DLP for small business: do you actually need it under 100 employees?

Short version. If your under-100-person company holds customer records, employee PAN numbers, or anything a regulator would call personal data, you need some form of DLP, and headcount is not the line that decides it. There is one honest exception where a small firm can genuinely skip it. It sits at the end of this piece, because most articles pretend it does not exist.
06:52 PM on a Tuesday, and the founder was still smiling when he said the line I have heard in a hundred rooms. We are sixty people, Priya. DLP is for banks. Behind him the office was emptying out, thanda chai going cold on three desks, a 62-person freight and logistics firm in Chennai winding down for the day. Nikhil ran it. Farah ran his operations. Neither of them was wrong to ask the question. They were wrong about the answer, and I nearly agreed with them anyway.
Here is the part small owners get wrong, and I say this as someone who has told a five-person firm to keep their money and walk away. Most companies have not had a breach they know about, which is a different sentence from not having had one. Data does not leave with an alarm. It leaves quietly on a resignation, a USB, or a personal email, and you find out when a customer or a regulator tells you. Sixty people does not protect you from that. It just means fewer people to notice.
The myth: we are too small to be a target
Nikhil pictured what everyone pictures. A hacker in a hoodie, a ransom note, a headline. His firm was not going to be on a headline. Fair enough. But that is not the risk that fits a company his size, and it is not the question his auditor will ask either. The finding, when it comes, is almost never about someone breaking in. It is about data walking out.
Every business tells me their data is not that sensitive, right up until they read what the DPDP Act actually counts as personal data, which is basically anything that identifies a person. Customer phone lists. Consignee addresses. Employee records with PAN and bank details. For a logistics firm, the client master file is the whole business. If you are still fuzzy on what DLP is, it is the tooling that watches what leaves and writes down the who, the when, and the where. Not a wall. A witness.
What actually happened, and the part I got wrong
I want to be honest about a mistake, because the mistake is the lesson. When Nikhil said DLP is for banks, my first instinct was to nod. Sixty people, no SEBI licence, no obvious regulator breathing down his neck. On a bad day I might have sold him a spreadsheet and left. Then Farah mentioned, almost in passing, that their accounts person had resigned in the spring. Achha. That one word changed the meeting.
We ran a scoping scan the following week. It flagged a shared mailbox rule quietly forwarding every customer invoice to an external Gmail. I have seen this shape before, so I did not read it as a vendor integration this time. It had been set up by the accountant who left, and it had been copying invoices, consignee details, and rate cards for months after her last day. She was now at a competitor. Nobody in the building had chosen this. It was just the gap nobody was watching. The number attached to that gap, once we mapped the lost contracts, landed near ₹47 lakh. One unmonitored mailbox rule, in a firm that was sure it was too small to bother.
That is what leaves when someone resigns, and it is the most common exit route we see in companies under 100 people. Not a hacker. A goodbye email and a forwarding rule.
So do you need it? Read the signals, not the headcount
The honest answer is not a number of employees. It is a set of signals. Here is the table I drew for Nikhil on the back of a delivery challan. Six rows. If two or more of the right-hand answers are yours, you are past the spreadsheet stage.
| The signal | You can wait (a spreadsheet and a quarterly hour) | You need DLP now |
|---|---|---|
| Customer data on devices | No customer PII, nothing beyond your own team | KYC, phone lists, addresses, or a client master file on laptops |
| Staff turnover | Tiny, stable team, nobody with export access leaving | People with data access have left in the last year |
| Regulated data | Genuinely nothing a regulator scopes | You process personal data, so DPDP already applies to you |
| Where the data goes | One office, one screen, no remote work | Laptops leave the building, staff use personal email or drives |
| Who watches alerts | You do not need alerts because there is nothing to watch | Nobody owns this today, and everybody assumes someone does |
| Cost of a bad day | A shrug and an apology | Lost contracts, a DPDP notice, a customer who now trusts a rival |
Note the third row. DPDP does not have a headcount exemption. The Act treats you as a data fiduciary the moment you decide how personal data gets processed, and it asks you to take reasonable security safeguards under Section 8(5). The penalty for failing that duty can reach ₹250 crore, per the DPDP Act schedule and the India Code text. That ceiling is for the worst cases. But there is no version of the law where sixty people means the rules do not reach you.
What I told Nikhil
Not the whole price list. That is how this category earned its bad name, and I say that out loud because it costs us deals. He did not need every module. He needed to watch three things: email, USB, and uploads to personal cloud. We scoped inDefend to exactly that, nothing more, and set Farah up as the person who reads the amber alerts every morning with her first coffee. Bas. That is the discipline, not the software.
Because DLP is not an install. It is a policy you write, tune, and watch, and the day it fires an alert is the day it matters who is actually watching. A DLP nobody monitors is just a false sense of safety, and it is worse than a spreadsheet because it looks like cover. We have seen firms this size run it well with one trained person and an hour a week. We have also seen the tool sit dark while data walked out under it. The difference was never the licence. It was whether someone owned the mornings.
If you are doing this yourself
What I learned in that Chennai office, written plainly for your Monday.
- Start with the exit routes, not the product. Email, USB, personal cloud, print. That is where under-100 firms lose data, in that order.
- Scope small and honest. Three watched channels beat twelve you never configured. Pay for what your data actually needs.
- Name the watcher before you buy the tool. If nobody reads the alerts, do not spend the money yet.
- Do the resignation drill. When someone with data access leaves, check the forwarding rules the same week, not the same quarter.
- Know your real number. Work out what a breach would actually cost you before you decide the risk is theoretical.
And the honest exception I promised. If you are a genuinely tiny team, no customer PII, nothing a regulator scopes, and no data leaving on any device, then you do not need DLP, and anyone forcing it on you is the vendor I claim to hate. Tell them so. Keep your money and run a quarterly hour instead. That case is real. It was just not Nikhil’s, and it is rarer than most owners hope. If your answer is yes, our starter guide for companies under 200 people is the next thing to read.
Questions Nikhil wishes he had asked earlier
We already have antivirus. Isn’t that enough?
For malware coming in, mostly yes. For the question your auditor asks, no. Antivirus watches for things arriving. The finding is about data going out, a client list on a personal drive, a KYC folder in a chat app, and the antivirus dashboard has no page for that. Different tool, different question.
We haven’t had a breach, so why spend?
Because you would not know yet. Data leaves quietly, and the discovery usually comes from outside, a customer or a regulator, months later. DLP exists to see it while it is happening, not to read about it after.
Is 60 people too small for this to be worth it?
Sixty is exactly the size where one lost laptop or one forwarding rule is a real problem and nobody has a system for it yet. It is cheaper to set up now than to retrofit after an incident. Small is the right time, not the reason to skip.
How fast do we have to act if something does leak?
Faster than most teams expect. Serious cyber incidents, including data breaches, must be reported to CERT-In within six hours of noticing them, per the 2022 directions. You cannot report what you cannot see, which is the whole argument for having a witness in the first place.
Still deciding
If any of this sounds like your firm, start with the honest version of the question, not a quote. We will map where your data actually sits, tell you which channels to watch and which to skip, and if you genuinely do not need us, we will say so. We have done this for 200+ Indian businesses, delivered pan-India from Vashi, Navi Mumbai, and we reply within 24 working hours. Reach us at care@siriusstar.in, or book the review below.
P.S. Priya here. Six months on, Farah still reads her amber alerts with her first coffee. Last month one of them was a junior trying to email a rate card to his personal address before a holiday, no bad intent, just habit. She caught it in eleven minutes by the wall clock. Nikhil forwarded me the log with one line. Turns out we were exactly the right size for this. That is the only quote I needed for this article.
The longer read for Indian buyers who want the real numbers before they commit.
Send me the field guide





