Resource / Checklist
Compliance Action Checklist
A step-by-step audit-readiness checklist for Data Fiduciaries. Work through the four phases below to move from unknown exposure to demonstrable DPDP compliance.
⏳~36 weeks until full enforcement on 13 May 2027
🔍
1. Discover
Know what personal data you hold before you can govern it.
- ✓Inventory every system, app and vendor that touches personal data
- ✓Scan your public domains for the cookies and trackers actually loading
- ✓Classify data by category and identify any sensitive or children's data
- ✓Map cross-border transfers and the processors handling them
📜
2. Notice & Consent
Make every request 'free, specific, informed and unconditional'.
- ✓Publish a plain-language privacy notice for each processing purpose
- ✓Capture itemised, per-purpose consent with a timestamped audit trail
- ✓Offer withdrawal that is as easy as giving consent
- ✓Provide the notice in English and the Eighth Schedule languages
👤
3. Rights & Grievances
Give Data Principals a working way to exercise their rights.
- ✓Stand up a Data Subject Rights (DSR) portal for access, correction and erasure
- ✓Define and track SLAs for responding to each request type
- ✓Publish a grievance redressal mechanism with a named contact
- ✓Verify requester identity before actioning any request
🛡️
4. Protect & Retain
Secure the data and hold it no longer than you need to.
- ✓Apply technical and organisational security safeguards
- ✓Set retention rules per purpose and schedule automatic erasure
- ✓Prepare a 72-hour breach notification workflow for the Board and Principals
- ✓Appoint a Data Protection Officer if you qualify as a Significant Data Fiduciary
Turn the checklist into a live workflow
DPDP Guard operationalises every item above — discovery, consent, rights, retention and breach reporting — in one purpose-built platform.