Skip to content

DPDP registers

The registers the DPDP Act expects you to keep

Consent, data principal requests, breaches, vendors, DPIAs and policies, each with an owner, a due date and the evidence behind it.

The registers the Act expects you to keep

Every record has an owner, a due date, a status that won't move without the facts it needs, a full history and evidence attached.

Privacy operations

Personal data
Discovery scans and a data inventory with purpose, legal basis, retention and owner.
Consent
Consent records for each purpose, with withdrawals.
Requests
Access, correction, erasure, grievance and nomination, on a response clock of up to 90 days (Rule 14(3)).
Breaches
Each breach tracked against the Board's detailed report, due 72 hours after awareness (Rule 7(2)(b)).

Compliance

Controls
The client's status for every obligation. "Not applicable" needs a reason and an admin; "implemented" needs evidence.
Tasks
Turn any gap, risk or control into assigned work with an owner and due date.
Evidence
A library of files checked against their type, stored under random names, downloadable only when signed in.
Policies
Version, approver and next review date for each policy.

Risk

Risk register
Every gap and failed check becomes a risk, scored likelihood × impact on a 5×5 matrix, with treatment and owner.
Vendors and processors
Contract, data location and review date for each one.
DPIA
Data protection impact assessments for Significant Data Fiduciaries.
Data-flow map
Where personal data is collected, stored and shared, and which flows leave India.