DPDP compliance checklist: 12 steps to get ready

Updated 19 Sep 2026 · 5min read · Reviewed by ConsentLo's DPDP audit team

Use this checklist to plan your DPDP Act programme. Each step is something the Data Protection Board could ask you to show evidence for.

The checklist

Work through these in order. Most organisations need three to six months.

  • Map your personal data: what you collect, from whom, why, where it is stored and who receives it.
  • Assign a legal basis to every processing activity: consent or a specific legitimate use.
  • Rewrite your notices: itemised data and purposes, in plain language, in English and the languages your users speak.
  • Capture consent purpose by purpose, with no pre-ticked boxes, and keep a tamper-evident record.
  • Make withdrawal one step, and make sure it reaches your processors.
  • Set up rights handling: access, correction, completion, update, erasure and nomination, on a clock.
  • Publish a contact for data questions and run a grievance process with defined response times.
  • Sign data processing contracts with every processor and review their safeguards.
  • Prepare your breach response: who decides, how the Board is told within 72 hours, how people are informed.
  • Handle children's data: age signals, verifiable parental consent, and no tracking or targeted ads.
  • Set retention periods and automate erasure, with 48-hour notice where the Rules require it.
  • Keep evidence of every step, so you can demonstrate compliance on request.

Doing it with software

Spreadsheets break down once requests, consents and deadlines pile up. ConsentLo runs each item on this list as a workflow with its statutory clock, and records every action in an evidence vault you can export for an audit.

Frequently asked questions

How long does DPDP compliance take?

Most organisations need three to six months for a first compliant setup, longer for large or complex data estates. Data mapping and notices usually take the most time.

Do I need a Data Protection Officer under DPDP?

Only Significant Data Fiduciaries must appoint a Data Protection Officer based in India. Every Data Fiduciary must still publish the contact of a person who can answer questions about data processing.

What evidence should I keep for DPDP compliance?

Notice versions, consent records, rights and grievance handling, processor contracts and instructions, breach reports and retention actions, each with dates and responsible people.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.