Skip to content

DPDP Compliance Checklist: 12 Steps Before May 2027

A practical DPDP compliance checklist: data mapping, notices, consent, security, a 72-hour breach plan, rights requests, vendors, children's data and evidence.

By the GRC-Flow team · Published · 10 min read

Key takeaways

  • DPDP compliance means meeting every duty of a Data Fiduciary under the DPDP Act 2023 and Rules 2025, and being able to prove it with records and evidence.
  • Start with a data map: you cannot write a notice, secure data or answer requests for data you have not found.
  • The most-penalised gaps are weak security safeguards (up to ₹250 crore) and unreported breaches (up to ₹200 crore).
  • Most obligations apply from 13 May 2027; a full programme typically takes six to twelve months, so start now.

Use this checklist as the backbone of a DPDP readiness project. Each step names what to do and what evidence to keep, because under the DPDP Act it is not enough to comply: you must be able to show it.

The checklist at a glance

#StepEvidence to keep
1Appoint an owner and confirm scopeNamed owner, scope note, list of entities and systems
2Map personal dataData inventory / record of processing
3Confirm the lawful ground for each purposePurpose register: consent or legitimate use
4Rewrite noticesItemised notice per channel
5Fix consent and withdrawalConsent records, withdrawal flow
6Put security safeguards in placeEncryption, access, logging and backup proofs
7Prepare for breachesBreach playbook, contact list, drill record
8Set retention and erasureRetention schedule, deletion logs
9Handle rights and grievancesRequest register with 90-day due dates
10Review vendors and contractsProcessor list, data processing agreements
11Check children's dataAge-gating and parental consent records
12Train, review and keep evidenceTraining records, review dates, audit log

1. Appoint an owner and confirm scope

Name one person accountable and a small working group across legal, IT, product and HR. List the legal entities, products, websites, apps and offline processes that touch personal data, and check whether you might be named a Significant Data Fiduciary.

2. Map your personal data

For each system, record what personal data it holds, whose it is, why you have it, where it is stored (including outside India), who it is shared with, and how long you keep it. Include spreadsheets and exports: they are where personal data hides. This map becomes your record of processing.

3. Confirm the lawful ground for each purpose

For every purpose, decide whether you rely on consent or on a legitimate use under Section 7 (such as employment or a legal obligation). Drop purposes you cannot justify.

4. Rewrite your notices

Under Rule 3, a notice must be standalone, clear and plain, list each item of personal data with its specific purpose, and explain how to withdraw consent, exercise rights and complain to the Board. One generic privacy policy is not enough for every channel.

5. Fix consent and withdrawal

Consent must be a clear affirmative action, separate for each purpose, never bundled with terms, and as easy to withdraw as to give. Record when and how each consent was given and withdrawn, and stop processing when it is withdrawn.

6. Put security safeguards in place

Rule 6 sets the minimum: encryption, masking or tokenisation; access controls; logging and monitoring; backups and continuity; and the same safeguards required of processors by contract. Failing here carries the highest penalty, up to ₹250 crore (see DPDP Act penalties).

7. Prepare for breaches

Write a playbook for the Rule 7 timeline: tell affected people and the Board without delay, and send the Board a detailed report within 72 hours. Decide who decides, keep templates ready, and run a drill.

8. Set retention and erasure

Set a retention period for each purpose and erase data when the purpose is served or consent is withdrawn. Keep processing logs for at least one year as the Rules require, and record deletions.

9. Handle rights requests and grievances

Publish how people can ask for access, correction, erasure or nomination, verify who is asking, and answer within 90 days. Publish the contact of the person who answers data questions (Rule 9), and track every request and complaint to closure.

10. Review vendors and contracts

List every processor (cloud, CRM, payroll, marketing, support tools), where they store data, and sign data processing agreements that require security safeguards, breach notice to you and deletion at the end of the contract.

11. Check children's data

If anyone under 18 may use your service, add age checks and verifiable parental consent (Rule 10), and switch off tracking, behavioural monitoring and targeted advertising for children.

12. Train, review and keep evidence

Train staff who handle personal data, set review dates for policies, and keep a log of who did what. When the Board asks, your evidence is your answer.

Run the checklist faster

GRC Flow turns this checklist into a guided workflow: an intake mapped to every obligation in the Act and Rules, personal-data discovery for your exports, AI-drafted findings that cite the exact section and are reviewed by a person, a readiness plan that tracks progress from real data, and an evidence library that checks each document actually covers its obligation. Book a demo to see it on your own case.

Frequently asked questions

What is DPDP compliance?

Meeting the obligations the DPDP Act 2023 and the DPDP Rules 2025 place on a Data Fiduciary: lawful grounds and notice, consent, security, breach reporting, retention and erasure, rights handling, grievance redressal and, for some, extra duties as a Significant Data Fiduciary. Compliance also means keeping the evidence to show it.

How long does DPDP compliance take?

For a mid-sized business, typically six to twelve months from data mapping to tested processes. Smaller organisations with simple data flows can be ready sooner.

Do we need a Data Protection Officer under the DPDP Act?

Only a Significant Data Fiduciary must appoint a Data Protection Officer based in India. Every other Data Fiduciary must publish the contact of a person who can answer questions about personal data.

Is there an official DPDP compliance certificate?

No. The Act and Rules do not create a government certificate. You show compliance through your records, policies and evidence. See our guide on DPDP certification.

Sources

This guide explains the law in general terms and is not legal advice. Check specific situations with a qualified lawyer.