Sector wise readiness
Non profits and NGOs: there is no small charity exemption
- Are small charities and NGOs exempt from DPDP?
- No. There is no small organisation exemption, no non profit exemption, and no turnover threshold below which the law switches off. Beneficiary data is often the most sensitive of all: health conditions, financial hardship, immigration status, and data about children.
- Who this affects
- Charities, NGOs and community organisations of any size.
- What to do about it
- Apply the full baseline, and pay particular attention to beneficiary and volunteer records, which are usually held with the thinnest controls.
The most common sentence I hear from non profits about DPDP: "we are a small charity, surely this does not apply to us."
It does. There is no small organisation exemption, no non profit exemption, no turnover threshold below which the law switches off. The baseline applies regardless of your size, staff count or budget.
That is hard, because the organisations most likely to assume exemption often have the least capacity to comply. But the auditor's observation is direct: NGOs assume they are exempt, they are not, and their beneficiary data is frequently the most sensitive of all.
Think about what a charity holds. Health conditions of the people it serves. Financial hardship records. Immigration status. Data about children and vulnerable adults. Exactly the data DPDP protects most strongly, held by the organisations with the thinnest controls.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent and easy withdrawal
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What this sector carries from day one
- ✅ A basis for donor and beneficiary data. Establish a lawful basis for both. Beneficiaries may include children or vulnerable persons, which raises the bar.
- ✅ Parental or guardian consent where you serve minors or persons with disability. If your beneficiaries include children, the children's data duties apply in full, absolutely.
- ✅ The baseline applies regardless of size. A two volunteer trust holding beneficiary health data owes the same baseline as a large NGO.
The good news, because it matters for a stretched team
You do not need enterprise tooling. Lightweight consent capture and basic access control on beneficiary records carry most of the load. The gap here is almost never a missing product. It is the assumption that the law did not apply.
The better question
The better question is not "are we small enough to be exempt?"
It is "do the people whose data we hold, especially the vulnerable ones, have the protection the law says they do?"
Law creates obligations. Scale and risk influence implementation. But the baseline does not scale down. It applies from your first donor and first beneficiary.
If you run or advise a non profit, had you assumed the law applied more lightly to you?