Small Entity Exemption Under India’s Digital Personal Data Protection Rules, 2025: What It Means for the Optical Industry

CORE_Summarizes_TFOS_DEWS_III_Reports_to_Boost_Dry_Eye_Knowledge_(20).jpg

The Digital Personal Data Protection (DPDP) Rules, 2025—officially notified on 14 November 2025—introduce a transformative compliance relief mechanism for micro and small businesses in India. One of the most relevant provisions for the optical and eye-care sector is the Small Entity (Small Data Fiduciary) Exemption, designed to ease the regulatory burden on low-volume practitioners who handle limited personal data.

Who Qualifies as a Small Entity?

• Handles low volumes of personal data (e.g., neighbourhood optical stores)

• Does not process sensitive health data at scale

• Classified as MSME or small-scale establishment

• Limited operations such as a single shop or rural practice

Major Compliance Exemptions for Small Entities

Small Entities are not required to:

• Appoint a Data Protection Officer (DPO)

• Conduct DPIAs

• Undergo annual third?party audits

• Maintain purpose registers

• Implement advanced grievance frameworks

• Deploy enterprise-grade cybersecurity systems

Obligations That Still Apply

• Clear privacy notice

• Explicit consent

• Purpose limitation

• Basic digital security

• Consent withdrawal & data deletion rights

• Reporting significant data breaches

• Parental consent for children’s data

When the Exemption Does Not Apply

• Large-scale processing of health data

• Large-scale children’s data (e.g., school screenings)

• Multi-outlet operations

• Automated profiling or targeted marketing

• Entities classified as Significant Data Fiduciaries

Practical Impact on India’s Optical Industry

Most Likely to Qualify for exemptions :

• Independent optical stores

• Solo optometry clinics

Not Likely to Qualify for exemptions:

• Multi-store optical chains

• High-volume speciality eye-care centres

• Franchise networks

Conclusion

The Small Entity Exemption offers a balanced framework that protects patient privacy while reducing compliance burdens for India’s optical and optometry sector.

Keratometry Driven IOP Correction: Are We Measuring Eye Pressure Accurately?

Keratometry Driven IOP Correction: Are We Measuring Eye Pressure Accurately?

IOP (Intraocular Pressure) is the measure of pressure inside the eye created by the balance between aquous humor production and its drainage.   IOP...

read more
Not Just Glasses: How Smart Lens Choices Accuracy Shape the Future of Myopia Control

Not Just Glasses: How Smart Lens Choices Accuracy Shape the Future of Myopia Control

Abstract The rapid rise of childhood myopia has transformed lens prescribing from a routine refractive task into a strategic public-health measure. Today&rsq...

read more
Screen Time & the Eyes: Why the Digital Age Is Straining Our Vision

Screen Time & the Eyes: Why the Digital Age Is Straining Our Vision

Introduction In the 21st century, digital devices — from smartphones, tablets, laptops, to televisions — dominate both work and leisure activitie...

read more
From Clinics to Classrooms: 50 Years of Wisdom with Prof. Gobinda Chandra Monda

From Clinics to Classrooms: 50 Years of Wisdom with Prof. Gobinda Chandra Monda

Interview taken by Md. Zakaria Midya, Optometrist | Myopia Educator  Q 1: Sir, congratulations on completing 50 years in the Optometry profession. How d...

read more
Small Entity Exemption Under India’s Digital Personal Data Protection Rules, 2025: What It Means for the Optical Industry

Small Entity Exemption Under India’s Digital Personal Data Protection Rules, 2025: What It Means for the Optical Industry

The Digital Personal Data Protection (DPDP) Rules, 2025—officially notified on 14 November 2025—introduce a transformative compliance relief mechani...

read more