Share 💬 💼
DPDP

DPDPA Compliance Checklist 2025 — Complete Guide for Every Business

📅 Mar 04, 2026
👤 Adv. Deepak Kumar
⏱️ 11 min read
📂 DPDP
DPDPA Compliance Checklist 2025 — Complete Guide for Every Business
The DPDP Act 2023 applies to every business — no size exemption, no revenue threshold. This complete DPDPA compliance checklist covers all 35 obligations across consent, rights, breach notification, vendor management, children's data, and more — with legal references and a free PDF download.
DPDP Act 2023 + DPDP Rules 2025 — Complete Compliance Checklist

India's Digital Personal Data Protection Act, 2023 is now fully framed — the DPDP Rules 2025 were notified on 13 November 2025, and the compliance clock is running. This checklist gives you every obligation you must fulfil, in priority order, with the specific section of the Act or Rule that requires it. Bookmark it. Share it. Download it. And start checking boxes.

📥 Checklist PDF Available

This checklist is available as a downloadable PDF — pre-formatted for print, team sharing, and investor due diligence packs. Contact us to get your copy and speak with a compliance expert.

Nov 2025
Rules notified — Board active
Nov 2026
Consent Manager registration opens
May 2027
All obligations enforceable — DEADLINE
📋 Checklist Sections
  1. How to use this checklist
  2. Consent — the foundation of everything
  3. Privacy notice and transparency obligations
  4. Data Principal rights — your response obligations
  5. Data minimisation and purpose limitation
  6. Data retention and erasure
  7. Grievance Officer and internal governance
  8. Breach detection and notification
  9. Children's data — heightened requirements
  10. Vendor and third-party management (Data Processors)
  11. Significant Data Fiduciary — additional obligations
  12. Documentation and audit-readiness checklist

1. How to Use This Checklist

This checklist follows the structure of the DPDP Act 2023 and DPDP Rules 2025 and is organised by obligation type — not by section number — so you can assign items to the right team member and track progress practically.

🟢 MUST DO (All businesses)
Items that apply to every Data Fiduciary regardless of size, sector, or revenue. Non-negotiable.
🟡 CONDITIONAL (Specific triggers)
Items that apply only if you process children's data, cross-border data, or are designated an SDF.
⚪ BEST PRACTICE (Recommended)
Items not explicitly required but that significantly reduce legal risk and improve investor/client confidence.

Penalties reminder: The DPDP Act prescribes penalties up to ₹250 crore per breach of data security safeguards, ₹200 crore for failure to notify breaches, and ₹50 crore for most other violations. The Data Protection Board can investigate based on complaints or suo motu. There is no small-business exemption on penalties.

2. Consent — The Foundation of Everything

Consent under the DPDP Act is the primary lawful basis for processing personal data. It must meet specific legal standards — it cannot be buried in terms and conditions or pre-ticked.

Legal standard (Section 6, DPDPA): Consent must be free, specific, informed, unconditional, and unambiguous — given by a clear affirmative action. It cannot be a precondition for a service unless that data is genuinely necessary.

# Obligation Status Legal Ref Priority
2.1 Consent request is separate — not buried inside terms of service or a privacy policy ☐ TODO S.6(1) 🟢 MUST
2.2 Consent notice clearly states the data collected, purpose of processing, and how to withdraw consent ☐ TODO S.5, S.6 🟢 MUST
2.3 Consent is obtained before data is collected — not retroactively or at the time of delivery ☐ TODO S.6(1) 🟢 MUST
2.4 Consent withdrawal mechanism is as easy as giving consent — a single click, no friction or dark patterns ☐ TODO S.6(4) 🟢 MUST
2.5 Consent records maintained — timestamp, version of notice shown, method of consent, and withdrawal records ☐ TODO R.3 🟢 MUST
2.6 Legitimate use (non-consent) processing is identified, documented, and limited to Schedule 1 permitted purposes only ☐ TODO S.7 🟢 MUST
2.7 Consent Manager integration — prepare for registration requirement (opens November 2026 per DPDP Rules) ☐ PLAN S.6(5), R.4 🟡 PLAN

3. Privacy Notice and Transparency Obligations

Under the DPDP Act, a privacy notice is not optional. It must exist, it must be accessible, it must be accurate, and it must be updated whenever your data practices change.

# Obligation Status Legal Ref Priority
3.1 Privacy Policy published at a publicly accessible URL — linked from website footer, app store listing, and sign-up flow ☐ TODO S.5 🟢 MUST
3.2 Privacy Policy covers all 6 mandatory disclosures: data types collected, purposes, third parties, retention period, rights, and contact details ☐ TODO S.5, R.3 🟢 MUST
3.3 Privacy Policy is written in plain language — the Act requires clarity and comprehensibility, not legalese ☐ TODO S.5(1) 🟢 MUST
3.4 Privacy Policy is available in Indian languages where users can reasonably request it (recommended for consumer-facing apps) ☐ LATER S.5(2) ⚪ BEST
3.5 Separate consent notices drafted for each distinct purpose (e.g. marketing emails vs. service delivery vs. analytics) ☐ TODO S.6(2) 🟢 MUST
3.6 Privacy Policy version control — previous versions archived with effective dates; users notified of material changes ☐ LATER Best Practice ⚪ BEST

4. Data Principal Rights — Your Response Obligations

Every individual whose data you process (a "Data Principal") has six enforceable rights under the DPDP Act. You are legally required to have a process to receive, verify, and respond to each of them.

👁
Right to Information
What data you hold and how it's used — Section 11
✏️
Right to Correction
Fix inaccurate or incomplete data — Section 12
🗑
Right to Erasure
Delete data when consent is withdrawn — Section 12
🙋
Right to Grievance Redressal
Escalate unresolved issues to the Board — Section 13
👤
Right to Nominate
Designate a person to exercise rights posthumously — Section 14
# Obligation Status Legal Ref Priority
4.1 Rights request intake mechanism exists — a dedicated email address, form, or portal clearly stated in the Privacy Policy ☐ TODO S.11–S.14 🟢 MUST
4.2 Response SLA documented — internal timeline to acknowledge, verify identity, and respond to each rights request type ☐ TODO R.7 🟢 MUST
4.3 Identity verification process for rights requests — to prevent third-party abuse while not making verification unnecessarily burdensome ☐ TODO R.7 🟢 MUST
4.4 Erasure workflow covers downstream — when you delete data, the process also triggers deletion requests to your Data Processors ☐ TODO S.12(3) 🟢 MUST
4.5 Nomination mechanism — users can designate a nominee to exercise rights in case of death or incapacity (required under S.14) ☐ PLAN S.14 🟡 PLAN
4.6 Rights request log maintained — date received, type, identity verified, action taken, date resolved, outcome ☐ LATER Best Practice ⚪ BEST

5. Data Minimisation and Purpose Limitation

Two principles that run through the entire DPDP Act: collect only what you need, and use it only for what you said. These are not aspirational guidelines — they are enforceable obligations.

# Obligation Status Legal Ref Priority
5.1 Data inventory completed — every data type you collect, why you collect it, the lawful basis, and who has access ☐ TODO S.8(1) 🟢 MUST
5.2 No collection of data without a stated purpose — every data field on every form is justified and mapped to a purpose ☐ TODO S.4(1)(b) 🟢 MUST
5.3 No secondary use of data without fresh consent — data collected for onboarding cannot be used for marketing without a separate consent ☐ TODO S.4(1)(b) 🟢 MUST
5.4 Data accuracy maintained — reasonable steps taken to ensure data is accurate and up-to-date for the purpose it is used ☐ TODO S.8(3) 🟢 MUST

6. Data Retention and Erasure

You cannot keep personal data indefinitely. The DPDP Act requires you to define how long you keep data, erase it when the purpose ends, and have a system to do this reliably.

# Obligation Status Legal Ref Priority
6.1 Retention schedule drafted — every data category has a defined retention period with the legal or business justification ☐ TODO S.8(7) 🟢 MUST
6.2 Auto-deletion or manual review process in place — data is actually deleted when the retention period ends, not just flagged ☐ TODO S.8(7) 🟢 MUST
6.3 Consent withdrawal triggers data deletion within a reasonable period — unless another legal basis permits retention ☐ TODO S.6(4), S.12 🟢 MUST
6.4 Backup and archive data included in retention policy — deletion must cover backups, not just live databases ☐ PLAN S.8(7) 🟡 PLAN

7. Grievance Officer and Internal Governance

Every Data Fiduciary must appoint a Grievance Officer. This is not optional and not size-dependent. The officer's contact details must be publicly accessible in your privacy notice.

# Obligation Status Legal Ref Priority
7.1 Grievance Officer appointed — name, designation, and contact email published in Privacy Policy and on website ☐ TODO S.13 🟢 MUST
7.2 Grievance resolution process documented — acknowledge within 48 hours, resolve within timelines per Rule 7 ☐ TODO R.7 🟢 MUST
7.3 Internal data protection policies — employee data handling, access control, and acceptable use policy documented and acknowledged ☐ TODO S.8(5) 🟢 MUST
7.4 Annual compliance review scheduled — revisit policies, data flows, vendor list, and consent mechanisms at least yearly ☐ LATER Best Practice ⚪ BEST

8. Breach Detection and Notification

The DPDP Act imposes mandatory breach notification — to the Data Protection Board and to affected users. There is no minimum threshold. Any breach of personal data must be reported.

Penalty alert: Failure to notify a breach carries a penalty of up to ₹200 crore per instance. This is the second-highest individual penalty in the Act. And "not knowing" you had a breach is not a defence — you are required to have detection mechanisms in place.

# Obligation Status Legal Ref Priority
8.1 Breach response plan documented — who is notified internally, who leads the response, what constitutes a reportable breach ☐ TODO S.8(6), R.6 🟢 MUST
8.2 Board notification process mapped — your team knows how to file a breach report with the Data Protection Board under Rule 6 ☐ TODO R.6 🟢 MUST
8.3 Affected user notification templates drafted — clear, plain-language notice explaining what happened, what data, and what to do ☐ TODO S.8(6) 🟢 MUST
8.4 Security safeguards in place — technical and organisational measures appropriate to the nature and volume of data (encryption, access control, logging) ☐ TODO S.8(5) 🟢 MUST
8.5 Vendor breach notification clause in all Data Processor agreements — your vendors must notify you promptly if they suffer a breach involving your data ☐ TODO S.8(6), S.9 🟢 MUST

9. Children's Data — Heightened Requirements

If your product or service is accessible to users under 18, or if you process data of any child (under 18), you face significantly higher obligations. These are not discretionary — they are the most strictly enforced provisions of the Act.

Critical trigger: If your app, website, or service can be used by someone under 18 — even if you didn't design it for children — these rules may apply. You must either implement age verification or implement the heightened standards across the board.

# Obligation Status Legal Ref Priority
9.1 Verifiable parental consent obtained before processing any child's data — not just a tick-box age declaration ☐ IF APPLIES S.9(1) 🟡 COND.
9.2 No tracking, behavioural monitoring, or targeted advertising directed at children — these are hard prohibitions, not defaults ☐ IF APPLIES S.9(3) 🟡 COND.
9.3 Age verification or assurance mechanism implemented — for platforms where child users are a realistic possibility ☐ IF APPLIES R.10 🟡 COND.
9.4 Enhanced deletion process for children's data — upon consent withdrawal by parent or child reaching 18, deletion is prompt and comprehensive ☐ IF APPLIES S.9, S.12 🟡 COND.

10. Vendor and Third-Party Management (Data Processors)

Every SaaS tool, cloud provider, analytics platform, or email service you use that processes personal data on your behalf is a "Data Processor" under the DPDP Act. You remain responsible for their actions — and you must have binding agreements in place.

# Obligation Status Legal Ref Priority
10.1 Vendor inventory compiled — list of every third party that receives or accesses personal data (CRM, cloud, payments, analytics, HR, etc.) ☐ TODO S.9 🟢 MUST
10.2 Data Processing Agreement (DPA) in place with each significant vendor — covering purpose, security, breach notification, and deletion ☐ TODO S.9 🟢 MUST
10.3 Cross-border transfer controls reviewed — if vendors are outside India, verify that the country is not on the restricted list (to be notified by the Board) ☐ PLAN S.16 🟡 PLAN
10.4 Vendor DPAs reviewed annually — especially after vendor updates their terms of service or undergoes acquisition or change of data practices ☐ LATER Best Practice ⚪ BEST

11. Significant Data Fiduciary — Additional Obligations

If the government designates your business as a "Significant Data Fiduciary" (SDF) based on volume, sensitivity, national security risk, or impact on rights — you face a second tier of obligations. The designation criteria will be notified by the Board.

Who should prepare for SDF designation now: Large consumer apps with millions of users, fintech platforms, healthcare data businesses, companies processing sensitive categories of data at scale, and any platform critical to digital infrastructure or national security.

# Additional SDF Obligation Status Legal Ref Priority
11.1 Data Protection Officer (DPO) appointed — independent, senior, and accountable for the compliance programme ☐ IF SDF S.10(1) 🟡 COND.
11.2 Data Protection Impact Assessment (DPIA) conducted for high-risk processing activities — before launch and for existing products ☐ IF SDF S.10(2) 🟡 COND.
11.3 Independent data audit conducted annually by a recognised auditor — report submitted to the Data Protection Board ☐ IF SDF S.10(3) 🟡 COND.
11.4 Algorithmic transparency measures — if you use automated decision-making that significantly affects users, document and disclose the logic ☐ IF SDF S.10(4) 🟡 COND.

12. Documentation and Audit-Readiness Checklist

The Data Protection Board can request documentation at any time — and during a breach investigation, within very short timelines. Having these records ready is what separates managed compliance from firefighting.

📁 Core Documents (Have These Ready)
  • DPDPA-compliant Privacy Policy (version-controlled)
  • Consent Notice templates for each purpose
  • Data inventory / processing register
  • Vendor list + DPA status tracker
  • Grievance Officer appointment letter
  • Breach response plan
  • Retention schedule
  • Rights request log
  • Employee data handling policy
🏆 Investor / Enterprise Pack (Additional)
  • DPDPA compliance summary memo from advocates
  • Compliance certificate (third-party attestation)
  • Security safeguards summary
  • Sub-processor / vendor list (sanitised)
  • DPIA report (if applicable)
  • DPO appointment letter (if SDF)
  • Last annual compliance review report
  • Data breach history (nil or resolved)
📊 Your Compliance Progress Summary
35
Total obligations
in this checklist
23
🟢 MUST DO
(all businesses)
9
🟡 CONDITIONAL
(specific triggers)
3
⚪ BEST PRACTICE
(recommended)
May 2027
Final enforcement
deadline

Get the Full Checklist PDF — and Expert Help Completing It

This checklist gives you visibility on everything you need to do. But completing it correctly — with legally sound documents, properly structured consent flows, and vendor DPAs that will actually hold up — requires expert review. Template documents rarely meet DPDPA standards, and the Board has made clear it will not accept generic or pre-filled compliance documentation.

Our DPDPA Compliance Packages are fixed-price, fast-delivery, and built specifically for startups and SMEs — from a ₹25K base package to a fully managed outsourced DPO service. We cover every item on this checklist.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp