Call +91 98955 44492
All Posts
CybersecurityMay 19, 20269 min read

The DPDP Act 2023: What a Kerala Business Actually Has to Do

The DPDP Act 2023: What a Kerala Business Actually Has to Do

India's Digital Personal Data Protection Act applies to far more businesses than realise it. Here is what it requires, in plain language.

India's Digital Personal Data Protection Act 2023 is the first law to place real, enforceable duties on ordinary Indian businesses handling personal data. Most Kerala SMEs we speak to have not yet assessed what it means for them.

Does it apply to you?

If you hold personal data about identifiable people in India — customers, staff, students, patients, suppliers — it applies. There is no small-business exemption of the kind people assume.

A twelve-person trading firm with a customer database is in scope. So is a clinic, a school, a jeweller with a loyalty list, and a business that only keeps employee records.

The duties, in plain terms

Collect only the personal data you actually need for a stated purpose

Tell people what you are collecting and why, in clear language

Secure it with reasonable safeguards

Delete it when the purpose ends, rather than keeping it indefinitely

Report a breach to the Data Protection Board and to affected individuals

Respond when someone asks what you hold about them, or asks you to correct it

Children's data carries a higher bar

Data concerning anyone under eighteen requires verifiable parental consent, and tracking or behavioural advertising directed at children is prohibited outright.

For Kerala's schools, coaching centres and paediatric clinics this is the most consequential part of the Act, and the one least often assessed.

The penalties are not nominal

Financial penalties under the Act run to substantial amounts, with the largest tied to failure to take reasonable security safeguards to prevent a breach. The exact figure is less important than the direction: this is no longer a matter of best practice.

The practical exposure for most SMEs is not a regulator arriving unannounced. It is a breach that forces disclosure, at which point the question becomes what safeguards you had in place beforehand.

Where to start, in order

Compliance is not a product you buy. Start with the unglamorous work and most of the exposure closes.

Write down what personal data you hold, where it lives, and who can reach it. Most businesses have never done this.

Remove access nobody needs — former staff accounts are the most common finding

Turn on multi-factor authentication everywhere it is available

Make sure backups exist, are offline, and have actually been restored in a test

Stop staff sharing customer or student data through personal messaging accounts

What technology can and cannot do

Technical controls close part of the gap. The rest is documented process and staff awareness, and no vendor can sell you those.

Be sceptical of anyone offering DPDP compliance as a product. What is genuinely available is an assessment of where you stand and a prioritised plan — which is what our cybersecurity service in Kerala.

Most of the work is knowing what personal data you hold and who can reach it, which is unglamorous and the part that gets deferred. Our cybersecurity services in Kerala page covers the controls, and Microsoft 365 covers the retention and access settings most businesses already own and have not configured.

Related service

Cybersecurity in Kerala

Protect your digital assets with Kerala's trusted cybersecurity partner. We deliver end-to-end security services from threat detection and prevention to incident response and recovery.

Interested in learning more about this topic? Our experts can help you navigate the best approach for your business.

Get in Touch