What the DPDP Act Means for an Indian SME Using AI Tools in 2026

There is no turnover exemption and no employee-count exemption. A fifteen-person business holding customer names and phone numbers is a Data Fiduciary, and the transition period is running out. Here is the operator’s version, not the law firm’s.

Curious with MayankAugust 20269 min read

Does the DPDP Act Apply to a Small Business in 2026?

Yes, in almost all cases. India’s Digital Personal Data Protection framework does not provide a blanket exemption based on turnover, headcount or revenue. Any organisation deciding why and how personal data gets processed is a Data Fiduciary, which in 2026 includes a fifteen-person business holding a spreadsheet of customer names and phone numbers.

What varies by size is the level of obligation rather than whether obligations exist at all. A separate and heavier category, the Significant Data Fiduciary, carries additional duties such as independent audits. Reported thresholds for that category include processing data belonging to very large numbers of residents, high annual turnover, or handling sensitive data and using AI for profiling and automated decisions. Most SMEs sit outside it, and inside the core requirements regardless.

What Are the DPDP Deadlines That Matter in 2026?

The DPDP Rules were notified in November 2025 and carry an eighteen-month transition, which places full enforcement and the Data Protection Board’s ability to impose penalties around mid-May 2027. Through 2026 the regime is in its softer phase, with the Consent Manager framework reported as due to become operational during the year. The practical reading for 2026 is that this is preparation time, not spare time.

MilestoneReported timingWhat it means for an SME
DPDP Rules notifiedNovember 2025The eighteen-month clock starts
Consent Manager framework operationalDuring 2026Consent infrastructure becomes available
Soft enforcement phaseThrough 2026Time to fix records and consent language
Full enforcement and penaltiesAround mid-May 2027The Board can act on complaints

Treat these as reported timings rather than settled fact. Government implementation dates have moved before and the sensible planning assumption for 2026 is to be ready earlier than required rather than to time the work to a deadline that may shift.

What Changes When You Put Customer Data Into an AI Tool?

Pasting a customer list into a general-purpose AI tool is a disclosure of personal data to a third party. It does not become anonymous because it went into a chat box. The questions that matter in 2026 are what consent was obtained for that use, where the vendor stores and processes the data, whether it is used to train models, and whether any of that is documented.

  • Names, phone numbers, email addresses and order histories are personal data, whatever tool they are pasted into.
  • Consumer-tier AI accounts frequently have different data handling terms from business or enterprise tiers.
  • Free trials and personal accounts used for work are a common and invisible source of exposure in 2026.
  • Screenshots of customer records shared into chat tools count too.
  • A vendor promising not to train on your data is meaningful only if it is written into the terms you accepted.

How Should an SME Prepare in 2026?

Start with an inventory, because nothing else can be decided without one. Most businesses cannot immediately answer which systems hold customer personal data, which staff have access, and which external tools it has been shared with. Producing that list in 2026 usually surfaces two or three exposures nobody had considered, and it is the input every later decision depends on.

Step 1: List where personal data actually lives

Every system, spreadsheet, inbox and third-party tool holding customer information. Include the personal accounts staff use for work, because those are where undocumented processing tends to occur and where an inventory built only from official systems will be wrong.

Step 2: Fix the consent language

Consent under the DPDP framework is expected to be specific, informed and given in clear language, with a genuine ability to withdraw it. A pre-ticked box or a link buried in a footer is weak in 2026. State plainly what is collected, why, and how somebody withdraws consent later.

Step 3: Put vendor terms in writing

Where a third party processes personal data on your behalf, the arrangement should be documented rather than assumed from a marketing page. That includes AI vendors, CRM providers, marketing platforms and anyone with access to your customer records.

Step 4: Decide how you would answer a request

Individuals can ask what data you hold and ask for it to be corrected or erased. Deciding in 2026 who receives that request, where it is logged and how it gets answered is far easier than improvising it under pressure with a complaint already filed.

Can You Still Use AI in an Indian Business in 2026?

Yes. The framework governs how personal data is handled, not whether AI may be used. A large share of useful AI work in 2026 involves no personal data at all: summarising a supplier contract, drafting marketing copy, classifying enquiries by topic. Those carry no DPDP exposure and should not be paused while the compliance work happens.

Where personal data is genuinely required, the workable pattern in 2026 is to minimise what is sent, use business-tier accounts with documented terms, keep processing inside tools you have assessed, and record the decision. The objective is a defensible process, not the elimination of a useful category of tool.

Data does not become anonymous because it went into a chat box.

Key Takeaways for 2026

  • There is no size or turnover exemption. Most Indian SMEs are Data Fiduciaries.
  • Full enforcement is reported for around mid-May 2027, so 2026 is preparation time.
  • Pasting customer data into an AI tool is a disclosure to a third party.
  • The biggest practical risk is the unapproved tool nobody documented.
  • Start with an inventory of where personal data actually lives.
  • AI work involving no personal data carries no DPDP exposure at all.

Frequently asked


Does the DPDP Act apply to small businesses in India?

Yes. The framework provides no blanket exemption by turnover or headcount, so an organisation deciding why and how personal data is processed is a Data Fiduciary regardless of size. A small business holding customer names and phone numbers is covered. Heavier obligations apply only to Significant Data Fiduciaries.

What is the DPDP compliance deadline?

The DPDP Rules were notified in November 2025 with an eighteen-month transition, placing full enforcement and the Data Protection Board’s penalty powers around mid-May 2027. Through 2026 the regime sits in a softer phase intended for preparation. Treat reported dates as subject to change and prepare earlier rather than later.

Can I put customer data into ChatGPT or another AI tool in India?

Doing so is a disclosure of personal data to a third party and needs to be treated as one. Consider what consent covers that use, what the vendor’s terms say about storage and model training, and whether the arrangement is documented. Business-tier accounts typically carry different terms from consumer accounts.

What is the first thing an SME should do about DPDP in 2026?

Build an inventory of where customer personal data actually lives: every system, spreadsheet, inbox and third-party tool, including personal accounts staff use for work. Most businesses discover two or three exposures they had not considered, and every subsequent decision depends on having that list.

Does DPDP mean an Indian business should stop using AI?

No. The framework governs how personal data is handled rather than whether AI may be used. Much useful AI work involves no personal data, such as summarising contracts or drafting copy. Where personal data is needed, minimise what is sent, use assessed tools with documented terms, and record the decision.

Working out which AI uses are actually exposed

The AI integration programme covers tool selection, what data should never leave your systems, and how to document the decisions, against your own operation rather than a generic checklist.

See the training programmes