Founder & CEO, Meridian Bridge Strategy
The law makes no distinction based on turnover. Small businesses are MORE vulnerable, not less.
"I'm too small. Why would the Government notice me?"
Answer: The Government doesn't need to notice you. An angry customer or a smart competitor will. Small businesses are easier targets because they rarely have the documentation to defend themselves during an inquiry.
When the Data Protection Board asks "who was responsible for protecting this data?" — if your answer is "nobody specifically" — you just handed them a ₹250 Cr fine with no defense. No documentation. No accountability trail. No one who can demonstrate you took reasonable safeguards.
You run a business in India. You file GST returns. You do income tax. You didn't hire a CA because you're a big company. You hired one because:
The law created an obligation
The obligation has consequences
Having someone costs less than ignoring it
A Data Protection Officer is the same thing for DPDP. That's it. That's the whole logic.
The DPDP Act prescribes ZERO qualifications for a DPO. It says the person must be: based in India, report to the board, and capable of doing the job.
It also explicitly allows one person to serve as DPO for multiple companies.
This is not a C-suite hire. This is a profession waiting to be built — the same way CAs serve 50 clients across GST and IT.
| Cost | Compliance | Non-Compliance |
|---|---|---|
| Data Mapping | ₹50K - ₹2L | — (You don't know what data you have) |
| Consent Architecture | ₹1L - ₹3L | ₹50 Cr per violation |
| Vendor DPAs | ₹50K - ₹1.5L | ₹50 Cr (liable for vendor's mistakes) |
| User Rights Mechanism | ₹50K - ₹1L | ₹50 Cr |
| Total | ₹2L - ₹8L | ₹50 Cr minimum |
Think of it like your CA. A CA keeps you out of tax trouble — a DPO keeps you out of ₹250 Crore trouble. Same retainer model, same ongoing relationship, same accountability.
Here’s exactly what you’re paying for, broken down by frequency:
Under DPDP, someone has to be the official person customers can contact about their data. That’s the DPO.
Compliance isn’t a one-time project — it drifts. The DPO keeps things from slipping.
Targeted checks to make sure nothing broke since last review. Keeps you audit-ready year-round.
Full re-assessment once a year. New hires get trained, policies get updated, certificate gets renewed.
When a breach happens, 72 hours is all you get. The DPO is your crisis manager — not your IT guy figuring it out on Google.
Full-Time DPO Hire
₹2.5-5L/month
+ office + benefits + bench time
Overkill for most SMEs
Fractional DPO
₹50K–₹3L/mo
Scales with your complexity
One DPO, 3-5 companies max
Non-Compliance
₹50Cr+
Per violation
Not a real option
Your CA keeps you out of tax trouble. A fractional DPO keeps you out of ₹250 Crore trouble.
+ office + benefits + bench time
Overkill for most SMEs
Fractional DPO
₹50K–₹3L/mo
Scales with your complexity
One DPO, 3-5 companies max
Non-Compliance
₹50Cr+
Per violation
Not a real option
Your CA keeps you out of tax trouble. A fractional DPO keeps you out of ₹250 Crore trouble.
Map Every Place You Store Personal Data
Excel sheets with customer phone numbers. WhatsApp groups with employee Aadhaar. Google Sheets with vendor PAN numbers. Find everything.
Fix Your Consent
Replace "I Agree to Everything" with purpose-specific consent. Order updates = implied. Marketing = explicit. Each purpose separately.
Sign Data Processor Agreements
Every vendor handling personal data needs a signed DPA. Your CRM, email platform, payment gateway, cloud provider. Weak contract = you pay their fines.
Build a "Delete Me" Mechanism
Users must be able to request data deletion and withdraw consent. Even a simple Google Form linked to a process is better than nothing.
Assign Someone as Accountable
Designate a person (fractional DPO, internal lead) responsible for data protection. When the Board asks "who was responsible?" — you need a name.

Founder & CEO, Meridian Bridge Strategy
Sushant has built and sold products in identity verification, cybersecurity, and e-commerce at IDfy, CyberArk, and Cyware. He specializes in helping Indian SMEs navigate DPDP compliance without enterprise budgets. Master's from IE Business School, Computer Science from BITS Pilani.
We work exclusively with Indian SMEs on DPDP compliance. Free 30-minute clarity call — your specific risks mapped, not generic advice.
Book Free Clarity Call