Checklist

DPDP Compliance Checklist (2026)

Most DPDP checklists list the Act's sections. That is not useful for someone who has to get compliant, because the sections are not in the order the work happens. This checklist is ordered the way the programme actually runs, and names the evidence each step has to leave behind — evidence is what an auditor or the Data Protection Board asks for, not intentions.

Priya Gupta

Know what you hold

Nothing later is defensible until this is true. Every subsequent obligation is defined against the personal data you actually process.

  • 1. Discover personal data across databases, object storage, SaaS and file shares. Evidence: a dated inventory that regenerates, not a one-off spreadsheet.
  • 2. Classify it, marking anything relating to children or requiring verifiable parental consent. Evidence: the classification rules and their coverage.
  • 3. Map flows, including transfers to processors and outside India. Evidence: a current data flow map tied to named systems.
  • 4. Build and version your Records of Processing Activities. Evidence: RoPA with change history.

Establish lawful basis

This is the step organisations most often skip, and the one that most often fails on inspection.

  • 5. State a purpose for each processing activity and confirm the data collected is no wider than that purpose requires. Evidence: purpose register, approved by a named owner.
  • 6. Publish notices in English or a language in the Eighth Schedule. Evidence: versioned notices, with the version bound to each consent record.
  • 7. Capture consent by clear affirmative action, with withdrawal as easy as giving. Evidence: consent records showing purpose, language, notice version and timestamp.
  • 8. Confirm withdrawal actually stops downstream processing. Evidence: a withdrawal traced end to end.

Be able to answer people and incidents

These two are time-bound, which is what makes manual handling risky.

  • 9. Run an intake for access, correction and erasure requests with SLA tracking. Evidence: a request log showing every one answered in the statutory window.
  • 10. Publish a grievance redressal route and staff it. Evidence: grievance log with outcomes.
  • 11. Operate a breach lifecycle — detect, assess, notify, remediate. Evidence: an incident record with the decision and its timing.

Govern it

The last step is the one that determines whether the rest survives staff turnover.

  • 12. Determine whether you are a Significant Data Fiduciary and, if so, appoint a Data Protection Officer, run DPIAs and arrange independent audits. Evidence: the determination itself, the appointment, and DPIA sign-offs.

Frequently asked questions

What is on a DPDP compliance checklist?

Discover and classify personal data, map flows, build a RoPA, establish and record lawful basis, publish notices in a scheduled language, capture and honour consent, run data principal rights and grievance handling to their statutory timelines, operate a breach lifecycle, and determine whether you are a Significant Data Fiduciary.

Where should we start with DPDP compliance?

With discovery. Every other obligation is defined against the personal data you actually hold, so an inventory that regenerates is the prerequisite for making any later step defensible.

Does the DPDP Act require a Data Protection Officer?

A DPO is required of Significant Data Fiduciaries. The first task is therefore the determination itself — deciding, and recording, whether your organisation falls into that class.

What evidence does DPDP compliance require?

A current data inventory and RoPA, versioned notices bound to consent records, consent and withdrawal logs, a rights-request log showing statutory timelines were met, grievance outcomes, incident records, and DPIA sign-offs where applicable.

Priya GuptaPriya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →