Checklist · DPDP Act

The DPDP checklist, in the order it has to be done.

Nine workstreams for organisations working back from 13 May 2027, when the core obligations under India’s DPDP Act become enforceable. No email form, no download, no badge at the end of it — just the list, and an honest note about what it cannot do for you.

How to use this

The order matters more than the content. Workstream one produces the inventory every other workstream depends on, and organisations that start at workstream two because it looks easier end up doing workstream two twice. Work down the list.

Two things this checklist is not. It is not a certification, because there is no DPDP certification — the Act created the Data Protection Board of India to adjudicate, not a scheme to certify, and there is no accredited DPDP certifier anywhere. If someone offers you a DPDP badge, be suspicious about everything else they have told you. And it is not legal advice: it is general information, current as of August 2026, written to be worked through by the people who own the systems. Where a question turns on contested interpretation, take that question to counsel.

What a completed version of this list gives you is defensibility. The Board sets penalty amounts by weighing the nature, gravity and duration of a violation, the personal data involved, whether harm was caused, and the cooperation and mitigation that followed. Documented good-faith readiness is the specific thing that moves that number, and it is the only variable on the list you control.

The clock

Three dates, all counted from one.

The DPDP Rules, 2025 were notified in the Gazette on 13 November 2025. Rule 1 divides them into three tranches and counts each one from that publication date, so every deadline below is derived rather than announced.

  • On notificationRules 1, 2 and 17–21 — the Data Protection Board of India
  • +12 months, around 13 Nov 2026Rule 4 — Consent Manager registration
  • +18 months, around 13 May 2027Rules 3, 5–16, 22–23 — the core obligations
  • ₹250 croreMaximum penalty — reasonable security safeguards
  • ₹200 croreMaximum penalty — failure to notify a breach
  • 72 hoursDetailed breach report to the Board

The checklist

Nine workstreams, run in this order.

Each one assumes the one above it is finished. Treat a workstream as done when someone outside the team that built it could demonstrate it working, not when the document describing it exists.

Each one assumes the one above it is finished 1 Data map 2 Notice & consent 3 Rights 4 Breach 5 Retention 6 Children's data 7 Processors 8 Safeguards 9 SDF duties start not here Map first — starting at two means doing two twice
  1. 01 · Data mapping

    Inventory every processing activity across product, engineering, HR, marketing, support, finance and third-party tools. For each one record what personal data is collected, the purpose, the basis relied on, where it is stored, who it is shared with and how long it is kept. Include the systems nobody owns: the spreadsheet on someone’s drive, the analytics tool marketing signed up for, the support inbox. Then determine your role per activity — Data Fiduciary, Data Processor, or both — because the obligations attach differently to each, and doing this once at company level is the most common and most expensive shortcut in a DPDP programme.

  2. 02 · Notice and consent

    Rewrite notices so they are clear, in plain language, and state what is collected, for what purpose, and how the individual exercises their rights or complains. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action — no pre-ticked boxes, no consent bundled into terms of service. Build withdrawal so that it is as easy as giving consent was, and make sure withdrawal actually stops the processing downstream rather than only setting a flag. Keep consent records that show what was consented to and when, because a consent you cannot evidence is a consent you do not have.

  3. 03 · Data-principal rights

    Publish a mechanism for access, correction and erasure, grievance redressal, and nomination — the right to name another individual to exercise your rights if you die or become incapacitated, which has no equivalent in any framework you have already implemented. Then test it: run a real access request, then a correction, then an erasure, end to end through your own systems, and record how long each took and what broke. A rights process that has only ever been described in a policy will fail the first time a real person uses it, and the first real person may well be a complainant.

  4. 04 · Breach detection and reporting

    The obligation has two clocks. Notify the Data Protection Board and every affected data principal without delay, then file a detailed report with the Board within 72 hours. Work backwards from that: you cannot report inside 72 hours if your logging, alerting and escalation would not tell you inside 72 hours, which makes most of this an engineering task rather than a legal one. Write the playbook — who decides it is a breach, who notifies, what goes to the Board, what goes to individuals — then rehearse it as a tabletop at least once. Failure to notify carries its own maximum penalty of ₹200 crore, separate from any penalty for the failure that caused the breach.

  5. 05 · Retention and erasure

    Set retention periods per processing activity rather than one policy for the whole organisation, and tie each period to the purpose that justifies it. Erase personal data when consent is withdrawn or the purpose is served, unless a law requires you to keep it — and be able to show that erasure happened in backups, logs, analytics and anywhere the data was copied, not only in the primary database. Where the Rules require advance notice to the data principal before deletion, build that notification rather than assuming it will be handled by whoever runs the deletion job.

  6. 06 · Children’s data

    The Indian threshold is 18, not 16 and not 13, so a consent flow designed for GDPR is under-scoped here by several years of users. Establish whether you process the data of anyone under 18 — including through a product that does not target children but does not prevent them either. Where you do, implement verifiable parental or guardian consent, and stop tracking, behavioural monitoring and targeted advertising directed at children. Notified exemptions exist for defined purposes such as healthcare and education; confirm you are actually inside one before relying on it.

  7. 07 · Processors and contracts

    Every vendor that processes personal data on your behalf must do so under a valid contract, and paperwork signed before November 2025 almost certainly does not contain what the Act now requires. Work through the vendor list from the data map, not from the procurement system, because the two do not match. Update the terms to bind processors to security obligations and to breach cooperation on a timeline that lets you meet your own 72-hour deadline — a processor who tells you about an incident on day four has made your compliance failure for you.

  8. 08 · Security safeguards

    This is the limb the largest penalty is attached to: up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach. Encryption in transit and at rest, access control and review, logging and monitoring that would actually surface an incident, patching that happens, and backups that have been restored at least once. If you hold an ISO 27001 certificate this is where it does most of its work for you — but the safeguards are judged against the data you hold and the harm a breach would cause, not against the scope statement of your ISMS.

  9. 09 · Significant Data Fiduciary duties

    Designation is a government decision based on the volume and sensitivity of the personal data processed and the risk it carries — you cannot volunteer for it and you cannot rule it out yourself. Assess whether your volumes put it within reach, and if they do, plan for four additional duties: a Data Protection Officer based in India, an annual Data Protection Impact Assessment, an independent data audit, and algorithmic due diligence over the systems that process personal data. The point of doing this early is that designation should not arrive with a build programme attached.

Common failures

Where this list usually goes wrong.

Patterns we see often enough to be worth naming. None of them are exotic, and all of them cost more to fix later than to avoid now.

Starting at workstream two

Notices are the visible part, so they get rewritten first. Then the data map arrives, reveals four processing activities nobody mentioned, and the notices are rewritten again. Map first, even though it is the least satisfying week of the programme.

Assuming ISO 27001 covers it

It covers workstream eight well and almost nothing else. A certificate is a reasonable basis for confidence about security safeguards and no basis at all for confidence about consent, rights, notices or breach reporting to an Indian regulator.

Declaring one role for the whole company

Most organisations are a Data Fiduciary for some processing and a Data Processor for other processing. Deciding once, at company level, quietly mis-assigns obligations across every activity that does not fit the decision.

A breach plan nobody has run

The plan is fine. The problem is that the first time anyone follows it is during an incident, at which point the 72-hour clock is already running and the person named in it has left. One tabletop exercise finds more than three revisions of the document.

Erasure that only deletes the row

The record goes from the primary database and stays in backups, warehouse tables, analytics exports and the support tool. Erasure has to be demonstrable everywhere the data went, which is a question the data map answers and nothing else does.

Waiting for enforcement to clarify things

The commencement dates are written into rule 1 of a notified instrument. Waiting for a first enforcement action means starting a three-to-six-month programme after the obligations have already become enforceable.

Are you actually ready?

You are ready when all of these are true.

Not when the documents exist. When someone who did not write them could produce the evidence on the day it is asked for, without a week of preparation first.

Talk to us about DPDP
  • You can produce a current inventory of every processing activity within a day.
  • You can show, per activity, whether you are a Data Fiduciary or a Data Processor and why.
  • Someone can service an access, correction, erasure or nomination request without escalating it.
  • Withdrawing consent stops the processing downstream, and you can demonstrate that it does.
  • Your logging would surface a personal data breach well inside 72 hours.
  • The breach playbook has been rehearsed by the people named in it.
  • Every processor that touches personal data is under a contract written after November 2025.
  • You know whether Significant Data Fiduciary designation is a realistic prospect for you.

If the list found something

Most organisations get through workstream one and discover the problem is bigger than the meeting that commissioned it. That is the normal outcome, and it is a better place to be in 2026 than in 2027. Our DPDP readiness assessment is the fixed-scope version of workstreams one to three, delivered as an inventory, a written role determination, a RAG-rated gap register and a roadmap dated to May 2027. The wider programme — implementation, validation and ongoing assurance — is set out on the DPDP Act compliance page.

Facts on this page are current as of August 2026 and are re-checked against Data Protection Board of India notifications before each update. This is general information, not legal advice.

Next step

Bring us the list and the awkward findings.

A 30-minute call about where you actually are, then a fixed-scope assessment if you want one. No obligation, and no charge for the conversation.