Full DPDPA enforcement begins 13 May 2027. The Data Protection Board is already operational. This checklist covers every obligation your organisation must address — from consent and DSR to breach response and vendor management.
Use it to score your current readiness, identify gaps, and prioritise what needs to happen first.
For a downloadable PDF version, visit our DPDPA Compliance Checklist Download.
Review each item. Mark it as Compliant, Partially Compliant, or Not Addressed. Count your scores at the end. Items marked "Not Addressed" are your highest-priority gaps. Items marked "Partially Compliant" need strengthening.
Privacy notices are clear, standalone, and available before data collection begins
Notices available in English and relevant scheduled Indian languages (Rule 3)
Each processing purpose has separate, unbundled consent capture
Consent is captured through clear affirmative action (not pre-ticked boxes)
Consent records are timestamped with notice version history
Consent withdrawal is as easy as consent collection (Section 6(4))
Withdrawal propagates to all downstream systems and processors
Cookie and tracker consent is purpose-specific (analytics, marketing, functional)
Non-essential scripts are blocked until consent is obtained
Consent audit logs are immutable and exportable
Re-consent mechanism exists for when privacy notices change
Accessible mechanism exists for rights requests (portal, form, or documented email)
Identity verification performed before processing any request
All four right types supported: access, correction/erasure, grievance, nomination
Request tracking with 90-day SLA monitoring (Rule 14)
Escalation process defined for approaching deadlines
Automated or systematic data location across all systems for fulfilment
Erasure executed across all systems including backups and third parties
Proof of resolution generated and stored for audits
Grievance redressal process documented and accessible (Section 13)
Nomination mechanism available (Section 14)
Personal data encrypted at rest across all storage systems
Data encrypted in transit (TLS/SSL for all data transmissions)
Role-based access controls implemented and periodically reviewed
Multi-factor authentication for systems containing personal data
Audit logging enabled for all access to personal data
Vulnerability assessments conducted at least annually
Penetration testing conducted at least annually
Security incident response plan exists and is tested
Backup and disaster recovery procedures documented
Security awareness training delivered to all employees
Breach detection and classification process defined
CERT-In 6-hour notification workflow in place
DPDPA Stage 1 intimation process defined ("without delay")
DPDPA Stage 2 detailed report within 72 hours prepared
Data Principal notification templates ready (clear, plain language)
Dual-clock tracking mechanism exists (CERT-In + DPDPA)
Evidence collection and secure storage procedures documented
Post-incident review process defined
Tabletop exercises conducted at least annually
Complete inventory of personal data across all systems exists
India-specific identifiers detected (Aadhaar, PAN, mobile, UPI, GSTIN)
Data classified by type, sensitivity, purpose, and retention period
Data flow mapping documented (internal, external, cross-border)
Records of Processing Activities (RoPA) maintained
Shadow data sources identified and remediated
Discovery scans run continuously (not one-time)
Data retention policies defined per data category
Automated deletion when retention period expires
Complete vendor inventory maintained
Data Processing Agreements signed with all vendors processing personal data
DPAs include all 12 mandatory clauses (see DPA page)
Sub-processor disclosure obtained from all vendors
Vendor risk assessments conducted periodically
Vendor compliance monitored on an ongoing basis
Cross-border data transfers to vendors documented
Vendor deletion/return obligations enforced upon contract termination
(Skip if your product/service does not serve users under 18)
Age verification mechanism implemented
Verifiable parental/guardian consent obtained before processing
Consent verification via existing parent account or DigiLocker (Rule 10)
Behavioural tracking disabled for identified child accounts
Targeted advertising disabled for child accounts
Profiling disabled for child accounts
Guardian consent workflow available for children with disabilities (Rule 11)
Data Protection Officer appointed (mandatory for SDFs, recommended for all)
DPO is independent of business functions (CISO should not double as DPO)
DPIA process established with templates and risk methodology
Annual DPIA cycle in place (mandatory for SDFs)
Employee privacy training delivered (role-specific, assessed, certified)
Training refreshed annually with event-triggered updates
Privacy-by-design integrated into product development process
Compliance documentation maintained and audit-ready
Compliance dashboard provides real-time visibility
Benchmark your readiness score against regulatory standards:
| Compliant Items | Level | Recommendation |
|---|---|---|
| 50+ of 60 | Strong | Focus on continuous monitoring and improvement |
| 35-49 | Partially Ready | Key areas covered but significant gaps remain. Address before May 2027. |
| 20-34 | Early Stage | Most obligations unaddressed. Start implementation now. |
| Under 20 | Not Started | Significant risk. Immediate action required. |
Every gap in this checklist maps to a PrivacyOS module. Consent gaps → Consent Management. DSR gaps → DSR Automation. Security gaps → Security Services. Vendor gaps → Vendor Risk Management.
Start with a free compliance assessment — we review your checklist results, confirm the gaps, and provide a prioritised implementation roadmap.