Other · 12 min read · 17 min 11 sec listen · Published 3 August 2026

Does My Small Business Website Need to Comply with DPDP Act? A Developer’s Guide

Understand when the Digital Personal Data Protection Act, 2023 applies to simple websites with contact forms or WhatsApp links. Clarity for developers, doctors, and small businesses.

Does My Small Business Website Need to Comply with DPDP Act? A Developer’s Guide
One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.

Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.

TL;DR: A basic website with a contact form collects personal data. So, the website owner is a Data Fiduciary under the DPDP Act, 2023 — the law applies. Switching to a WhatsApp link doesn't bypass the law if the business still receives and processes personal data. Compliance is achievable with simple steps, and the real risk isn't the Act itself, it's ignoring it.

A web developer, Vikram Joshi, runs a lean agency in Bhopal. His clients are mostly local doctors — general physicians, a couple of dermatology clinics. He builds them clean five-page sites with a contact form. Simple. Nothing fancy. By early April 2025, his inbox began filling with anxious messages. "Does my website fall under the new data protection law?" "Should I pull the contact form?" Vikram tried piecing together answers from a few online articles and a half-read summary of the Act. He only grew more confused. That's when he approached the Chamber of Advocate Sudhir Rao. The core worry wasn't just legal theory — it was practical. Vikram didn't want his clients to face notices or penalties, and he didn't want to over-engineer a solution that would scare them away. Advocate Sudhir Rao reviewed the exact data flow: a visitor fills in a name, phone number, and query on the doctor's site; the form stores it in the WordPress backend and emails it to the clinic. The advocate explained that this simple act made the doctor a "Data Fiduciary" — someone who determines the purpose and means of processing personal data. But the obligations aren't monstrous. After a single consultation, Vikram received a step-by-step compliance checklist that covered consent notices, a privacy policy, and data retention practices — all without breaking the monthly-payment model he offered his clients. The doctors stayed focused on patients. Vikram handled their legal hygiene. And here's the thing: a general practitioner lawyer had earlier told one clinic to take down the entire website, which was plainly unnecessary. Specialised understanding made all the difference.

Key Facts of the Case

  • The developer builds basic five-page websites for professionals, primarily medical practitioners in Bhopal.
  • Each site includes a contact form that collects names, phone numbers, and messages.
  • The form data is stored on the website server and emailed to the clinic.
  • No sensitive personal data (health records, financial info) is collected through the public website.
  • An alternate approach — embedding a WhatsApp Click-to-Chat link — was considered to avoid storing data on the website.
  • The developer charges a simple monthly fee and wants to take accountability for the website's legal compliance.
  • Conflicting online advice created uncertainty about whether even minimal data collection triggers the DPDP Act.
Does a basic website with a contact form need to follow the DPDP Act?

Yes. The Digital Personal Data Protection Act, 2023, applies to the processing of digital personal data within India. Under Section 4, "processing" includes collection, recording, storage, and transmission. When a visitor submits a contact form containing their name and phone number, personal data is being collected and stored. The website owner — the doctor's clinic in this scenario — becomes a Data Fiduciary under Section 2(f). The Act does not have a blanket exemption for small businesses or for "basic" websites. The obligations attach the moment you determine the purpose and means of processing personal data. And the purpose here is clear: gathering leads or queries.

Will I / my client come under the Act if I replace the contact form with a WhatsApp link and store no record on the website?

In all likelihood, yes. The logic is straightforward. The website may not store any record, but when a visitor clicks the link and sends a message via WhatsApp, the business receives that message — along with the visitor’s phone number and whatever personal data they type. That receipt and any subsequent use (replying, saving the chat) is "processing" under the Act. The Data Fiduciary obligation doesn't vanish because the data capture happens one step away from the website's server. What changes is the technical risk — there is no database of form entries to secure. But the legal duty to provide notice, obtain consent, and handle the data responsibly persists. Compliance is still required, though the surface area of risk shrinks.

Advice in Such Cases

Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.

Map your data flows before you panic. List exactly what information is collected, where it sits, and who has access. Then build compliance around that map.

Don't over-correct. Stripping away a contact form entirely or moving everything to an unmanaged WhatsApp channel can create operational hassles without eliminating legal responsibility. A clear privacy notice and consent checkbox often does more good than a technical overhaul.

This type of matter rewards an advocate who regularly works with data protection law. Procedural quirks — like what counts as "deemed consent" under Section 7(4) — are easy for a general practitioner to misread. Domain experience saves real money and anxiety.

Applicable Sections of Law

  • Section 2(f) — Data Fiduciary: Defines any person who determines the purpose and means of processing personal data. Website owners collecting form data fall squarely within this definition.
  • Section 4 — Application of the Act: The Act covers processing of digital personal data, including data collected in digital form. A contact form or WhatsApp interaction is squarely digital.
  • Section 5 — Consent: Processing must be for a lawful purpose, with the Data Principal’s consent. The website must provide a notice describing the data collected and the purpose.
  • Section 9 — Notice: The Data Fiduciary is required to give a detailed notice before or at the time of seeking consent.

Jurisdiction — Where to File the Case

If a data breach occurs or a complaint arises, it won't land in a regular civil court right away. The DPDP Act establishes the Data Protection Board of India, which will have original jurisdiction over grievances and non-compliance. A Data Principal can complain to the Board. The Board can investigate, impose penalties, and direct remedial measures. The forum isn't a district court — it's this regulatory body. For any subsequent civil claim for compensation, the appropriate civil court with territorial and pecuniary jurisdiction may be approached. But the first stop is the Board.

Limitation Period

The DPDP Act itself does not prescribe a hard limitation period for filing a complaint with the Data Protection Board. However, if a claim for compensation or damages is to be raised before a civil court, the Limitation Act, 1963 applies — typically three years from the date the cause of action arose. Delaying a complaint can weaken the evidentiary record. It’s prudent to act as soon as a breach or non-compliance is discovered. For proactive compliance, there's no limitation; you must be compliant from day one.

Interim Reliefs Available

  • Interim directions by the Data Protection Board: The Board can pass urgent orders to stop ongoing data processing or mandate the securing of data pending full inquiry.
  • Mandatory reporting orders: The Board can direct the Data Fiduciary to notify affected Data Principals of a breach if immediate harm is likely.
  • Preservation of evidence: The Board can require the preservation of logs, records, and infrastructure to prevent destruction of evidence.
  • In civil suits: Courts can grant temporary injunctions under Order 39 Rule 1 and 2 CPC to restrain further misuse of personal data.

If You Are the Victim

  • Document everything: screenshots of the website, the form, any privacy policy (or its absence), and all communications.
  • Send a formal notice to the Data Fiduciary — the website owner — pointing out the non-compliance and asking for removal of your data or corrective action.
  • If no resolution, file a complaint with the Data Protection Board of India as soon as the grievance redressal mechanism is operationalised under the Act.
  • For urgent harm — like leaked sensitive details — consider approaching a civil court for an injunction while regulatory proceedings continue.

Documents You Must Keep Ready

  • Aadhaar or other government ID of the business owner (to establish identity of the Data Fiduciary).
  • Screenshot printouts of the website pages where data is collected.
  • The website’s privacy policy or terms, if any exist.
  • Server logs or database exports showing stored form entries (for a victim proving collection).
  • Copies of any consent checkboxes, pop-ups, or notices displayed to visitors.
  • Screenshots of the WhatsApp conversation if a click-to-chat link was used.
  • Any communication with the developer or business about data handling.

What Evidence Is Required?

  • Preserved digital evidence: full-page screenshots showing the contact form and what information is being collected.
  • Browser developer tools or backend records proving storage of form data.
  • Email receipts showing form data transmitted to the business.
  • Server access logs to establish the flow and retention periods.
  • For WhatsApp-based interactions, chat exports and metadata that tie the conversation to the business.
  • Any prior correspondence where the Data Fiduciary admits or explains the processing.
  • Primary evidence (original digital records) is preferred; secondary evidence like printouts is admissible if the original can't be practically produced.

How Courts Typically Approach Such Cases

Although the Data Protection Board is the primary forum, civil courts hearing personal data disputes under the broader right to privacy framework (drawing from Justice K.S. Puttaswamy v. Union of India, 2017) treat data collection with seriousness. Courts examine whether consent was informed, whether processing was proportional, and whether the Data Fiduciary had reasonable security safeguards. A clear privacy notice and demonstrable compliance go a long way. Courts tend not to sympathize with businesses that collect data first and figure out legality later. The inquiry is factual — what did you tell the user, what did you do with their data, and could you have done less?

  • Notice & grievance: A data principal reaches out to the fiduciary for redress — 15 to 30 days is typical for a response.
  • Board complaint: Filing a complaint with the Data Protection Board initiates an inquiry that may take a few months to a year for a final order, depending on complexity and procedural rules yet to be prescribed.
  • Appeal: Any order of the Board can be appealed to the Appellate Tribunal within 60 days; that process can add 6-12 months.
  • Civil suit: If a compensation claim is filed separately in a civil court, from plaint to final judgment can span 2-4 years, factoring in written statements, evidence, arguments, and possible appeals.

Understanding the Costs

The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.

A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.

Can the Matter Be Settled Out of Court?

Under the DPDP Act, the Data Protection Board can facilitate a voluntary resolution of complaints. The Act provides for mediation and settlement provisions, particularly where the data principal’s grievance can be remedied by deleting the data, updating a privacy policy, or offering an apology within a specified timeline. Before escalating to a penalty order, the Board may give the Data Fiduciary a chance to set things right. For pre-litigation matters, parties can also enter into a compromise deed clarifying data handling obligations going forward. Where the issue is truly technical — say a missing consent checkbox — prompt correction often ends the matter without a formal penalty.

Common Mistakes People Make

  • Assuming that a “small” website doesn’t collect personal data. A contact form with a name and phone number is enough to trigger the Act.
  • Believing that switching to a WhatsApp link removes all legal obligations. The business still processes personal data when it receives and responds to those messages.
  • Copying a privacy policy from a random template without customising it to the actual data practices — courts see right through that.
  • Not consulting an advocate early and instead relying on a web developer’s legal guesswork. This often results in over-correction or under-correction.
  • Engaging a lawyer who doesn’t regularly handle data protection matters. A general practitioner may miss how the Act interacts with sectoral rules, or how consent can be structured, leading to unnecessary risk or expense.
  • Ignoring the obligation to enter into a valid contract with any data processor — like a web developer — and assuming the developer bears all the legal burden.
  • Deleting website records after receiving a complaint. That can be seen as destruction of evidence and makes the legal position much worse.

FAQs People Normally Have

I’m a web developer, not the business owner. Am I liable under the DPDP Act?

You are likely a Data Processor if you determine the technical means of collecting data but not the purpose. The business owner — the doctor — is the Data Fiduciary. However, if you collect data for your own purposes, you can become a fiduciary too. A clear contract between you and your client defining your role is crucial.

Can I just put a disclaimer saying “by submitting this form you consent to our privacy policy”?

Only if the privacy policy is linked, specific, and conveys exactly what data is collected, why it’s collected, and how it’s used. A vague disclaimer won’t meet the notice requirement under Section 9. The consent must be free, specific, informed, and unambiguous.

What if the website doesn’t store personal data — it just sends an email directly?

If the form data is emailed to the business and the email is stored, that’s still storage. Even if you configure the email to be deleted after response, the act of collection and transfer itself is processing. You remain a Data Fiduciary.

Do I need to register anywhere or obtain a license under the DPDP Act?

No. There is no licensing regime. The Act imposes obligations, not a registration requirement. You just have to comply — give notice, take consent, honour data principals' rights, and report certain breaches.

Is there a fine for small businesses who don’t comply right away?

The Act provides for substantial penalties — up to Rs 250 crore in some cases — but the Board would consider the nature, gravity, and duration of non-compliance. Practically, a small clinic with a contact form that missed a consent checkbox is unlikely to face the maximum penalty if they fix it quickly, but the risk isn’t zero.

This article is general legal information, not legal advice. Consult a qualified advocate about your specific situation.

Advocate Sudhir Rao, Supreme Court of India

Was this article useful?

/5 (0 ratings)