Data Privacy & User Rights

Data Privacy Compliance Checklist for Indian Businesses

Actionable DPDP Act checklist for Indian businesses: notices, consent, rights, security, breach response, vendors, and a 90-day plan while detailed Rules are still forthcoming.

Working summary: Indian businesses that process digital personal data need a concrete DPDP Act and forthcoming Rules work list, not a slogan. Use this checklist to close gaps before once Rules and commencement are notified, when core obligations and data principal rights are scheduled to commence.

  • Scope and map: Confirm Section 3 coverage, inventory systems, and tag each purpose as consent or Section 7.
  • Notice and consent: Rule 3 standalone notices, purpose-specific affirmative consent, and easy withdrawal under Section 6.
  • Rights: Publish access, correction, erasure, grievance, and nomination paths with Rule 14 identifiers and a 90-day grievance cap.
  • Security and breach: Rule 6 safeguards (encryption, access control, logs) and Rule 7 Board and Principal notice runbooks.
  • 90-day plan: Data map, UI and vendor fixes, then tabletop exercises before Rules commence.

Indian businesses that process digital personal data need a concrete work list, not a slogan. The Digital Personal Data Protection Act, 2023 and the forthcoming DPDP Rules from MeitY set the requirements. MeitY had not yet notified commencement or detailed Rules as of this writing stages when those duties become operative.

use this checklist to close gaps before once Rules and commencement are notified, when Sections 3 to 5, most of Section 6, Sections 7 to 10, and Sections 11 to 17 are scheduled to commence. Consent Manager registration under Section 6(9) is on the earlier one-year track (a future Consent Manager registration date once notified).

For deeper rights design, see DPDP Act User Rights: A Practical Guide for Indian Websites. For access, correction, and erasure tooling patterns, see How to Handle DSARs with OneTrust.

How to use this checklist

  • Mark each item Done, In progress, or Not applicable (with a reason).
  • Store evidence: screenshots, policy versions, contracts, ticket IDs, and training records.
  • Assign an owner and a target date on every open item.
  • Re-run the list after major product launches or vendor changes.

1. Confirm you are in scope

  1. Confirm you process digital personal data in India, or process digital personal data outside India in connection with offering goods or services to Data Principals in India (Section 3).
  2. Exclude purely personal or domestic processing and publicly available personal data that falls under Section 3(c) carve-outs, with legal review.
  3. List brands, apps, websites, and offline-to-digital flows that digitise personal data.
  4. Note whether any Central Government Significant Data Fiduciary (SDF) criteria could apply later (Section 10 factors include volume, sensitivity, risk to rights, and related grounds).

2. Map personal data and purposes

  1. Inventory systems that hold personal data: CRM, billing, support, analytics, email, ads, HR, and backups.
  2. For each processing activity, record purpose, data categories, source, retention trigger, and processors.
  3. Tag each purpose as consent-based (Section 6) or a Section 7 certain legitimate use, or flag as unclear for counsel.
  4. Identify children’s data (under 18 under Section 2(f)) and high-risk processing for extra controls.

3. Notices (Section 5 and Rule 3)

  1. Draft standalone notices that work without relying on other site copy (Rule 3(a)).
  2. Itemise personal data and state specified purposes plus the goods, services, or uses enabled (Rule 3(b)).
  3. Add links or other means to withdraw consent, exercise rights, and complain to the Board (Rule 3(c); Section 5).
  4. Offer notice content in English or an Eighth Schedule language where Section 5(3) applies.
  5. Plan legacy-consent refresh notices under Section 5(2) for pre-commencement consent.
  6. Publish the business contact of a Data Protection Officer (if SDF) or another person who can answer processing questions (Section 8(9)).
  1. Use free, specific, informed, unconditional, unambiguous consent with a clear affirmative action (Section 6(1)).
  2. Limit consent to data necessary for the specified purpose; drop bundled unnecessary asks (see Section 6(1) illustration pattern).
  3. Reject consent language that waives Board complaint rights or otherwise breaks the Act (Section 6(2)).
  4. Present consent requests in clear language with contact details for rights questions (Section 6(3)).
  5. Make withdrawal as easy as giving consent (Section 6(4)).
  6. On withdrawal, cease processing and cause processors to cease within a reasonable time unless other law still authorises processing (Section 6(6)).
  7. Store proof that notice was given and consent obtained (Section 6(10) burden).
  8. If you will operate as a Consent Manager, track Section 6(9) registration timing (one year from forthcoming MeitY commencement notifications publication).

5. Section 7 legitimate uses (only where they fit)

  1. Document each non-consent purpose against a specific Section 7 clause (voluntary provision, State benefits, employment-related uses, emergency, and other listed uses).
  2. Stop processing when the person indicates they do not consent to a Section 7(a) voluntary-use scenario, per the Act’s illustrations.
  3. Do not treat open-ended marketing as a Section 7 use without a clear statutory fit and legal sign-off.

6. Data Principal rights and grievances

  1. Publish how to submit access, correction, erasure, grievance, and nomination requests, plus required identifiers (Rule 14(1); Sections 11 to 14).
  2. Build an access pack that can deliver a processing summary and sharing list where Section 11 applies.
  3. Enable correction, completion, and updating under Section 12(2).
  4. Enable erasure under Section 12(3), with documented retention exceptions for specified purpose or law.
  5. Publish a grievance response period not exceeding ninety days and staff to meet it (Rule 14(3); Section 13).
  6. Add nomination capture for Section 14 when product and legal agree the proof rules (Rule 14(4)).
  7. Log identity checks, systems searched, outcomes, and refusals.

7. General fiduciary obligations (Section 8)

  1. Accept accountability for processing you do and processing done by processors on your behalf (Section 8(1)).
  2. Engage processors only under a valid contract (Section 8(2)).
  3. Keep personal data complete, accurate, and consistent when it may drive decisions about the person or be disclosed to another fiduciary (Section 8(3)).
  4. Implement technical and organisational measures for effective observance of the Act and Rules (Section 8(4)).
  5. Take reasonable security safeguards to prevent personal data breach (Section 8(5); forthcoming Rules Rule 6).
  6. Prepare Board and affected-principal breach intimations (Section 8(6); Rule 7).
  7. Erase when consent is withdrawn or the specified purpose is no longer served, unless law requires retention, and cause processors to erase (Section 8(7)).
  8. Establish an effective grievance mechanism (Section 8(10)).

8. Reasonable security safeguards (Rule 6)

Rule 6 sets minimum safeguards. Check each item:

  1. Encryption, obfuscation, masking, or virtual tokens mapped to personal data.
  2. Access control on computer resources used by you or processors.
  3. Logs, monitoring, and review to detect, investigate, and remediate unauthorised access.
  4. Backups and continuity measures if confidentiality, integrity, or availability is compromised.
  5. Retain relevant logs and personal data needed for detection and continuity for one year, unless another law requires otherwise.
  6. Processor contracts that require reasonable security safeguards.
  7. Technical and organisational measures so the safeguards are actually observed.

9. Breach response (Section 8(6) and Rule 7)

  1. Write a breach runbook with severity triage and on-call owners.
  2. Prepare Data Principal notice fields: nature, extent, timing; likely consequences; mitigation; safety tips; contact person (Rule 7(1)).
  3. Notify the Board without delay with nature, extent, timing, location, and likely impact (Rule 7(2)(a)).
  4. Send the detailed Board update within seventy-two hours of awareness, or longer if the Board allows in writing (Rule 7(2)(b)).
  5. Keep a report of principal intimations for the Board package.
  6. Tabletop the runbook at least once before Rules commence.

10. Children and persons with disability (Section 9)

  1. Obtain verifiable consent of the parent or lawful guardian before processing a child’s personal data, in the manner prescribed (Section 9(1)).
  2. Avoid processing likely to cause detrimental effect on a child’s well-being (Section 9(2)).
  3. Do not track or behaviourally monitor children or run targeted advertising directed at children, subject to Section 9 exemptions that may be prescribed or notified (Section 9(3) to (5)).
  4. Age-gate or otherwise identify under-18 users where your service may attract children.

11. Processors and vendors

  1. List every vendor that processes personal data for you.
  2. Put Section 8(2) contracts in place with security, assistance on rights, breach notice, and erasure or return clauses.
  3. Flow Rule 6 security expectations into those contracts.
  4. Test whether you can pull data for access packs and delete data on erasure within your SLA.

12. Retention and erasure operations

  1. Define retention periods by purpose and legal hold.
  2. Automate or schedule erasure when purpose ends or consent is withdrawn (Section 8(7)).
  3. Document why you keep tax, KYC, dispute, or fraud records when a erasure request arrives (Section 12(3)).
  4. Include backups and analytics stores in erasure runbooks, not only the primary CRM row.

13. Cross-border transfers (Section 16)

  1. Inventory countries and vendors that receive personal data from India processing.
  2. Watch for Central Government notifications restricting transfer to specific countries or territories (Section 16(1)).
  3. Keep higher protections from other Indian laws that may still apply (Section 16(2)).

14. Significant Data Fiduciary readiness (Section 10)

  1. If designated SDF, appoint a Data Protection Officer based in India with the duties in Section 10(2)(a).
  2. Appoint an independent data auditor (Section 10(2)(b)).
  3. Plan periodic Data Protection Impact Assessment and audit (Section 10(2)(c)).
  4. Even if not designated, keep volume and risk metrics so you can respond quickly if notified.

15. Penalties awareness (Schedule to the Act)

Section 33 and the Schedule set monetary penalties that may extend, among other amounts, to:

  • up to INR 250 crore for failure to take reasonable security safeguards (Section 8(5));
  • up to INR 200 crore for failure to notify a personal data breach as required (Section 8(6));
  • up to INR 200 crore for children’s obligation breaches (Section 9);
  • up to INR 150 crore for SDF obligation breaches (Section 10);
  • up to INR 50 crore for other Act or Rules breaches.

Use the figures as urgency signals for security, breach, and children’s controls. Exact exposure depends on Board findings and Section 33(2) factors.

90-day action plan (example)

  1. Days 1 to 30: finish data map, gap list, and owner assignments.
  2. Days 31 to 60: ship notice and consent UI changes; sign priority processor addenda; draft rights and grievance pages.
  3. Days 61 to 90: implement Rule 6 security gaps; run breach and rights tabletop exercises; lock retention jobs.

Then keep a monthly review until once Rules and commencement are notified and after go-live.

Sources

  • Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Sections 3 to 10, 11 to 16, 33 and the Schedule: MeitY PDF; India Code.
  • MeitY commencement notification forthcoming MeitY commencement notifications, a future MeitY notification date.
  • forthcoming DPDP Rules from MeitY, Rules 3, 6, 7, and 14; MeitY publication: DPDP forthcoming Rules.
  • MeitY Explanatory Note on forthcoming DPDP Rules (security safeguards and breach intimation summary): PDF.

Disclaimer

This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, privacy policies, or other privacy and data-protection controls. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.

Last updated on 14 September 2026

Share this article

Leave a Reply

Your email address will not be published. Required fields are marked *