Small Entity Exemption Under India’s Digital Personal Data Protection Rules, 2025: What It Means for the Optical Industry

CORE_Summarizes_TFOS_DEWS_III_Reports_to_Boost_Dry_Eye_Knowledge_(20).jpg

The Digital Personal Data Protection (DPDP) Rules, 2025—officially notified on 14 November 2025—introduce a transformative compliance relief mechanism for micro and small businesses in India. One of the most relevant provisions for the optical and eye-care sector is the Small Entity (Small Data Fiduciary) Exemption, designed to ease the regulatory burden on low-volume practitioners who handle limited personal data.

Who Qualifies as a Small Entity?

• Handles low volumes of personal data (e.g., neighbourhood optical stores)

• Does not process sensitive health data at scale

• Classified as MSME or small-scale establishment

• Limited operations such as a single shop or rural practice

Major Compliance Exemptions for Small Entities

Small Entities are not required to:

• Appoint a Data Protection Officer (DPO)

• Conduct DPIAs

• Undergo annual third?party audits

• Maintain purpose registers

• Implement advanced grievance frameworks

• Deploy enterprise-grade cybersecurity systems

Obligations That Still Apply

• Clear privacy notice

• Explicit consent

• Purpose limitation

• Basic digital security

• Consent withdrawal & data deletion rights

• Reporting significant data breaches

• Parental consent for children’s data

When the Exemption Does Not Apply

• Large-scale processing of health data

• Large-scale children’s data (e.g., school screenings)

• Multi-outlet operations

• Automated profiling or targeted marketing

• Entities classified as Significant Data Fiduciaries

Practical Impact on India’s Optical Industry

Most Likely to Qualify for exemptions :

• Independent optical stores

• Solo optometry clinics

Not Likely to Qualify for exemptions:

• Multi-store optical chains

• High-volume speciality eye-care centres

• Franchise networks

Conclusion

The Small Entity Exemption offers a balanced framework that protects patient privacy while reducing compliance burdens for India’s optical and optometry sector.

From Classroom to Clinic: Learning Case of Keratoconus

From Classroom to Clinic: Learning Case of Keratoconus

By: Devanshi Dalal, Assistant Professor, Department of Optometry, BDIAS, CHARUSAT, Gujarat, Jaini Patel, Optometry Student, Department of Optometry, B...

read more
Low-Dose Atropine: Miracle for Myopia or a Risk for Esotropia?

Low-Dose Atropine: Miracle for Myopia or a Risk for Esotropia?

Exacerbation of esotropia ( crossed eye ) is one of the potential factors with low dose atropine treatment , However on the other hand it’s now an effecti...

read more
Differential Diagnosis of Diplopia: A Structured Clinical Review

Differential Diagnosis of Diplopia: A Structured Clinical Review

Abstract Diplopia, or double vision, is a multifactorial symptom encountered in ophthalmic and neurologic practice. Distinguishing monocular from binocular d...

read more
Vision Beyond Optics: The Neurochemical Story of Amblyopia

Vision Beyond Optics: The Neurochemical Story of Amblyopia

  Vision is often described in optical terms — refractive power, retinal image formation, contrast sensitivity. Yet the eye is only the entry poin...

read more
Uncorrected Refractive Errors in School Children: An Epidemic affecting Education and Development

Uncorrected Refractive Errors in School Children: An Epidemic affecting Education and Development

Introduction Imagine a child in a classroom, listening to the teacher with full attention, yet unable to copy notes from the board because it appears blurred...

read more