Confidential Dispatch

What makes a data-collection form DPDP-compliant? A checklist

3 min readUpdated 2026-07-04
On this page
  1. 01Who this is for
  2. 02The compliant-form checklist
  3. 03The items people get wrong
  4. 04FAQ
At a glance

A compliant data-collection form does five things beyond gathering answers: it shows a clear notice of what and why at the point of collection; it takes specific, per-purpose consent with unticked opt-ins; it asks only for the minimum the purpose needs; it stores responses securely with a set retention limit; and it lets you prove the consent and honour withdrawal. Miss any one and the form gathers data but not compliance. Use the checklist below on any form you run.

Educational resource only. This is a practical checklist for data-collection forms under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single form.

Who this is for

If you run any intake form — enquiry, registration, booking, onboarding, KYC — this is the run-through to check it against. It applies whether the form is a web form, a Google Form, or a paper form that gets digitised; the tool changes, the requirements don’t.

The compliant-form checklist

Work top to bottom — notice first, consent next, then fields, storage, and the after-care.

Notice (shown on the form, before submission)

  • States what personal data you’re collecting.
  • States the purpose — specific, not “for our records.”
  • Says how to withdraw consent, and how to raise a grievance (your contact, and the Data Protection Board of India).
  • Written in plain language, visible on the form — not just a link to a policy.

Consent (a real, specific opt-in)

  • Consent is per purpose — separate opt-ins for separate uses (e.g. fulfilling the request vs marketing).
  • Boxes are unticked by default; the person actively opts in.
  • No bundling (“Submit = you agree to everything”) and no “by continuing you agree.”
  • Withdrawal is as easy as giving consent was.

Fields (minimisation)

  • Every field maps to the stated purpose — no “nice to have” extras.
  • Mandatory fields are only those genuinely required; the rest are optional or removed.
  • Sensitive items (Aadhaar, PAN, documents) are collected only if truly needed, and masked where the full value isn’t required.

Storage & retention (after submit)

  • Responses are stored with access controls — not an open, shareable sheet.
  • A retention limit is set, and data is deleted when the purpose is over (unless a law requires keeping it).
  • Any third-party tool holding the responses is covered by appropriate processor terms.

Proof & rights (the part that’s easy to skip)

  • You keep a record of the consent — what notice was shown and what was agreed.
  • There’s a process to honour access, correction, and erasure requests.

The items people get wrong

Three failures account for most non-compliant forms — and none are about the fields themselves.

  • Bundled consent. One checkbox (or none) covering several purposes is the most common miss. Split them.
  • The missing consent record. Storing answers isn’t the same as being able to prove what was consented to. The burden of proof is yours, so capture the notice-and-opt-in, not just the data.
  • Forms that never forget. Responses sitting in an unrestricted, never-purged sheet quietly break the security and retention duties long after collection. Lock access and set a deletion habit.

Fix those three and most forms clear the bar; the rest of the checklist keeps them there.

FAQ

What’s the single most important thing on a data-collection form?

A clear notice paired with specific, unbundled consent at the point of collection — that’s what makes any consent valid, and it’s the most commonly missed.

Do I need a separate consent checkbox for each purpose?

Yes. Consent is per purpose, so distinct uses need distinct, unticked opt-ins. One blanket agreement doesn’t meet the standard.

Does storing form responses count as a consent record?

Not by itself. You need a record of the notice shown and the specific consent given — the answers alone don’t prove what the person agreed to.

Can any form tool be made compliant?

Most can, if you add notice, purpose-split consent, minimisation, secure storage, and a consent record — and handle withdrawal and deletion. The tool is the channel; the duties are yours.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →