Skip to content

SMEs

SMEs need a smaller operating surface, not weaker safeguards or a fictional blanket exemption. Section 17 can enable notified class/startup relief for specific provisions; no exemption is applied until an exact notification and entity fit are captured.

The guided setup asks:

  1. legal entity, business, India presence and sector/licence;
  2. customer, employee, child or patient populations;
  3. collection channels and ten most important systems/vendors;
  4. five main purposes and whether consent or an exact section 7 use applies;
  5. current notices, privacy/grievance contact and incident owner;
  6. essential record-retention sources;
  7. website/app, CRM, payroll, payments, email/SMS/WhatsApp and cloud.

The result is a risk-ranked checklist, not automated legal advice.

  • one entity/role register;
  • approved notice templates in English plus actual customer languages;
  • simple consent receipt/withdrawal endpoint where consent is used;
  • shared rights/grievance inbox with case tracking and assisted intake;
  • spreadsheet/import inventory with ten system owners;
  • record-class retention and manual deletion tasks;
  • processor/vendor list and minimum clause checklist;
  • incident card with CERT-In/DPDP/contract tests and an external escalation contact;
  • monthly evidence export and backup.

An MSP or professional adviser may operate workflow under scoped roles, but the customer retains accountability. Support access is time-bound, logged and excludes raw PII by default. Legal decisions require a named customer approver. The provider cannot reuse customer case/subject data for unrelated benchmarking.

Pages work at 320 px, save draft locally only when safe, resume idempotently, and avoid large attachments. Branch/phone intake creates a reference and reads neutral acknowledgement copy. Notices have print/QR versions. A manual connector template records who completed the source-system task and how it was verified.

Price by legal entity/support tier and optional connectors, not by rights request, withdrawal, incident or deletion. Community edition supports core records and self-hosting; managed service adds operation, updates, backup and response—not a compliance certificate.

Readiness approval, notice versions, receipt/withdrawal, case log, system task proof, incident decisions, vendor checklist, retention rules and monthly export.

  • Is the organisation within any notified startup/class exemption?
  • Which sector, tax, employment or licence records must be retained?
  • Which vendor is a processor versus an independent service Fiduciary?
  • Who provides 24×7 incident judgement if there is no internal CISO/DPO?