Checklist
The DPDP compliance checklist (2026)
A practical, step-by-step DPDP Act compliance checklist for Indian businesses — what to do, in what order, to be ready before the deadline.
DPDP compliance can feel overwhelming. It needn't be. This checklist breaks it into clear stages — roughly the order we work through with clients. Treat it as a map, then scan your readiness to see where you actually stand.
Stage 1 — Discover
- Map your personal data. What do you collect, where does it live, who can access it, where does it flow?
- Build a record of processing (ROPA). Purposes, categories, retention, recipients.
- List your processors. Every vendor and tool that touches personal data.
- Check your SDF likelihood. Could you be notified a Significant Data Fiduciary?
A readiness audit does all of this systematically.
Stage 2 — Notice & consent
- Rewrite your notices to be clear, itemized, and specific.
- Offer notices in the user's language (English + Eighth Schedule languages).
- Capture consent properly — free, specific, informed, unconditional, unambiguous.
- Make withdrawal as easy as consent, and stop downstream processing when it's withdrawn.
- Keep a consent ledger — tamper-evident evidence of who agreed to what, when.
- Plan for Consent Managers. Architect so you can integrate when they go live.
See Consent & Notice Management.
Stage 3 — Data Principal rights
- Stand up a rights workflow for access, correction, completion, updating, and erasure.
- Add grievance redressal that's readily available.
- Support nomination.
- Track SLAs so you respond within the required timelines.
See Data Principal Rights Automation.
Stage 4 — Security & retention
- Encrypt personal data in transit and at rest.
- Lock down access with role-based controls.
- Log processing and retain logs as required.
- Set retention rules by purpose, and automate deletion.
- Back up safely, with a defensible deletion approach.
Stage 5 — Breach readiness
- Deploy breach detection / monitoring.
- Write a notification runbook for the Board and affected users.
- Run a drill so the process is tested, not theoretical.
Stage 6 — Governance
- Appoint a grievance officer (and a DPO if you're an SDF or your customers require one).
- Draft your policies and DPAs (via legal partners).
- Train your team — awareness and engineering workshops.
- Schedule ongoing reviews with Managed Compliance.
Stage 7 — Special cases
- Children's data: verifiable parental consent; no tracking or targeting of minors.
- Large-platform retention: inactivity-based deletion if you cross notified thresholds.
- Cross-border transfers: documentation in line with the framework.
Your fastest first step
Don't guess which of these you've missed. The free DPDP Quick Scan turns this checklist into a personalized scorecard in five minutes — then a readiness audit turns that into a costed plan to the deadline.
General information, not legal advice. Confirm specifics against the notified DPDP Rules.
Frequently asked questions
It's a strong starting framework, but real compliance depends on your specific data and systems. Use it to orient, then validate with a readiness audit and, where needed, legal advice.
Start by mapping your data — you can't protect or govern what you haven't found. A readiness audit does this systematically.
See how this applies to you
The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.
Take the free Quick Scan