Home/Services/Compliance Checklist
STATUTORY COMPLIANCE SELF-ASSESSMENT

DPDPA Compliance Checklist — 60+ Action Items Across 8 Compliance Areas

Full DPDPA enforcement begins 13 May 2027. The Data Protection Board is already operational. This checklist covers every obligation your organisation must address — from consent and DSR to breach response and vendor management.

Use it to score your current readiness, identify gaps, and prioritise what needs to happen first.

For a downloadable PDF version, visit our DPDPA Compliance Checklist Download.

Compliant Items
0/ 73
Current Status: Not Started

How to Use This Checklist

Review each item. Mark it as Compliant, Partially Compliant, or Not Addressed. Count your scores at the end. Items marked "Not Addressed" are your highest-priority gaps. Items marked "Partially Compliant" need strengthening.

Compliant Partial Not Addressed

Section 1 — Consent & Privacy Notices (Section 5, 6)

[1]

Privacy notices are clear, standalone, and available before data collection begins

[2]

Notices available in English and relevant scheduled Indian languages (Rule 3)

[3]

Each processing purpose has separate, unbundled consent capture

[4]

Consent is captured through clear affirmative action (not pre-ticked boxes)

[5]

Consent records are timestamped with notice version history

[6]

Consent withdrawal is as easy as consent collection (Section 6(4))

[7]

Withdrawal propagates to all downstream systems and processors

[8]

Cookie and tracker consent is purpose-specific (analytics, marketing, functional)

[9]

Non-essential scripts are blocked until consent is obtained

[10]

Consent audit logs are immutable and exportable

[11]

Re-consent mechanism exists for when privacy notices change

Section 2 — Data Principal Rights (Section 11-14, Rule 14)

[1]

Accessible mechanism exists for rights requests (portal, form, or documented email)

[2]

Identity verification performed before processing any request

[3]

All four right types supported: access, correction/erasure, grievance, nomination

[4]

Request tracking with 90-day SLA monitoring (Rule 14)

[5]

Escalation process defined for approaching deadlines

[6]

Automated or systematic data location across all systems for fulfilment

[7]

Erasure executed across all systems including backups and third parties

[8]

Proof of resolution generated and stored for audits

[9]

Grievance redressal process documented and accessible (Section 13)

[10]

Nomination mechanism available (Section 14)

Solution Module:

Section 3 — Data Security & Safeguards (Section 8(4), Rule 6)

[1]

Personal data encrypted at rest across all storage systems

[2]

Data encrypted in transit (TLS/SSL for all data transmissions)

[3]

Role-based access controls implemented and periodically reviewed

[4]

Multi-factor authentication for systems containing personal data

[5]

Audit logging enabled for all access to personal data

[6]

Vulnerability assessments conducted at least annually

[7]

Penetration testing conducted at least annually

[8]

Security incident response plan exists and is tested

[9]

Backup and disaster recovery procedures documented

[10]

Security awareness training delivered to all employees

Section 4 — Breach Notification (Section 8(6), Rule 7)

[1]

Breach detection and classification process defined

[2]

CERT-In 6-hour notification workflow in place

[3]

DPDPA Stage 1 intimation process defined ("without delay")

[4]

DPDPA Stage 2 detailed report within 72 hours prepared

[5]

Data Principal notification templates ready (clear, plain language)

[6]

Dual-clock tracking mechanism exists (CERT-In + DPDPA)

[7]

Evidence collection and secure storage procedures documented

[8]

Post-incident review process defined

[9]

Tabletop exercises conducted at least annually

Solution Module:

Section 5 — Data Discovery & Inventory (Section 8)

[1]

Complete inventory of personal data across all systems exists

[2]

India-specific identifiers detected (Aadhaar, PAN, mobile, UPI, GSTIN)

[3]

Data classified by type, sensitivity, purpose, and retention period

[4]

Data flow mapping documented (internal, external, cross-border)

[5]

Records of Processing Activities (RoPA) maintained

[6]

Shadow data sources identified and remediated

[7]

Discovery scans run continuously (not one-time)

[8]

Data retention policies defined per data category

[9]

Automated deletion when retention period expires

Section 6 — Vendor & Processor Management (Section 8(2))

[1]

Complete vendor inventory maintained

[2]

Data Processing Agreements signed with all vendors processing personal data

[3]

DPAs include all 12 mandatory clauses (see DPA page)

[4]

Sub-processor disclosure obtained from all vendors

[5]

Vendor risk assessments conducted periodically

[6]

Vendor compliance monitored on an ongoing basis

[7]

Cross-border data transfers to vendors documented

[8]

Vendor deletion/return obligations enforced upon contract termination

Section 7 — Children's Data (Section 9)

(Skip if your product/service does not serve users under 18)

[1]

Age verification mechanism implemented

[2]

Verifiable parental/guardian consent obtained before processing

[3]

Consent verification via existing parent account or DigiLocker (Rule 10)

[4]

Behavioural tracking disabled for identified child accounts

[5]

Targeted advertising disabled for child accounts

[6]

Profiling disabled for child accounts

[7]

Guardian consent workflow available for children with disabilities (Rule 11)

Section 8 — Organisational Governance

[1]

Data Protection Officer appointed (mandatory for SDFs, recommended for all)

[2]

DPO is independent of business functions (CISO should not double as DPO)

[3]

DPIA process established with templates and risk methodology

[4]

Annual DPIA cycle in place (mandatory for SDFs)

[5]

Employee privacy training delivered (role-specific, assessed, certified)

[6]

Training refreshed annually with event-triggered updates

[7]

Privacy-by-design integrated into product development process

[8]

Compliance documentation maintained and audit-ready

[9]

Compliance dashboard provides real-time visibility

What Your Score Means

Benchmark your readiness score against regulatory standards:

Compliant ItemsLevelRecommendation
50+ of 60StrongFocus on continuous monitoring and improvement
35-49Partially ReadyKey areas covered but significant gaps remain. Address before May 2027.
20-34Early StageMost obligations unaddressed. Start implementation now.
Under 20Not StartedSignificant risk. Immediate action required.
OPERATIONAL REMEDIATION

Close the Gaps with PrivacyOS

Every gap in this checklist maps to a PrivacyOS module. Consent gaps → Consent Management. DSR gaps → DSR Automation. Security gaps → Security Services. Vendor gaps → Vendor Risk Management.

Start with a free compliance assessment — we review your checklist results, confirm the gaps, and provide a prioritised implementation roadmap.

Download Checklist PDF