Cybersecurity
DPDP Act Compliance Checklist for Indian Businesses
Affix Center · · 6 min read

Most Indian businesses hold far more personal data than they realise: customer records in the CRM, employee files in HR, CCTV footage, visitor logs, marketing lists and vendor contacts. Much of it sits in spreadsheets and shared folders with no clear owner. With the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 now notified, a structured DPDP Act compliance checklist is the most practical way to turn legal text into work your teams can actually do.
The risk of waiting is real. The main obligations apply from May 2027, but mapping data, rewriting notices, fixing vendor contracts and changing systems takes many months, especially for companies with several locations or legacy software. This article explains the timeline and gives a step-by-step checklist that IT, legal and business teams in Mumbai, Pune and across India can use.
The DPDP Timeline: What Applies When
The Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 in November 2025. The rules follow a phased approach:
- From notification (November 2025): definitions and the provisions setting up the Data Protection Board of India came into force.
- After 12 months (November 2026): provisions on registration and obligations of Consent Managers take effect.
- After 18 months (May 2027): the core obligations on data fiduciaries apply, including notice, consent, security safeguards, breach intimation, data retention and rights of data principals.
The Act allows penalties of up to Rs 250 crore for certain failures, such as not taking reasonable security safeguards to prevent a personal data breach. That makes the remaining months a preparation window, not a waiting period.
Step 1: Know Your Personal Data
You cannot protect data you have not found. Start with a data inventory.
- List every system and file store that holds personal data: ERP, CRM, HRMS, email, websites, mobile apps, CCTV, access control and backups.
- Record what data is collected, from whom, for what purpose, where it is stored and who can access it.
- Identify data shared with vendors, such as payroll providers, cloud hosts, courier firms and marketing agencies.
- Flag sensitive groups, especially children and persons with disabilities, which need verifiable consent of a parent or lawful guardian.
- Assign a business owner for each dataset.
Step 2: DPDP Act Compliance Checklist for Notice and Consent
Consent under the Act must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action. Check the following:
- Notices: rewrite privacy notices in clear and plain language, stating the personal data collected, the specific purpose, and how people can withdraw consent, exercise their rights and complain to the Board.
- Standalone notice: make sure the notice can be understood on its own, not buried in long terms and conditions.
- Consent capture: replace pre-ticked boxes with clear opt-in actions and keep a record of each consent.
- Withdrawal: make withdrawing consent as easy as giving it, and ensure systems stop processing once consent is withdrawn.
- Legitimate uses: document where you rely on grounds other than consent, such as certain employment purposes, and why.
- Languages: plan for notices in English and in languages listed in the Eighth Schedule of the Constitution where users need them.
Step 3: Security Safeguards and Breach Response
The Rules set out reasonable security safeguards that data fiduciaries must adopt. Use this as a baseline:
- Encryption, masking or tokenisation of personal data where appropriate.
- Access control so only authorised staff and systems can reach personal data.
- Logging and monitoring of access, with logs retained for at least one year.
- Backups and measures to keep processing going after an incident.
- Contract clauses requiring processors to apply the same safeguards.
Breach intimation
When a personal data breach occurs, the fiduciary must inform affected individuals and the Data Protection Board without delay, and give the Board a detailed report within 72 hours of becoming aware of it. Write a breach playbook now: who decides, who drafts the notices, and how evidence is preserved. Remember that separate CERT-In reporting duties for cyber incidents also apply. Our cybersecurity services can help test this process through tabletop exercises.
Step 4: Rights, Retention and Vendors
Data principal rights
People can ask for a summary of their data, correction, completion, updating and erasure, and can nominate someone to act for them. Publish a clear way to raise these requests on your website or app, name a contact person who can answer questions, and set up a grievance process with defined response times.
Retention and erasure
Personal data should be erased once the purpose is served and it is no longer needed for legal reasons. Set retention periods for each dataset. For certain large platforms, the Rules fix specific periods and require the individual to be informed at least 48 hours before erasure.
Vendors and processors
- Review all contracts with processors for data protection, breach reporting and deletion clauses.
- Check where vendors store and process data.
- Keep a register of processors and the data each one handles.
Step 5: Governance and Significant Data Fiduciaries
Assign clear accountability. Most companies set up a small privacy committee with IT, legal, HR and business heads, reporting to senior management. Train staff who handle personal data, starting with HR, sales and customer service.
Companies notified by the government as Significant Data Fiduciaries have extra duties, including appointing a Data Protection Officer based in India, an independent data auditor, and conducting a Data Protection Impact Assessment and audit every twelve months. If your volume or type of data could put you in this group, plan for these early.
Good data management also helps analytics. Clean, well-labelled data with known consent status makes reporting and AI projects safer. Our data and AI team builds this into data platform designs.
A practical sequence before May 2027
With roughly eight months left before the core obligations apply, a phased plan keeps the work manageable:
- Next two months: finish the data inventory, appoint owners and run a gap assessment against this checklist.
- Following three months: rewrite notices, fix consent capture on websites and apps, update vendor contracts and set retention periods.
- Final three months: complete security control changes, test the breach playbook and rights request process, train staff and document evidence of compliance.
Keep a simple tracker with owners and dates, and review it every month with senior management. Evidence matters: record what was done, when and by whom.
Frequently Asked Questions
When do DPDP Act obligations apply to businesses?
Most obligations of data fiduciaries, including notice, consent, security safeguards and breach intimation, apply 18 months after the Rules were notified in November 2025, that is, from May 2027.
What is the maximum penalty under the DPDP Act?
Penalties can go up to Rs 250 crore, depending on the nature of the breach of the Act.
Does the DPDP Act apply to employee data?
Yes. Employee personal data is covered, although the Act allows some processing for employment purposes without consent.
Where should a DPDP Act compliance checklist start?
Start with a data inventory. Every other step, from notices to security and retention, depends on knowing what data you hold and where.
How Affix Center Can Help
Our team helps Indian businesses carry out data mapping, gap assessments, security control reviews, breach playbooks and system changes for consent and data rights. We work alongside your legal advisers so that technical controls match your policies.
To plan your DPDP readiness programme, speak with our cybersecurity team.