DPDP Act Compliance Checklist: 12 Steps After the 2025 Rules
A practical DPDP Act compliance checklist - 12 steps covering consent, data mapping, security, breach reporting and DPO setup. Self-assess your DPDP readiness.
10 min readBy Sachin Shirish, Director
Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX

Why Break the Act Into a Checklist
The Digital Personal Data Protection Act, 2023 is dense, but compliance becomes manageable when you break it into steps. A clear DPDP Act compliance checklist turns the law into actions your team can tick off, system by system.
This guide gives you 12 practical steps, from data mapping to breach reporting, so you can self-assess readiness, spot gaps and prioritise fixes before a regulator or customer asks.
Use it as a living document. Reviewed each quarter, it keeps you compliant as you add features, vendors and data.
In short: the checklist is a step-by-step list of the duties the Act and the DPDP Rules, 2025 place on a business: data mapping, consent, notices, data principal rights, security safeguards, processor contracts, breach reporting and, where required, DPO appointment. Work it in order: confirm your role, map all personal data, rewrite notices, build consent capture, add rights workflows, apply security safeguards, set retention rules, prepare breach intimation, and finish with an internal audit. A small business can complete a first pass in two to four weeks; larger firms take six to twelve. It is a self-assessment, so pair it with an independent audit before you claim full compliance to partners.
What the Checklist Covers
It is a structured list of every obligation the Act places on your business (consent, notice, security, data principal rights and breach response) mapped to who owns each one.
Think of it as the readiness list your auditor would use. It does not replace expert help, but it shows where you stand and what to fix first.
Crucially, it assigns an owner to each item. Compliance fails when nobody is responsible, so naming who handles consent, security and breach response is half its value.
At a glance
- Whether you act as a Data Fiduciary or a Data Processor.
- A full map of personal data across systems, vendors and backups.
- Consent, notices and data principal rights handled end to end.
- Security safeguards and breach intimation readiness.
- DPO or contact person, processor contracts and retention schedules.
Does the Act Apply to You, and When?
The Act applies to the processing of digital personal data in India, and to processing outside India connected with offering goods or services to people in India. There is no general size threshold, though the government may exempt classes of Data Fiduciaries, including startups, from certain duties by notification.
The timeline is now fixed. The DPDP Rules, 2025 were notified on 13 November 2025, when the Data Protection Board provisions came into force. Most duties for Data Fiduciaries, including notices, security safeguards, breach intimation and data principal rights, apply from 13 May 2027, eighteen months after notification.
Penalties are significant: up to Rs 250 crore for failing to take reasonable security safeguards to prevent a personal data breach. That is why early-stage teams keep a checklist to show readiness to investors, partners and customers before it is demanded.
The 12 Steps
Steps one to four cover foundations: name an owner, confirm whether you are a Data Fiduciary or Processor, map all personal data, and rewrite privacy notices in clear language.
Steps five to eight build controls: consent capture with easy withdrawal, data principal rights workflows, security safeguards, and processor contracts.
Steps nine to twelve close the loop: retention and erasure schedules, breach intimation to the Board and affected people, DPO appointment if you are a Significant Data Fiduciary (or a published contact person otherwise), and an internal audit.
Tick each step and attach evidence, and you build an audit trail. When a customer's security team sends a questionnaire, a completed checklist with evidence answers most of it in minutes rather than days.
How Long It Takes
A small business can work through the list in two to four weeks; larger firms with many systems take six to twelve. The first pass always takes longest because data mapping surfaces surprises.
Startups can speed it up by handling the essentials first (consent, security and breach response) and layering the rest. Momentum matters more than perfection on day one.
Build in review time. Rerun the DPDP Act compliance checklist each quarter, because new features, vendors and datasets quietly create fresh gaps between formal reviews.
Checklist or Full Audit?
The checklist is a self-assessment; an audit is independent verification. The first tells you where you stand, while the audit proves it to a third party who may demand evidence.
Most teams start with the checklist or a gap analysis, fix the obvious gaps, then book an audit. Doing it the other way round wastes audit time on issues a self-assessment would have caught for free.
Overseas firms serving people in India can use the same steps, mapping each to GDPR, UK GDPR or CCPA duties so one programme covers several regimes.
How SecureRoot Helps
SecureRoot turns the DPDP Act compliance checklist into a working programme through its DPDP Act compliance services, and connects the work to your wider compliance programme so compliance runs as one system. Ask us for a copy of the checklist mapped to the Act and its Rules.
Our team has supported BFSI, fintech, healthcare and government clients across India and abroad. The official text of the law is published by MeitY, and every engagement maps directly to the Act and its Rules.
Frequently asked questions
Straight answers, no marketing speak. If you don’t see your question here, just ask at info@secureroot.co or call +91 73071 48874.
Is a DPDP Act compliance checklist enough on its own?
No. It is the right place to start and a genuine self-assessment, but it is not evidence anyone outside your team can rely on. The checklist tells you where you stand across the twelve steps, from confirming whether you are a Data Fiduciary or a Data Processor through to internal audit; an independent audit proves it to a customer, an investor or a regulator. The difference matters most in complex, multi-system environments, where the first pass at data mapping keeps surfacing stores nobody listed, and a tick on paper hides an unmapped backup or an unsigned processor contract. Work the steps in order, attach evidence to each item rather than a yes or no, fix what the first pass exposes, and only then book verification. Our DPDP Compliance Audit guide sets out what independent verification involves, and the DPDP Gap Analysis guide covers the lighter scoped view if a full audit is premature.
When do the DPDP Act duties apply?
The dates are fixed and they are staggered. The DPDP Rules, 2025 were notified on 13 November 2025, and the Data Protection Board provisions came into force that day, so the regulator exists now. The rules governing registration and obligations of Consent Managers apply from 13 November 2026. Most duties that affect ordinary businesses, meaning notices, security safeguards, breach intimation and data principal rights, apply from 13 May 2027, eighteen months after notification. Read that as a work schedule rather than a grace period. A first pass through the checklist takes two to four weeks in a small business and six to twelve in a larger one, and the long items are the ones nobody can compress: mapping personal data across systems, vendors and backups, rewriting notices in clear language, and getting processor contracts amended by counterparties who have their own queue.
Does the Act apply to small businesses and startups?
Yes. The Act covers digital personal data processed in India with no general size threshold, so a two-person startup handling customer records is in scope on the same terms as a bank. The government may notify exemptions from certain provisions for classes of Data Fiduciaries, including startups, so check what has actually been notified rather than assuming relief exists, and plan on the core duties applying. Size changes the effort, not the obligation. A small team can complete a first pass in two to four weeks by taking the essentials first, meaning consent capture with easy withdrawal, security safeguards and breach intimation readiness, then layering data mapping, retention schedules and processor contracts behind them. The penalty for failing to take reasonable security safeguards reaches Rs 250 crore, and a completed checklist with evidence attached is also the fastest way to answer a customer's security questionnaire.
How often should we review the checklist?
Quarterly at minimum, and immediately on any change that creates new processing. The triggers are specific: a new system, a new vendor, a product feature that collects something it did not collect before, or a new category of personal data. Each can require a fresh notice, a lawful basis, a retention rule or a processor contract, and none of them announce themselves in a compliance calendar. Treat the checklist as a living document with a named owner per step, because the failure mode is rarely disagreement about the answer; it is that nobody was responsible for asking. Rerun the twelve steps, re-attach current evidence rather than carrying last quarter's forward, and record what changed and why. That rhythm also keeps you ready on demand: when a customer's security team sends a questionnaire, a current checklist with evidence answers most of it in minutes rather than days.
Do foreign companies need this checklist?
Yes, if you process the personal data of people in India in connection with offering goods or services to them. The Act reaches processing outside India on that basis, so a company with no Indian entity, office or infrastructure can still be a Data Fiduciary. What changes is the starting point, not the obligation. If you already run a GDPR, UK GDPR or CCPA programme, most of the underlying work is done: data mapping, notices, rights handling, security safeguards and processor contracts. Extend that programme rather than build a parallel one, and add the India-specific pieces, which are the notice content and language, consent capture with easy withdrawal, breach intimation to the Data Protection Board and to affected people, retention and erasure schedules, and a DPO or a published contact person. Map each of the twelve steps onto a control you already operate, and what is left over is the actual project.
Does the checklist help with other privacy laws?
Largely yes, and that is the argument for running one programme instead of three. Data mapping, privacy notices, consent, data principal rights handling, security safeguards, retention schedules and processor contracts are common ground across the DPDP Act, GDPR and CCPA, so one set of controls and one evidence trail can serve several regimes. Map each of the twelve checklist steps to the corresponding duty in each law, then handle local differences as additions to a shared control rather than as separate workstreams: the India-specific notice requirements, breach intimation to the Data Protection Board, and the timing set by the DPDP Rules, 2025. Two cautions are worth keeping. Equivalent-looking concepts are not always equivalent, so check the wording before you reuse a control, and your evidence has to show which standard you met for which person. Done properly this is configuration and documentation work, not a second compliance stack.
Related service pages
DPDP Act Compliance Services · Compliance Services · Virtual DPO
Ready to get DPDP-ready?
This guide was researched against the DPDP Act, 2023 and its Rules, and reviewed by SecureRoot’s compliance team for accuracy.
Have a Question About This?
If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.
We reply within one business day.

