DPDP compliance checklist
for the Act and Rules 2025.
52 obligations from the Digital Personal Data Protection Act and the DPDP Rules 2025, grouped the way the work is done, each with the section or Rule it comes from and the date it comes into force. Tick what you can evidence, and copy the rest as a gap list.
Applicability and scope5 items
Decide what the Act covers before you build anything. Every later item assumes you know which processing is in scope and in which role.
Notice5 items
A notice is short, itemised and given at or before the request for consent. A privacy policy linked from a footer is not one.
Consent6 items
Consent under the Act is free, specific, informed, unconditional and unambiguous, and the burden of proving it sits on you.
Legitimate uses3 items
The Act has no general legitimate-interests basis. Processing without consent needs one of the uses listed in s.7.
Data Principal rights4 items
Rights need a published route in, a way to identify the person, and a clock.
Grievance redressal and contact3 items
A Data Principal must exhaust your grievance route before going to the Board, so the route has to exist and work.
Children and persons with disability5 items
Everyone under 18 is a child. The duties apply from the first account a child opens.
Reasonable security safeguards5 items
The largest penalty in the Schedule, up to ₹250 crore. Rule 6 sets the minimum.
Personal data breach3 items
Every breach is reportable. There is no materiality threshold and no risk test.
Retention and erasure4 items
Two duties that pull in opposite directions: erase when the purpose ends, but keep logs for at least a year.
Processors and transfers3 items
You stay responsible for what your processors do, whatever the contract says.
Significant Data Fiduciaries6 items
Only if the Central Government notifies you, or a class you belong to. The extra duties then run on a twelve-month cycle.
Ticks are saved in this browser only. Nothing is sent to us.
What does the DPDP Act require a company to do?
The DPDP Act requires a Data Fiduciary to give an itemised notice, take specific consent or rely on a listed legitimate use, keep data secure, report every breach to the Board and affected people, erase data when its purpose ends, honour access, correction, erasure and nomination requests, and protect children's data. Significant Data Fiduciaries carry extra audit and DPIA duties.
The checklist above breaks those duties into the 52 things a reviewer would actually test, each tied to the section of the Digital Personal Data Protection Act, 2023 or the rule of the DPDP Rules 2025 it comes from. Tick an item only when you could show the evidence for it today. A tick that rests on a policy paragraph and no working system is the most common way a readiness exercise overstates itself.
When do the DPDP obligations come into force?
The DPDP obligations come into force in three stages counted from the Rules' publication on 13 November 2025. The Board provisions applied at once. Consent Manager registration starts on 13 November 2026. Notice, consent, security, breach reporting, retention, children's data, rights and Significant Data Fiduciary duties all apply from 13 May 2027.
| Date | What commences | Items on this checklist |
|---|---|---|
| 13 Nov 2025 | Definitions and the Data Protection Board (Rules 1, 2, 17–21, and the Board sections of the Act) | None directly. There is now a body that can receive complaints. |
| 13 Nov 2026 | Consent Manager registration: section 6(9), section 27(1)(d) and Rule 4 | Honouring consent that arrives through a registered Consent Manager |
| 13 May 2027 | The substantive duties in sections 3 to 17, and Rules 3, 5–16, 22 and 23 | Everything else, 51 of the 52 items |
From Rule 1 of the DPDP Rules 2025 and the commencement notification published with them, announced by MeitY on 14 November 2025. MeitY consulted in January 2026 on bringing the May 2027 date forward for the largest companies; as of 28 September 2026 no amending notification has been published.
Which DPDP items take longest to build?
The DPDP items that take longest are the ones that need a system rather than a document: proof of consent under section 6(10), withdrawal that reaches your processors, erasure when the purpose ends, a 72-hour breach report to the Board, access logs kept for a year, and verifiable parental consent. Each needs engineering time, not only legal review.
Start with the data inventory, because nothing else can be scoped without it: you cannot set an erasure trigger for data you have not found, list the recipients an access request asks for, or bound a breach across an unknown estate. Automated data discovery fills most of that inventory from the systems themselves. Notice and consent come second, because they are visible to every user and the burden of proof is explicitly yours. The DPDP consent notice template covers the Rule 3 content, and a consent management platform with a versioned, append-only ledger covers the proof.
Erasure is the item most often ticked too early. The Act asks for deletion when consent is withdrawn or the purpose is served, across your processors as well as your own stores, while Rule 8(3) asks you to keep processing logs for at least a year. Our platform raises a dated erasure obligation naming the purpose, the person and the deadline, tells the processors that hold the data, and records the attested outcome; your own data owner performs the deletion. The guide to DPDP retention and erasure works through how the two duties fit.
How to use this checklist
Work through it once per business, not once per product, and then revisit the groups that changed. Three habits make the result worth having:
- Tick against evidence. For every tick, name the artefact you would hand a reviewer: a consent record, a signed processor agreement, a dated access review, a drill report
- Copy the gaps into a tracker. The Copy my gaps button gives you a plain-text list with the section and date for each open item, ready to paste into a ticket system or a board paper
- Check scope first. If you are unsure whether the Act reaches some of your processing, run the DPDP applicability checker; if you might be designated, the Significant Data Fiduciary checker explains how the section 10 factors read for you
To put a number on the gaps, the DPDP penalty calculator prices each obligation against the Schedule, and the DPDP penalties guide explains how the Board sets the amount. For the obligations explained in prose, read the DPDP Act and Rules 2025 guide; for the vocabulary, the compliance glossary.
The things people ask us
What is the first step in DPDP compliance?
Build a data inventory: what personal data you hold, in which systems, for which purposes, shared with whom, and for how long. Every later obligation depends on it. Notice needs the purposes, erasure needs the locations, access requests need the recipients, and breach reporting needs to know whose data sat in the affected system.
Does every company need a Data Protection Officer under DPDP?
No. Only a Significant Data Fiduciary must appoint a DPO, who has to be based in India and responsible to the board. Every other Data Fiduciary must publish the business contact details of a person who can answer questions about its processing, under section 8(9) and Rule 9, and must run a grievance mechanism.
How long do we have to report a personal data breach under DPDP?
Rule 7 requires notice to each affected person and to the Board without delay, and a detailed report to the Board within 72 hours of becoming aware, unless the Board allows longer on a written request. There is no materiality threshold. CERT-In's separate six-hour reporting rule for cyber incidents may also apply.
Is this checklist enough to be DPDP compliant?
No checklist is. It lists what the Act and Rules require and where each duty comes from, but compliance is whether your systems behave that way and whether you can prove it. Use the ticks to prioritise, attach evidence to each one, and have counsel review the result against how you actually process data.
Where are my ticks stored?
In your own browser, using local storage, so they survive a page reload on the same device. Nothing is sent to us and there is no account. If your browser blocks site storage or you use a private window, the ticks are forgotten when you close the page, so copy your gaps before you leave.
Do startups get an exemption from the DPDP Act?
Not automatically. Section 17(3) lets the Central Government notify classes of Data Fiduciaries, including startups, that are exempt from notice, accuracy, erasure, Significant Data Fiduciary and access duties. The exemption exists only once notified, so check for a notification that names your class before relying on it.
Tick the evidence, not the intention.
The checklist records what you believe. The platform records what your systems did, with the notice version, the consent and the erasure obligation on file for each person.