Two points to settle before the checklist. First, DPDP is not optional and it is not only for large technology firms. It reaches almost every organisation that holds customer, employee or user data. Second, compliance is not a document you file once. It is an operating capability you build and then maintain, because the regulator can ask you to demonstrate it at any time.
The DPDP checklist in brief#
Here is the whole checklist at a glance. Each item is explained in full below, but if you read nothing else, read this.
- Confirm whether the Act applies to you, and whether you might be a Significant Data Fiduciary.
- Map the personal data you hold, where it lives, and how it moves.
- Rewrite every privacy notice to be clear, itemised and specific.
- Build a consent mechanism that is free, informed, and as easy to withdraw as to give.
- Create working processes to honour data principal rights and grievances.
- Stand up a breach response process that can notify the Board and affected individuals promptly.
- Apply and document reasonable security safeguards.
- Set retention limits, a deletion routine, and written contracts with every data processor.
- If you are a Significant Data Fiduciary, add a Data Protection Officer in India, annual audits and Data Protection Impact Assessments.
Now the detail, step by step.
First, understand what the DPDP Act is#
The Digital Personal Data Protection Act, 2023, is India's first comprehensive law governing how organisations handle digital personal data. It received Presidential assent in August 2023, and the operational rules that make it enforceable, the Digital Personal Data Protection Rules, 2025, were notified in November 2025. The Data Protection Board of India, the body that adjudicates complaints and imposes penalties, has been established.
The Act uses a small vocabulary you need to know. A Data Principal is the individual the data is about. A Data Fiduciary is the organisation that decides how and why personal data is processed, in other words, you. A Data Processor is a third party that processes data on your behalf. A Significant Data Fiduciary is a Data Fiduciary the government designates for heavier duties, based on the volume and sensitivity of the data it handles and the risks involved.
The whole framework rests on a simple principle: you may process someone's personal data only for a lawful purpose, with their informed consent or another lawful basis, and you remain accountable for protecting it throughout.
Where the DPDP timeline stands#
Understanding the timeline helps you plan, and it is best understood as a phased switch-on rather than a single date. The Rules were notified in November 2025, and the obligations come into force in stages. The first phase established the Data Protection Board and the core definitions. A later phase brings the enforcement and penalty framework and the registration of Consent Managers into effect. The final phase, in 2027, is when the full set of obligations that most businesses care about, notice, consent, security safeguards, breach reporting, retention and data principal rights, becomes fully enforceable.
That final phase is the one to plan your programme around. It can look generous from a distance, but anyone who lived through GDPR implementation knows the programme consumes the runway. Redesigning consent flows, building a processing register, integrating with Consent Managers and standing up a breach process is months of cross-functional work involving legal, IT, product, HR and marketing. Treat the 2027 milestone as a firm project deadline, not a distant one, and start with scope now.
One evergreen caution. India's data protection regime is still maturing, and the government issues clarifications and additional rules over time. Always confirm the current requirements and the exact in-force dates for your obligations before you act on them, rather than assuming a fixed position.
Step 1, confirm scope and your classification#
Begin by confirming the Act applies to you. It almost certainly does. The DPDP Act governs the processing of digital personal data within India, and it also applies extraterritorially to organisations outside India that offer goods or services to individuals in India. If you hold customer records, employee files, or website leads relating to people in India, you are a Data Fiduciary and this checklist is yours.
Then ask a second question that shapes the size of your task: could you be a Significant Data Fiduciary? The government designates SDFs based on the volume and sensitivity of personal data processed and the risk to Data Principals. Most organisations will be ordinary Data Fiduciaries, which is a lighter burden. But if you handle large volumes of sensitive data, plan as though you may be designated, because the additional duties, an in-India Data Protection Officer, annual audits and impact assessments, take time to build. Knowing which category you fall into prevents both under-preparing and over-engineering.
Step 2, map your personal data#
You cannot protect or govern what you have not mapped. Before writing a single policy, build a record of the personal data your organisation holds: what categories you collect, from whom, for what purpose, where it is stored, who has access, which third parties you share it with, and how long you keep it.
This data map, sometimes called a processing register, is the foundation everything else sits on. Your notices, your consent design, your retention schedule and your breach response all depend on knowing what data you actually hold. Do this first. Designing consent before you understand your data flows is building the house before surveying the ground.
Step 3, rewrite your privacy notices#
Under the Rules, the notice you give individuals must be clear, standalone and specific. A buried paragraph in a long terms-and-conditions document does not meet the standard.
At minimum, your notice must contain an itemised description of the personal data you collect, the specific purpose for processing it, including a clear description of the goods, services or uses that purpose enables, and a straightforward way for the individual to withdraw consent, exercise their rights, and complain to the Data Protection Board. The notice should be understandable, and made available in English and the languages listed in the Eighth Schedule of the Constitution.
Practical actions for this step:
- Write one clear notice per purpose, not a single wall of text covering everything.
- Itemise the data, do not use vague phrases like "information about you".
- Include a working link or mechanism to withdraw consent and exercise rights.
- Make the notice available in the required languages.
Step 4, build genuine consent#
Consent is the heart of the DPDP Act, and it is where most Indian businesses have the furthest to travel. Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. A pre-ticked box, a bundled acceptance, or an assumption of consent does not count.
Just as important, and frequently overlooked, withdrawal must be as easy as granting. If a person can opt in with one tap, they must be able to opt out with comparable ease, and you must act on that withdrawal without undue delay.
The Rules also introduce Consent Managers, a registered class of intermediary that gives individuals a single interface to grant, review and withdraw consent across multiple businesses. Where you rely on consent as your basis for processing, you will need systems technically ready to integrate with registered Consent Managers, receiving consent signals, recording them accurately, and acting on withdrawals. Consent records are expected to be retained for a significant period, on the order of seven years, so your architecture must capture and store them reliably. This is a genuine engineering task, not a checkbox, so scope it early.
Step 5, honour data principal rights and grievances#
Individuals whose data you hold have enforceable rights, and you need working processes to satisfy them, not just promises on a web page.
Be ready to let a person access a summary of the personal data you hold about them, correct or complete inaccurate data, and request erasure when the purpose has been served. You must also provide a readily available grievance redressal mechanism, and publish the contact details of the person or office responsible for answering questions about your data processing.
Build the process before the requests arrive. Decide who receives a request, how you verify the requester's identity, where you log it, how you track it to completion, and the timeframe within which you respond. A request that arrives to no defined process becomes a complaint to the Board.
Step 6, prepare for breach reporting#
A personal data breach triggers clear duties, and the timelines are tight enough that this cannot be improvised on the day it happens.
When a breach occurs, you must inform every affected individual without delay, in plain language, explaining what happened, the likely consequences, the steps you are taking in response, and how the person can get help. You must also report the breach to the Data Protection Board. Given the speed expected, you need detection and internal escalation in place ahead of time.
Prepare in advance:
- A simple, shared definition of what counts as a breach, so staff recognise one.
- A named owner and a clear escalation path.
- Ready notification templates for both affected individuals and the Board.
- A log recording what happened, when, and what you did, which also serves as evidence.
- A tested response plan, ideally rehearsed through a tabletop exercise.
Step 7, apply and document reasonable security safeguards#
The Act requires you to protect personal data with reasonable security safeguards, and this is the area with the most serious financial consequences for failure. Penalties under the Act are substantial, running up to very large sums for failures to maintain reasonable security safeguards, so this is not a corner to cut.
Reasonable safeguards typically include access controls, encryption or equivalent protection, logging and monitoring, secure backups, and the ability to detect and respond to incidents. The Rules also point toward retaining certain logs for a defined period to support traceability and breach response. If you already operate an information security management system aligned to ISO 27001, a large share of these safeguards already exists, which is why we often help clients extend an existing security programme into privacy rather than start from zero.
Whatever you implement, document it. During an inquiry, documented, operating controls are your evidence that you took security seriously.
Step 8, control retention, deletion and your vendors#
Two duties that are easy to miss and important to get right.
First, do not keep personal data indefinitely. Define how long you retain each category of data, tie it to the purpose, and delete it once that purpose is complete, subject to any legal retention requirement. Build an automated or scheduled deletion routine rather than relying on occasional manual clean-ups, because "we meant to delete it" is not a defence.
Second, you remain accountable for the third parties who process data on your behalf. Every processor, from your payroll provider to your email and analytics tools, should be governed by a written contract setting out their obligations to process only on your instructions, protect the data, cooperate with breach handling, and delete or return data when the engagement ends. Maintain a current list of who processes your data and for what.
Step 9, the extra duties of a Significant Data Fiduciary#
If the government designates you a Significant Data Fiduciary, you take on a heavier set of obligations reflecting the greater risk you carry.
These additional duties include appointing a Data Protection Officer who is based in India and accountable to your board or governing body, conducting periodic Data Protection Impact Assessments to evaluate risks to individuals before undertaking significant or higher-risk processing, and commissioning independent data audits to verify your compliance. SDFs are also expected to exercise additional diligence when deploying new or sensitive technologies.
Even if you are not designated today, if you are a large organisation handling sensitive data at scale, it is far easier to build these habits early than to retrofit them under regulatory pressure later.
How we help you get DPDP-ready#
This is where an experienced, independent adviser earns its place. The Act is broad and cross-functional, and the common failure is to buy a tool before understanding the obligation. The right order is the reverse: understand what applies to you, then build to it.
Our approach follows the checklist above. We confirm your scope and likely classification, map your data, and run a gap assessment that tells you precisely which obligations you already meet and which you do not. We then help you design compliant notices and consent, stand up your rights, grievance and breach processes, put reasonable security safeguards in place, and set your retention and vendor controls. Where you are, or may become, a Significant Data Fiduciary, we help you build the DPO function, DPIA practice and audit readiness those duties require.
There is a real efficiency for organisations that already hold ISO 27001 or are pursuing it. Much of the security foundation the Act expects overlaps with an information security management system, and privacy can be built on top of it rather than beside it. You can see how the two connect in our guide on ISO 42001, AI governance and DPDP, and our dedicated DPDP Act consulting service takes you from gap assessment to a defensible, working programme.
Frequently asked questions#
Conformite Assist is an independent compliance advisory, helping organisations across 13 regions and four continents get audit-ready since 2011. We help you build and maintain compliance. We are not a certification body.
This article is for general information only and does not constitute legal advice. Regulatory requirements evolve, and organisations should seek advice specific to their circumstances. Details of the DPDP Act and Rules are accurate to the best of our knowledge at the time of writing, August 2026.
Who does the DPDP Act apply to?
It applies to any organisation processing digital personal data within India, and to organisations outside India that offer goods or services to individuals in India. Most businesses holding customer, employee or user data of people in India are Data Fiduciaries and must comply.
What is the DPDP compliance deadline?
The DPDP Rules were notified in November 2025 and the obligations switch on in phases, with the full set of core obligations, notice, consent, security, breach reporting and data principal rights, becoming enforceable in 2027. Because dates can be refined by further notifications, confirm the current in-force date for each obligation before acting.
Do we need a Data Protection Officer under the DPDP Act?
Only if the government designates you a Significant Data Fiduciary. Other Data Fiduciaries do not need a formal DPO, but every business must publish a contact point for data-related queries and provide a grievance redressal mechanism.
What are the penalties for non-compliance?
The Act provides for substantial financial penalties, with the highest amounts attached to failures to maintain reasonable security safeguards, and separate penalty heads for other failures such as breach notification and obligations relating to children's data. Penalties are assessed by the Data Protection Board.
How is the DPDP Act different from GDPR?
Both are consent-based privacy regimes with rights, notice and breach duties, but DPDP is India-specific, with its own rules on notice language, Consent Managers, the Data Protection Board and Significant Data Fiduciary obligations. If you already meet GDPR you have a head start, but you must adapt your approach rather than reuse GDPR documents unchanged.
Can we build DPDP compliance on top of ISO 27001?
Yes, and it is efficient. Many of the security safeguards the Act expects already exist in an ISO 27001 information security management system, so extending that foundation into a privacy programme covers a substantial part of the requirement.
