Back to all posts

September 18, 2026

DPDP Compliance Checklist: 25 Things Every Business Needs to Do

A practical 25-point DPDP compliance checklist for businesses handling personal data of individuals in India, based on the DPDP Act 2023 and DPDP Rules 2025.


India's Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025 are now being brought into effect through a phased implementation process. The Ministry of Electronics and Information Technology (MeitY) notified the final Rules on 13 November 2025, and different provisions are being rolled out in stages over an 18-month commencement period. If you haven't yet mapped out what the law actually requires, it's worth starting with our complete guide to India's DPDP Act & Rules 2025, which breaks down the law, the timeline, and the penalty structure in detail. 


This checklist picks up from there. It's a practical, action-oriented list of the 25 things every business SaaS platform, e-commerce store, app, or service provider needs to do to get compliant, grouped into five areas: data governance, notice and consent, data principal rights, security and breach response, and children's data.


1. Data Governance and Mapping 


  • Run a full personal data inventory. Catalogue every category of personal data you collect, why you collect it, where it's stored, who can access it, and how long you keep it. This is the foundation every other step depends on. 


  • Confirm your role under the law. Work out whether you're a Data Fiduciary (you decide why and how data is processed), or a Data Processor acting on someone else's instructions. Your obligations differ depending on which one you are. 


  • Assess whether you qualify as a Significant Data Fiduciary (SDF). SDFs are designated based on factors like data volume, sensitivity, and risk to sovereignty or public order. If you might qualify, plan for the extra obligations early a Data Protection Officer, impact assessments, and independent audits. 


  • Audit every third-party vendor and processor. List every cloud provider, analytics tool, CRM, and outsourced partner that touches personal data on your behalf. Review whether existing contracts hold up under DPDP requirements. 


  • Appoint a designated point of contact. Every Data Fiduciary needs to make available a person data principals and the Data Protection Board of India can reach for grievances. The requirement to appoint a full Data Protection Officer based in India applies specifically to Significant Data Fiduciaries (SDFs).


2. Notice and Consent 


  • Rewrite your consent notices to be itemized and specific. Generic "we value your privacy" notices don't meet the bar. Notices need to spell out exactly what data is collected, for what purpose, and what happens if consent is refused. 


  • Set up a proper consent management system. You need a way to capture, store, and manage consent per purpose not a single blanket checkbox. If you plan to route consent through a registered Consent Manager down the line, note that only India-incorporated entities with a minimum net worth requirement can register in that role. 


  • Offer notices in relevant Indian languages. Consent has to be meaningful, which means it has to be understandable. If your user base spans multiple Indian states, plan for regional language versions of your key notices. 


  • Make withdrawing consent as easy as giving it. A data principal must be able to withdraw consent with the same ease they gave it no dark patterns, no hidden settings, no multi-step opt-outs. 


  • Keep consent logs and audit trails. Be able to show, for any user, what they consented to, when, and what notice they saw at the time. You'll need this both for internal audits and if the Data Protection Board comes asking.



3. Data Principal Rights


  • Build a Right to Access workflow. Individuals can request a summary of their data, who else has access to it, and how it's being processed. Have a defined process to pull this together. 


  • Build a Right to Correction workflow. Inaccurate or outdated data has to be correctable on request, without unnecessary friction. 


  • Build a Right to Erasure workflow. When a purpose is fulfilled or consent is withdrawn, personal data generally has to be erased, subject to applicable legal retention requirements and other circumstances permitted under the Act and Rules. This should tie into automated retention and deletion schedules, not a manual, ad hoc process. 


  • Set up a grievance redressal mechanism. Data principals need a channel to complain directly to you before escalating to the Data Protection Board. Build this with a clearly defined internal process and a reasonable response SLA, so requests don't sit unresolved. 


  • Add a Right to Nominate feature. Individuals can nominate someone to exercise their data rights on their behalf in case of death or incapacity. This needs to exist somewhere in your account settings or request process.

4. Security and Breach Response


  • Put reasonable technical and organizational safeguards in place. Encryption, access controls, logging, and monitoring aren't optional extras they're the baseline the law expects, and the highest penalty tier is reserved for failing to implement them. 


  • Build and test a breach notification process. A personal data breach has to be notified to affected Data Principals without delay and to the Data Protection Board without delay. Detailed information about the breach must be provided to the Board within 72 hours of becoming aware of the breach, unless a longer period is permitted. 


  • Maintain processing and breach logs. Keep records of processing activity and any incidents for the periods prescribed under the Rules. These logs are your evidence trail if you're ever investigated. 


  • Run periodic security reviews. Independent testing, vulnerability assessments, penetration testing, and access reviews are recommended as recurring practices rather than one-time pre-launch checks. SDFs face a separate, mandatory annual audit requirement. 


  • Prepare a breach communication plan. Beyond notifying the regulator, have templates and a process ready for informing affected users clearly and quickly, so a breach doesn't turn into a trust crisis.


5. Children's Data and Vendor Obligations 


  • Implement age verification wherever minors might sign up. If your product is accessible to anyone under 18, you need a way to identify that before processing their data, subject to the exemptions set out under the DPDP Rules for certain categories of service. 


  • Set up verifiable parental consent. Before processing a child's data, you need verifiable consent from a parent or guardian through account details, verification tokens, or Digital Locker–based verification. Note that essential services like healthcare and education carry specific exemptions. 


  • Rule out tracking, profiling, and targeted ads directed at children. The law expressly prohibits behavioural monitoring and targeted advertising aimed at children. This needs to be enforced in your ad tech and analytics stack, not just your policy document. 


  • Plan for SDF-specific obligations if they apply to you. This includes annual Data Protection Impact Assessments (DPIAs), algorithmic fairness checks, and restrictions on transferring certain traffic data outside India. 


  • Update every Data Processing Agreement (DPA) with vendors. Your contracts with processors need to explicitly reflect DPDP obligations, including instructions, security expectations, breach notification duties, and audit rights. An outdated DPA is a compliance gap even if your own house is in order. 


Eighteen months sounds like a long runway, but most of this checklist touches product, legal, and engineering all at once which is exactly why the businesses that start mapping data and rebuilding consent flows now are the ones that won't be scrambling as later commencement deadlines arrive.

FAQ

Got Questions? We've Got Answers

A quick, practical checklist of 25 things every business needs to do to get DPDP-ready.

A quick, practical checklist of 25 things every business needs to do to get DPDP-ready.

What is the deadline for DPDP compliance in India?

Does the DPDP Act apply to companies outside India?

What happens if a business doesn't comply?

Do small businesses and startups need to comply too?

Is a privacy policy enough to be DPDP-compliant?

Related resources

Related resources

Explore More

Explore More