Updated July 2026 · DPDP Act 2023 + Rules 2025

DPDP compliance checklist. 60 points. Ten categories. Free PDF.

The complete self-assessment for Indian Data Fiduciaries subject to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Ten categories, 60 items, section citations to the Act and Rules. Written by the DPO practitioners behind dcomply and used by hundreds of Indian companies preparing for the May 2027 enforcement deadline. Read on-page below, or download the PDF, no signup.

60 items, 10 categories Section citations to Act & Rules Written by practising DPOs
The full 60-point checklist

Every DPDP obligation, mapped to Act & Rules

Work through each of the ten categories. Tick items you have evidence for today. Log gaps against the Section 33(2) mitigation register, the DPB rewards documented remediation.

1 Governance & DPO

DPDP Act Sec. 2(i), 10 · DPDP Rules 2025 Rule 12
Identified whether the entity is a Data Fiduciary, joint Data Fiduciary, or Data Processor for each processing activity.
Published contact details of a person answering questions about the processing (Section 5), visible on website + privacy notice.
Assessed Significant Data Fiduciary (SDF) status against Section 10(1) criteria: volume, sensitivity, risk to rights, sovereignty considerations.
If SDF: appointed a DPO based in India, reporting to the Board or governing body.
If SDF: engaged an independent data auditor for periodic audits.
Board or executive sponsor named for the DPDP programme.

2 Data Mapping & RoPA

DPDP Act Sec. 8(2) · DPDP Rules 2025 Rule 3
Record of Processing Activities (RoPA) created, every purpose, every category of personal data, every source, every recipient.
Legal basis identified per activity, consent, or the four legitimate uses under Section 7.
Data flow map produced, collection, storage, processing, sharing, deletion.
Sensitive categories flagged, financial, health, biometric, minor, even though DPDP does not use a formal "sensitive" tier.
Every processor (SaaS vendor, cloud, sub-processor) named in RoPA and cross-referenced to a signed DPA.
RoPA reviewed at least annually and after any material change.

3 Consent & Notice

DPDP Act Sec. 5, 6, 7 · DPDP Rules 2025 Rules 3–4
Privacy notice available in English and each of the 22 languages listed in the Eighth Schedule, in itemised form.
Consent request is free, informed, specific, unambiguous, capable of withdrawal, and evidenced by clear affirmative action.
Purposes disclosed with itemised granularity, no bundled "all future purposes" catch-alls.
Withdrawal mechanism is as easy as the original consent, with no dark patterns.
Consent evidence stored as an auditable artefact: version, timestamp, IP, medium, purpose.
Consent Manager (if used) registered under DPDP Rules 2025 Rule 4.

4 Data Principal Rights (DSR)

DPDP Act Sec. 11–14 · DPDP Rules 2025 Rule 13
Public DSR portal or intake channel published, access, correction, erasure, grievance, nomination.
DSR response SLA published (default 90 days maximum; internal target much lower).
Grievance mechanism escalates unresolved requests to DPB within the statutory window.
Nomination facility (Section 14) available so a person can be named to exercise rights after death or incapacity.
Every DSR logged with identity verification, request, response, evidence pack.
Denial reasons documented against exemptions in Section 17.

5 Security Safeguards

DPDP Act Sec. 8(5) · CERT-In Directions 2022
Encryption at rest and in transit for all systems holding personal data.
Role-based access control with least-privilege, joiner-mover-leaver process, quarterly review.
Immutable audit logging retained per CERT-In direction (180 days) and DPDP Rules retention.
Backup and disaster-recovery tested at least once a year.
Vulnerability management: SAST, DAST, dependency scan, patch SLA.
Third-party penetration test at least annually and after major architecture change.

6 Breach Notification

DPDP Act Sec. 8(6) · DPDP Rules 2025 Rule 7 · CERT-In 2022
Incident response plan documents roles, escalation, and internal timelines.
DPB notification template pre-filled and hosted for one-click submission.
Affected data principal notice template ready in 22 languages.
CERT-In 6-hour notice format prepared and rehearsed.
Breach register maintained with root cause, containment, evidence, remediation.
Breach drill run at least twice a year with an executive tabletop.

7 Children's Data

DPDP Act Sec. 9 · DPDP Rules 2025 Rule 11
Age determination in place at intake (self-declaration + verifiable check for high-risk services).
Verifiable parental consent flow implemented (e-KYC, government ID, or approved token).
Behavioural tracking of children explicitly disabled.
Targeted advertising to children explicitly disabled.
Processing that causes detrimental effect on children identified and mitigated.
DPB exemption filed for any lawful health / research use-case if applicable.

8 Cross-Border Transfer

DPDP Act Sec. 16
Register of cross-border transfers: destination country, category, purpose, safeguard.
Section 16 whitelist checked. Central Government notified list of restricted destinations.
Contractual safeguards in place with foreign processors. DPA, sub-processor list, breach flow-through.
Sectoral overlays (RBI data localisation, insurance data residency) mapped and reconciled.
Data localisation obligations satisfied for classified sensitive categories.

9 Retention & Deletion

DPDP Act Sec. 8(7), 8(8) · DPDP Rules 2025 Rule 8
Retention schedule documented per data category, tied to purpose.
Automated purge or archival process in place at end of retention window.
Legal-hold exceptions documented (litigation, statutory record-keeping).
Erasure request evidence retained, what was erased, when, from which systems.
Retention alignment done with sectoral laws (Companies Act, IT Act, KYC Direction).

10 Vendor / Processor Management

DPDP Act Sec. 8(2)
Vendor register lists every processor and sub-processor, with contact + jurisdiction.
Signed DPA with every processor before onboarding.
Processor risk assessed at onboarding, security posture, data location, sub-processing.
Processor breach obligation flowed through in contract (within 24 hours to fiduciary).
Audit right reserved and exercised for critical processors.
Off-boarding process erases or returns data at end of engagement.
DPDP checklist FAQs

What DPOs ask before running a self-assessment.

Yes. The 60-point checklist is available on this page in full, and downloadable as PDF without email capture. dcomply publishes it because founders and DPOs need this information whether or not they buy our software.

It is written for Indian Data Fiduciaries, companies that determine the purpose and means of processing personal data. Startups, SMEs, mid-market and large enterprises across all sectors will find sections relevant. Data Processors (SaaS vendors) should map to Section 8(2) obligations.

Typical timing: a 50-person startup takes 2–4 weeks for a first pass, an SME with 500 employees takes 6–10 weeks, an enterprise takes a quarter. dcomply's Gap Assessment module runs this against your live data in hours.

Yes. This July 2026 revision incorporates the DPDP Rules 2025 (notified November 2025) covering breach notification format, consent-manager registration, children age-verification, DPIA triggers, and cross-border regime.

Log each gap, assign an owner, set a target date, and treat the compliance programme as an ongoing operational function, not a one-time project. dcomply's Gap Assessment module is designed exactly for this workflow.

The checklist is a self-assessment tool, not legal advice. Companies classified as Significant Data Fiduciaries or subject to sector overlays (RBI, IRDAI, SEBI, healthcare) should have a qualified DPO or advocate review the programme. dcomply's vDPO Premium tier includes an advocate on retainer from ₹19,999/month.

The DPDP Rules 2025 were notified in November 2025 with an 18-month transition window. Most obligations become fully enforceable by May 2027, but DPB adjudication of breaches under the Act itself is already possible. Starting now is the sensible position.

The checklist is DPDP-specific. GDPR and DPDP overlap on about 70% of controls but differ materially on: sensitive data category (GDPR has one, DPDP does not), lawful basis (GDPR has six, DPDP is consent + legitimate use), and cross-border regime (GDPR adequacy, DPDP whitelist).

Run this checklist for you, automatically.

dcomply’s Gap Assessment module runs all 60 items against your live systems and gives you a live readiness score. Free tier, no card.