TruPath Compliance
§ B.01 · Data Protection
Published12 JUN 2026Last rev.12 JUN 2026Length9 min readAll resources

DPDP Readiness: A Practical Checklist for Indian Businesses

TruPath Compliance · 12 JUN 2026 · 9 min read

The Digital Personal Data Protection Act, 2023 ("the DPDP Act") Citation 01: Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) is now the governing data-protection law in India, and it changes what "handling customer data responsibly" actually requires. For most businesses the gap is not unwillingness — it is that nobody has translated the Act into a concrete list of things to do, owners to assign, and evidence to keep.

This is that list. It is the working checklist we use at the start of a DPDP engagement to move a company from unaware to defensible. It is written for the person who has been handed "sort out DPDP" with no further instruction — a founder, a CFO, an HR head, a general counsel. It is general information, not legal advice; treat it as a map, not a substitute for review of your specific circumstances.

Before you start: know which hat you wear

The Act distinguishes between a Data Fiduciary — the entity that decides why and how personal data is processed — and a Data Processor, which processes data on a Fiduciary's behalf and instruction. Most businesses are Fiduciaries for their own employee and customer data, and Processors when they handle another company's data under contract. You can be both, in different relationships. Your obligations differ depending on which role applies, so map this first.

1. Know what data you hold

You cannot protect or account for data you have not mapped. This is the foundation, and it is where most readiness efforts are won or lost.

  • Inventory every system, tool, and spreadsheet that holds personal data — HR, payroll, CRM, support, marketing, finance, vendor records.
  • For each, record what categories of personal data are held, whose data it is (employees, customers, prospects, vendors), and why you hold it.
  • Identify the source of each dataset and the lawful basis on which you hold it — consent, or one of the legitimate uses permitted by the Act.
  • Flag any data you hold without a current, identifiable purpose. That data is a liability, not an asset.

2. Fix your notice and consent

Under the Act, consent must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action — and it must be requestable in plain language, with the option to access the request in English or any language in the Eighth Schedule to the Constitution.

  • Review every point where you collect personal data — web forms, app sign-ups, paper forms, point of sale.
  • Ensure each is preceded or accompanied by a notice stating what data is collected, for what purpose, and how the individual can exercise their rights.
  • Remove pre-ticked boxes and bundled consent. Consent for one purpose cannot be conditioned on consent for an unrelated one.
  • Build a mechanism to withdraw consent as easily as it was given, and to act on withdrawal.
  • Where you already hold data collected before your notice was compliant, plan how you will issue a fresh, compliant notice to those existing Data Principals.

3. Stand up the Data Principal rights workflow

The Act gives individuals enforceable rights. You need an operational process to honour them within the required timelines — not an ad-hoc scramble each time a request arrives.

  • A single intake channel for rights requests (access, correction, completion, erasure).
  • A defined internal process: who receives the request, who verifies identity, who locates the data, who acts, who responds.
  • The ability to erase personal data when its purpose is served and no law requires its retention.
  • A process for the right to nominate — allowing an individual to nominate another person to exercise their rights in the event of death or incapacity.

4. Appoint the right accountable people

  • Appoint a Grievance Officer and publish their contact details. Every Data Fiduciary needs a readily available means for Data Principals to raise grievances.
  • Determine whether you are likely to be classified as a Significant Data Fiduciary. If so, additional obligations apply, including appointing a Data Protection Officer based in India and conducting periodic Data Protection Impact Assessments and audits.
  • Assign internal ownership for the data inventory, the rights workflow, and breach response. Accountability that belongs to everyone belongs to no one.

5. Bring your vendors and contracts into line

You remain accountable for personal data even when a processor handles it for you. Your contracts must reflect that.

  • Identify every third party that processes personal data on your behalf — cloud providers, payroll processors, marketing tools, analytics, support platforms.
  • Ensure each engagement is governed by a written contract that binds the processor to process data only on your instructions and to maintain appropriate safeguards.
  • Where you act as a processor for your own clients, ensure your contracts reflect that role and its limits.

6. Prepare for a breach before you have one

The Act requires notification of a personal data breach to the Data Protection Board of India and to affected Data Principals. The time to design that process is now, not during the incident.

  • A documented breach response plan: detection, containment, assessment, notification, and remediation.
  • Clear internal escalation — who declares a breach, who notifies, on what timeline.
  • A log of incidents and the response taken, retained as evidence of diligence.

7. Protect children's data and special cases

  • If you process the data of children (individuals under eighteen), you must obtain verifiable consent of a parent or lawful guardian, and you must not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
  • If your service is not intended for children, state so, and design your collection to avoid inadvertently gathering their data.

8. Keep the evidence

DPDP readiness is not a one-time project; it is a posture you must be able to demonstrate. Across all of the above, the recurring discipline is the same: keep the record.

  • Retain your data inventory, notices, consent records, rights-request logs, vendor contracts, and breach logs.
  • Date them, version them, and assign owners.
  • When a regulator, an auditor, or an acquirer asks how you handle personal data, the answer should be a file you can hand over — not a meeting you have to schedule.

Where this leaves you

Work through these eight areas and you move from a vague sense of exposure to a concrete, defensible position — one you can show a board, a buyer, or the Data Protection Board. Most businesses find that the first pass surfaces more than they expected, particularly in data mapping and vendor contracts, which is exactly why doing it on a calm day beats doing it under a notice.

If you would rather not run this alone, our DPDP Readiness & Implementation service takes a company through every step of this checklist end-to-end, and our readiness review is the usual first conversation.


This article is general information about the Digital Personal Data Protection Act, 2023 and does not constitute legal advice or create any professional relationship. Regulation and its interpretation change; obtain advice tailored to your circumstances before acting. See our Terms of Use.

FREE DOWNLOAD

The DPDP Readiness Checklist

A 40-point working checklist, formatted for circulation to your board and team.

Download the PDF