The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy law. Full enforcement begins on 13 May 2027. With penalties up to ₹250 crore per violation, every organisation processing personal data in India needs a systematic compliance plan.
This checklist covers all 8 critical operational areas under the DPDP Act and DPDP Rules 2025. Use it to audit your current data practices, identify compliance gaps, and build your implementation roadmap before enforcement begins.
The 8 operational pillars required for complete statutory compliance before May 2027.
Clear, itemised notices, affirmative consent, withdrawal mechanisms, multilingual requirements.
Access, correction, erasure, nomination, and grievance redressal workflows.
Reasonable security safeguards, encryption, access controls, logging, vulnerability management.
72-hour Board notification, Data Principal notification, CERT-In coordination.
Data Processing Agreements, processor audits, cross-border transfer documentation.
Age verification, verifiable parental consent, prohibition on tracking and profiling.
DPO appointment, Data Protection Impact Assessments, periodic independent audits.
Employee training, compliance documentation, data retention and disposal policies.
Interactive sample of sections 1 and 2. Download the full PDF for all 8 complete sections.
Sections 3-8 (Data Security, Breach Response, Vendor Risk, Children's Data, SDF Obligations, Governance) are available in the full PDF download.
Completed your manual audit? Here is your systematic roadmap to full automated compliance:
Focus on high-risk areas first: consent mechanisms, personal data inventory, and breach notification readiness.
Get a quantitative compliance score and category breakdown with our free self-assessment tool.
Automate consent management, DSR processing, breach response, and vendor risk from a single platform.
Talk to our compliance team for a tailored review of your DPDPA readiness and implementation timeline.
Deploy purpose-based consent banners, automated DSR request fulfilment, and CERT-In synchronized breach monitoring in under 14 days.