Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Free Excel worksheet

DPDP Act Breach Readiness Worksheet (Free Excel)

An Excel worksheet that makes your data map ready for the day something goes wrong. For each system it records what data is held, roughly how many people, how to reach them, where the logs are, how to contain and recover, and who to call out of hours. It is built to sit beside our guide to data mapping for breach readiness.

  • 9 sheets
  • 40 systems, 30 processors, 20 drills
  • Gap flags are formulas
FREE XLSX

Get the free worksheet

Free XLSX, about 27 KB. Link appears on the next page.

Free. Internal self-assessment aid, not certification or legal advice. If you do not get your download link, write to hi@dpdpactindia.in.

How to use the worksheet in five steps

  1. Fill the Systems sheet first, one row for each system that holds personal data. Record the data categories, a rough count of people, how to reach them, where the logs are, how to contain, how to recover, the owner and an out-of-hours contact.
  2. Fill the Processors sheet. Record a named escalation contact, how to reach it, whether the contract covers incidents, whether the processor can give you logs and whether you know its sub-processors.
  3. Run a rehearsal. Pick a short fictional scenario and, using only this workbook, list the systems, data, people and processors it involves. Note how long it took and log it on the Drills sheet.
  4. Close every gap you find. Name an owner and a date on the Drills sheet, then update the Systems or Processors sheet.
  5. Read the gap flags and the Summary sheet, and re-verify rows when a vendor, tool or team changes.

Who it is for, and what it does not do

It suits security and IT leads, privacy and compliance owners, and operations managers who would be pulled into an incident call. It works best beside a personal data inventory and a processor register, because it uses the same activity IDs and processor IDs.

It helps you scope an incident. It does not decide whether an event is a breach, draft a report or tell you how to notify the Board or Data Principals. The file will hold out-of-hours contact details, so limit who can open it and record categories of data and rough counts, not personal data.

What the law says. Section 2 of the Act defines a personal data breach. Section 8(5) requires reasonable security safeguards, and Rule 6 lists what they include. Section 8(6) and Rule 7 require the Data Fiduciary to intimate the Board and each affected Data Principal. Section 8(5), Section 8(6), Rule 6 and Rule 7 are not yet in force: they commence on 13 May 2027. We found no provision requiring a data map or a readiness sheet for breach response. This worksheet is a practical tool.

Frequently asked questions

Is this a breach notification template?

No. It helps you scope an incident: which systems, which data, how many people, how to reach them and which processors are involved. It does not tell you how to notify the Board or Data Principals, or what the deadlines are. Our reporting guide covers that.

When do the breach duties start?

Section 8(5), Section 8(6), Rule 6 and Rule 7 commence on 13 May 2027. Section 8(6) and Rule 7 require the Data Fiduciary to intimate the Board and each affected Data Principal.

Is minutes to scope a legal time limit?

No. It is your own measure of how long a rehearsal takes when you use only the worksheet to list the systems, data, people and processors involved.

Why should access to the file be limited?

It will contain contact details for people who must be reachable out of hours. Record categories of data and rough counts, not personal data, and share the file only with those who need it.

Is the worksheet free?

Yes. It costs nothing. You enter your name, work email, organisation and role (phone is optional) and tick the consent box. The next page gives you a download link that works for one hour. If it expires, submit the form again.

What happens to my details?

We use them to send you the worksheet and to contact you about it. We send DPDP updates only if you tick the second box. You can withdraw your consent at any time by writing to hi@dpdpactindia.in. The Privacy Policy has the detail.