King Stubb & Kasiva Talk to KSK
Insight · Data Privacy

DPDP Compliance Checklist for Indian Companies: A Practical Roadmap for Compliance with the DPDP Act and Rules

India’s data protection regime has entered a critical implementation phase. The Digital Personal Data Protection Act, 2023 (DPDP Act), read with the Digital Personal Data Protection Rules, 2025 (DPDP Rules), establishes the principal framework governing the processing of digital personal data in India.

The DPDP Rules were notified in November 2025 and provide for a phased implementation. The provisions relating to the Data Protection Board came into force at the first stage, the provisions concerning Consent Managers are scheduled to take effect in November 2026, and the principal operational obligations applicable to Data Fiduciaries are scheduled to take effect after 18 months from notification, i.e. in May 2027.

Are you a Significant Data Fiduciary?

Answer 25 questions to see your DPDPA risk level and whether the DPO obligation applies to you — free, instant, with a branded PDF.

Check your compliance score →

For Indian businesses, therefore, the relevant question is no longer simply whether the DPDP framework will apply. The focus should now be on what needs to be done, by when, and which parts of the organisation need to be involved. The DPDP Act provides for significant financial exposure. Penalties may extend to ₹250 crore for failure to take reasonable security safeguards, ₹200 crore for certain personal data breach notification failures and children’s-data obligations, and ₹150 crore for specified Significant Data Fiduciary obligations.

This article sets out a practical DPDP compliance checklist for Indian companies, covering data mapping, privacy notices, consent management, security safeguards, breach response, data principal rights, vendor management, retention and deletion, and preparedness for potential classification as a Significant Data Fiduciary.

What is the DPDP Act and Who Does It Apply To?

The DPDP Act regulates the processing of digital personal data and establishes obligations for organisations that determine the purpose and means of processing such data. The principal concepts under the framework include:

Data Principal: A Data Principal is the individual to whom the personal data relates.

Data Fiduciary: A Data Fiduciary is a person who, alone or in conjunction with others, determines the purpose and means of processing personal data. In practical terms, this may include companies, employers, financial institutions, technology businesses, e-commerce platforms and other organisations that determine how and why personal data is processed.

Data Processor: A Data Processor processes personal data on behalf of a Data Fiduciary. Examples may include cloud service providers, payroll vendors, customer relationship management platforms and other outsourced service providers, depending on the nature of their activities.

Significant Data Fiduciary: The Central Government may notify certain Data Fiduciaries or classes of Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on factors including the volume and sensitivity of personal data processed, risks to the rights of Data Principals and potential impact on matters such as sovereignty, security of the State and public order. SDFs are subject to additional compliance requirements.

Does the DPDP Act Apply to Foreign Companies?

The territorial scope of the DPDP Act is important for multinational businesses. The framework applies to the processing of digital personal data within India. It may also apply to processing undertaken outside India where such processing is connected with offering goods or services to Data Principals in India.

Accordingly, organisations should not assume that having their servers, processing teams or corporate headquarters outside India automatically takes them outside the scope of the DPDP framework.

DPDP Act and Rules: Implementation Timeline

The DPDP framework is being implemented in phases rather than through a single compliance deadline.

PhaseEffective DateKey Developments
Phase 1November 2025Establishment and functioning of the Data Protection Board and specified institutional provisions
Phase 2November 2026Consent Manager-related provisions
Phase 3May 2027Core obligations relating to notice, consent, security safeguards, breach reporting, Data Principal rights, children’s data, SDF obligations and other substantive requirements

The DPDP Rules expressly provide for this staggered commencement. For businesses, the period leading up to May 2027 should therefore be treated as a compliance implementation window, rather than a reason to defer preparations.

DPDP Compliance Checklist for Indian Companies

1. Establish Governance and Accountability

DPDP compliance should be treated as an organisation-wide governance programme rather than solely an IT or legal exercise. Companies should identify a senior person responsible for overseeing implementation and establish clear ownership across:

  • Legal and compliance;
  • Information technology;
  • Cybersecurity and information security;
  • Human resources;
  • Product and business teams;
  • Procurement and vendor management;
  • Marketing and customer operations; and
  • Senior management and the Board, where appropriate.

Organisations should document responsibilities, escalation mechanisms and decision-making authority. Companies that may potentially be notified as Significant Data Fiduciaries should assess the additional governance requirements that may become applicable, including the requirement relating to an India-based Data Protection Officer.

2. Conduct a Personal Data Inventory and Data Mapping Exercise

A comprehensive data inventory and data-flow mapping exercise should be the starting point of any DPDP compliance programme. Organisations should identify:

  • What personal data they collect;
  • Whose personal data is being processed;
  • Where the data is collected;
  • The purposes for which it is processed;
  • Where the data is stored;
  • Who has access to it;
  • Which Data Processors receive the data;
  • Whether the data is transferred outside India;
  • How long the data is retained; and
  • When and how the data is deleted.

This exercise should cover employee data, customer data, vendor data, website data, application data, marketing databases and other relevant processing activities. A properly maintained data inventory or Record of Processing Activities-style register can become the foundation for several subsequent compliance requirements.

Companies should review their existing privacy policies, website notices, application notices, employee-facing notices and consent forms. The DPDP framework places emphasis on providing information to Data Principals in clear and understandable language. Organisations should ensure that their notices appropriately communicate matters such as:

  • What personal data is being processed;
  • The purpose of processing;
  • How Data Principals can exercise their rights; and
  • Relevant contact details.

Where consent is the applicable basis for processing, organisations should also ensure that consent is properly captured and can be demonstrated. Consent should be capable of being withdrawn, and the mechanism for withdrawal should not be disproportionately difficult compared with the mechanism through which consent was provided. Businesses should also begin assessing how their consent architecture may interact with the Consent Manager framework scheduled to take effect in November 2026.

4. Implement Reasonable Security Safeguards

Data security is one of the most important areas of DPDP compliance. The DPDP Rules prescribe a range of security measures, including measures relating to encryption, obfuscation, masking or use of virtual tokens, access controls, logging and monitoring, backups, contractual safeguards with Data Processors, and technical and organisational measures. The Rules also contemplate retention of relevant logs for at least one year, subject to applicable legal requirements.

Companies should therefore assess whether their existing security framework adequately addresses:

  • Role-based and need-to-know access;
  • Encryption and masking;
  • Authentication controls;
  • Privileged-access management;
  • Vulnerability management;
  • Security monitoring;
  • Incident logging;
  • Backup and recovery;
  • Business continuity;
  • Processor security; and
  • Periodic security assessments.

Security compliance should not be limited to the organisation’s own systems. Data processed by third-party Data Processors also needs to be appropriately addressed through contractual and operational controls.

5. Prepare a Data Breach Response Framework

Organisations should have a documented personal data breach response plan before the substantive breach obligations become applicable. The framework should establish:

  1. How a breach is detected;
  2. Who is notified internally;
  3. Who determines whether an incident constitutes a personal data breach;
  4. How affected Data Principals are identified;
  5. How regulatory notifications are prepared;
  6. How evidence is preserved;
  7. How remediation is undertaken; and
  8. How recurrence is prevented.

Under the DPDP Rules, affected Data Principals are to be informed without delay in clear and concise terms, while the Board is to receive an initial intimation without delay followed by a more detailed report within the prescribed period, including the circumstances of the breach, its consequences and mitigation measures. Companies should also ensure that their DPDP incident-response framework is coordinated with other applicable cybersecurity and sector-specific reporting obligations, including applicable CERT-In requirements.

6. Build Processes for Data Principal Rights

The DPDP framework provides Data Principals with rights relating to their personal data and requires organisations to establish mechanisms through which those rights can be exercised. Companies should create a documented process for receiving, authenticating, tracking and responding to requests relating to applicable rights, including:

  • Access to information about personal data;
  • Correction of personal data;
  • Erasure of personal data;
  • Withdrawal of consent;
  • Grievance redressal; and
  • Nomination.

Organisations should maintain appropriate records of requests received, decisions taken and responses provided. The process should also identify the internal team responsible for handling such requests and establish clear escalation procedures.

7. Address Children’s Data

Processing the personal data of children requires additional safeguards. Businesses that provide services likely to involve children should identify such processing during their data-mapping exercise and determine whether their systems are capable of obtaining and verifying the required parental consent. This may require changes to:

  • Age-verification mechanisms;
  • Parental-consent workflows;
  • User onboarding;
  • Product design;
  • Marketing practices; and
  • Data-sharing arrangements.

Companies should not assume that a generic privacy policy is sufficient to address children’s-data compliance.

8. Review Data Processor and Vendor Contracts

A DPDP compliance programme should extend across the organisation’s third-party ecosystem. Companies should identify all vendors and Data Processors that handle personal data and review their existing contracts. Relevant contractual arrangements should address matters including:

  • Purpose and scope of processing;
  • Instructions of the Data Fiduciary;
  • Security safeguards;
  • Confidentiality;
  • Incident and breach reporting;
  • Sub-processing;
  • Data deletion or return;
  • Assistance with Data Principal requests; and
  • Audit or compliance rights, where appropriate.

A DPDP vendor due diligence programme can help organisations identify high-risk processors and prioritise contractual remediation.

9. Establish Data Retention and Deletion Policies

The DPDP framework requires organisations to think carefully about how long personal data should be retained and when it should be deleted. Companies should create retention schedules linked to specific processing purposes and applicable legal or regulatory retention requirements.

The DPDP Rules prescribe specific retention periods for certain categories of large e-commerce entities, online gaming intermediaries and social media intermediaries. For the specified purposes, the relevant threshold entities may be required to retain personal data for three years from the relevant trigger, subject to the conditions and exceptions prescribed under the Rules. The Rules also provide for advance notice before applicable erasure. Accordingly, organisations should avoid adopting a blanket policy of retaining all personal data indefinitely.

Instead, they should establish: Collection → Purpose → Retention Period → Review → Deletion/Anonymisation. This approach can also reduce cybersecurity and operational risk associated with unnecessary data accumulation.

10. Assess Whether the Organisation Could Be a Significant Data Fiduciary

Organisations processing large volumes or categories of sensitive or high-risk personal data should assess whether they may potentially fall within the SDF framework. Once notified as an SDF, an organisation may be subject to additional obligations, including requirements relating to:

  • Appointment of an India-based Data Protection Officer;
  • Independent data audits;
  • Data Protection Impact Assessments;
  • Periodic reporting;
  • Algorithmic due diligence; and
  • Compliance with applicable government directions relating to specified categories of data.

An SDF assessment should therefore form part of an organisation’s initial DPDP gap assessment rather than being postponed until formal designation.

11. Train Employees and Update Internal Policies

DPDP compliance cannot be achieved through technology and contracts alone. Employees frequently interact directly with personal data through email, HR systems, CRM platforms, customer support systems, spreadsheets and cloud applications. Companies should therefore update:

  • Privacy policies;
  • Employee privacy notices;
  • Information-security policies;
  • Data retention policies;
  • Incident-response SOPs;
  • Vendor-management procedures;
  • Data subject/Data Principal request procedures; and
  • Employee handbooks.

Role-based training should also be conducted for teams that regularly handle personal data.

12. Maintain Evidence of Compliance

A significant but often overlooked aspect of privacy compliance is documentation. Companies should maintain evidence of:

  • Data inventories;
  • Data-flow maps;
  • Consent records;
  • Privacy notices;
  • Vendor assessments;
  • Contracts;
  • Security assessments;
  • Breach-response exercises;
  • Data Principal requests;
  • Training programmes;
  • Retention and deletion decisions; and
  • Internal compliance reviews.

A documented compliance programme can be particularly important if an organisation is required to demonstrate how it identified and addressed a particular risk.

Standard Data Fiduciary vs Significant Data Fiduciary

Not every organisation will have the same compliance burden under the DPDP framework.

Compliance AreaData FiduciarySignificant Data Fiduciary
Privacy notice and applicable consent requirementsApplicableApplicable
Reasonable security safeguardsApplicableApplicable
Personal data breach responseApplicableApplicable
Data Principal rightsApplicableApplicable
Data Processor managementApplicableApplicable
Data Protection OfficerContact mechanism as prescribedIndia-based DPO with additional responsibilities
Independent data auditNot generally applicableApplicable as prescribed
Data Protection Impact AssessmentNot generally applicableApplicable
Algorithmic due diligenceNot generally applicableApplicable
Additional SDF complianceNot applicableApplicable

The distinction is commercially important because organisations that may qualify as SDFs should prepare for a substantially more intensive compliance framework.

Cross-Border Data Transfers Under the DPDP Act

Cross-border data transfers are an important consideration for multinational companies, cloud-based businesses and organisations using global technology infrastructure. The DPDP Act does not impose a blanket requirement that all personal data must be stored in India. Instead, the framework permits transfers outside India subject to restrictions that may be prescribed or notified by the Central Government.

Organisations with international data flows should therefore map: India → Global cloud infrastructure → Overseas Data Processor → Sub-processor; and identify the contractual, security and regulatory implications at each stage. Cross-border data transfer assessments should also be reviewed against sector-specific requirements and other applicable Indian laws.

What Should Companies Do in 2026?

For most organisations, the priority should not be to wait for May 2027. A practical implementation programme can be divided into four stages:

Stage 1: Identify

  • Map personal data;
  • Identify Data Fiduciaries and Data Processors;
  • Identify processing purposes;
  • Assess territorial applicability;
  • Identify high-risk processing.

Stage 2: Assess

  • Conduct a DPDP gap assessment;
  • Review privacy notices;
  • Review consent mechanisms;
  • Assess security controls;
  • Review vendor contracts;
  • Assess SDF exposure.

Stage 3: Remediate

  • Implement technical safeguards;
  • Update contracts;
  • Build Data Principal rights mechanisms;
  • Establish breach-response procedures;
  • Implement retention and deletion processes;
  • Train relevant employees.

Stage 4: Test and Monitor

  • Conduct tabletop breach exercises;
  • Test consent withdrawal;
  • Test Data Principal request workflows;
  • Review processor compliance;
  • Conduct periodic internal audits;
  • Report progress to senior management and the Board.

This turns DPDP compliance from a one-time legal exercise into an ongoing governance programme.

Explore KSK Data Privacy Hub

Free compliance tools and expert guidance covering 75+ jurisdictions.

Continue reading — Latest Insights