← Resources/ChecklistLegal & Compliance

India DPDP Act 2023 Compliance Checklist for SMBs

24 April 2026·6 min read

# India DPDP Act 2023 Compliance Checklist for SMBs

The Digital Personal Data Protection (DPDP) Act, 2023 is India's first comprehensive data protection law. It applies to any entity (a Data Fiduciary) that collects, stores, or processes the personal data of individuals (Data Principals) in India - regardless of where the fiduciary is located.

Non-compliance can attract penalties up to ₹250 crore per instance. This checklist helps SMBs build a defensible compliance posture systematically.


How to Use This Checklist

Work through each section in order. Mark items ✅ Done, 🔄 In Progress, or ❌ Not Started. Revisit quarterly or whenever you launch a new product feature that touches personal data.


Section 1 - Scoping & Classification

TaskOwnerStatus
Identify all personal data your business collects (name, email, phone, device ID, location, etc.)Legal / IT
Map every data flow: collection → storage → processing → deletionIT / Operations
Determine if you qualify as a **Significant Data Fiduciary** (large-scale processing, sensitive data, children's data)Legal
List all third-party **Data Processors** (cloud vendors, analytics tools, payment gateways)Procurement
Significant Data Fiduciaries face additional obligations: appointing a Data Protection Officer (DPO), conducting Data Protection Impact Assessments (DPIAs), and periodic audits.

The DPDP Act requires a clear, specific, and informed consent before processing personal data, except for certain legitimate uses.

Consent Checklist

  • Consent requests are written in plain language (not legalese)
  • Each purpose of processing is stated separately - bundled consent is not valid
  • Consent is obtained before data collection begins
  • Users can withdraw consent as easily as they gave it
  • Withdrawal of consent triggers a data deletion workflow within a reasonable timeframe
  • Consent records (who consented, when, to what) are stored and auditable
  • Consent is re-obtained whenever the purpose changes

Legitimate Use Exceptions

Consent is not required for:

  • •Compliance with a court order or law
  • •Medical emergencies
  • •Employment-related processing (within limits)
  • •State functions for subsidies/benefits

Document the specific exemption relied upon for each non-consent processing activity.


Section 3 - Notice Requirements

Every Data Principal must receive a Notice at or before the point of data collection.

  • Notice is available in English and at least one scheduled Indian language (if users request it)
  • Notice clearly states: what data is collected, why, how long it will be retained, and with whom it will be shared
  • Notice includes contact details of the Data Fiduciary and the Grievance Officer
  • Notice is version-controlled - old versions are archived for audit purposes
  • Existing users (pre-Act) have been sent a retroactive notice

Section 4 - Data Principal Rights

You must have operational processes to honour these rights within the timeframes set by the Act (rules pending; plan for 30 days as a safe default).

RightRequired ActionProcess Owner
Right to accessProvide a summary of personal data held and processing activitiesIT / Legal
Right to correctionUpdate inaccurate or incomplete data on requestIT
Right to erasureDelete data when consent is withdrawn or purpose is fulfilledIT
Right to grievance redressalAcknowledge within 48 hours; resolve within 30 daysCustomer Support
Right to nominateAllow users to nominate someone to exercise rights on their behalfLegal / Product
  • A self-service portal or email channel exists for Data Principals to submit requests
  • Requests are logged with timestamps
  • [Escalation](/blog/customer-support-escalation-management-system) path to the Data Protection Board is documented for unresolved complaints

Section 5 - Data Fiduciary Obligations

Accuracy & Minimisation

  • Only data necessary for the stated purpose is collected (data minimisation)
  • Data is kept accurate and up to date
  • Retention periods are defined per data category and enforced automatically where possible

Security Safeguards

  • Personal data is encrypted at rest and in transit
  • Access controls follow the principle of least privilege
  • Regular vulnerability assessments are conducted
  • Employee training on data handling is completed annually

Children's Data

  • Age verification mechanism is in place before collecting data from users under 18
  • Verifiable parental consent is obtained for minors
  • No behavioural tracking or targeted advertising directed at children

Section 6 - Data Processor Agreements

  • All Data Processors have signed a Data Processing Agreement (DPA) that mirrors your DPDP obligations
  • DPAs specify: purpose limitation, security standards, sub-processor restrictions, breach notification timelines
  • Processor compliance is reviewed annually or on [contract renewal](/blog/contract-renewal-tracking-system-design)
  • Cross-border data transfers are only to countries on the approved list (to be notified by the Central Government)

Section 7 - Data Breach Response

The DPDP Act requires notification to the Data Protection Board and affected Data Principals in the event of a breach.

Breach Response Workflow

  1. 1Detect - Security monitoring alerts trigger an incident ticket
  2. 2Contain - Isolate affected systems within 1 hour of detection
  3. 3Assess - Determine scope: what data, how many individuals, what risk
  4. 4Notify Board - Report to the Data Protection Board as soon as possible (draft rules expected to specify a 72-hour window)
  5. 5Notify Principals - Inform affected individuals with details of the breach and remediation steps
  6. 6Document - Record the incident, root cause, and corrective actions taken
  7. 7Review - Post-incident review within 14 days; update controls
  • Incident response plan is documented and tested (tabletop exercise at least annually)
  • Breach notification templates are pre-drafted and approved by Legal
  • Contact details for the Data Protection Board are on file

Section 8 - Significant Data Fiduciary (SDF) Add-ons

*Complete this section only if classified as an SDF.*

  • Data Protection Officer (DPO) appointed; contact details published
  • Data Protection Impact Assessment (DPIA) conducted for high-risk processing activities
  • Annual independent audit of data processing practices scheduled
  • Algorithmic accountability measures documented (if using automated decision-making)

Section 9 - Governance & Documentation

DocumentFrequencyOwner
Privacy Policy (public-facing)Review annually or on material changeLegal
Internal Data Processing RegisterContinuous updateIT / Legal
Consent recordsRetained for duration of relationship + 3 yearsIT
Breach logRetained for 5 yearsSecurity
DPA with processorsRenewed on contract renewalProcurement
Employee training recordsAnnualHR

Quick-Reference Penalty Table

ViolationMaximum Penalty
Failure to implement security safeguards₹250 crore
Failure to notify breach₹200 crore
Non-compliance with children's data provisions₹200 crore
Breach of additional SDF obligations₹150 crore
Breach of any other provision₹50 crore

Next Steps

  1. 1Assign owners to every unchecked item above
  2. 2Set a 90-day remediation deadline for critical gaps (Sections 2, 5, 7)
  3. 3Schedule a quarterly review - the DPDP Rules are still being finalised; stay current
  4. 4Consider engaging a legal counsel specialising in Indian data protection for a formal gap assessment

*This checklist is for informational purposes and does not constitute legal advice. Consult a qualified attorney for advice specific to your business.*

DPDP Actdata privacycomplianceIndia