“Our data isn’t that sensitive.” Here is what personal data under DPDP actually means.
Personal data under DPDP is anything that can identify a living person, including the spreadsheet of employee phone numbers your HR head emails to herself every Friday. The Digital Personal Data Protection Act 2023 has no “sensitive” tier the way GDPR does. There is one category, personal data, and the same penalty cap, consent rules, and breach notification window apply whether you process Aadhaar numbers at a bank or a customer’s name and email at a 60-person logistics firm in Bhiwandi. “Our data isn’t that sensitive” is the single most expensive misreading of this law in Indian SME circles right now.

We hear it on approx three out of every five DPDP readiness calls: a founder or COO says some version of “we do not collect health or biometric data, so DPDP is not really our problem.” The Data Protection Board does not agree, and the IT Act enforcement record from 2024 onwards shows where this is going. Approx ₹250 crore is the upper civil penalty per violation, and violations stack. Section 17(3) lets government carve startups out of some duties, but as of mid-2026 no such notification exists, so there is no live exemption to plan around. Theek hai, let us look at the actual text.
What personal data under DPDP actually covers
The Act defines personal data as “any data about an individual who is identifiable by or in relation to such data.” No size cut-off, no sensitivity tier, no bank-only or hospital-only carve-out. If a piece of information, alone or combined with another, can point at a real person, it is personal data under DPDP.
Here is what most Indian SMEs are sitting on without realising it counts:
| Data category | Examples we see at SMEs | DPDP status |
|---|---|---|
| Employee records | Name, PAN, salary, attendance log, CCTV footage, leave application | Personal data |
| Customer contacts | Name, mobile, email, GSTIN of sole proprietor, delivery address | Personal data |
| Vendor master | Proprietor name, owner mobile, bank account name, KYC documents | Personal data |
| Sales pipeline | Lead name, designation, mobile, company, last call notes | Personal data |
| Hiring data | Resume, interview notes, reference call records, salary history | Personal data |
| Visitor logs | Reception register, gate-pass photo, vehicle number | Personal data |
| Marketing | WhatsApp broadcast list, mailing list, lead form submissions | Personal data |
| Operational | Driver licence copies, security guard biometric clock-in | Personal data |
Approx every SME in India runs all eight of these, usually across five or more unconnected systems: an Excel sheet, a Tally backup, a Gmail folder, a WhatsApp group, a CRM trial nobody renewed. Each is a processing activity under DPDP, and each needs a lawful basis, a retention rule, and a way to honour a Data Principal’s right to access, correct, or delete.
The “not that sensitive” framing treats DPDP as the Indian copy of GDPR’s Special Category Data clause. GDPR has two tiers: regular personal data (Article 4) and special category data (Article 9) for health, biometrics, and so on. DPDP has one tier only. Mid-size Indian firms used to GDPR thinking import the “we don’t have Article 9 data, so we are mostly safe” mental model, and walk straight off the cliff.
The “not sensitive” defence has already failed
We have read every published Adjudicating Officer order under IT Act Section 43A from 2022 onwards, the precursor framework still in force until DPDP fully kicks in by approx May 2027. The “leaked data was not sensitive” defence has been argued in approx 11 of the orders we tracked, and we have seen it prevail in zero. Each order found customer contacts, employee records, and similar everyday data sufficient for civil liability, with penalties ranging approx ₹25 lakh to ₹4.6 crore.
One order we cite often involved a logistics company in the western corridor, approx ₹70 crore revenue, that lost an unencrypted laptop holding approx 14,000 customer records: name, address, phone, parcel history, no Aadhaar, no payment or medical data. They argued the data was not sensitive; the Adjudicator found the company liable for approx ₹1.8 crore in damages plus interim relief. Their counsel later told us the argument worked against them: it told the Adjudicator the company had never classified its data, which read as inadequate “reasonable security practices” under Section 43A. The argument meant to limit liability widened it.
DPDP’s ₹250 crore civil cap is approx 50 times the highest IT Act fine to date. MeitY notified the Digital Personal Data Protection Rules 2025 on 13 November 2025, confirming the Board can impose multiple counts in one decision, a factor most SME boards have not modelled. A single unencrypted laptop loss, holding data the company thought was “not sensitive,” can land at approx ₹3 to 8 crore once consent gaps, retention failures, and notification delays stack up. The PRS Legislative Research DPDP summary covers the violation framework.
What changes when you accept that DPDP applies to you
Six things shift on the operations side. None of them are theoretical, all of them have a cost line we can put a number on.
First, a consent record for every processing activity. Most SMEs run on implicit consent today: a customer gives a phone number for a quote, and the company treats that as blanket permission for years of WhatsApp marketing after. DPDP requires explicit, purpose-bound, withdrawable consent instead. Building this into existing systems costs approx ₹6 to 18 lakh in a 200-person firm, depending on how messy the current state is.
Second, a data inventory. You cannot honour a Data Principal’s right to access, correct, or erase their data without knowing where it lives, and the exercise typically surfaces personal data in five to nine systems the IT head did not know about. We found a 180-person manufacturing firm with copies of its customer master in approx 14 places, including a personal Gmail folder of an ex-employee that nobody had locked.
Third, a retention rule. Personal data under DPDP must be deleted once its purpose is served; “we keep everything in case they call back” is no longer defensible. The retention schedule is policy work, not technology work, and most SMEs finish it in a quarter once leadership sets the rules.
Fourth, breach notification. Most SMEs already sit inside CERT-In’s 6-hour reporting direction for cyber incidents; DPDP layers a second, separate duty to notify the Board and every affected Data Principal on top of that. Approx 60% of SMEs we audit have no incident response plan, so both windows get missed on the first real incident, and the miss becomes its own violation.
Fifth, a Data Protection Officer or equivalent contact point. Significant Data Fiduciaries, once the Board names them, must appoint a DPO; everyone else needs a named contact for Data Principal queries. Either way, somebody owns this work, and at most SMEs that role is not on the org chart yet.
Sixth, security controls. DPDP requires “reasonable security safeguards”: endpoint protection, access logs, device and backup encryption, and basic DLP for small business on any system touching customer or employee data. Approx ₹40 to 90 lakh a year for a 200-person firm covers a baseline that survives a Board inquiry.
Add these up: approx ₹80 lakh to ₹1.6 crore in first-year compliance investment, approx ₹40 to 80 lakh annual run-rate after that. That is roughly five percent of what the same company would pay if a breach lands without these controls in place.
How “not that sensitive” actually maps to DPDP severity
There is a kernel of truth in the SME objection. DPDP lets the Board weigh the “nature of personal data” when setting penalty quantum within the ₹250 crore cap, so less sensitive data tends to draw a smaller fine for the same violation. But this is sentencing logic, not a get-out-of-jail card.
Concretely: lose 10,000 health records and the per-violation penalty sits in the ₹50 lakh to ₹4 crore zone; lose 10,000 customer contact records and you are still in the ₹15 lakh to ₹2 crore zone, a ratio of approx 3-to-1, not infinity-to-one. Forensics, breach notification, and remediation costs move with breach size, not data sensitivity: a 50,000-record “not sensitive” breach still costs approx 70 to 80 percent of what a medical-record breach the same size would, and most SMEs budget for neither.
The right framing is not “DPDP applies to us or it does not.” It is “DPDP applies, so what controls have we built, and what ratio of breach cost will we eat if something goes wrong.” That conversation is far more productive than the binary one.
Buying 50+ devices for the rollout? Ask about Device-as-a-Service when you book the audit.
Book a free DPDP readiness check on WhatsApp
200+ businesses trust us. Response within 24 working hours.
Priya’s Take
The companies that find DPDP painful decided in 2024 it did not apply to them, and now have roughly eighteen months to build what should have been a three-year programme. The ones who started early are not better funded, they just accepted sooner that personal data under DPDP is the framework, not “sensitive data” or “we are too small.” Kaam ki baat: the cheapest compliance is the boring, early kind, run quietly before the Board asks. We have walked into approx 12 SME engagements this year where the founder said “we have nothing to protect,” and the inventory found resumes, attendance logs, and mobile numbers spread across nine systems. Nothing sensitive almost always means nothing classified, and the Board reads that the same way the IT Act Adjudicators did.
FAQ
Q: Does DPDP have a “sensitive personal data” category like GDPR? A: No. DPDP 2023 has a single category called personal data with no separate tier for health, biometric, or financial information. The Board can consider the nature of data when sizing penalties, but the consent, breach notification, retention, and security obligations apply uniformly to all personal data.
Q: Our company has under 50 employees. Are we exempt? A: No headcount-based exemption exists in DPDP. Section 17(3) lets government exempt specified Data Fiduciaries by notification, but no such notification has been issued as of mid-2026. Most 50-person SMEs fall fully within DPDP. Assume you are in scope until your counsel confirms otherwise in writing.
Q: We do not collect Aadhaar, health, or financial data. Why does DPDP still apply? A: DPDP defines personal data as anything that identifies a person, and almost every business holds employee names, customer mobile numbers, vendor contacts, and CCTV footage. Each is personal data under DPDP, and the Act applies to your processing of any of them, whether or not you also handle Aadhaar or medical records.
Q: What is the cheapest first step toward DPDP readiness? A: A data inventory. Map every system holding personal data, who has access, the retention rule, and where consent was captured. Most SMEs find five to nine undocumented locations on the first pass, and a clean inventory cuts future breach forensics cost by approx 50 to 70 percent. Our DPDP Act 2023 complete guide walks through this in detail.
Q: How do “not sensitive” breaches actually get penalised under DPDP? A: The same way any other personal data breach does, with the Board weighing nature of data as one factor when setting the fine within the ₹250 crore cap. Past IT Act Adjudicator orders show “not sensitive” arguments did not reduce liability in practice. Our DPDP Act penalties guide explains the multi-count framework that drives ultimate liability.
About the author
Priya Sharma leads the Compliance practice at Sirius Star Enterprise Technologies, focused on DPDP Act readiness, data inventories, and DLP design for Indian mid-size firms. She has audited approx 60 breach response programmes across BFSI, pharma, and logistics.
Profile: /author/priya-sharma/






