Close

DPDP Compliance in India: Complete Checklist for Businesses under the Digital Personal Data Protection Act

  • Home
  •  / 
  • Legal Blogs
  •  / 
  • DPDP Compliance in India: Complete Checklist for Businesses under the Digital Personal Data Protection Act

Understand DPDP compliance in India, consent notices, privacy policy, data breach reporting, children’s data, Data Fiduciary obligations and practical steps for businesses.

DPDP Compliance in India: What Every Business Must Do and How to Do It

The Digital Personal Data Protection Act, 2023, commonly known as the DPDP Act, is India’s principal law for protection of digital personal data. It applies to processing of digital personal data within India where data is collected digitally or later digitised, and may also apply to processing outside India if it relates to offering goods or services to individuals in India. The Act does not generally apply to personal or domestic use by individuals, or to personal data made publicly available by the individual concerned or under law.

With the notification of the Digital Personal Data Protection Rules, 2025, the DPDP framework has become a practical compliance requirement for businesses, startups, hospitals, schools, e-commerce platforms, telecom companies, apps, SaaS providers, HR consultants, law firms, financial entities and any organisation collecting personal information of customers, employees, vendors or users. The Government has stated that the Rules provide an 18-month phased compliance timeline and require clear consent notices, breach protocols, grievance mechanisms and stronger accountability.

What is DPDP compliance?

DPDP compliance means ensuring that your organisation collects, stores, uses, shares and deletes personal data in the manner permitted under the DPDP Act and Rules. “Personal data” means any data about an individual who is identifiable by or in relation to such data. This may include name, phone number, email, Aadhaar details, PAN, address, photographs, IP address, employee records, customer records, KYC documents, payment information, health information, location data and login credentials.

Under the DPDP Act, an organisation that decides the purpose and means of processing personal data is called a Data Fiduciary. The individual whose data is processed is called a Data Principal. A vendor or service provider processing data on behalf of the business is generally a Data Processor.

Step 1: Prepare a data inventory

The first practical step is to identify what personal data your organisation collects. Most businesses collect data through website forms, WhatsApp enquiries, CRM tools, billing software, employment forms, CCTV, mobile apps, cookies, payment gateways and vendor onboarding forms. A DPDP audit should record:

What data is collected, from whom it is collected, why it is collected, where it is stored, who has access to it, whether it is shared with third parties, and how long it is retained.

This data mapping exercise is the foundation of all further compliance.

Step 2: Identify the legal basis for processing

A business may process personal data only for a lawful purpose, either with the consent of the Data Principal or for certain legitimate uses recognised under the Act. The Act defines lawful purpose as any purpose not expressly forbidden by law.

For example, if a customer fills a contact form to receive a quotation, the business may use that information to respond to the enquiry. However, using the same information for unrelated marketing, profiling or sharing with third parties may require separate consent.

Step 3: Create a clear consent notice

One of the most searched DPDP compliance requirements is the DPDP consent notice. The notice must be clear, plain and specific. It should inform the individual about the personal data being collected, the purpose of processing, how rights can be exercised, and how a complaint can be made. The Act also requires the notice to be available in English or any language specified in the Eighth Schedule of the Constitution.

A proper consent notice should not be hidden inside a long privacy policy. It should be presented at the point of collection, such as before submitting a website form, signing up for an app, onboarding as an employee, or sharing KYC documents.

Step 4: Take valid consent

Consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, with clear affirmative action. Consent should also be limited to personal data necessary for the specified purpose. The Act also gives individuals the right to withdraw consent, and withdrawal must be as easy as giving consent.

Businesses should therefore avoid pre-ticked boxes, bundled consent, vague language such as “we may use your data for business purposes”, or forcing unnecessary data collection. Separate consent should be taken for separate purposes, such as service delivery, marketing, newsletters, analytics and third-party sharing.

Step 5: Update privacy policy and internal policies

A DPDP-compliant privacy policy should clearly explain the categories of data collected, purposes of processing, data sharing practices, retention period, grievance contact, rights of individuals, withdrawal of consent, breach communication and security practices.

However, website privacy policy alone is not enough. Businesses should also prepare internal documents such as a data retention policy, access control policy, employee data policy, vendor data processing agreement, breach response SOP, consent logs and grievance redressal process.

Step 6: Secure personal data

Every Data Fiduciary must take reasonable security safeguards to prevent personal data breach. The Act also makes the Data Fiduciary responsible for processing undertaken by it or on its behalf by a Data Processor. Data Processors must be engaged only under a valid contract.

Practically, this means using access controls, encryption where required, password policies, two-factor authentication, secure cloud storage, limited employee access, audit trails, backup systems, confidentiality obligations and proper vendor contracts. Cybersecurity and legal compliance must work together.

Step 7: Prepare for data breach reporting

A personal data breach can include unauthorised access, leakage, loss, alteration, disclosure or compromise of personal data. In case of a breach, the Data Fiduciary must intimate the Data Protection Board and each affected Data Principal in the prescribed manner.

The 2025 Rules further require affected individuals to be informed in plain language about the nature and possible consequences of the breach, steps taken to address it and contact details for assistance.

Every organisation should have a breach response plan identifying who will investigate, who will notify, what records will be preserved, and how customers will be informed.

Step 8: Honour rights of individuals

Individuals have rights to access information about their personal data, seek correction, completion, updating and erasure, raise grievances and nominate another person to exercise rights on their behalf.

The Rules state that Data Fiduciaries must respond to such requests within a maximum of 90 days.

A business should therefore create a simple mechanism through email, website form or dashboard where individuals can submit DPDP requests.

Step 9: Manage children’s data carefully

If a business processes data of children, it must obtain verifiable parental consent. The Act also prohibits processing likely to cause detrimental effect on the well-being of a child, and prohibits tracking, behavioural monitoring and targeted advertising directed at children.

Schools, ed-tech platforms, gaming apps, healthcare platforms and social platforms must be particularly cautious.

Step 10: Check if you may become a Significant Data Fiduciary

The Central Government may notify certain Data Fiduciaries as Significant Data Fiduciaries based on factors such as volume and sensitivity of personal data, risk to individuals, public order, security of the State and other considerations. Such entities may have additional obligations, including appointment of a Data Protection Officer based in India, independent data audit and periodic Data Protection Impact Assessment.

Why DPDP compliance matters

Non-compliance can invite significant penalties. The Schedule to the DPDP Act provides penalties that may extend up to ₹250 crore for failure to take reasonable security safeguards, up to ₹200 crore for failure to notify breach, and up to ₹200 crore for breach of obligations relating to children’s data.

DPDP compliance is not merely a legal formality. It builds customer trust, improves data governance, reduces cyber risk and protects businesses from regulatory action. Every organisation handling personal data should begin with a DPDP audit, prepare consent notices and privacy documentation, review vendor contracts, create breach response procedures and train employees.

For businesses seeking DPDP compliance services in India, a structured legal and technical review is the safest starting point.