Compliance

DPDP Act Compliance Checklist for Indian Businesses

A practical checklist covering data inventory, consent, notices, rights handling, security, and everything your business needs to operationalize DPDP compliance.

By: ConsentLog Research
Published: 7 September 2026
Last reviewed: 7 September 2026
10 min read

Executive Summary

This checklist provides a structured approach to DPDP Act compliance. It covers governance, data inventory, consent, notices, rights handling, security, breach response, and ongoing monitoring. Use it to assess your current state and identify gaps.

How to Use This Checklist

This checklist distinguishes between:

  • Statutory Requirements: Obligations mandated by the DPDP Act and Rules
  • Implementation Practices: Recommended approaches for operationalizing compliance
  • Best Practices: Going beyond the minimum to reduce risk and improve operations

Review each section and assess your current state. Identify gaps and prioritize remediation based on risk and business impact.

Section 1: Governance & Organization

Appointed a Grievance Officer

Statutory Requirement: Designate an individual to handle Data Principal complaints

Documented the Grievance Officer contact details

Statutory Requirement: Make contact information available to Data Principals

Established a grievance handling process

Implementation Practice: Define how complaints are received, logged, investigated, and resolved

Assessed if your company is a Significant Data Fiduciary

If designated, additional obligations apply: DPO appointment, impact assessments, compliance certifications

Trained key staff on DPDP obligations

Best Practice: Ensure privacy awareness across relevant departments (engineering, product, marketing, legal)

Section 2: Data Inventory & Classification

Completed a data inventory across your systems

Implementation Practice: Document all locations where personal data is collected, stored, or processed

Classified data by sensitivity and category

Implementation Practice: Identify sensitive categories (health, biometric, financial) which require additional protection

Documented the retention period for each data category

Implementation Practice: Define how long data should be kept before deletion

Mapped data processors and sub-processors

Statutory Requirement: Maintain a list of vendors/contractors who process data on your behalf

Section 3: Consent & Notice Management

Defined specific purposes for data processing

Statutory Requirement: Clearly articulate each distinct purpose (marketing, customer support, analytics, etc.)

Created purpose-specific notices

Statutory Requirement: Provide clear, independent notices explaining each purpose before requesting consent

Obtain affirmative, unambiguous consent

Statutory Requirement: Use opt-in mechanisms; avoid pre-checked boxes or ambiguous language

Record consent with timestamp and version

Implementation Practice: Capture the exact time, notice version, and consent state for audit purposes

Provide easy consent withdrawal mechanism

Statutory Requirement: Allow Data Principals to withdraw consent with the same ease they gave it

Section 4: Data Principal Rights Handling

Established process for access requests

Statutory Requirement: Respond to "Right to Know" requests in reasonable timeframe (typically 30 days)

Established process for correction requests

Statutory Requirement: Allow Data Principals to correct inaccurate or incomplete data

Established process for erasure requests

Statutory Requirement: Delete data on request (subject to legal/regulatory exceptions)

Documented systems for tracking requests

Implementation Practice: Log all rights requests with dates, responses, and outcomes for audit

Handle children's data with parental consent

Statutory Requirement: Obtain verified guardian consent for data of individuals under 18

Section 5: Data Security

Implemented encryption for sensitive data

Implementation Practice: Encrypt personal data at rest and in transit

Implemented access controls

Implementation Practice: Limit access to personal data to authorized employees only

Conducted security assessments

Implementation Practice: Regularly assess security posture and vulnerability

Established data handling procedures

Best Practice: Document how employees should handle personal data securely

Managed third-party vendor security

Implementation Practice: Ensure processors/vendors meet security standards

Section 6: Data Breach Response

Established breach detection process

Implementation Practice: Have systems and procedures to identify data breaches quickly

Created breach response procedure

Implementation Practice: Define steps for investigating, containing, and documenting breaches

Notify Data Protection Board within 72 hours of breach

Statutory Requirement: Provide detailed breach report to DPBI

Notify affected individuals promptly

Statutory Requirement: Inform affected Data Principals "as soon as practicable"

Maintained breach documentation

Implementation Practice: Keep detailed records of all breaches for regulatory review

Key Takeaways

Use this checklist to systematically assess your DPDP compliance posture. Prioritize governance, consent management, and security first. Address gaps incrementally with clear ownership and timelines.

Sources & Further Reading

Digital Personal Data Protection Act, 2023

Parliament of India — Full Text

https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sections

Digital Personal Data Protection Rules, 2025

Ministry of Electronics and Information Technology — Implementation Rules

https://www.meity.gov.in/

Building your DPDP compliance infrastructure?

ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.