DPDP compliance checklist 2026: steps every Indian business must take now
At a glanceDPDP compliance for a typical business comes down to a repeatable set of steps: know what personal data you hold and why; give a clear notice and take valid consent at collection; collect only what you need; secure it; set retention and delete on schedule; be able to prove consent; publish a contact and grievance route; be ready to honour access, correction and erasure requests; and manage the vendors who touch your data. The checklist below walks each one. It won’t make you “certified” — DPDP compliance is organisation-wide — but it covers what most businesses must have in place.
Educational resource only. This is a practical checklist under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single checklist.
How to use this checklist
Run it against your business as it actually operates, not an ideal version. Most items scale with how much data you hold — a solo consultancy does a light version, a larger firm a fuller one. The goal isn’t a binder; it’s being able to show you handle personal data responsibly and act on requests.
The DPDP compliance checklist
Work through it in order — you can’t secure or delete data you haven’t mapped.
Know your data
- Map what personal data you collect, where it’s stored, and who can access it.
- Record why you hold each type — the purpose it serves.
- Note who you share it with (vendors, tools, partners).
Notice & consent
- Give a clear notice at every point of collection — what, why, how to withdraw, how to complain.
- Take specific, per-purpose consent with unticked opt-ins; no bundling.
- Where you rely on a legitimate use instead of consent, confirm it genuinely fits.
- For anyone under 18, route consent through a verifiable parent.
Minimise & secure
- Collect only what each purpose needs; drop “nice to have” fields.
- Apply reasonable security safeguards (access control, sensible storage, encryption where appropriate).
- Accept masked documents (e.g. masked Aadhaar) where the full version isn’t required.
Retain & delete
- Set a retention limit per data type; delete when the purpose is over, unless a law requires keeping it.
- Have a routine to purge what you no longer need.
Prove & respond
- Keep a demonstrable record of the consent you relied on.
- Be able to honour access, correction, and erasure requests.
- Publish a contact and a working grievance-redressal route.
Manage vendors & breaches
- Put a written contract in place with any processor that handles data for you.
- Have a breach-response plan: who acts, and how you’ll notify the Board and affected people.
What to prioritise first
If you can’t do everything at once, start where the risk and the duty are highest. In order:
- Map your data — everything else depends on knowing what you hold.
- Fix collection — notice and per-purpose consent at every intake point, since new data keeps arriving.
- Lock down security and retention — reduce what you hold and protect what’s left; this cuts breach exposure fastest.
- Stand up rights and grievance handling — you must be able to respond when someone asks.
- Contract your vendors and write a breach plan — the things you’ll wish you’d done before an incident.
FAQ
Does a small business really need to do all of this?
Proportionately, yes — the duties have no size cut-off, but they scale down. A small operation does a lighter version of each step, not none.
Can I become “DPDP certified” by completing a checklist?
No. Compliance is an organisation-wide, ongoing obligation, not a certificate. A checklist helps you cover the core duties; it doesn’t issue a verdict.
What’s the single most important step?
Mapping your data. You can’t give notice, secure, delete, or answer rights requests for data you haven’t accounted for.
Do I need a Data Protection Officer?
Only if you’re notified as a Significant Data Fiduciary. Otherwise you need a published contact and a grievance route, not a statutory DPO.
Related Articles
Collecting personal data from your own customers?
These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.
Run the compliance self-check →