← All posts
Compliance 14 Sept 2026 · Harshit Rajput

Digital Personal Data Protection Act 2026: What It Means for Your Small Business Website

The DPDP Act's Consent Manager deadline hits in November 2026. A practical guide to what small business websites need to do about customer data now.

Priya runs a small online boutique out of Surat, taking custom stitching orders through a WhatsApp catalog, an Instagram page, and a simple contact form on her website. Last month, a customer messaging her about a return asked a question Priya had never been asked before: what exactly does your business do with my phone number, my address, and the photos I sent you for the blouse design? Priya did not have a good answer. She had never written a privacy policy, never asked anyone to agree to one, and had no idea whether the answer even mattered for a business her size.

It does now. India's Digital Personal Data Protection Act, passed back in 2023, finally has its operating rules in place after the rules were notified in November 2025, and the law is moving into its active phase through 2026 and 2027. The first hard, date bound obligation, the Consent Manager framework, becomes operational on November 13, 2026, a little under two months from now. A fuller compliance deadline for businesses follows in May 2027. For a lot of small business owners, this still sounds like something meant for big banks and large platforms. It is not only that. If your website, WhatsApp catalog, or Google Business Profile form collects a customer's name, phone number, email, or delivery address, you are handling personal data, and the law's basic principles already apply to you.

Why this is not just a big company problem

The DPDP Act defines almost anyone who decides how and why personal data is collected as a data fiduciary, and that includes a boutique owner collecting addresses for delivery, a clinic collecting patient phone numbers for appointment reminders, or a tutoring business keeping a spreadsheet of student names and parent contact numbers. The heaviest, most complex obligations under the law, such as running a formal Consent Manager system, are aimed at large data fiduciaries handling data at scale. But the underlying principles, collecting only what you need, telling people clearly what you collect and why, and letting them ask you to correct or delete it, apply far more broadly.

The realistic risk for a small business is not a headline grabbing penalty. The Act's own penalty schedule allows for fines running into hundreds of crores, but those are built for serious, large scale breaches, not a boutique that quietly never wrote a privacy page. The more immediate risk is the one Priya ran into: a customer asking a direct question you cannot answer, or a marketplace, payment gateway, or ad platform asking you to link to a privacy policy before they will work with you at all. That awkward, trust eroding moment is already happening to small businesses today, well ahead of any 2027 deadline.

What to actually do before November

You do not need a legal team to get the basics right, and doing it now, while your data collection is still simple, is far easier than trying to retrofit it later.

Start with a real privacy policy. It should say, in plain language, what information you collect through your website, WhatsApp, and any order forms, why you collect it, and whether it is shared with anyone, such as a courier partner for delivery or a payment gateway for processing an order. Our privacy policy generator builds a policy suited to an Indian small business in a few minutes, which is enough for most website and WhatsApp catalog setups.

Pair it with proper terms and conditions, covering things like your return policy, delivery timelines, and how a customer can reach you with a complaint. The terms and conditions generator covers the same ground without requiring a lawyer for a first draft.

Ask for consent, not just data. A simple checkbox on your contact or order form, or a line in your WhatsApp catalog message linking to your privacy policy, is enough to show a customer that you told them what you were collecting and gave them a chance to agree to it.

Collect less. If your order form asks for a date of birth or a second phone number you never actually use, drop the field. Data you never collected cannot be the subject of a complaint, a breach, or a deletion request.

Give people a way to reach you about their data. A dedicated email address, or even a line in your privacy policy pointing to your existing WhatsApp business number, satisfies the basic expectation that a customer can ask what you hold on them and have it corrected or removed.

Secure what you do keep. If customer details sit in a spreadsheet on a shared laptop or an unsecured WhatsApp group, that is a bigger practical risk than any single clause in your privacy policy. Our guide on website security basics for small business walks through the low cost steps that matter most.

The gap that catches WhatsApp only businesses

A meaningful share of small businesses in India run entirely through Instagram DMs and a personal WhatsApp number, with no proper website behind them. That setup makes basic compliance genuinely awkward. There is nowhere sensible to host a privacy policy, no consistent place to put a consent checkbox, and no simple page to link a customer to when they ask a fair question about their data. A proper website solves this cleanly: one place to publish your policies, one form that captures consent by design, and one link you can send anyone who asks. Our guide on building an online presence covers why this matters well beyond data privacy, but the DPDP timeline is one more concrete reason to stop treating a website as optional.

It is worth remembering that customer data does not only arrive through contact forms. Every UPI payment, every saved delivery address, and every order confirmation is also a data trail. Our piece on collecting payments via UPI for business is worth revisiting with this in mind, since it touches on what payment information actually passes through your hands versus what stays with the payment provider.

Start now, while it is still simple

Priya spent an afternoon writing a proper privacy policy, added a small consent line to her order form, and stopped asking customers for details she never used anyway. None of it required a lawyer or a large budget, and it turned an uncomfortable question from a customer into a two line reply with a link.

The November 2026 deadline is really aimed at large platforms running formal consent infrastructure, and most small businesses will never interact with a Consent Manager directly. But the broader shift the DPDP Act represents, customers expecting to know what a business does with their information, is already here, and it rewards businesses that got the basics done early rather than scrambling once a customer, a marketplace, or a regulator asks. A business built on nothing but Instagram DMs and a WhatsApp number is going to find this harder than one with a proper website, a clear privacy policy, and a place to point people when they ask a fair question about their own data.

H
Harshit Rajput
Founder, Neweb

Ready to ship your presence?

Claim your free domain and get your site, Google Business, and SEO set up in 38 seconds.