Yes. The DPDP Act does not exempt startups or small businesses from its core obligations — notice, valid consent, purpose limitation, security safeguards, breach reporting and data principal rights apply regardless of headcount or revenue. What does scale is the Significant Data Fiduciary regime, whose additional duties (a Data Protection Officer, DPIAs and independent audits) attach only where an organisation is notified as Significant.
The Act does allow the Central Government to notify certain classes of Data Fiduciary, including startups, for whom some obligations may be applied differently. That is a targeted provision rather than a general small-business exemption, and it should not be assumed.
In practice the cheapest path for a small company is to keep the data footprint small: collect less, retain it for less time, and use fewer processors. Every obligation is defined against the data you hold.
General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →