Business insurance · Cyber
Decoding the DPDP Act: What Every Indian SME Needs to Know
A simple guide to data protection, penalties, and the role of cyber insurance under the Digital Personal Data Protection Act, 2023.
If you collect so much as a phone number or an email address, this law applies to you.

As a business owner in India, your customer's data is one of your most valuable assets — and under a new law, it can also become your biggest liability. The Digital Personal Data Protection (DPDP) Act, 2023 affects every business that handles the personal data of individuals in India, regardless of size.
This isn't just a compliance headache for large corporations. If you collect so much as a phone number or an email address, the law applies to you. Here's what it means for your SME, in plain terms.
What is the DPDP Act, in simple terms?
At its core, the DPDP Act does two things: it grants individuals (“Data Principals”) rights over their personal information, and it places clear duties on businesses (“Data Fiduciaries”) that collect and process that data.
Think of it as a digital trust deed. You are the custodian of your customers' data, and the law now sets strict rules for how you must safeguard it — from obtaining clear consent before collecting data to implementing security measures that prevent breaches.
The high stakes of non-compliance
The penalties are severe by design. For an SME, a single data breach can be a catastrophic event — which is why ignoring the DPDP Act is a risk you can't afford.
What non-compliance can cost
- ·Heavy penalties: the Data Protection Board can impose fines of up to ₹250 crore for a single instance of non-compliance or a data breach.
- ·Reputational damage: a public breach can instantly erode the trust you've built, costing business and brand.
- ·Business disruption: investigations, customer claims and remediation divert resources from your core operations.
Your 3-step SME compliance starter kit
Getting compliant doesn't have to be overwhelming. Three foundational steps build a strong base for data protection — use this to see where you stand.
The final safety net: where cyber insurance fits in
Compliance is your first line of defence, but it's not a guarantee. A determined attacker, an employee mistake or a software flaw can still expose data — and that's where cyber insurance becomes your financial safety net.
A cyber insurance policy is designed to help your business survive a breach by covering the costs involved — regulatory penalties under the DPDP Act, legal fees, forensic investigation, customer notification and the public-relations response. For the full picture, see the complete guide to cyber insurance and what a policy covers and excludes.
Is your business prepared for a data breach?
Don't let a single cyber-attack derail your business. Talk to us for an honest read on your exposure and your current cover — no obligation.
Request a cyber risk conversationWhat happens when you talk to us
A 20-minute video call with a Growth Advisor — no obligation, and no quote pushed. It opens with a five-minute video from our founder on how the benefits stack works and why Ethika exists; the rest is your questions. You'll leave with an honest read on your current cover and claims experience, and a straight answer on whether we can genuinely help — even if you never become a client.
20 minutes with a Growth Advisor. No obligation.
Read next
A note on this page. Everything here is general information, not insurance, legal, financial or tax advice, and nothing is an offer. For advice about your situation, talk to us.