Skip to content
Guides
Guide

The DPDP readiness checklist

A step-by-step readiness checklist for the DPDP Act 2023 — data mapping, lawful basis, notice and consent, Data Principal rights, breach response, and more.

12 min read

This guide is a working checklist for getting your organisation ready for India’s Digital Personal Data Protection Act, 2023 (DPDP). Work through it section by section. Each item is a concrete deliverable, not a vague principle — so by the end you will have an auditable, defensible programme rather than a binder of good intentions.

Before you start: understand your role

Under DPDP you are a Data Fiduciary — the entity that decides why and how personal data is processed. The individuals whose data you hold are Data Principals. Anyone processing data on your behalf is a Data Processor. Knowing which hat each party wears determines who owes which duty.

If the government designates you a Significant Data Fiduciary (based on data volume, sensitivity, and risk), you take on extra duties: an India-based Data Protection Officer, an independent data auditor, and periodic Data Protection Impact Assessments. Assess this early so it doesn’t surprise you later.

1. Map your personal data

You cannot protect or govern what you cannot see. Build and maintain a record of processing.

  • List every system, app, and vendor that touches personal data
  • For each, record what data you hold, why, the lawful basis, who it is shared with, and how long you keep it
  • Flag data flows that leave India (cross-border transfers)
  • Identify any children’s data (under 18) in your systems
  • Keep the map current — assign an owner and a review cadence

2. Establish a lawful basis for every purpose

DPDP allows processing only on consent or a defined legitimate use. There is no broad “legitimate interests” basis.

  • For each processing purpose, document whether you rely on consent or a specific legitimate use
  • Remove or re-base any processing that has no valid basis
  • Separate distinct purposes — don’t bundle unrelated processing under one consent

3. Fix your notice

Before or at the time you seek consent, you must give a clear notice.

  • State the personal data collected and the purpose of processing
  • Explain how Data Principals can exercise their rights
  • Explain how to lodge a complaint with the Data Protection Board
  • Make the notice available in plain language (English and the languages in the Eighth Schedule of the Constitution, as applicable)
  • Version the notice so you can prove what was shown and when

Consent under DPDP must be free, specific, informed, unconditional, and unambiguous, with a clear affirmative action.

  • Capture consent per purpose, with a timestamp and the notice version shown
  • Make withdrawal as easy as giving consent
  • On withdrawal, stop the relevant processing and cascade to processors
  • Store the consent artefact as evidence
  • If you use a Consent Manager, integrate with it

5. Stand up Data Principal rights workflows

Data Principals have rights to access, correction, completion, updating, erasure, grievance redressal, and nomination.

  • Publish a simple way to submit requests
  • Verify identity before acting
  • Locate the person’s data across all systems (your data map makes this possible)
  • Fulfil access, correction, and erasure within a tracked turnaround time
  • Provide a grievance redressal channel and respond to it
  • Support nomination — letting a principal nominate someone to act on their behalf

6. Set retention and deletion rules

DPDP requires you to erase data once its purpose is served, unless law requires retention.

  • Define a retention period per data category
  • Automate deletion where possible
  • Cascade deletion to processors and backups on a defined schedule
  • Keep a deletion log as evidence

7. Strengthen security safeguards

You must implement reasonable security safeguards to prevent breaches.

  • Enforce access control and least privilege
  • Encrypt data in transit and at rest
  • Log access to personal data and monitor for anomalies
  • Patch and manage vulnerabilities
  • Train staff on data handling

If you already run SOC 2 or ISO 27001, most of this is in place — see how the controls overlap in our SOC 2 framework guide.

8. Manage your processors

Processing by a Data Processor must be under a valid contract.

  • Inventory every processor and sub-processor
  • Ensure a written contract is in place with DPDP obligations flowed down
  • Confirm processors only act on your instructions
  • Review processor security and breach-notification commitments

9. Prepare for breaches

You must notify the Data Protection Board and affected Data Principals of a personal data breach.

  • Write a breach-response runbook with roles and the notification timeline
  • Define how you detect, triage, and contain incidents
  • Pre-draft notification templates for the Board and individuals
  • Run a tabletop exercise so the team has rehearsed it
  • Keep an evidence trail of detection, decisions, and notifications

10. Handle children’s data

  • Identify where you process data of anyone under 18
  • Add age assurance and verifiable parental consent where required
  • Stop behavioural tracking and targeted advertising directed at children

11. Govern the programme

  • Appoint a contact person (or DPO) and publish how to reach them
  • Maintain your data map, consent records, and request logs as living artefacts
  • Schedule periodic reviews and, if you are a Significant Data Fiduciary, DPIAs and independent audits

Operationalise it

A first pass through this checklist gets you to a defensible baseline. The ongoing challenge is keeping consent records, data maps, and request logs current as your systems and vendors change. Comply ships DPDP as a native module — data mapping, consent and notice management, Data Principal request workflows, and the breach clock — mapped to your existing controls. Explore the DPDP framework, the privacy platform, and our transparent pricing to plan your rollout.

See your compliance prove itself

Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.

Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.