The Digital Personal Data Protection Act, 2023 applies to any business that handles customers' or employees' personal data digitally — a phone number in a CRM counts. The practical minimum fits on one page.
Notice and consent
Tell people what you collect and why (a short privacy notice on the website, the form or the invoice footer), collect only what you need for that purpose, and keep a record of consent where it is the basis (marketing messages).
Use, retention, security
Use the data only for the stated purpose; delete it when the purpose is served or the person withdraws consent; protect it with reasonable safeguards — access control, backups, encryption on devices, the policy every employee signs.
Rights and grievances
People can ask what you hold, ask for corrections and erasure, and withdraw consent. Name a contact for grievances and answer within the time the rules prescribe.
Breach
A personal-data breach must be notified to the Data Protection Board and to every affected person; keep an incident log and use the breach-notification generator. Processors (your accountant's software, an agency) act under your instructions — get it in writing.
Checklist
- ☐Privacy notice published and linked from forms
- ☐Data inventory: what, why, where, how long
- ☐Consent recorded for marketing
- ☐Access to customer data limited to those who need it
- ☐Retention / deletion schedule written down
- ☐Grievance contact named
- ☐Breach process = incident plan + notification generator
- ☐Vendor / processor terms in writing