DPDP Act Compliance Checklist for Indian Businesses
A practical checklist covering data inventory, consent, notices, rights handling, security, and everything your business needs to operationalize DPDP compliance.
Executive Summary
This checklist provides a structured approach to DPDP Act compliance. It covers governance, data inventory, consent, notices, rights handling, security, breach response, and ongoing monitoring. Use it to assess your current state and identify gaps.
How to Use This Checklist
This checklist distinguishes between:
- Statutory Requirements: Obligations mandated by the DPDP Act and Rules
- Implementation Practices: Recommended approaches for operationalizing compliance
- Best Practices: Going beyond the minimum to reduce risk and improve operations
Review each section and assess your current state. Identify gaps and prioritize remediation based on risk and business impact.
Section 1: Governance & Organization
Appointed a Grievance Officer
Statutory Requirement: Designate an individual to handle Data Principal complaints
Documented the Grievance Officer contact details
Statutory Requirement: Make contact information available to Data Principals
Established a grievance handling process
Implementation Practice: Define how complaints are received, logged, investigated, and resolved
Assessed if your company is a Significant Data Fiduciary
If designated, additional obligations apply: DPO appointment, impact assessments, compliance certifications
Trained key staff on DPDP obligations
Best Practice: Ensure privacy awareness across relevant departments (engineering, product, marketing, legal)
Section 2: Data Inventory & Classification
Completed a data inventory across your systems
Implementation Practice: Document all locations where personal data is collected, stored, or processed
Classified data by sensitivity and category
Implementation Practice: Identify sensitive categories (health, biometric, financial) which require additional protection
Documented the retention period for each data category
Implementation Practice: Define how long data should be kept before deletion
Mapped data processors and sub-processors
Statutory Requirement: Maintain a list of vendors/contractors who process data on your behalf
Section 3: Consent & Notice Management
Defined specific purposes for data processing
Statutory Requirement: Clearly articulate each distinct purpose (marketing, customer support, analytics, etc.)
Created purpose-specific notices
Statutory Requirement: Provide clear, independent notices explaining each purpose before requesting consent
Obtain affirmative, unambiguous consent
Statutory Requirement: Use opt-in mechanisms; avoid pre-checked boxes or ambiguous language
Record consent with timestamp and version
Implementation Practice: Capture the exact time, notice version, and consent state for audit purposes
Provide easy consent withdrawal mechanism
Statutory Requirement: Allow Data Principals to withdraw consent with the same ease they gave it
Section 4: Data Principal Rights Handling
Established process for access requests
Statutory Requirement: Respond to "Right to Know" requests in reasonable timeframe (typically 30 days)
Established process for correction requests
Statutory Requirement: Allow Data Principals to correct inaccurate or incomplete data
Established process for erasure requests
Statutory Requirement: Delete data on request (subject to legal/regulatory exceptions)
Documented systems for tracking requests
Implementation Practice: Log all rights requests with dates, responses, and outcomes for audit
Handle children's data with parental consent
Statutory Requirement: Obtain verified guardian consent for data of individuals under 18
Section 5: Data Security
Implemented encryption for sensitive data
Implementation Practice: Encrypt personal data at rest and in transit
Implemented access controls
Implementation Practice: Limit access to personal data to authorized employees only
Conducted security assessments
Implementation Practice: Regularly assess security posture and vulnerability
Established data handling procedures
Best Practice: Document how employees should handle personal data securely
Managed third-party vendor security
Implementation Practice: Ensure processors/vendors meet security standards
Section 6: Data Breach Response
Established breach detection process
Implementation Practice: Have systems and procedures to identify data breaches quickly
Created breach response procedure
Implementation Practice: Define steps for investigating, containing, and documenting breaches
Notify Data Protection Board within 72 hours of breach
Statutory Requirement: Provide detailed breach report to DPBI
Notify affected individuals promptly
Statutory Requirement: Inform affected Data Principals "as soon as practicable"
Maintained breach documentation
Implementation Practice: Keep detailed records of all breaches for regulatory review
Key Takeaways
Use this checklist to systematically assess your DPDP compliance posture. Prioritize governance, consent management, and security first. Address gaps incrementally with clear ownership and timelines.
Sources & Further Reading
Digital Personal Data Protection Act, 2023
Parliament of India — Full Text
https://indiacode.gov.in/act/c058fa9f-eaf0-4ca3-98f1-3443b087bca9/sectionsDigital Personal Data Protection Rules, 2025
Ministry of Electronics and Information Technology — Implementation Rules
https://www.meity.gov.in/Related Articles
What Is the DPDP Act? A Practical Guide for Indian Businesses
Understand India's Digital Personal Data Protection Act 2023: scope, key concepts, obligations, and what compliance means for your business.
What Is Consent Under the DPDP Act?
A deep dive into consent under India's DPDP Act: requirements, notice, informed decision-making, withdrawal, and how to implement consent properly.
How to Implement DPDP Consent Management
An implementation guide to DPDP consent management: consent models, notice versions, event recording, withdrawal, and downstream propagation.
Building your DPDP compliance infrastructure?
ConsentLog helps Indian businesses operationalize DPDP consent requirements across their systems. Learn how we're approaching consent infrastructure.