0 of 136 controls passed
Domains
DPDP Act 2023 · DPDP Rules 2025
Work through DPDP by applicability, legal source, recommended evidence, ownership and remediation. Know what applies to you, what evidence to keep, and what to fix before obligations take effect.
Statutory obligations, Rules, regulatory triggers and implementation controls are separately labelled, so a legal duty is never presented as a recommendation.
Answer a few questions to see which controls are relevant to your processing. This runs entirely in your browser: nothing is sent or stored. It is guidance, not a legal determination.
Timing
The DPDP Rules being notified does not mean every obligation is enforceable today. Commencement is staged.
Framework and notified provisions in force, including the Data Protection Board and specified administrative provisions.
Consent Manager registration-related stage.
Core Data Fiduciary and Significant Data Fiduciary operational obligations represented in this checklist.
Sources: DPDP Act, 2023, DPDP Rules, 2025 and the commencement notification (MeitY).
Why this checklist is different
A generic checklist flattens everything into one line and one deadline. That is where mistakes start. Take breach notification.
Notify a data breach within 72 hours.
Collapsing that into a single "72-hour rule" gets the obligation wrong. Legal-source precision is the point of this checklist.
Every control keeps the classification from the source register, so a legal obligation is never mistaken for a recommendation.
The master framework currently covers 136 controls across 14 implementation domains. The number of controls is not the point; knowing which ones apply to you is.
No controls match these filters.
Free download
The page above is the legal and reference layer. The editable workbook adds the operating layer, so you can turn the checklist into a tracked project:
Free, and deliberately separate from any paid toolkit. Editable spreadsheet, based on the same 136-control register.
Your download has started.
If it did not, use this direct link:
Two quick optional questions help us improve the workbook:
Scope discipline
Many DPDP checklists import GDPR habits. These are the most common mis-framings this page deliberately avoids.
Consent is one of seven grounds. Large-scale legitimate use, legal obligation, medical emergency, public health, court order, employment, and public interest each stand independently (S.4). Treating consent as mandatory drags compliance into GDPR territory that the Act deliberately avoided.
The 72-hour number appears nowhere in the DPDP Act or Rules. Initial notification to Data Principals and the Board must happen “without delay” on becoming aware (S.8(6) & Rule 7). A 72-hour SLA is a GDPR construct; importing it wholesale into DPDP creates a false compliance target.
The DPDP Act does not mandate a Data Protection Officer. Significant Data Fiduciaries must designate a Consent Manager (Rule 11) and meet additional obligations (S.10), but the DPO concept is not in Indian law. If your checklist has a DPO appointment control, flag it as voluntary or imported from GDPR.
The Act gives the Central Government power to restrict cross-border transfers to specific countries or territories (S.16). Until that list is notified, transfers proceed subject to reasonable safeguards. Blanket data localisation is not a current statutory requirement.
Data Protection Impact Assessment is good practice and may emerge through SDF obligations or contractual requirements, but the DPDP Act does not use that term or mandate that process for all fiduciaries. The Significant Data Fiduciary regime (S.10, Rule 12) is the closest analogue.
GDPR Article 30 imposes this obligation. The DPDP Act does not have an equivalent provision. SDFs face additional audit and assessment obligations (Rule 12), but a full ROPA is not mandated for ordinary fiduciaries under Indian law.
The Act sets the children’s data threshold at 18 years (S.2(e)), not 13. COPPA-influenced thinking puts the bar lower. DPDP protections for children are more extensive than US law, covering all persons under 18 unless specifically exempted by the Central Government for a class of Data Fiduciaries.
The right to erasure under S.12 applies unless the fiduciary is required to retain data under any other law. Tax records, financial records, and court-mandated retention can override the Data Principal’s erasure request. This is materially different from GDPR’s right to be forgotten.
The Schedule penalty structure is per category of non-compliance, not per affected data principal or per incident. The highest tier (Rs 250 crore) applies to failure to implement reasonable security safeguards under S.8(5) — a category-level maximum, not per-breach.
The Data Protection Board adjudicates complaints and imposes penalties; it does not issue prior approvals, certifications, or binding guidance the way GDPR supervisory authorities do. Pre-clearance frameworks do not exist under current Indian law.
Consent obtained before the Act’s commencement must be reviewed against the new standard (S.40 read with Rule 22). Blanket reliance on historical consents without gap assessment is a material compliance risk, particularly for organisations that previously used omnibus or bundled consent language.
Common questions
136 controls across 14 domains: Accountability, Consent Management, Data Principal Rights, Data Retention and Deletion, Data Security, Data Sharing, Transparency and Notice, Children and Vulnerable Persons, Significant Data Fiduciary, Breach Notification, Cross-Border Transfers, Grievance Redressal, Consent Manager (if applicable), and Implementation Readiness. Each control maps to the specific section of the Act or the relevant Rule.
13 May 2027 is the date by which 135 of the 136 controls in this checklist become enforceable based on the current commencement notification. One control (APP-08, Consent Manager registration) is tied to the earlier date of 13 November 2026. These dates are drawn from official MeitY commencement notifications and will be updated if further notifications are issued.
Statutory controls derive directly from a numbered section of the DPDP Act 2023. Rule-based controls derive from the DPDP Rules 2025 issued under the Act. Regulatory-administrative controls relate to Board procedures and registration requirements. Implementation controls are operationally necessary best practices to meet the statutory and rule-based obligations but are not themselves a quoted legal requirement. This checklist distinguishes all four so you know exactly where the legal obligation sits.
Yes. The filter includes a question about SDF designation. If you are designated an SDF under S.10, additional controls activate covering consent management, data localisation readiness, annual audits, DPIAs, and the algorithmic accountability obligations under Rule 12. These controls remain hidden until you confirm SDF status to keep the checklist uncluttered for ordinary fiduciaries.
Yes. The DPDP Readiness Assessment tool generates a scored gap report across the same 14 domains. Use this checklist to understand the requirement framework, and the Assessment to measure your current state against it. The accompanying free workbook lets you document evidence owner and remediation status offline.
The downloadable workbook contains all 136 controls in a tabular format with columns for applicability, classification, legal source, recommended evidence type, evidence owner, remediation status, and target date. It is the same data set that powers this page, exported to a structured spreadsheet so you can use it as your compliance tracking register.
The checklist is updated when MeitY issues new commencement notifications, when the DPDP Rules are amended, or when the Data Protection Board issues binding decisions that clarify obligations. The current version reflects the Act as enacted in August 2023 and the Rules notified in January 2025. Check the Article publication date at the bottom of this page for the last review date.
No. This checklist is an information resource and compliance framework tool. It does not constitute legal advice and should not be relied upon as such. Organisations should obtain advice from qualified legal counsel for their specific circumstances, particularly for complex consent architectures, cross-border transfer strategies, and SDF designation analysis.
Further reading
Official sources
This page is an information resource and does not constitute legal advice. Consult qualified legal counsel for advice specific to your organisation.
Free download
All 136 controls in a spreadsheet with evidence, owner and remediation columns.
↓ Download WorkbookFree assessment tool
Scored across the same 14 domains. Get your gap report in 10 minutes.
Start free assessment →Filter status
of 136 controls visible
Use the applicability tool above to filter.
Find an Implementation Partner
Vetted firms who deliver DPDP programmes.