Home / Blog / Security

DPDP Act: What Indian MSMEs Actually Need to Do in the Cloud

SECURITY · JULY 2026 · 6 MIN READ · TEKPRO CLOUD TEAM

Most Indian businesses know the Digital Personal Data Protection Act exists and quietly hope it does not apply to them. It almost certainly does. If you hold customer names, phone numbers, email addresses or any other personal data, and nearly every business does, the Act speaks to you. The good news is that for a typical MSME, compliance is far less daunting than the legal language suggests. Here is what it actually asks, in plain terms, and what to do about it in your cloud environment.

A necessary note before we start: this is practical guidance from a cloud engineering perspective, not legal advice. For your specific obligations, talk to a lawyer. What we can tell you is how the technical side is usually handled, because that is the part we implement for clients every week.

The core idea, in one paragraph

The Act rests on a simple principle: personal data belongs to the person, not to you. You are holding it on their behalf. That means you should collect only what you genuinely need, be clear about why you are collecting it, keep it safe, use it only for the stated purpose, and let people see, correct or remove their data when they ask. Everything else follows from that one idea.

What the Act actually asks of you

Strip away the legal drafting and the practical obligations for most businesses come down to a handful of things.

  • Get proper consent. People must know what data you are taking and why, and agree to it. Pre-ticked boxes and buried terms do not count.
  • Collect only what you need. Data you do not hold cannot be leaked, misused or requested. Minimisation is both a legal principle and free security.
  • Use it only for the stated purpose. Data collected to fulfil an order should not quietly become a marketing list without consent.
  • Keep it secure. Reasonable safeguards are expected. Access control, encryption, and the ability to detect problems.
  • Honour people's rights. They can ask what you hold, ask you to correct it, and ask you to delete it. You need a way to actually do that.
  • Report breaches. If personal data is exposed, there is an obligation to notify. You need to know when it happens, which means you need monitoring.
  • Delete what you no longer need. Data kept forever, for no reason, is a liability, not an asset.

Where MSMEs typically fall short

In practice, the gaps we see when we audit a client's environment are remarkably consistent, and none of them are exotic.

  • Nobody knows where the data actually is. It is in the CRM, in spreadsheets, in an old database, in someone's inbox, in a WhatsApp export. You cannot protect or delete what you cannot find.
  • Everyone has access to everything. No role-based permissions, so the intern can see the full customer database. This is the single most common finding.
  • Consent is an afterthought. Forms collect phone numbers with no clear statement of why, and marketing consent is assumed rather than asked.
  • Data is kept indefinitely. No retention policy, so records from years ago sit in production databases with no business reason.
  • No way to answer a deletion request. When a customer asks to be removed, there is no process, and the data lives on in five systems.
  • No logging. If data were accessed improperly, nobody would know.

The practical cloud steps to close those gaps

Here is the sequence we work through with clients, in the order that gives the most protection for the least effort.

1. Find your data. Before anything else, map it. Which systems hold personal data, what fields, and who can reach them. This is unglamorous and it is the step everyone wants to skip. Do not skip it; every later decision depends on it.

2. Cut access down. Give people the minimum access their job requires, nothing more. Role-based access control in your cloud environment does this cleanly. Most breaches are not sophisticated attacks; they are someone having access they never needed.

3. Encrypt, at rest and in transit. Every major cloud platform makes this close to a checkbox. Enable it. There is no good reason not to, and it is exactly the kind of "reasonable safeguard" the Act expects.

4. Fix consent at the point of collection. Every form that takes personal data should say plainly what it is for. Separate consent for marketing from consent for service delivery. This is a copy change on your website more than a technical one, and it is cheap.

5. Set retention rules and automate deletion. Decide how long you actually need each kind of data, then let the cloud enforce it. Lifecycle policies can archive or delete automatically, so compliance does not depend on someone remembering.

6. Build a way to answer data requests. When someone asks what you hold or asks you to delete it, you need a repeatable process, not a panic. Knowing where the data lives (step one) makes this straightforward.

7. Turn on logging and monitoring. You cannot report a breach you never noticed. Cloud-native logging tells you who accessed what and alerts you when something looks wrong.

8. Write it down. A short, honest privacy policy that reflects what you actually do, and an internal note of your data practices. Not a fifty-page document nobody reads.

The mindset that makes this manageable

Compliance feels overwhelming when treated as a legal project to be survived. It becomes manageable when treated as good data hygiene that happens to also be the law. Every step above makes your business genuinely safer and your systems genuinely cleaner, regardless of regulation. Businesses that approach it that way finish faster and stay compliant, because the practices stick.

The other reassurance: none of this requires enterprise budgets. The cloud platforms already provide access control, encryption, logging and lifecycle automation. For most MSMEs the work is configuration and discipline, not expensive new tooling.

Where we help

At Tekpro we handle the technical side of this for clients: mapping where personal data lives, tightening access, enabling encryption and logging, setting retention and deletion policies, and making sure the environment can actually answer a data request. We work alongside your legal advisor rather than replacing them, they tell you what you must do, we make the systems do it.

If you are unsure how exposed you are, that uncertainty is itself worth resolving. Talk to our team and we will help you find where your personal data actually lives, and what it would take to protect it properly.

Share this Link copied

Want this applied to your business?

Book a free 30 minute strategy session with our certified experts.

Book a Session