dpdp

DPDP compliance checklist for Indian SMEs: 47 things to do before the rules are notified

JO
Joginder Poswal
26 May 2026 12 min read
Share:
DPDP compliance checklist for Indian SMEs: 47 things to do before the rules are notified

The DPDP Rules were notified on 13 November 2025.

The Data Protection Board of India is operational.

And the full compliance deadline is 13 May 2027.

It might seem like that's a long way off, but it's not.

Eighteen months can pass quickly when you're running a business. Many Indian founders may not realize that the Board is already accepting complaints. You could be investigated before May 2027. If a customer files a complaint about your data handling today, the Board can take action right away.

So putting things off until later can have real consequences now, not just in 2027.

This checklist includes 47 steps that every Indian SME should complete. Some tasks can be done in an afternoon, while others may take weeks. Eventually, you'll need to do all of them. Businesses that finish early will be much better prepared for increased enforcement after May 2027.

Let's get started.

First, understand where you stand under the law

Before we get to the checklist, there’s one important thing to clarify.

The DPDP Act applies to digital personal data—information about an identifiable individual, collected digitally or digitized after offline collection. Your customer database, your employee records, your website sign-up forms, your CRM, all of it is in scope.

Under the Act, if you decide why and how personal data is processed, you're a Data Fiduciary. That's most Indian businesses. The person whose data you process is the Data Principal. And any vendor or tool you use to process data on your behalf is a Data Processor.

The Fiduciary has the most responsibility. Most SMEs are Fiduciaries, even if they aren't aware of it.

The Rules also introduced Significant Data Fiduciaries (SDFs). These are organizations the Central Government selects based on how much data they handle, the sensitivity of that data, or national security reasons. SDFs have extra responsibilities. If you run an SME, you likely won't be named an SDF at first. However, the regular Data Fiduciary rules still apply to you.

Now, the checklist.

Section 1: Data mapping (8 items)

You cannot protect data you don't know you have.

This is where most SMEs struggle. Many believe compliance just means posting a privacy policy, but that's not the case. It actually begins with understanding what data comes into and leaves your business.

  1. List every place your business collects personal data. Website forms, WhatsApp conversations, walk-in registers, Excel sheets, app sign-ups, physical forms that get scanned later.

  2. For each collection point, note exactly what data is collected. Name, phone number, email address, address, Aadhaar, PAN, income details, health information. Be specific.

  3. Identify the purpose for each collection. Why are you collecting this data? If you can't answer in one clear sentence, that's a problem you need to fix before anything else.

  4. Map the data flow. Where does collected data go after you receive it? Which team handles it? Which software stores it? Which third parties receive it?

  5. Identify all your Data Processors -- every vendor, tool, and service that handles personal data on your behalf. Your CRM, your email platform, your payroll software, your accounting tool, your cloud hosting provider.

  6. Flag any data that crosses borders. If your cloud provider stores data in the US, Singapore, or anywhere outside India, that's a cross-border transfer. The Rules have provisions on this, and certain restrictions are expected to be notified separately.

  7. Categorize data by sensitivity. Aadhaar numbers, financial records, and health data are in a different risk category than a business email address. Your security measures should reflect this.

  8. Write all of this down. If your data map only exists in your head, it won't help you if the Board asks for it.

Section 2: Consent framework (9 items)

The DPDP Act and Rules clearly define what valid consent is. It must be given freely, be specific, be informed, be unconditional, and be clear. Pre-checked boxes are not valid. Hiding consent in the terms and conditions is invalid. Silence is not valid consent either.

The Rules also require you to obtain consent with clear notice. This notice should be separate from, or easy to tell apart from, any other information you give the user.

  1. Review every form on your website or in your app that collects personal data. Does each one explain what you're collecting and why, in plain language?

  2. Check whether you're using "by continuing to use this site, you agree to our privacy policy" language. That's not valid consent under DPDP.

  3. Set up a system to record consent. For each consent you collect, you must be able to show who gave it, when, and why.

  4. Check your email marketing list. If people didn't explicitly opt in for marketing communications, their consent doesn't cover that use. Implicit consent from a purchase isn't enough.

  5. Create a way for people to withdraw their consent. The Act allows Data Principals to take back their consent at any time. When this happens, you must stop using their data for that reason. This should be a working process, not just a 'contact us' link.

  6. Check any third-party scripts on your website. Analytics tools, retargeting pixels, chatbots, and embedded widgets may all collect personal data. If you use them without telling users, you have a gap in consent.

  7. For users under 18, the Act requires verifiable parental consent before processing their data. If any of your users could be minors, you need an age verification mechanism.

  8. Review your employee onboarding process. Employee data is personal data. The consent you collected during onboarding may not meet the DPDP standard.

  9. Create separate consent records for different purposes. Consent for service delivery is not consent for marketing. These should never be bundled.

Section 3: Privacy notice (5 items)

The DPDP Rules say you must give Data Principals notice when you collect their data. This is different from a privacy policy, which is usually a long document on your website that few people read. The notice is a clear, specific explanation given right when you collect the data.

The Rules specify what the notice must contain: what data is being collected, the purpose of processing, how to exercise rights, and how to raise a complaint.

  1. Create a privacy notice for every data collection point. Your website sign-up, your customer onboarding, your mobile app, your employee joining form. Each one needs its own notice.

  2. Write your notice in plain language, as the Act requires. If your lawyer wrote it and it's hard to understand, that's not just a communication issue—it's a compliance issue.

  3. Provide the notice in languages your users actually read. Your privacy notice being in English only doesn't serve a customer base that primarily reads Hindi or any regional language.

  4. Make sure your privacy policy and your notices are consistent with each other. Contradictions between the two are a red flag in any inquiry.

  5. Set up a process to update your notices whenever your data practices change. If your notice hasn't been updated since 2022, it's probably no longer accurate.

Section 4: Data Principal rights (6 items)

The DPDP Act gives Data Principals four core rights: the right to access information about their data, the right to correction, the right to erasure, and the right to raise grievances. You need to be able to honor all four.

  1. Set up a way for people to request their data rights, such as an email address, a form, or a section in your app. Make sure someone is responsible for handling these requests.

  2. Audit your systems for data access capability. Can you pull all the data you hold on a specific individual across all your tools? If your data is spread across five different systems with no linking mechanism, this is harder than it sounds.

  3. Audit for data correction capability. If a customer says their phone number is wrong in your records, can you fix it everywhere it appears—in your CRM, your marketing tool, and your support system?

  4. Check if you can actually erase data when someone asks you to delete it. This includes removing it from backups, from your processors' systems, and from any third parties you've shared it with. This is often the most challenging part.

  5. Build a grievance redressal mechanism. The Act requires this explicitly. You need an acknowledgment process, a resolution timeline, and a responsible person.

  6. Designate a contact person for data rights requests. Only Significant Data Fiduciaries are required to appoint a formal Data Protection Officer. But every Data Fiduciary needs someone who actually handles these requests.

Section 5: Third-party and vendor management (5 items)

The DPDP Act makes you responsible for what your Data Processors do with personal data on your behalf.

Just because your vendor has a privacy policy or is GDPR compliant doesn't mean you're protected. You need written agreements that clearly state how they will handle your customers' data.

  1. List every vendor who touches personal data on your behalf -- CRM, email platform, payroll, accounting software, cloud hosting, customer support tools, logistics partners.

  2. Review your contracts with each of them. Do they include data processing clauses? If your vendor agreement is a standard terms-of-service clickthrough with no data processing provisions, you have a gap.

  3. Check where your vendors store data. Some platforms, particularly US-based ones, may store data in jurisdictions that could be restricted under DPDP's cross-border transfer provisions once they are notified.

  4. Check whether your vendors use sub-processors. If your CRM uses a third-party analytics engine, that engine is also processing your customers' data. You need visibility into this chain.

  5. Make a list of all vendors who handle your data and review it at least once a year. Vendor relationships can change, platforms may be acquired, and data storage locations can move. Reviewing just once is not enough.

Section 6: Data security (7 items)

The DPDP Act says you must have 'reasonable security safeguards' to prevent data breaches. The Rules don't set a specific technical standard, but what is reasonable depends on the type and amount of data you have. For example, storing Aadhaar numbers without encryption or sharing database passwords over WhatsApp is not considered reasonable.

If there's a breach and you can't demonstrate reasonable safeguards, the penalty is up to ₹250 crore.

  1. Enable encryption for all databases containing personal data -- both at rest and in transit.

  2. Implement access controls. Restrict access to personal data to only those employees who actually need it for their work.

  3. Set up audit logging. If something goes wrong, you need to know what happened, when it happened, and who had access.

  4. Write a data breach response plan. The DPDP Rules require you to notify the Data Protection Board when a breach occurs. Do you know what you'd do in the first 48 hours? Who gets called, what gets documented, what gets communicated to affected users?

  5. Review employee data access practices. Shared passwords, ex-employees with active access to systems, and unlocked laptops with CRM access are the most common vectors for breaches in Indian SMEs.

  6. Assess the physical security of any devices or paper records that contain personal data.

  7. Run a basic vulnerability assessment on any software or app you've built. Unpatched vulnerabilities are how most data breaches at Indian SMEs occur.

Section 7: Governance and documentation (7 items)

If you don't have documentation, your compliance is just good intentions. If the Board investigates, it will ask for records. Saying 'we do it properly' won't help if you can't show proof.

  1. Appoint a data compliance owner. Someone in your organization needs to be accountable for data protection. They don't need a formal title, but they need actual responsibility.

  2. Create a data retention policy with clear timelines. Decide how long you keep customer data after they stop using your service, and how long you keep employee data after they leave. 'As long as needed' is not a real policy.

  3. Set up a data disposal policy. When the retention period ends, make sure data is deleted not just from your main database, but also from backups, archives, and any copies held by processors.

  4. Document the lawful basis for each processing activity. For most SMEs, this will be consent. But document it explicitly for each activity, not just as a general statement.

  5. Write an internal data protection policy for your employees. People are often the biggest data risk. Having a written policy and basic awareness training can greatly reduce that risk.

  6. Hold at least a basic training session with your team on data protection. Most data breaches occur due to human error.

  7. Set a reminder to review this checklist every six months. As your business grows, your data practices will change, so your compliance should keep up too.

The honest take on where to start

If you haven't started any of this yet, you probably won't finish all 47 items in two weeks—and that's okay.

Priorities like this.

Start with these tasks, which only take a day or two: appoint a compliance owner, set up a dedicated email for rights requests, write a basic privacy notice for your main data collection point, enable two-factor authentication on your databases, and document who in your company has access to which data.

Over the next few weeks, work on these: review your vendor contracts and add data processing clauses, set up a consent record system, write your data retention policy, and create a breach response plan.

Make these part of your regular operations: review vendors annually, check your policies quarterly, process rights requests, and hold team awareness sessions.

The final deadline is 13 May 2027, but the Board is already active. Begin working on the first set of tasks this week.

What dComply does for this

We built dComply to handle exactly this operational layer.

Consent management with records. Data mapping tools. Vendor tracking. Breach response workflows. Rights request handling. Privacy notice templates built for DPDP. A compliance calendar that tracks what needs to happen and when.

It covers DPDP and 10 other compliance frameworks, Labour Law, ISO 27001, CERT-In, POSH, FSSAI, RERA, and more. Because DPDP is rarely the only compliance obligation you're managing.

The Free plan covers the basics. If you're just getting started, that's the right place to begin.

You can start using dComply for free, with no credit card required and no sales call.

Found this useful? Share it:

Ready to Get DPDP Compliant?

Start free and explore All 89 compliance modules

Talk to Sales