At a glanceA customer list in an unprotected Excel file — sitting on a laptop, emailed around, synced to the cloud — is one of the most common data risks small businesses carry. Under India’s DPDP Act you owe reasonable security safeguards, and encrypting the file is a basic one. In Excel: use File → Info → Protect Workbook → Encrypt with Password to set strong at-rest encryption. But encryption is only step one — how many copies exist, who can open them, and how long you keep them matter just as much.
Educational resource only. This explains reducing breach risk on customer spreadsheets under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.
The situation
Almost every business has one: a spreadsheet of customers — names, numbers, emails, sometimes far more. It gets emailed, copied to a personal laptop, dropped in a shared drive. If any one of those copies leaks, that’s a personal data breach you’re accountable for. Encryption is the quickest way to make a lost or stolen file useless to whoever finds it.
Why a plain spreadsheet is a liability
An unprotected customer list is portable, copyable, and readable by anyone who gets hold of it — the opposite of a safeguard. The DPDP Act requires reasonable technical safeguards to protect personal data (Section 8). A spreadsheet with no password fails that at the most basic level: lose the laptop, misdirect the email, or leave the shared drive open, and the data is immediately exposed. Because these files are so easy to duplicate and move, they tend to sprawl — which is exactly why they’re a frequent breach source.
How to encrypt an Excel file
Excel has built-in, strong at-rest encryption — set it with a password. On desktop Excel:
- Open the file, then go to File → Info.
- Click Protect Workbook → Encrypt with Password.
- Enter a strong, unique password and confirm it.
- Save the file. It’s now encrypted at rest; without the password, the contents can’t be read.
Two cautions: store the password separately (a password manager, not the same folder or email as the file — a password sitting next to the file protects nothing), and remember Excel’s encryption is only as strong as the password, so avoid weak or reused ones. Equivalent options exist in other spreadsheet tools; the principle is the same.
Encryption alone isn’t enough
A password on one file doesn’t help if ten unprotected copies exist elsewhere. Encryption protects that file, but your real exposure is the sprawl around it: the emailed version, the export someone saved to their desktop, the backup, the copy in a chat. If those aren’t controlled, you’ve locked one door and left the others open. Encryption is necessary, not sufficient — the goal is fewer copies, in fewer places, each protected.
The habits that actually cut your risk
Combine encryption with minimisation, access control, and retention — that’s what moves the needle.
- Hold less. Trim the sheet to the fields you actually need; delete columns you don’t use. Less data, less to lose.
- Reduce copies. Keep one controlled master rather than emailing the file around; share access, not attachments.
- Control access. Store it somewhere with proper permissions; limit who can open or download it.
- Encrypt it (above) — and encrypt the device it lives on where you can.
- Set retention. Delete stale exports and old versions; don’t let customer lists pile up indefinitely.
- Prefer a real system over a spreadsheet for anything sizeable — a database with access controls beats a shared file for both security and rights handling.
FAQ
How do I password-protect a customer list in Excel?
File → Info → Protect Workbook → Encrypt with Password, then set a strong, unique password and save. Store the password separately from the file.
Does encrypting the file make me DPDP-compliant?
It’s one reasonable safeguard, not compliance in itself. You also need to control copies, limit access, minimise the data, and set retention — and meet the wider duties.
Is a password-protected Excel file safe enough for sensitive data?
It’s a reasonable baseline for at-rest protection, but only as strong as the password — and it doesn’t help if unprotected copies exist. For sensitive data at scale, a proper access-controlled system is better than a spreadsheet.
What’s the biggest spreadsheet risk?
Copy sprawl. One customer list emailed and re-saved across devices and backups multiplies the exposure. Fewer copies, controlled access, and retention limits matter as much as encryption.