

4. Does the DPDP Act apply to employee data?

Yes. Employee information can qualify as personal data. However, certain employment-related processing is specifically recognised under the Act. 

5. What should an MSME do first for DPDP compliance?

Start by creating a personal data inventory. Identify what information the business collects, why it is needed, where it is stored, who has access to it, which vendors receive it and how long it should be retained.