Ludhiana is an MSME city — hosiery and textiles, bicycle and auto components, light engineering — with thousands of small units supplying larger buyers. The DPDP question here is rarely about consumer data; it is about workforce records and about what larger customers will start demanding of their suppliers.
Smaller units are not exempt. The Act's core obligations apply regardless of headcount, though the additional Significant Data Fiduciary duties depend on that classification, which most MSMEs will not attract.
The more immediate commercial pressure comes from downstream: as larger buyers build their own programmes, suppliers become entries in a vendor register and start receiving assessments.
ProtectComply is built by Exuverse, whose team sits in Noida. We work with organisations across India — remotely for most of a programme, in person when discovery or a workshop genuinely needs it.
Yes. Core obligations apply regardless of size. The additional duties attaching to Significant Data Fiduciaries — DPO, DPIA, independent audit — depend on that classification, which most MSMEs will not attract.
Because as they build their own DPDP programmes you become an entry in their vendor register. Having ready answers about what data you hold and how you would delete it is a commercial advantage.
Dinkar Singh — Dinkar covers privacy engineering at ProtectComply — discovery, consent propagation and the evidence trail behind them.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →