Readiness assessment

DPDP Act 2023 · DPDP Rules 2025

DPDP Compliance Checklist 2026–27

Work through DPDP by applicability, legal source, recommended evidence, ownership and remediation. Know what applies to you, what evidence to keep, and what to fix before obligations take effect.

Statutory obligations, Rules, regulatory triggers and implementation controls are separately labelled, so a legal duty is never presented as a recommendation.

Not every DPDP requirement applies to every organisation

Answer a few questions to see which controls are relevant to your processing. This runs entirely in your browser: nothing is sent or stored. It is guidance, not a legal determination.

Does DPDP apply to your relevant processing? (Section 3)
Do you rely on consent for any processing?
Do you hold relevant consent obtained before commencement?
Do you rely on a Section 7 certain legitimate use?
Do you engage processors on your behalf?
Do you process personal data of anyone under 18?
Do relevant lawful-guardian situations apply?
Have you actually been notified as a Significant Data Fiduciary?
Does relevant processing involve locations outside India?
Do Rule 8 / Third Schedule conditions apply to you?
Are you seeking to operate as a registered Consent Manager?

Timing

When DPDP obligations take effect

The DPDP Rules being notified does not mean every obligation is enforceable today. Commencement is staged.

13 Nov 2025

Framework and notified provisions in force, including the Data Protection Board and specified administrative provisions.

13 Nov 2026

Consent Manager registration-related stage.

13 May 2027

Core Data Fiduciary and Significant Data Fiduciary operational obligations represented in this checklist.

Sources: DPDP Act, 2023, DPDP Rules, 2025 and the commencement notification (MeitY).

Why this checklist is different

Legal source, not just a to-do list

A generic checklist flattens everything into one line and one deadline. That is where mistakes start. Take breach notification.

Typical checklist

Notify a data breach within 72 hours.

This checklist preserves the actual structure
  • Initial notification to affected Data Principals and the Board without delay when a breach occurs.
  • A detailed or update report to the Board within 72 hours of becoming aware, unless additional time is granted.
  • Each carries its own legal source, who it applies to, recommended evidence and owner.

Collapsing that into a single "72-hour rule" gets the obligation wrong. Legal-source precision is the point of this checklist.

How to read each control

Every control keeps the classification from the source register, so a legal obligation is never mistaken for a recommendation.

  • Statutory obligation Expressly imposed by the DPDP Act, 2023.
  • Rule-based obligation Expressly imposed by the DPDP Rules, 2025.
  • Regulatory / administrative Depends on a Government or Board notification, designation, order or similar trigger.
  • Implementation control A practical way to implement or evidence compliance, not itself prescribed in that exact form.

The master framework currently covers 136 controls across 14 implementation domains. The number of controls is not the point; knowing which ones apply to you is.

The checklist, by domain

A Scope, Applicability & Role 8 controls

APP-04 Identify activities for which the organisation acts as Data Fiduciary. Implementation control Supports Act ss.4–8 All in-scope
Who this applies to
OrganisationBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Processing-role register showing activities where the organisation acts as Data Fiduciary.
Evidence type
Documentary
Suggested owner
Privacy / Legal
Official source
DPDP Act, 2023 (MeitY)
APP-05 Identify third parties acting as processors on the organisation's behalf. Implementation control Supports Act s.8 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Vendor/processor inventory mapped to processing activities.
Evidence type
Documentary
Suggested owner
Procurement / Privacy
Official source
DPDP Act, 2023 (MeitY)
APP-06 Determine roles based on the actual processing activity rather than contractual labels alone. Implementation control Supports Act s.8 Processors
Who this applies to
Data Fiduciary / third partiesApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Role-assessment notes for material third-party processing.
Evidence type
Documentary
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)
APP-08 Determine whether the organisation is seeking registration or operating as a Consent Manager rather than merely using consent mechanisms. Implementation control Act s.6(9); Rule 4 Consent Manager
Who this applies to
Relevant organisationApplies if operating as a registered Consent Manager
Effective date / trigger
13 Nov 2026
Recommended evidence operational guidance
Consent Manager applicability decision and registration status where relevant.
Evidence type
Regulatory / Documentary
Suggested owner
Legal / Privacy

B Processing Purpose & Legal Ground 7 controls

PUR-03 Where Section 7 is relied upon, identify the exact statutory circumstance rather than a generic 'legitimate interest'. Implementation control Act s.7 Section 7 use
Who this applies to
Data FiduciaryApplies if you rely on a Section 7 legitimate use
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Section 7 assessment referencing the precise clause and facts.
Evidence type
Documentary
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)
PUR-04 Do not treat analytics, advertising, marketing or general commercial interest as an automatic Section 7 basis. Implementation control Act s.7 Section 7 use
Who this applies to
Data FiduciaryApplies if you rely on a Section 7 legitimate use
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Review notes for marketing/analytics processing grounds.
Evidence type
Documentary
Suggested owner
Legal / Marketing / Privacy
Official source
DPDP Act, 2023 (MeitY)
PUR-05 Document each processing purpose sufficiently specifically to support notice and consent decisions. Implementation control Supports Act ss.5–7 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Processing-purpose register with specific purpose statements.
Evidence type
Documentary
Suggested owner
Privacy / Product
Official source
DPDP Act, 2023 (MeitY)
PUR-07 Record the rationale where processing continues without consent because it is required or authorised under DPDP or another Indian law. Implementation control Supports Act ss.6–7 Section 7 use
Who this applies to
Data FiduciaryApplies if you rely on a Section 7 legitimate use
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Exception/legal-authority record with applicable law and rationale.
Evidence type
Documentary
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)

C Personal-Data Inventory & Processing Mapping 8 controls

MAP-01 Maintain an inventory of personal-data categories being processed. Implementation control Supports Act ss.5–14; Rules 3, 6–8, 13–14 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Personal-data inventory.
Evidence type
Documentary
Suggested owner
Privacy / Data Governance
MAP-02 Map each personal-data category to the purpose for which it is processed. Implementation control Supports Act ss.4–7 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Processing register mapping data categories to purposes.
Evidence type
Documentary
Suggested owner
Privacy / Data Governance
Official source
DPDP Act, 2023 (MeitY)
MAP-03 Map the relevant consent or Section 7 basis for each processing purpose. Implementation control Supports Act ss.4–7 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Legal-ground mapping.
Evidence type
Documentary
Suggested owner
Privacy / Legal
Official source
DPDP Act, 2023 (MeitY)
MAP-04 Identify where personal data is collected, including forms, applications, APIs, offline-to-digital processes and other collection points. Implementation control Supports notice/consent obligations All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Collection-point inventory with URLs/screens/process owners.
Evidence type
Documentary / Technical
Suggested owner
Product / Privacy
MAP-05 Identify systems and repositories in which relevant personal data is processed or stored. Implementation control Supports Act ss.8, 11–12 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
System/data-flow map.
Evidence type
Technical / Documentary
Suggested owner
IT / Security / Privacy
Official source
DPDP Act, 2023 (MeitY)
MAP-06 Identify processors and other recipients with whom personal data is shared. Implementation control Supports Act ss.8, 11 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Recipient/vendor register.
Evidence type
Documentary
Suggested owner
Procurement / Privacy
Official source
DPDP Act, 2023 (MeitY)
MAP-07 Map retention and deletion dependencies for relevant processing activities. Implementation control Supports Act ss.8, 12; Rule 8 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Retention/deletion dependency map.
Evidence type
Documentary
Suggested owner
Privacy / Legal / IT
MAP-08 Identify processing involving children or persons with disabilities with lawful guardians so conditional controls can be activated. Implementation control Supports Act s.9; Rules 10–12 Children / guardian
Who this applies to
Data FiduciaryApplies to children and/or lawful-guardian situations
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Special-processing flags within processing inventory.
Evidence type
Documentary
Suggested owner
Privacy / Product

D Notice 12 controls

NOT-12 Maintain a mapping between notices and the collection or processing points to which they apply. Implementation control Supports Act s.5 / Rule 3 Consent
Who this applies to
Data Fiduciary relying on consentApplies if you rely on consent
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Notice inventory with version and collection-point mapping.
Evidence type
Documentary / Technical
Suggested owner
Privacy / Product

E Consent & Withdrawal 18 controls

CON-16 Maintain a mechanism to identify processing that may legitimately continue after withdrawal under DPDP or another Indian law. Implementation control Supports Act s.6(6) Consent
Who this applies to
Data FiduciaryApplies if you rely on consent
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Exception-decision record tied to applicable law/purpose.
Evidence type
Documentary
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)
CON-17 Test withdrawal propagation through relevant systems and processors. Implementation control Supports Act s.6(4)–(6) Consent
Who this applies to
Data FiduciaryApplies if you rely on consent
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
End-to-end withdrawal test results and defects/remediation.
Evidence type
Testing
Suggested owner
QA / Product / Privacy
Official source
DPDP Act, 2023 (MeitY)
CON-18 Maintain version linkage between the notice shown and the consent obtained. Implementation control Supports Act s.6(10) Consent
Who this applies to
Data Fiduciary relying on consentApplies if you rely on consent
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Consent record containing notice/version reference.
Evidence type
Technical / Documentary
Suggested owner
Product / Privacy
Official source
DPDP Act, 2023 (MeitY)

F Data Principal Rights & Grievances 14 controls

RGT-05 Determine and document whether any statutory disclosure exception applies to information requested. Implementation control Supports Act s.11 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Exception assessment and approval record.
Evidence type
Operational / Documentary
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)

G Children & Lawful-Guardian Situations 10 controls

CHD-01 Identify processing activities involving Data Principals under 18. Implementation control Supports Act s.9 Children's data
Who this applies to
Data FiduciaryApplies if you process children's data
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Processing inventory flagged for child-related processing.
Evidence type
Documentary / Technical
Suggested owner
Privacy / Product
Official source
DPDP Act, 2023 (MeitY)
CHD-10 Do not automatically treat disability itself as evidence that a lawful guardian exists. Implementation control Supports Rules r.11 Lawful guardian
Who this applies to
Data FiduciaryApplies in lawful-guardian situations
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Procedure requiring guardian-status determination before consent workflow.
Evidence type
Documentary / Technical
Suggested owner
Privacy / Legal

H Processors & Third Parties 9 controls

VEN-04 Maintain an inventory of processors and processing activities performed on the Data Fiduciary's behalf. Implementation control Supports Act s.8 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Processor register mapped to services, data and purpose.
Evidence type
Documentary / Contractual
Suggested owner
Procurement / Privacy
Official source
DPDP Act, 2023 (MeitY)
VEN-05 Determine each third party's actual role for each relevant processing activity rather than relying solely on the contract label. Implementation control Supports Act s.8 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Activity-level third-party role analysis.
Evidence type
Documentary / Contractual
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)
VEN-07 Maintain evidence of withdrawal or deletion instructions sent to processors and their completion. Implementation control Supports Act ss.6, 8 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Instruction log, acknowledgement and completion record.
Evidence type
Documentary / Contractual
Suggested owner
Privacy / Procurement
Official source
DPDP Act, 2023 (MeitY)
VEN-08 Assess whether processor arrangements support the Data Fiduciary's applicable security obligations. Implementation control Supports Act s.8(5); Rule 6 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Processor security due-diligence assessment and remediation.
Evidence type
Documentary / Contractual
Suggested owner
Security / Procurement / Privacy
VEN-09 Maintain sufficient records of relevant disclosures to support applicable Data Principal access rights. Implementation control Supports Act s.11 Processors
Who this applies to
Data FiduciaryApplies if you use processors
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Sharing/disclosure register linked to processors/other recipients.
Evidence type
Documentary / Contractual
Suggested owner
Privacy / Data Governance
Official source
DPDP Act, 2023 (MeitY)

I Reasonable Security Safeguards 8 controls

SEC-08 Periodically verify that implemented safeguards actually operate as intended. Implementation control Supports Act s.8(5); Rule 6 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Control tests, reviews, exercises or assurance results.
Evidence type
Technical / Documentary
Suggested owner
Security / Internal Audit

J Retention & Erasure 9 controls

RET-07 Reconcile DPDP erasure obligations with other statutory retention, litigation hold and sector-specific requirements. Implementation control Supports Act s.8; Rule 8 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Retention conflict matrix and approved exceptions.
Evidence type
Documentary / Technical
Suggested owner
Legal / Privacy
RET-08 Maintain a processing-linked retention and deletion schedule. Implementation control Supports Act ss.8, 12; Rule 8 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Retention schedule mapped to data, purpose, systems and legal basis.
Evidence type
Documentary / Technical
Suggested owner
Privacy / Legal / Data Governance
RET-09 Document why data continues to be retained where an exception prevents deletion. Implementation control Supports Act ss.8, 12 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Retention-exception rationale and approval.
Evidence type
Documentary / Technical
Suggested owner
Legal / Privacy
Official source
DPDP Act, 2023 (MeitY)

K Personal Data Breach 10 controls

BRH-01 Maintain a process for determining whether a security incident constitutes a personal-data breach. Implementation control Supports Act s.8(6); Rule 7 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Incident classification procedure and example assessment.
Evidence type
Operational / Documentary
Suggested owner
Security / Privacy
BRH-08 Preserve breach-response evidence, submission copies and timestamps. Implementation control Supports Act s.8(6); Rule 7 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Incident evidence repository and notification log.
Evidence type
Operational / Documentary
Suggested owner
Security / Privacy
BRH-09 Identify parallel CERT-In, RBI, SEBI, IRDAI, telecom, contractual or other incident-reporting obligations where applicable. Implementation control Other-law overlay All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Incident-reporting obligations matrix by sector/entity.
Evidence type
Operational / Documentary
Suggested owner
Legal / Security / Compliance
BRH-10 Maintain defined roles, escalation paths and response procedures capable of meeting the applicable notification chronology. Implementation control Supports Rule 7 All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Incident-response RACI, escalation tree and exercise/test results.
Evidence type
Operational / Documentary
Suggested owner
Security / Privacy

L Cross-Border Processing 5 controls

XBR-01 Identify relevant personal-data transfers or processing involving locations outside India. Implementation control Supports Act s.16 Cross-border
Who this applies to
Data FiduciaryApplies if processing involves locations outside India
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Cross-border processing/transfer register.
Evidence type
Documentary / Regulatory
Suggested owner
Privacy / Legal / IT
Official source
DPDP Act, 2023 (MeitY)
XBR-03 Identify other applicable laws imposing stronger cross-border or localisation restrictions. Implementation control Supports Act s.16 Cross-border
Who this applies to
Data FiduciaryApplies if processing involves locations outside India
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Sectoral/country restriction matrix.
Evidence type
Documentary / Regulatory
Suggested owner
Legal / Compliance
Official source
DPDP Act, 2023 (MeitY)
XBR-05 Maintain a cross-border processing register sufficient to determine which restrictions apply. Implementation control Supports Act s.16; Rule 15 Cross-border
Who this applies to
Data FiduciaryApplies if processing involves locations outside India
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Cross-border register with country, system, purpose, recipient and legal overlay.
Evidence type
Documentary / Regulatory
Suggested owner
Privacy / Data Governance

M Significant Data Fiduciary Module 11 controls

N Governance, Evidence & Regulatory Monitoring 7 controls

GOV-02 Assign accountable business or function owners to applicable controls. Implementation control Supports Act s.8(4) All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Control ownership matrix / RACI.
Evidence type
Documentary
Suggested owner
Compliance / PMO
Official source
DPDP Act, 2023 (MeitY)
GOV-03 Maintain an evidence register linking applicable controls to documentary, technical, contractual or operational evidence. Implementation control Supports compliance assurance All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Evidence register with links/locations, owners and dates.
Evidence type
Documentary
Suggested owner
Compliance / Privacy
GOV-04 Monitor relevant Government or Board notifications, designations, orders and clarifications affecting applicability. Implementation control Regulatory monitoring All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Regulatory watch log and ownership.
Evidence type
Documentary
Suggested owner
Legal / Compliance
GOV-05 Maintain a regulatory-change register containing effective dates and affected controls. Implementation control Regulatory monitoring All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Change register linking developments to impacted controls.
Evidence type
Documentary
Suggested owner
Compliance / Legal
GOV-06 Provide management with a periodic view of material gaps, remediation ownership and approaching obligations. Implementation control Governance All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Management dashboard / review minutes.
Evidence type
Documentary
Suggested owner
Compliance / Privacy
GOV-07 Maintain auditable records of significant applicability, exception and remediation decisions. Implementation control Compliance assurance All in-scope
Who this applies to
Data FiduciaryBaseline: applies to all in-scope Data Fiduciaries
Effective date / trigger
13 May 2027
Recommended evidence operational guidance
Decision log with rationale, approver and date.
Evidence type
Documentary
Suggested owner
Compliance / Legal

Free download

DPDP Implementation Readiness Workbook

The page above is the legal and reference layer. The editable workbook adds the operating layer, so you can turn the checklist into a tracked project:

  • Applicable? and working status per control
  • Gap / finding and remediation / next action
  • Priority, target date and notes
  • Self-scoping applicability questions
  • A roll-up readiness dashboard

Free, and deliberately separate from any paid toolkit. Editable spreadsheet, based on the same 136-control register.

Get the editable workbook

No spam. The download starts immediately after you submit.

Scope discipline

What this DPDP checklist does not assume

Many DPDP checklists import GDPR habits. These are the most common mis-framings this page deliberately avoids.

Consent is always required

Consent is one of seven grounds. Large-scale legitimate use, legal obligation, medical emergency, public health, court order, employment, and public interest each stand independently (S.4). Treating consent as mandatory drags compliance into GDPR territory that the Act deliberately avoided.

72 hours to notify a breach

The 72-hour number appears nowhere in the DPDP Act or Rules. Initial notification to Data Principals and the Board must happen “without delay” on becoming aware (S.8(6) & Rule 7). A 72-hour SLA is a GDPR construct; importing it wholesale into DPDP creates a false compliance target.

A DPO is mandatory

The DPDP Act does not mandate a Data Protection Officer. Significant Data Fiduciaries must designate a Consent Manager (Rule 11) and meet additional obligations (S.10), but the DPO concept is not in Indian law. If your checklist has a DPO appointment control, flag it as voluntary or imported from GDPR.

Data localisation applies to everyone

The Act gives the Central Government power to restrict cross-border transfers to specific countries or territories (S.16). Until that list is notified, transfers proceed subject to reasonable safeguards. Blanket data localisation is not a current statutory requirement.

DPIA is a statutory obligation

Data Protection Impact Assessment is good practice and may emerge through SDF obligations or contractual requirements, but the DPDP Act does not use that term or mandate that process for all fiduciaries. The Significant Data Fiduciary regime (S.10, Rule 12) is the closest analogue.

Every processing activity needs a Record of Processing

GDPR Article 30 imposes this obligation. The DPDP Act does not have an equivalent provision. SDFs face additional audit and assessment obligations (Rule 12), but a full ROPA is not mandated for ordinary fiduciaries under Indian law.

Children’s age threshold is 13

The Act sets the children’s data threshold at 18 years (S.2(e)), not 13. COPPA-influenced thinking puts the bar lower. DPDP protections for children are more extensive than US law, covering all persons under 18 unless specifically exempted by the Central Government for a class of Data Fiduciaries.

The right to erasure is absolute

The right to erasure under S.12 applies unless the fiduciary is required to retain data under any other law. Tax records, financial records, and court-mandated retention can override the Data Principal’s erasure request. This is materially different from GDPR’s right to be forgotten.

Penalties are per incident

The Schedule penalty structure is per category of non-compliance, not per affected data principal or per incident. The highest tier (Rs 250 crore) applies to failure to implement reasonable security safeguards under S.8(5) — a category-level maximum, not per-breach.

The DPGPDPA Board is a regulator like a data protection authority

The Data Protection Board adjudicates complaints and imposes penalties; it does not issue prior approvals, certifications, or binding guidance the way GDPR supervisory authorities do. Pre-clearance frameworks do not exist under current Indian law.

Existing consents are automatically grandfathered

Consent obtained before the Act’s commencement must be reviewed against the new standard (S.40 read with Rule 22). Blanket reliance on historical consents without gap assessment is a material compliance risk, particularly for organisations that previously used omnibus or bundled consent language.

Common questions

DPDP Compliance Checklist FAQ

How many controls are in this DPDP checklist?

136 controls across 14 domains: Accountability, Consent Management, Data Principal Rights, Data Retention and Deletion, Data Security, Data Sharing, Transparency and Notice, Children and Vulnerable Persons, Significant Data Fiduciary, Breach Notification, Cross-Border Transfers, Grievance Redressal, Consent Manager (if applicable), and Implementation Readiness. Each control maps to the specific section of the Act or the relevant Rule.

What does “13 May 2027” mean for compliance deadlines?

13 May 2027 is the date by which 135 of the 136 controls in this checklist become enforceable based on the current commencement notification. One control (APP-08, Consent Manager registration) is tied to the earlier date of 13 November 2026. These dates are drawn from official MeitY commencement notifications and will be updated if further notifications are issued.

What is the difference between a statutory, rule-based, and implementation control?

Statutory controls derive directly from a numbered section of the DPDP Act 2023. Rule-based controls derive from the DPDP Rules 2025 issued under the Act. Regulatory-administrative controls relate to Board procedures and registration requirements. Implementation controls are operationally necessary best practices to meet the statutory and rule-based obligations but are not themselves a quoted legal requirement. This checklist distinguishes all four so you know exactly where the legal obligation sits.

Does the applicability filter cover Significant Data Fiduciaries?

Yes. The filter includes a question about SDF designation. If you are designated an SDF under S.10, additional controls activate covering consent management, data localisation readiness, annual audits, DPIAs, and the algorithmic accountability obligations under Rule 12. These controls remain hidden until you confirm SDF status to keep the checklist uncluttered for ordinary fiduciaries.

Can I use this checklist for a gap assessment?

Yes. The DPDP Readiness Assessment tool generates a scored gap report across the same 14 domains. Use this checklist to understand the requirement framework, and the Assessment to measure your current state against it. The accompanying free workbook lets you document evidence owner and remediation status offline.

What is included in the free DPDP workbook?

The downloadable workbook contains all 136 controls in a tabular format with columns for applicability, classification, legal source, recommended evidence type, evidence owner, remediation status, and target date. It is the same data set that powers this page, exported to a structured spreadsheet so you can use it as your compliance tracking register.

How often is this checklist updated?

The checklist is updated when MeitY issues new commencement notifications, when the DPDP Rules are amended, or when the Data Protection Board issues binding decisions that clarify obligations. The current version reflects the Act as enacted in August 2023 and the Rules notified in January 2025. Check the Article publication date at the bottom of this page for the last review date.

Is this checklist a substitute for legal advice?

No. This checklist is an information resource and compliance framework tool. It does not constitute legal advice and should not be relied upon as such. Organisations should obtain advice from qualified legal counsel for their specific circumstances, particularly for complex consent architectures, cross-border transfer strategies, and SDF designation analysis.

Further reading

Related DPDP resources

Official sources

This page is an information resource and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation.

Free download

DPDP Implementation Workbook

All 136 controls in a spreadsheet with evidence, owner and remediation columns.

↓ Download Workbook

Free assessment tool

DPDP Readiness Assessment

Scored across the same 14 domains. Get your gap report in 10 minutes.

Start free assessment →

Filter status

136

of 136 controls visible

Use the applicability tool above to filter.

👥

Find an Implementation Partner

Vetted firms who deliver DPDP programmes.