Free Downloadable Compliance Framework

DPDPA Compliance Checklist — Are You Ready for May 2027?

The Digital Personal Data Protection Act, 2023 is India's comprehensive data privacy law. Full enforcement begins on 13 May 2027. With penalties up to ₹250 crore per violation, every organisation processing personal data in India needs a systematic compliance plan.

This checklist covers all 8 critical operational areas under the DPDP Act and DPDP Rules 2025. Use it to audit your current data practices, identify compliance gaps, and build your implementation roadmap before enforcement begins.

Instant download. No spam. Unsubscribe at any time.

What This Checklist Covers

The 8 operational pillars required for complete statutory compliance before May 2027.

01

Consent & Notice

Clear, itemised notices, affirmative consent, withdrawal mechanisms, multilingual requirements.

02

Data Principal Rights

Access, correction, erasure, nomination, and grievance redressal workflows.

03

Data Security

Reasonable security safeguards, encryption, access controls, logging, vulnerability management.

04

Breach Notification

72-hour Board notification, Data Principal notification, CERT-In coordination.

05

Vendor Risk

Data Processing Agreements, processor audits, cross-border transfer documentation.

06

Children's Data

Age verification, verifiable parental consent, prohibition on tracking and profiling.

07

SDF Obligations

DPO appointment, Data Protection Impact Assessments, periodic independent audits.

08

Governance

Employee training, compliance documentation, data retention and disposal policies.

Preview the Checklist

Interactive sample of sections 1 and 2. Download the full PDF for all 8 complete sections.

Section 1

Consent and Privacy Notices

Privacy notice is standalone (not buried in terms of service)
Notice clearly states what personal data is collected and why
Notice is available in English and 22 Eighth Schedule languages (as applicable)
Consent is free, specific, informed, unconditional, and unambiguous
Consent is collected through affirmative action (no pre-ticked boxes)
Notice specifies how Data Principals can withdraw consent
Notice provides DPO / grievance officer contact details
Consent records are timestamped, versioned, and auditable
Section 2

Data Principal Rights

Mechanism for Data Principals to access summary of personal data processed
Process for correcting, completing, and updating personal data
Process for erasing personal data upon consent withdrawal or purpose fulfillment
Identity verification procedure before processing rights requests
SLA tracking to ensure timely response to all requests
Nomination facility for Data Principals (death / incapacity)
Documented grievance redressal procedure with published timelines

Sections 3-8 (Data Security, Breach Response, Vendor Risk, Children's Data, SDF Obligations, Governance) are available in the full PDF download.

Download the full 8-section checklist now

What to Do After the Checklist

Completed your manual audit? Here is your systematic roadmap to full automated compliance:

1

Prioritise gaps

Focus on high-risk areas first: consent mechanisms, personal data inventory, and breach notification readiness.

2

Take readiness assessment

Get a quantitative compliance score and category breakdown with our free self-assessment tool.

3

Explore PrivacyOS

Automate consent management, DSR processing, breach response, and vendor risk from a single platform.

4

Schedule consultation

Talk to our compliance team for a tailored review of your DPDPA readiness and implementation timeline.

DPDPA AUDIT READY

Automate Every Item on Your Checklist with PrivacyOS

Deploy purpose-based consent banners, automated DSR request fulfilment, and CERT-In synchronized breach monitoring in under 14 days.