Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →
Resource / Checklist

Compliance Action Checklist

A step-by-step audit-readiness checklist for Data Fiduciaries. Work through the four phases below to move from unknown exposure to demonstrable DPDP compliance.

~36 weeks until full enforcement on 13 May 2027
🔍

1. Discover

Know what personal data you hold before you can govern it.

  • Inventory every system, app and vendor that touches personal data
  • Scan your public domains for the cookies and trackers actually loading
  • Classify data by category and identify any sensitive or children's data
  • Map cross-border transfers and the processors handling them
📜

2. Notice & Consent

Make every request 'free, specific, informed and unconditional'.

  • Publish a plain-language privacy notice for each processing purpose
  • Capture itemised, per-purpose consent with a timestamped audit trail
  • Offer withdrawal that is as easy as giving consent
  • Provide the notice in English and the Eighth Schedule languages
👤

3. Rights & Grievances

Give Data Principals a working way to exercise their rights.

  • Stand up a Data Subject Rights (DSR) portal for access, correction and erasure
  • Define and track SLAs for responding to each request type
  • Publish a grievance redressal mechanism with a named contact
  • Verify requester identity before actioning any request
🛡️

4. Protect & Retain

Secure the data and hold it no longer than you need to.

  • Apply technical and organisational security safeguards
  • Set retention rules per purpose and schedule automatic erasure
  • Prepare a 72-hour breach notification workflow for the Board and Principals
  • Appoint a Data Protection Officer if you qualify as a Significant Data Fiduciary

Turn the checklist into a live workflow

DPDP Guard operationalises every item above — discovery, consent, rights, retention and breach reporting — in one purpose-built platform.