DPDP Act, 2023: A Practical Compliance Checklist for Indian Businesses
The Digital Personal Data Protection Act, 2023 doesn't come with a single compliance certificate you can put on a slide. It's a set of obligations that show up in your privacy policy, your consent flows, your incident-response plan, and your vendor contracts — and most businesses we talk to have gaps in more than one of those places without realizing it. This isn't legal advice, but it is the same checklist our team runs through when we scope a DPDP readiness review.
1. Your privacy policy states a specific purpose, not a broad one
"We may use your data to improve our services" is the kind of language that gets flagged. The Act expects a specific, itemised purpose for each category of data you collect — name and email for account creation, payment details for billing, and so on. If your policy reads like a legal team wrote it to cover everything, it probably doesn't cover anything specifically enough.
2. Consent is opt-in, itemised, and as easy to withdraw as it was to give
Pre-ticked checkboxes and bundled consent ("I agree to the terms, privacy policy, and marketing emails") don't meet the bar. Each purpose needs its own, freely given consent — and a data principal needs a withdrawal path that's roughly as easy to use as the consent flow was.
3. You can name your Grievance Officer and DPO — and they respond within SLA
Every consumer-facing entity needs a published Grievance Officer contact, and Significant Data Fiduciaries need a Data Protection Officer based in India. It's not enough to name someone; the process behind that contact needs to actually work — acknowledge within 24 hours, resolve within a reasonable window, and keep a log of what came in.
4. You have a documented data retention period, and you actually delete data
"We keep data as long as necessary" isn't a retention policy — it's a placeholder for one. Pick a concrete period per data category, tied to why you're holding it, and have a real process (not a TODO) for deleting or anonymising data once that period lapses.
5. Trackers fire after consent, not before
This is the single most common finding in our automated DPDP scans: analytics, ad pixels, and session-recording scripts loading on page load, before the user has made any consent choice. If your cookie banner is decorative rather than gating, this is worth fixing first — it's usually a one-line change in how your tag manager is configured.
6. You have a breach notification plan that names the Data Protection Board
The Act requires notifying the Data Protection Board of India and affected individuals without undue delay after a personal data breach. "Without undue delay" is doing a lot of work in that sentence — you want a plan written down before an incident, not improvised during one.
7. Data principal rights (access, correction, erasure) have an actual workflow
Someone can email you asking "what data do you have on me, and please delete it." Do you know who picks that up, how they verify identity, and how long it takes to action? If the honest answer is "we'd figure it out," that's a gap worth closing before it's tested by a real request.
8. Cross-border data transfer isn't silently happening through a vendor
If your analytics, email, or AI vendor processes data outside India, that's a cross-border transfer under the Act. It's usually fine — but it should be a conscious decision reflected in your privacy policy and vendor contracts, not something you discover during an audit.
9. Children's data has verified parental consent, or you don't collect it
If there's any chance your product is used by under-18s, this needs an explicit answer, not an assumption. Age-gating without verification is a common half-measure that doesn't hold up.
10. Security safeguards match what you're claiming in writing
The Act expects "reasonable security safeguards" — encrypted transport, access controls, and a genuine incident-response capability. This is where DPDP compliance and a VAPT engagement overlap: a privacy policy that promises safeguards you haven't actually tested is a liability, not a shield.
Our free DPDP scanner checks most of the above automatically — tracker-before-consent, missing disclosures, and policy gaps — in a couple of minutes, no signup required for the basic report.
Run a free DPDP scan →