Checklist
Most DPDP checklists list the Act's sections. That is not useful for someone who has to get compliant, because the sections are not in the order the work happens. This checklist is ordered the way the programme actually runs, and names the evidence each step has to leave behind — evidence is what an auditor or the Data Protection Board asks for, not intentions.
Nothing later is defensible until this is true. Every subsequent obligation is defined against the personal data you actually process.
This is the step organisations most often skip, and the one that most often fails on inspection.
These two are time-bound, which is what makes manual handling risky.
The last step is the one that determines whether the rest survives staff turnover.
Discover and classify personal data, map flows, build a RoPA, establish and record lawful basis, publish notices in a scheduled language, capture and honour consent, run data principal rights and grievance handling to their statutory timelines, operate a breach lifecycle, and determine whether you are a Significant Data Fiduciary.
With discovery. Every other obligation is defined against the personal data you actually hold, so an inventory that regenerates is the prerequisite for making any later step defensible.
A DPO is required of Significant Data Fiduciaries. The first task is therefore the determination itself — deciding, and recording, whether your organisation falls into that class.
A current data inventory and RoPA, versioned notices bound to consent records, consent and withdrawal logs, a rights-request log showing statutory timelines were met, grievance outcomes, incident records, and DPIA sign-offs where applicable.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →