Cybersecurity

India's DPDP Startup Exemption Covers 0.3% of Small Business - And Not the Two Clauses That Matter Most

When the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules on 13 November 2025, the government's own press release closed with a reassuring line: the framework, it said, "provides a facilitative compliance regime for startups and smaller enterprises so that innovation can continue to thrive alongside strong data protection standards." That sentence has been quoted back at me by three separate small-business owners this month, each of them under the impression that the DPDP Act contains a size-based carve-out that will keep them out of its reach.

It does not. There is a startup provision in the Act, it is narrow, it has not yet been switched on, and — this is the part almost nobody reads — it deliberately leaves untouched the two obligations that carry the largest penalties in the entire statute. What follows is an attempt to read the actual text against the actual registration numbers, because the gap between the two is wide enough to matter.

Chart comparing DPIIT-recognised startups against Udyam registrations under DPDP Section 17(3)
Section 17(3) of the DPDP Act, read against India's small-business registers.

Section 17(3), Read Word by Word

The relevant text is short enough to quote in full. Section 17(3) of the Digital Personal Data Protection Act, 2023 says:

"The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or class of Data Fiduciaries, including startups, as Data Fiduciaries to whom the provisions of section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 shall not apply."

Three things follow from that sentence, and each of them cuts against the popular reading.

First, it is a power, not a grant. The words are "may ... notify." Until a notification issues, nothing is disapplied to anyone. Second, the beneficiary class is defined by an explanation appended to the same sub-section, which ties "startup" to a private limited company, partnership firm, or LLP "recognised as such in accordance with the criteria and process notified by the department to which matters relating to startups are allocated" — in practice, recognition by the Department for Promotion of Industry and Internal Trade. A proprietorship is not eligible. Neither is an unrecognised partnership. Third, and most consequentially, the sub-section names precisely five provisions: section 5, sub-sections (3) and (7) of section 8, section 10, and section 11.

Those five are notice, data accuracy, erasure on withdrawal of consent, the additional obligations of a Significant Data Fiduciary, and the right of a data principal to demand a summary of processing. They are real obligations and relief from them is worth something. But look at what is absent from the list.

The Two Clauses the Exemption Leaves Untouched

Section 8(5) — the duty to take reasonable security safeguards to prevent a personal data breach — is not in the list. Section 8(6) — the duty to notify the Data Protection Board and every affected individual when a breach occurs — is not in the list either.

Now turn to the Schedule appended to the Act, which sets the penalty ceilings under section 33(1). The two highest single entries in the entire statute are these:

Provision breachedPenalty may extend toIn Section 17(3) exemption list?
s.8(5) — reasonable security safeguardsRs 250 croreNo
s.8(6) — breach notificationRs 200 croreNo
s.9 — children's data obligationsRs 200 croreNo
s.10 — Significant Data Fiduciary dutiesRs 150 croreYes
Any other provision of the Act or RulesRs 50 crore

The arithmetic is blunt. The startup exemption, if and when it is notified, relieves a qualifying entity of an obligation carrying a Rs 150 crore ceiling while leaving in place two obligations carrying Rs 450 crore between them. A small firm that reads "startup exemption" and concludes it need not encrypt its customer database or report a ransomware incident has drawn exactly the wrong inference from the text.

This is not an accident of drafting. Section 10 applies only to entities the government designates as Significant Data Fiduciaries — a designation a genuinely small company was never going to attract. Removing it costs the state nothing. The security and breach-notification duties, by contrast, are the operative core of the law, and the legislature declined to soften them for anybody.

The Arithmetic: 2.35 Lakh Against 7.9 Crore

Even taken at its most generous, the exemption reaches a small fraction of the constituency that believes it applies to them.

As of 2026, the Startup India portal records 2,35,205 DPIIT-recognised startups, a figure that has grown quickly — 2,12,283 as of 31 January 2026, and more than 55,200 recognitions granted in FY26 alone, the highest in a single year since the scheme began in 2016.

Against that, the Ministry of MSME's registration base. A PIB release records over 7.83 crore enterprises registered across the Udyam Registration Portal and the Udyam Assist Platform as of 28 February 2026, rising to roughly 7.9 crore by March 2026 — about 4.72 crore on Udyam proper and 3.21 crore on the Assist platform, which exists specifically to formalise informal micro enterprises.

Set 2,35,205 against 7.9 crore and the DPIIT-recognised population is around 0.3% of the registered small-business base — roughly one enterprise in 336. And that is the ceiling, not the estimate: it assumes every recognised startup would be covered by a notification that has not been issued, and it ignores that the two populations overlap imperfectly, since DPIIT recognition and Udyam registration are separate processes with different eligibility rules.

The mismatch has a structural cause worth naming. DPIIT recognition requires incorporation as a private limited company, LLP, or registered partnership. The Udyam Assist Platform's 3.21 crore entries are, by design, informal micro enterprises — the tea stall, the two-person tailoring unit, the single-truck logistics operator. Those entities are constitutionally incapable of qualifying as startups under section 17(3)'s explanation, no matter what MeitY eventually notifies. The exemption was never built for them.

An Exemption That Has Not Actually Been Granted

There is a further wrinkle. As of early 2026, no notification had been issued under section 17(3), and none under section 17(5) either — the broader power letting the Centre disapply any provision of the Act to a class of data fiduciaries for a specified period, exercisable only within five years of commencement.

That five-year clock is worth watching. The Act was passed on 11 August 2023, which puts the outer limit of the section 17(5) window in August 2028. If a genuine small-enterprise carve-out is coming, it has to come through that door, and the door closes. Meanwhile the operative position is simple: any entity that digitally processes the personal data of people in India is a data fiduciary, and the Act applies to it in full.

The PIB release is not lying when it describes a facilitative regime. It is describing the phased timeline, the plain-language SARAL drafting, the 90-day window to answer data-principal requests, and the consultation process that drew input from startups and MSMEs across seven cities. Those are real accommodations of tempo. They are not accommodations of scope. Reading a timing concession as a size exemption is where the confusion begins.

What the Readiness Numbers Say

A 2026 EY India survey of more than 150 professionals across sectors puts numbers on the gap. Around 64% of Indian organisations had not allocated a dedicated budget for DPDP compliance, and only 18% had completed a cost-estimation exercise. Close to 70% of respondents described themselves as not very familiar with the Act and the Rules; roughly 71% said they struggled to interpret them; 45.3% cited budget limitations as a constraint.

Those are figures from professionals in organisations large enough to be surveyed and to have someone whose job includes answering questions about data protection. The readiness distribution among 7.9 crore Udyam registrants — most of them micro units with no compliance function at all — is not something anyone has measured, and there is no honest way to extrapolate it from a 150-person sample. But it is hard to construct a scenario in which it is better.

The practical exposure is not theoretical. Breach notification under the Rules runs to the Board within 72 hours of becoming aware, and there is no minimum-size threshold and no record-count floor. A breach touching ten customer records triggers the same notification duty as one touching ten million. For a firm with no incident-response process, the failure mode is not usually malice — it is simply not noticing, or noticing and not knowing whom to tell. For readers who want the threat side of this in more detail, our e-book Cyberthreat to the Indian MSME 2026 covers the attack patterns that most often produce exactly this kind of reportable incident.

The Calendar Most Coverage Gets Wrong

DPDP Rules 2025 phased compliance timeline showing 13 November 2026 and 13 May 2027
The Rule 4 consent-manager date and the substantive-compliance date are not the same deadline.

A good deal of recent commentary treats 13 November 2026 as a universal deadline. It is not, and the distinction matters for anyone allocating a limited compliance budget.

The Rules run on an 18-month phased schedule from notification. Rule 4, the consent-manager framework, comes into force on 13 November 2026. That date governs entities that wish to operate as consent managers — a registered business with the Data Protection Board, incorporation in India, a minimum net worth of Rs 2 crore, and demonstrated technical capacity to run consent across multiple fiduciaries. That is a licensing regime for a specialised intermediary, not a compliance date for the general population of data fiduciaries.

The date that actually governs the substantive obligations — notice, consent, security safeguards, breach reporting, data-principal rights — is 13 May 2027, eighteen months from notification. A small enterprise budgeting for DPDP should be working to May 2027, not November 2026, and should not be sold a consent-manager product on the strength of a deadline that does not apply to it. That last point is worth stating plainly, because a compliance-vendor market has grown up around the November date and small buyers are its most likely casualties.

Five Things Worth Doing Before May 2027

These follow from the specific findings above rather than from any general checklist.

  1. Write down where personal data actually sits. Not a formal data map — a list. WhatsApp Business chats, the billing software, the Google Sheet of customer phone numbers, the CCTV recorder, the ex-employee's laptop. Section 8(5) asks for reasonable safeguards; you cannot safeguard an inventory you have never taken, and this is the step that costs nothing but an afternoon.
  2. Decide now who makes the 72-hour call. Name one person, with a deputy, who is authorised to declare an incident and start the clock. The Rs 200 crore ceiling under s.8(6) attaches to failing to notify, not to being breached. Most small firms lose this one to ambiguity about who had the authority to act.
  3. Check whether you are actually DPIIT-recognised. If you are, note precisely what section 17(3) would and would not do for you, and plan for s.8(5) and s.8(6) regardless. If you are not — and 99.7% of the registered base is not — then treat the exemption as irrelevant to your planning and stop waiting for it.
  4. Separate the November 2026 question from the May 2027 question in your budget. Unless you intend to register as a consent manager and can meet the Rs 2 crore net-worth bar, Rule 4 is not your deadline. Push consent-manager spending to the far side of the substantive work.
  5. Deal with children's data explicitly if you touch it. Section 9 carries a Rs 200 crore ceiling and is not in the exemption list either. Coaching centres, paediatric clinics, toy retailers, and school-adjacent businesses are carrying an exposure they mostly have not priced.

Where This Reading Could Be Wrong

Three ways, and they are worth stating because the argument above is a reading of text and arithmetic, not a prediction.

MeitY could yet notify under section 17(3) or 17(5) with a scope wider than the statutory explanation suggests — the 17(5) power is broad enough to disapply "any provision," including, in principle, section 8(5) itself, for a specified period. That would change the picture materially, and the August 2028 outer limit gives the government real room to act.

Second, the 0.3% figure compares two registers that were built for different purposes and count differently; treat it as an order-of-magnitude statement about coverage, not a precise ratio. What it will not do is move by an order of magnitude — 2.35 lakh against 7.9 crore is not a number that becomes large through a better methodology.

Third, enforcement posture is unknown. The Data Protection Board is newly constituted and digital-first, appeals lie to TDSAT, and the Schedule sets ceilings rather than tariffs. A first-year enforcement practice built around the largest fiduciaries would leave micro enterprises with a formal exposure and a negligible practical one for some years. That is a reasonable bet. It is not a compliance strategy, and it is not what the statute says.

The honest summary is this: the DPDP framework gives Indian small business time, plain language, and a phased runway. What it does not give it — yet, and possibly ever — is a size-based exemption from the duty to secure personal data and to say so when that fails.

Further Reading

Sources

  • Press Information Bureau, Ministry of Electronics & IT, "Government notifies DPDP Rules to empower citizens and protect privacy," Release ID 2190014, 14 November 2025.
  • The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), section 17(3) and the Explanation thereto; and the Schedule read with section 33(1).
  • Digital Personal Data Protection Rules, 2025, notified 13 November 2025 — Rule 4 (Consent Manager registration, in force 13 November 2026) and the 18-month phased schedule ending 13 May 2027.
  • Press Information Bureau, Ministry of MSME, "Over 7.83 crore enterprises registered on Udyam Registration Portal," data as of 28 February 2026; Udyam and Udyam Assist Platform totals, March 2026.
  • Startup India portal / DPIIT recognition data, 2026: 2,35,205 recognised startups; 2,12,283 as of 31 January 2026; 55,200+ recognised in FY26.
  • EY India, DPDP compliance and readiness survey, 2026 (150+ respondents): 64% without a dedicated compliance budget, 18% having completed cost estimation, ~71% reporting interpretation difficulty, 45.3% citing budget constraints.
Dr. Dibyendu Choudhury

Dr. Dibyendu Choudhury

Author of 9 published books. Retd. Govt. Employee (MoMSME) · MSME Policy Expert · Visiting Faculty at NI-MSME · Vedic Philosophy Scholar. Writing at the intersection of ancient Indian wisdom, modern entrepreneurship, and national policy.

Never Miss an Insight

Join 47,000+ readers — free fortnightly newsletter on MSME policy, Vedic wisdom & leadership.