Free download · 150-point DPDP checklist
150-point DPDP Act 2023 implementation checklist
A practical, obligation-by-obligation checklist to take you from “we should do DPDP” to a working programme — consent, data-principal rights, data inventory, breach and grievance workflows, processor contracts and Significant Data Fiduciary duties.
Checkpoints
150
Domains
9
Format
Excel + PDF
Basis
DPDP Act + Rules
Get the 150-point dpdp checklist
Enter your work email and we’ll send it straight to your inbox.
What’s included
150 checkpoints across 9 domains
Notice & consent, data-principal rights, RoPA/inventory, security safeguards, breach, grievance, processors, transfers and governance.
SDF add-on
The extra Significant Data Fiduciary duties — DPO, DPIA and independent audit — flagged separately.
Evidence per checkpoint
What good looks like and the artefact that evidences each control, so an audit finds a working programme.
Prioritised roadmap
Sequencing so you build the highest-risk obligations first, not a generic policy pack.
Who it’s for
- Data Fiduciaries operationalising the DPDP Act
- DPOs, privacy and legal teams building the programme
- Organisations that have policies but no working inventory or rights workflow
Inside the 150-point dpdp checklist
- 150 checkpoints across 9 privacy domains
- Consent, notice and rights workflows
- RoPA / data-inventory structure
- Breach and grievance-redressal steps
- Significant Data Fiduciary duties
- Prioritised implementation roadmap
Prepared by CyberSigma privacy practice · Reviewed by a DPDP privacy specialist · Last updated July 2026
Turn the checklist into a working programme
A DPDP gap assessment maps these 150 points to how you actually process data and returns a costed remediation plan.
