DPDP Act Compliance Checklist
Every Data Fiduciary duty, the penalty for missing it, and a countdown to the deadline.
Checks
Preview
Highlighted hints mark fields you have not filled in; downloads and printouts show a blank line there instead. To print, choose your printer or “Save as PDF” and turn off “Headers and footers”.
For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.
About the DPDP Act Compliance Checklist
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 apply to every business that handles personal data in digital form in India — customers, employees, website visitors — and to businesses abroad that offer goods or services to people in India. Most of the duties start on 13 May 2027, eighteen months after the Rules were notified, and the maximum penalties run to ₹250 crore for weak security and ₹200 crore for not reporting a breach.
This checklist walks through each duty of a Data Fiduciary — notice and consent, legitimate uses, security safeguards, breach intimation (a detailed report to the Data Protection Board within 72 hours), retention and erasure, children’s data, grievances answered within 90 days, processors and transfers, and the extra duties of Significant Data Fiduciaries — with the section or rule behind it. Answer a few questions about your processing and only the duties that apply are shown. Mark each one in place, partly or not yet, add an owner and a target date for the gaps, and export a gap report that lists every gap with the maximum penalty in the Act’s Schedule. Nothing you enter leaves your browser.
How to use it
- Enter your organisation’s name and the review date, then answer About this review: do you rely on consent, use processors, process children’s data, transfer data abroad, or run a large platform?
- Work through each section and choose In place, Partly, Not yet or N/A for every item. For a gap, add who owns it, a target date and what is left to do.
- Use Show: Gaps to see only the open items, and read the Checks for the most serious gaps first — they are sorted by maximum penalty.
- Download the gap report as Word, PDF, Markdown or text, or print it, and take it to your management or your lawyer.
- Tick Keep a draft in this browser to come back to the assessment later on the same device.
Examples
Relies on consent · uses processors · data stored abroad · 30 items answered
7 of 30 in place (23%), 14 not yet, 9 partly. First in the report: access logs kept for only 30 days (r.6(1)(c), (e) — up to ₹250 crore) and no breach plan (r.7 — up to ₹200 crore).
Children’s data ticked
Adds verifiable parental consent (s.9(1), r.10), no detrimental processing (s.9(2)) and no tracking or targeted ads at children (s.9(3)) — each up to ₹200 crore — and a note on the Fourth Schedule exemptions for educational institutions.
E-commerce entity with 2 crore+ users · Significant Data Fiduciary
Adds three-year inactivity erasure with 48 hours’ warning (r.8, Third Schedule) and the DPO, independent auditor, yearly DPIA and audit, algorithm checks and data localisation duties (s.10, r.13 — up to ₹150 crore).
Common uses
- A startup or SME preparing for May 2027 and wanting a list of what to fix first.
- A compliance officer presenting the gaps and their maximum penalties to management.
- A company checking whether its processor contracts and breach plan meet rules 6 and 7.
- A consultant running a first readiness workshop with a client.
When the duties apply
The Act came into force in stages. The provisions on the Data Protection Board are already in force; the duties of Data Fiduciaries — notice (s.5), consent (s.6), legitimate uses (s.7), general obligations (s.8), children (s.9), Significant Data Fiduciaries (s.10), the rights of Data Principals (ss.11–14) and the penalties (s.33) — apply eighteen months after notification, together with Rules 3 and 5 to 16: on 13 May 2027. Consent Managers register with the Board under s.6(9) and r.4, which start a year after notification. When the duties apply, s.43A of the IT Act and the SPDI Rules 2011 fall away.
The maximum penalties (Schedule)
- Failing to take reasonable security safeguards to prevent a breach (s.8(5)): up to ₹250 crore.
- Failing to tell the Board or affected people about a breach (s.8(6)): up to ₹200 crore.
- Breaking the additional obligations for children (s.9): up to ₹200 crore.
- Breaking the additional obligations of a Significant Data Fiduciary (s.10): up to ₹150 crore.
- A Data Principal’s breach of their own duties (s.15): up to ₹10,000.
- Breaking any other provision of the Act or the Rules: up to ₹50 crore.
The Board imposes a penalty only after an inquiry finds a significant breach, and sets the amount by the nature, gravity and duration of the breach, the data affected, repetition, gain made or loss avoided, mitigation and proportionality (s.33(2)).
A breach: two intimations, one deadline
Rule 7 asks for two things as soon as you become aware of a personal data breach. Each affected person is told without delay, through their user account or registered contact: what happened, the likely consequences for them, what you are doing, what they can do, and whom to contact. The Board gets a description without delay and, within 72 hours, a detailed report — facts and reasons, mitigation, findings about who caused it, steps to prevent it happening again, and a report on the intimations sent. The Board can allow longer on a written request. Put the same duty in your processor contracts, or you will hear about their breaches too late.
Children, persons with disabilities and large platforms
A child is anyone under 18. Before processing a child’s data you need the verifiable consent of a parent who is an identifiable adult (r.10), and you may not track, behaviourally monitor or target advertising at children (s.9(3)) — unless the Fourth Schedule exempts your class (clinics, educational institutions, crèches, school transport) or purpose (for example real-time location for safety). For a person with a disability, verify that the guardian was appointed by a court or authority (r.11). E-commerce entities and social media intermediaries with 2 crore registered users in India, and online gaming intermediaries with 50 lakh, must erase data after three years of inactivity and warn 48 hours before (r.8, Third Schedule).
Sources
- Digital Personal Data Protection Act, 2023 — ss.2–17, 33 and the Schedule; commencement notification G.S.R. 843(E)
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — rr.1, 3, 6–15 and the Third and Fourth Schedules
Limitations
- A self-assessment, not an audit or legal advice. The report reflects only the answers given — have a lawyer review it.
- It covers the duties of a Data Fiduciary. Consent Managers, the processing by the State (r.5) and the research exemption (r.16) are not covered; sector rules (RBI, IRDAI, health, telecom) may add duties.
- Significant Data Fiduciary duties apply only once you are notified; which personal data must stay in India (r.13(4)) and any restricted countries (s.16) depend on notifications not yet issued.
- The Data Protection Board may publish guidance that changes how duties are read. Review the checklist when it does.
Privacy
Everything happens in your browser. Your answers are not uploaded or stored by MySmartCoPilot. If you tick Keep a draft in this browser, they are saved in this browser’s local storage until you untick it.
Frequently asked questions
When does the DPDP Act apply to my business?
Most duties of Data Fiduciaries — notice, consent, security, breach intimation, erasure, children, rights and grievances — and the penalties apply from 13 May 2027, eighteen months after the DPDP Rules were notified. Until then, the IT Act’s s.43A and the SPDI Rules 2011 apply. Changing systems, notices and contracts takes time, so start with the gaps that carry the highest penalties.
What is the maximum penalty under the DPDP Act?
Up to ₹250 crore for failing to take reasonable security safeguards, ₹200 crore each for not reporting a breach and for breaking the rules on children’s data, ₹150 crore for a Significant Data Fiduciary’s extra duties, and ₹50 crore for any other breach of the Act or the Rules (Schedule). The Board decides the amount in each case under s.33(2).
How fast must a data breach be reported?
Tell each affected person and the Board without delay once you become aware of it, and send the Board a detailed report within 72 hours (or a longer period it allows on a written request) — DPDP Rules r.7.
How long do we have to answer a grievance?
You publish your own period, which may not exceed 90 days (r.14(3)), and must meet it. People have to use your grievance process before they can complain to the Data Protection Board (s.13(3)).
Do we need consent for employee data?
Not always. Processing for employment, or to protect the employer from loss or liability (for example preventing corporate espionage or keeping trade secrets confidential), is a legitimate use under s.7(i). Record the purpose and keep the processing to what that purpose needs.
Are small businesses and startups exempt?
Not automatically. The Act lets the Central Government exempt classes of Data Fiduciaries, including startups, from some duties (s.17(3)), but only by notification. Until such a notification covers you, plan for all the duties shown here.