Readiness assessment

Browse by workflow

What do you need to do?

People do not think in sections of an Act, they think in tasks. Pick what you need to do and this page routes you straight to the governing provision, the terms that explain it, and the tool for the job. Every task is a step toward the Consent Manager framework on 14 November 2026 and full DPDP compliance by 13 May 2027.

16 compliance tasks6 stagesEach linked to its Section or RuleRoutes to the right tool

Set up consent and notice

Get lawful consent and notice in place before you process anything.

03

How do I handle children's data?

Before processing anyone under 18, obtain verifiable parental or guardian consent, and never track, behaviourally monitor, or serve targeted advertising to children. Breaching this carries a penalty up to two hundred crore rupees.

Section 9 and Rule 10

Handle rights and the data lifecycle

Serve the requests people are entitled to make, and retire data on time.

04

How do I respond to a data principal request?

On request you must give a summary of the personal data you process and who it was shared with, and correct, complete, update or erase it, within the timelines the Rules set.

Section 11 and Section 12
06

How do I manage data retention and erasure?

Erase personal data once consent is withdrawn or the specified purpose is no longer served, whichever is earlier, and make your processors erase it too, unless a law requires you to keep it.

Section 8(7) and Rule 8Retention Checklist launching 2026

Secure and report

Protect the data you hold, and disclose fast when something goes wrong.

07

How do I secure personal data?

Protect all personal data you hold or control, including data handled by your processors, with reasonable security safeguards to prevent a breach. Weak security carries the highest penalty on the Schedule, up to two hundred and fifty crore rupees.

Section 8(5) and Rule 6
08

How do I report a data breach?

After any personal data breach, notify both the Data Protection Board and every affected individual in the prescribed form and manner. Accidental disclosure and loss of access both count as breaches.

Section 8(6) and Rule 7

Govern and prove compliance

Stand up the roles and evidence the Act expects of higher-risk fiduciaries.

09

How do I appoint a Data Protection Officer?

A Significant Data Fiduciary must appoint an India-based Data Protection Officer, answerable to its governing body, as the contact point for the grievance mechanism.

Section 10(2)(a)
10

How do I run a data audit and DPIA?

A Significant Data Fiduciary must appoint an independent data auditor and run periodic Data Protection Impact Assessments that assess and manage the risks to data principals' rights.

Section 10(2)(b) and (c)
11

How do I select a data processor or vendor?

You may engage a processor only under a valid contract, and you stay responsible for its compliance, so vet its security and instructions before you sign. The duty cannot be contracted away.

Section 8(1) to (2)Vendor Directory launching 2026

Manage risk and enforcement

Know your exposure and what happens if the Board comes knocking.

12

How do I assess my DPDP readiness?

Map where you stand against every obligation, consent, notice, rights, security, breach, retention and governance, ahead of the Consent Manager framework on 14 November 2026 and full compliance by 13 May 2027.

DPDP Rules 2025Readiness Assessment launching 2026
13

How do I estimate my penalty exposure?

Penalties are set by the Schedule and imposed by the Board for significant breaches, up to two hundred and fifty crore rupees for weak security and two hundred crore for breach or children's failings.

Section 33 and the SchedulePenalty Calculator launching 2026
14

How do I prepare for a Data Protection Board proceeding?

The Board inquires into breaches and complaints and can impose penalties after a hearing. You can also offer a voluntary undertaking to resolve a matter before it proceeds.

Section 28 to 33
15

How do I transfer data across borders?

You may transfer personal data outside India unless the government notifies a country or territory as restricted, and any stricter sector law continues to apply.

Section 16

Become a Consent Manager

The regulated intermediary role, and how to qualify for it.