We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Checklist

DPDP compliance readiness

Use this executive checklist to align legal, product, security, and vendor risk owners before you operationalize notices, consent, and grievance handling under India's Digital Personal Data Protection Act.

The deadlines you are working to

The DPDP Rules were notified on 13 November 2025 with a phased commencement, so the date that matters depends on which obligation you are looking at.

  • 13 November 2025 — already in force. The Data Protection Board is operational and the complaint mechanism is live. A data principal can complain about you now, ahead of the compliance deadline.
  • 13 November 2026 — Consent Manager registration opens. Relevant if your consent model depends on that ecosystem.
  • 13 May 2027 — substantive obligations enforceable. Consent, notice, data-principal rights, retention and breach response are all testable from this date.

1. Data inventory — everything else depends on it

  • List every system holding personal data of Indian users, including the analytics warehouse, CRM, support desk, marketing platform, backups, vendor systems and the spreadsheet someone maintains for reconciliation.
  • For each: what data, why, on what lawful basis, retained how long, shared with whom, located where.
  • Name an owner per system. Unowned data is unanswerable data.
  • Test it honestly — pick one real customer and try to answer an erasure request end to end. The gaps surface within an hour.

2. Notice & lawful basis

  • Publish clear notices in English and the required languages; no bundled “I agree to the terms and privacy policy” checkbox.
  • State the purpose specifically enough that a person can tell what they are agreeing to.
  • Document the lawful basis per processing activity — this is a business decision about what you actually need, not a legal drafting exercise.

3. Consent that is granular, revocable and evidenced

  • Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action.
  • Withdrawal must be as easy as giving it — and must propagate to downstream systems, not just flip a flag in one database while the marketing platform carries on.
  • Store consent as a record with enough context to reconstruct what was agreed and when.
  • Separate marketing consent where applicable and keep the opt-in trail.

4. Data-principal rights you can service at volume

  • Working process, named owner and a route in for access, correction, erasure and grievance redressal.
  • Evidence of the outcome, not just the request.
  • Track SLAs in the ticketing system — the failure mode is being unable to fulfil in a reasonable period because data is scattered.

5. Breach response inside 72 hours

  • Personal data breaches must be reported to the Data Protection Board within 72 hours.
  • This is a different clock from your CERT-In obligation — if you operate in India you run two notification regimes with different triggers, timelines and recipients. Deconflict them on paper before you need them.
  • Rehearse it. Detection, triage, scoping which individuals were affected and the decision to notify usually lands over a weekend.
  • Pre-agree who is authorised to make the notification call.

6. Retention & purpose limitation you can enforce

  • Retain personal data only as long as necessary for the stated purpose — which contradicts a decade of “keep everything in case it is useful”.
  • Deletion routines that actually run, including in backups and analytics copies.
  • A defensible rationale for each retention period.

7. Vendors & processors

  • Map subprocessors; align DPAs with security annexes and breach notification timelines that let you meet your own 72 hours.
  • Apply encryption and access control to sensitive personal data flows.
  • Secure the contractual right to evidence — you cannot demonstrate what you cannot obtain.

If you may be a Significant Data Fiduciary

  • A comprehensive DPIA and an independent data-protection audit at least once every twelve months.
  • The independent professional reports key findings and significant observations to the Data Protection Board — the output reaches the regulator, not only your board, which changes the character of the exercise.
  • Appoint a DPO and publish the grievance route.
  • Build the auditable evidence base now rather than assembling one in the quarter before the first audit.

Where this overlaps with what you already run

No certification makes you DPDP-compliant — DPDP is law and the standards are voluntary. But if you hold ISO 27001 you have the security half and very little of the privacy half, while ISO/IEC 27701maps far more closely: a privacy information management system makes you build the inventory, lawful basis, retention and rights machinery DPDP then asks you to evidence. Building them together is materially cheaper than building them twice.

Free tool
DPDP Readiness Checker
Check your readiness for India’s DPDP Act and see your priority gaps — free.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Get the one-page DPDP readiness checklist

Enter your work email and we’ll unlock the Excel + PDF instantly.

DPDP checklist — common questions

When do DPDP obligations actually become enforceable?

The Rules were notified on 13 November 2025 with phased commencement. The Data Protection Board and the complaint mechanism took effect immediately, Consent Manager registration opens on 13 November 2026, and the substantive obligations on Data Fiduciaries become enforceable on 13 May 2027.

We are a B2B company. Does DPDP apply to us?

Almost certainly. DPDP governs processing of digital personal data of individuals, and B2B organisations hold plenty of it — employees, contacts at customer accounts, prospects, support users and contractors. Having no consumer product does not put you outside the Act.

How quickly must a personal data breach be reported?

To the Data Protection Board within 72 hours. It runs alongside, and does not replace, CERT-In incident reporting, which has different triggers and timelines — so plan for two notification paths rather than one.

What extra applies to a Significant Data Fiduciary?

Additional obligations including a comprehensive DPIA and an independent data-protection audit at least once every twelve months, with the independent professional reporting key findings and significant observations to the Data Protection Board. Because the output reaches the regulator, evidence quality and auditor independence matter more than in an internal review.

Does ISO 27001 or ISO 27701 make us DPDP-compliant?

No. DPDP is law; those are voluntary standards. ISO 27001 covers information security and little of the privacy side. ISO 27701 overlaps substantially because it makes you build the inventory, lawful basis, retention and rights capability DPDP expects, so it is a strong accelerator and shared evidence base — but not a substitute.

Where should we start if we have nothing today?

The data inventory. Every other obligation reduces to a lookup against it — rights requests, retention, breach scoping and cross-border questions are all unanswerable without knowing what personal data you hold and where. It is also the item most organisations underestimate.

Ready to discuss your DPDP checklist consult requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →