Free Readiness Toolkit & Self-Assessment

DPDP Compliance Checklist & Readiness Guide

Assess where your organisation stands before you start fixing gaps. Convert legal requirements of the DPDP Act 2023 and DPDP Rules 2025 into 40 specific questions, owners, operational evidence and practical engineering actions.

40Technical Checks
8Core Domains
100%Evidence-Backed
2026–27Phased Phasing
DPDP Compliance Checklist & Readiness Guide
ARCHITECTURE // LIVESEC-CORE // 0x7F-DPDP
Checklist Engine40 CHECKS
Evidence RigorOPERATIONAL
Phased Framework2026–27
40-Point Technical & Legal Checklist
Evidence-Tested Verification
Phased 2026-27 Timeline
Interactive Readiness Scoring
Statutory Enforcement Phasing

Important: Readiness is not the same as current legal commencement

The distinction between immediate readiness and legal commencement is essential for a 2026 checklist. The Government notified the DPDP Act's commencement in phases on 13 November 2025. The final DPDP Rules were also notified on 13 November 2025. A readiness checklist should distinguish between obligations already in force, obligations with a future commencement date, conditional obligations and recommended implementation controls.

13 Nov 2025Phase 1: Initial Group Active

Provisions on publication: Establishment of Data Protection Board, definitions, rulemaking powers and administrative machinery are in force.

13 Nov 2026Phase 2: 1-Year Scheduled Group

Rule 4 (registration and operational standards of Consent Managers) and specified institutional provisions take effect 12 months post-Gazette.

13 May 2027Phase 3: Core Provisions (18 Months)

Sections 3–17 (Data Fiduciary obligations, notices, consent, Principal rights, Rule 6 security safeguards, processor mandates, breach reporting) and Rules 3, 5–16, 22, 23 take effect.

OPERATIONAL TEST

How to Use This DPDP Checklist

DPDP readiness is easier to manage when legal requirements are converted into specific questions, owners, evidence and actions. For each question, mark:

YES

Implemented & Evidence Available

The control or process is fully implemented and verifiable operational proof (audit logs, approval records, architecture diagrams) exists.

PART

Partial / Incomplete Evidence

Implemented incompletely, inconsistent across business units, or documentation exists without verifiable production proof.

NO

Not Implemented

No active control, workflow, or capability currently exists in the technology or business environment.

N/A

Genuinely Not Applicable

The statutory provision does not apply to your processing activities (with documented rationale recorded in your register).

Do not mark an item 'Yes' merely because a written policy exists. A stronger test is: Can we show evidence that the control or process actually operates?

SELF-ASSESSMENT TOOL

Quick DPDP Readiness Self-Assessment

Before reviewing all 40 detailed checks or downloading the full tracker, answer these 5 foundational questions to instantly see where your baseline stands.

Interactive Self-Assessment

Quick 5-Question DPDP Readiness Score

Answer these 5 core questions to immediately gauge where your readiness baseline stands before downloading the full 40-point tracker.

01

Can you identify where personal data is processed?

Across all apps, databases, cloud accounts, SaaS tools, and backups.

02

Can you explain why each important processing activity exists?

Documented legal grounds (consent or statutory legitimate use) for each flow.

03

Can you demonstrate the controls protecting relevant personal-data systems?

Access control, encryption/masking, logging, and verifiable backup testing.

04

Can you identify the third parties processing personal data?

Active processor register, vendor contracts with security clauses, and sub-processor chains.

05

Can you produce evidence for the controls you say are implemented?

Actual operational audit logs, approvals, and test results rather than just written policies.

40-POINT AUDIT

The 40-Point DPDP Readiness Checklist

Organised across 8 foundational governance and engineering domains. Every check connects statutory grounding to specific operational evidence.

01

Scope, Applicability & Processing Roles

5 Checks

Determine where the Act applies, which systems fall within scope, and whether your organisation is acting as Data Fiduciary or Data Processor.

01.Have we assessed whether the processing activities fall within the statutory scope of the DPDP Act?

Section 3 sets out the Act's application to specified processing of digital personal data in India and certain processing outside India connected with offering goods or services to Data Principals in India.

Evidence:Applicability assessment / documented scope decision

02.Have we identified the organisation's role for each material processing activity?

Determine whether the organisation is acting as a Data Fiduciary, Data Processor or another relevant party for each activity. The Act defines a Data Fiduciary as the person determining the purpose and means of processing and a Data Processor as a person processing personal data on behalf of a Data Fiduciary.

Evidence:Processing-role register

03.Have we documented the business units and systems included in the DPDP scope?

The scope should be tied to actual processing activities, not simply the legal entity name.

Evidence:Scope statement / system inventory

04.Have we identified applicable statutory exemptions or conditional requirements?

Do not assume that every DPDP control applies identically to every organisation.

Evidence:Applicability matrix

05.Have we documented important scope decisions and their rationale?

A recorded decision is more useful than an undocumented assumption.

Evidence:Scope decision log
02

Processing Purpose & Lawful Grounds

5 Checks

Connect every category of personal data to a lawful basis—either valid consent or statutory specified legitimate uses.

06.Have we identified the purpose for each material processing activity?

The Act provides for processing based on consent or specified legitimate uses, subject to the applicable conditions.

Evidence:Purpose register / processing inventory

07.Have we identified which processing activities rely on consent?

Do not assume every activity is consent-based.

Evidence:Processing-basis matrix

08.Have we identified relevant processing based on the Act's specified legitimate uses?

This is particularly important for business processes where consent may not be the applicable basis.

Evidence:Legal-basis assessment

09.Can we explain why each material category of personal data is processed?

The objective is to connect: Data → Purpose → Processing activity.

Evidence:Data-purpose mapping

10.Do product, marketing, operations and engineering teams understand the defined purpose of relevant processing?

A processing purpose should not exist only in a legal document while the product operates differently.

Evidence:Approved process documentation / product requirements
03

Notice & Consent Readiness

5 Checks

Ensure privacy notices are clear, itemised, standalone, and consent withdrawal is as easy to execute as giving consent.

11.Is the relevant privacy notice clear and understandable?

The final Rules specify requirements for notices, including standalone presentation, clear language, an itemised description of personal data and specified purposes. Those Rule 3 requirements have a later commencement date.

Evidence:Notice versions / approval record

12.Does the notice clearly connect personal data with the relevant purpose?

A generic statement such as 'for business purposes' should not replace a meaningful description of the processing.

Evidence:Notice-to-purpose mapping

13.Where consent is relied upon, can we demonstrate what was presented to the Data Principal?

The organisation should be able to reconstruct the relevant consent experience.

Evidence:Consent record / notice version

14.Where consent is relied upon, can the Data Principal withdraw it through an appropriate mechanism?

The Rules specify a communication mechanism for withdrawal and require the ease of withdrawal to be comparable to the ease of giving consent, when the relevant provisions commence.

Evidence:Withdrawal workflow / test result

15.Have we reviewed consent across different processing purposes rather than treating every use as one broad permission?

Examples may include product functionality, communications, marketing or other distinct processing activities.

Evidence:Purpose-level consent map
04

Data Principal Rights & Grievance Readiness

5 Checks

Operationalise mechanisms for individuals to access, correct, erase, nominate, and submit grievances regarding their personal data.

16.Do we have a defined process for receiving Data Principal requests?

Establish structured request intake channels for access, correction, erasure, and nomination.

Evidence:Request workflow

17.Can we identify the systems and data relevant to a legitimate request?

Ability to query all production stores, caches, analytics, and SaaS instances for an individual's personal data.

Evidence:System/data lookup procedure

18.Can we support correction or erasure processes where applicable?

Support cascading erasure and correction across live databases, search indexes, and downstream processors.

Evidence:Correction/deletion workflow

19.Is there a documented grievance-handling process?

Clear grievance redressal mechanism with an identified grievance officer and defined response SLAs.

Evidence:Grievance procedure / ownership

20.Can we demonstrate how requests and grievances are tracked through closure?

Maintain auditable ticket trails from initial submission through verification, fulfillment, and formal closure.

Evidence:Ticket/request records
05

Children's Data & Significant Data Fiduciary Applicability

5 Checks

Conditional obligations covering verifiable parental consent, behavioral tracking restrictions, and SDF governance mandates.

21.Have we determined whether we process personal data relating to children?

The Act defines a child as an individual who has not completed 18 years of age. Determine if children are in the user base.

Evidence:User-population assessment

22.If children's data is relevant, have we assessed the applicable parental-consent and child-protection requirements?

The final Rules contain specific provisions for verifiable parental consent and child-related processing, with later commencement.

Evidence:Child-data applicability assessment

23.Have we assessed whether tracking, behavioural monitoring or targeted advertising involving children creates a relevant compliance issue?

Section 9 contains specific restrictions and the Rules contain prescribed exemptions.

Evidence:Product/marketing assessment

24.Have we assessed whether the organisation may be designated as a Significant Data Fiduciary?

Do not assume SDF status merely because of sector, size or volume. Evaluate against official designation factors.

Evidence:SDF applicability assessment

25.If SDF obligations become applicable to us, have we identified the additional governance, DPIA and audit requirements that would follow?

These are conditional obligations under Section 10 and the corresponding Rules, including resident DPO, independent auditor, and Periodic DPIA.

Evidence:SDF readiness plan
06

Security Safeguards & Technical Measures

6 Checks

Rule 6 reasonable security safeguards: encryption/masking/tokenization, access controls, audit logging, backups, and resilience.

26.Are appropriate security safeguards implemented for systems processing personal data?

Deploy proactive technical and organisational measures across applications, APIs, networks, and databases.

Evidence:Security-control inventory

27.Are access controls implemented for relevant personal-data systems?

Least-privilege role-based access control, privileged identity management, and enforced multi-factor authentication.

Evidence:Access-control configuration / review

28.Are relevant logs, monitoring and access activity reviewed?

Continuous telemetry, centralized SIEM/log capture, and regular audit log reviews to detect unauthorized access.

Evidence:Monitoring records / review evidence

29.Are appropriate backup and continuity mechanisms available for relevant personal-data environments?

Immutable snapshots, tested disaster recovery procedures, and verified backup restoration to prevent data loss.

Evidence:Backup records / recovery test

30.Have we assessed whether encryption, masking, obfuscation or virtual-token mechanisms are appropriate for relevant processing?

The Rules use a risk/context-sensitive formulation rather than mandating one universal encryption product or algorithm.

Evidence:Security architecture / control assessment

31.Are technical and organisational safeguards documented and periodically reviewed?

Maintain periodic vulnerability assessment, penetration testing (VAPT), and configuration baseline reviews.

Evidence:Control register / review record
07

Data Processors, Third Parties & Cross-Border Transfers

4 Checks

Contractual governance, sub-processor visibility, security diligence, and Section 16 international transfer compliance.

32.Have we identified the organisations that process personal data on our behalf?

Maintain a complete inventory of vendors, cloud providers, SaaS tools, and contractors processing personal data.

Evidence:Processor register

33.Do applicable Data Processor contracts contain the required security provisions?

The final Rules expressly address security provisions in relevant Data Fiduciary–Data Processor contracts.

Evidence:Contract review matrix

34.Can we identify important downstream processors or technology dependencies?

This is especially relevant where cloud, SaaS, analytics or managed-service providers are involved.

Evidence:Vendor/process-flow register

35.Have we assessed relevant cross-border processing and transfer restrictions?

Section 16 concerns transfers outside India and provides for possible restrictions to notified countries or territories; it is not a blanket India-only storage requirement.

Evidence:Transfer map / contractual assessment
08

Retention, Breach & Evidence Readiness

5 Checks

Enforce purpose-based data erasure, incident classification, dual-track breach notification, and central evidence tracking.

36.Do we know what personal data is retained, where it is retained and why?

Map data lifecycle across production databases, analytical warehouses, file servers, and backup archives.

Evidence:Retention register

37.Do relevant systems have a defined process for deletion or other lifecycle action when the applicable purpose or retention requirement ends?

Do not use an arbitrary universal deletion period; the relevant purpose and applicable requirements should determine the lifecycle.

Evidence:Retention/deletion workflow

38.Can the organisation identify whether a security event involves personal data?

Establish triage workflows to immediately differentiate infrastructure incidents from events impacting personal data.

Evidence:Incident classification procedure

39.Is there a breach-response process aligned with the DPDP Rules?

The Rules provide for notification to affected Data Principals and the Board without delay, with detailed information to the Board within 72 hours of becoming aware of a personal-data breach unless additional time is permitted. This should not be reduced to the inaccurate statement 'DPDP has a blanket 72-hour breach-notification deadline.'

Evidence:Incident playbook / notification workflow

40.Can we produce evidence showing how relevant DPDP controls operate?

Centralize notice versions, consent logs, access reviews, processor agreements, security assessments, incident records, and deletion logs.

Evidence:Central evidence register
BENCHMARKING

How to Score Your Readiness

Calculate your internal readiness percentage: Points Achieved (Yes = 2, Partial = 1, No = 0) ÷ Applicable Points × 100. (N/A items are excluded from the denominator).

80–100%Structured Readiness

Most assessed areas have an active implementation and evidence foundation. Focus on technical validation, exception remediation, and continuous audit readiness.

60–79%Material Work Remains

Core principles are understood, but major gaps remain in operational evidence, access control enforcement, third-party contracts, or deletion workflows.

Below 60%Establish the Baseline

High compliance and operational exposure. Prioritise data discovery, system scoping, ownership assignment, and baseline technical security before optimising individual policies.

A score alone should never be treated as proof of legal compliance. It is an internal readiness indicator to prioritize engineering and governance budgets.

OPERATIONAL PROOF

The Evidence Test: Weak Evidence vs. Stronger Evidence

A checklist is only as dependable as the evidence backing it. The critical difference is having written documentation versus demonstrating how a safeguard actually operates in production.

Checklist AreaWeak Evidence (Documentation Only)Stronger Evidence (Operational Proof)
Privacy Notice✕ 'We have an updated privacy policy on our website.'✓ Approved standalone notice + version history + UI deployment evidence + purpose-to-data mapping.
Consent Management✕ 'Users accept our standard terms and conditions during registration.'✓ Purpose-specific consent record + exact notice version shown + working withdrawal mechanism test results.
Access Control✕ 'We use role-based access control across our cloud accounts.'✓ Formal role matrix + quarterly access review records + privileged account MFA enforcement + remediation logs.
Data Processor Governance✕ 'The vendor is approved by our procurement department.'✓ Central processor register + signed contracts with security clauses + third-party security due diligence reports.
Data Erasure & Retention✕ 'We delete old customer records periodically.'✓ Documented retention rule + automated purge workflow + cryptographic erasure verification evidence.
Breach Response✕ 'Our internal IT security team handles security incidents.'✓ Tested incident playbook + personal-data classification triage + dual-track notification workflow (Principals & Board).
Free Downloadable Tool

Download the Free DPDP Compliance Checklist & Tracker

Get the complete, operational 2026–27 readiness tracker designed specifically for privacy officers, CISOs, engineering leaders and legal counsel.

1. Applicability Gate (6 Pre-flight Scoping Questions)
2. Complete 40-Point Statutory Audit Checklist
3. 8-Column Evidence, Owner & Priority Tracker
4. Automated Readiness Percentage Scoring Engine
5. Action Summary (Top 5 Immediate Gaps & Target Dates)
6. 2026–27 Phased Commencement Enforcement Timetable
Get the Free Tracker Now

Instant access · XLSX + PDF formats · Includes 2026-27 phased enforcement roadmap

NUAGESEC DIFFERENTIATION

Why This Checklist is Different

Current 2026 checklist competitors range from short 12–20 item lists to generic 60-point legal summaries. NuageSEC's approach bridges legal analysis and offensive security engineering.

DPDP + Cybersecurity DepthCombines statutory legal provisions with offensive technical testing—covering APIs, cloud IAM, databases, and encryption.
The Operational Evidence TestReplaces policy complacency with verifiable production proof—audit logs, access reviews, and remediation validation.
Dynamic Applicability GatesPrevents applying irrelevant rules by separating baseline, conditional (children, SDF), and recommended controls.
Phased 2026–27 RealismClearly distinguishes between provisions currently active and core sections commencing in November 2026 and May 2027.
Built-In AccountabilityIncludes dedicated fields for ownership, priority scoring, remediation timelines, and target engineering dates.
Direct Remediation RoutingConnects checklist findings directly to specialized implementation, data mapping, and security testing paths.
PITFALLS TO AVOID

Common Checklist Mistakes to Avoid

Avoid these five critical pitfalls when conducting internal DPDP readiness self-assessments.

Assuming every business needs the exact same checklist

Treating all DPDP controls as universally applicable to every company.

Separate baseline, conditional, and recommended controls

The Act contains conditional provisions (e.g., children's data and Significant Data Fiduciaries) that require specific applicability analysis.

Believing DPDP has a blanket 72-hour breach deadline

Over-simplifying breach reporting into a single 72-hour timer.

Follow the dual-track notification requirements

The Rules require notification to affected Data Principals and the Board without delay, followed by detailed reporting to the Board within 72 hours.

Assuming DPDP mandates that all data must stay in India

Halting global operations under a false 'India-only data localization' belief.

Assess cross-border transfers under Section 16

The Act establishes a framework for possible restrictions to notified countries or territories, rather than a blanket prohibition on international processing.

Assuming every organization is legally required to appoint a DPO

Appointing unnecessary DPOs under premature assumptions.

Make DPO requirements conditional on SDF designation

Statutory Data Protection Officer requirements apply primarily to Significant Data Fiduciaries (SDFs) and specific regulated conditions.

Thinking having a written privacy policy means you are compliant

Assuming paperwork proves security controls, consent flows, and access rights operate in production.

Enforce the evidence test across engineering and IT

A document does not prove that access is restricted, consent withdrawal works, processors are governed, or data is securely erased.

NEXT STEPS

What to Do After Completing the Checklist

Your self-assessment answers should lead directly to practical engineering and governance actions. Connect your highest-priority gap to the relevant specialist service:

I don't know what personal data we have or where it movesData Discovery & Mapping
I know our technology stack but don't know our compliance gapsDPDP Gap Assessment
Our primary exposure is technical safeguards and application/API securitySecurity & Safeguards Assessment
We rely heavily on external vendors, cloud tools and third-party processorsVendor & Processor Compliance
We need to operationalise incident detection, containment and breach responseBreach & Incident Readiness
We have an assessment report and need to implement technical remediationImplementation & Remediation
We need comprehensive end-to-end program governance and advisoryDPDP Compliance Consulting
We operate across national or regional technology corridors in IndiaDPDP Compliance in India
FAQ

Frequently Asked Questions About the DPDP Checklist

What is a DPDP compliance checklist?

A DPDP compliance checklist is a structured self-assessment tool that translates the legal provisions of the Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 into specific operational questions, evidence requirements, and prioritized remediation actions.

Does completing this checklist mean my company is legally compliant?

No. This checklist is a readiness assessment, gap discovery, and internal planning tool. It helps identify strengths and deficiencies but does not constitute a legal determination or official certification of compliance.

When do the obligations in this checklist legally take effect?

Commencement is phased. Administrative machinery and the Data Protection Board provisions took effect on 13 November 2025. Rule 4 (Consent Managers) takes effect 12 months later (13 November 2026), and core obligations in Sections 3–17 and Rules 3, 5–16 take effect 18 months post-Gazette (13 May 2027).

Why does the checklist focus heavily on evidence rather than policies?

Regulatory scrutiny and breach investigations examine whether controls actually operate in production systems. Having a privacy policy or security document is meaningless if access controls, consent records, deletion workflows, and logging mechanisms are not actively functioning.

Do all 40 checklist items apply to every organization?

No. The checklist includes an Applicability Gate because the Act contains conditional provisions—such as verifiable parental consent for children's data and advanced governance obligations for Significant Data Fiduciaries.

What is the difference between a self-assessment checklist and a technical gap assessment?

A self-assessment checklist provides an internal baseline score and points to potential problem areas. A professional technical gap assessment from NuageSEC involves hands-on architecture reviews, API/application penetration testing, access-control audits, and verified remediation roadmaps.

Get in Touch

Start Your DPDP Assessment

Tell us about your organization. Our DPDP team will get back within one business day to define the right scope and next steps.

WhatsApp