Checklist

The DPDP compliance checklist (2026)

A practical, step-by-step DPDP Act compliance checklist for Indian businesses — what to do, in what order, to be ready before the deadline.

By DreamyHook Consultancy ServicesUpdated 7 min read

DPDP compliance can feel overwhelming. It needn't be. This checklist breaks it into clear stages — roughly the order we work through with clients. Treat it as a map, then scan your readiness to see where you actually stand.

Stage 1 — Discover

  • Map your personal data. What do you collect, where does it live, who can access it, where does it flow?
  • Build a record of processing (ROPA). Purposes, categories, retention, recipients.
  • List your processors. Every vendor and tool that touches personal data.
  • Check your SDF likelihood. Could you be notified a Significant Data Fiduciary?

A readiness audit does all of this systematically.

  • Rewrite your notices to be clear, itemized, and specific.
  • Offer notices in the user's language (English + Eighth Schedule languages).
  • Capture consent properly — free, specific, informed, unconditional, unambiguous.
  • Make withdrawal as easy as consent, and stop downstream processing when it's withdrawn.
  • Keep a consent ledger — tamper-evident evidence of who agreed to what, when.
  • Plan for Consent Managers. Architect so you can integrate when they go live.

See Consent & Notice Management.

Stage 3 — Data Principal rights

  • Stand up a rights workflow for access, correction, completion, updating, and erasure.
  • Add grievance redressal that's readily available.
  • Support nomination.
  • Track SLAs so you respond within the required timelines.

See Data Principal Rights Automation.

Stage 4 — Security & retention

  • Encrypt personal data in transit and at rest.
  • Lock down access with role-based controls.
  • Log processing and retain logs as required.
  • Set retention rules by purpose, and automate deletion.
  • Back up safely, with a defensible deletion approach.

See Technical Implementation.

Stage 5 — Breach readiness

  • Deploy breach detection / monitoring.
  • Write a notification runbook for the Board and affected users.
  • Run a drill so the process is tested, not theoretical.

Stage 6 — Governance

Stage 7 — Special cases

  • Children's data: verifiable parental consent; no tracking or targeting of minors.
  • Large-platform retention: inactivity-based deletion if you cross notified thresholds.
  • Cross-border transfers: documentation in line with the framework.

Your fastest first step

Don't guess which of these you've missed. The free DPDP Quick Scan turns this checklist into a personalized scorecard in five minutes — then a readiness audit turns that into a costed plan to the deadline.

General information, not legal advice. Confirm specifics against the notified DPDP Rules.

Frequently asked questions

It's a strong starting framework, but real compliance depends on your specific data and systems. Use it to orient, then validate with a readiness audit and, where needed, legal advice.

Start by mapping your data — you can't protect or govern what you haven't found. A readiness audit does this systematically.

See how this applies to you

The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.

Take the free Quick Scan

The deadline isn't moving. Start today.

Get your free DPDP Quick Scan — no obligation, instant results. See where you stand in five minutes.