Starting point

DPDP Compliance Checklist

Use this checklist as an implementation-planning aid for India’s DPDP framework. It expands common workstreams — discovery, notice and consent, rights, security, retention, children and governance — with short practical notes. It does not by itself establish compliance.

What this checklist is for

The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 create a framework of purposes, processing bases, Fiduciary obligations, Principal rights and institutional enforcement. A checklist cannot list every obligation for every organisation. It can help teams structure discovery and gap analysis before deeper legal review.

Always confirm which Act provisions and Rules have commenced for your planning horizon, and read the official text for your facts. Cross-link deeper explainers from the DPDP hub as you work through each group.

Checklist groups in practice

Data discovery

Sections 2–4; operational inventory
  • Identify digital personal data you collect, generate, store, share or otherwise process.
  • Document processing activities by system, channel and business unit.
  • State a clear purpose for each activity before deciding the processing basis.

Notice + consent

Sections 4–6; Rule 3
  • Review notices that accompany or precede consent requests for personal data and purpose content.
  • Assess where consent is required versus where a Section 7 certain legitimate use may apply.
  • Establish consent capture that is free, specific, informed, unconditional and unambiguous.
  • Provide withdrawal with comparable ease and record the decision lifecycle.

Data Principal

Sections 11–14; Rule 14
  • Publish and staff means for access, correction, erasure, grievance and nomination requests.
  • Assign operational owners and SLAs aligned to applicable Rules once commenced.
  • Track requests, identity verification steps and outcomes for accountability.

Security

Section 8(5); Rule 6
  • Map Rule 6 minimum safeguards: protection measures, access control, logging, continuity, processor contracts and organisational measures.
  • Retain security-relevant logs and associated personal data for the Rule 6 one-year period where that Rule applies.
  • Establish breach detection and escalation linked to Rule 7 intimation duties.

Retention

Section 8; Rule 8
  • Tie retention to specified purpose and legal retention requirements.
  • If you fall within a Third Schedule class, apply the corresponding deemed periods and 48-hour pre-erasure intimation.
  • Account for Rule 8(3) one-year processing logs for Seventh Schedule purposes, distinct from Rule 6 security logs.

Children

Section 9; Rules 10–12
  • Determine whether personal data of individuals under eighteen is processed.
  • Design verifiable parental or lawful-guardian consent where Section 9 applies; see also lawful guardian / Rule 11 paths.
  • Review tracking, behavioural monitoring and targeted advertising restrictions and any Fourth Schedule exemptions.

Governance

Section 8; Section 10; Rule 13
  • Clarify Data Fiduciary vs Data Processor roles and contracts.
  • Assess whether Significant Data Fiduciary designation could apply; do not self-invent thresholds.
  • Document ownership for privacy, security, rights, breach and Board engagement.

How to use this without over-claiming

Work group by group with cross-functional owners. Record decisions on processing basis, exemptions and SDF status rather than assuming industry folklore. Revisit the checklist when products, vendors or purposes change.

Related deep-dives include purpose, children’s data, Rule 6 security, Rule 7 breach, Rule 8 retention and penalties.

Official source

ConsentifyAI’s explanation is educational. Authoritative text is published by the Government of India / MeitY.

Information on this page is provided for general educational and implementation-planning purposes. It is not legal advice. Organizations should assess their specific obligations with qualified legal or privacy professionals.