Compliance · Jul 01, 2026 · 12 min read

    DPDP Act Compliance Checklist 2026: What Every Indian Business Must Do

    India's DPDP Act is now enforceable. A practical, step-by-step compliance checklist for Data Fiduciaries: consent, breach notification, and penalties up to ₹250 crore...

    Nithien Aachinthya · Founder & CEO

    The Digital Personal Data Protection (DPDP) Act, 2023, with its implementing Rules notified in late 2025, is now the operative privacy law for every business processing personal data of individuals in India. Penalties reach ₹250 crore per violation. This checklist breaks compliance into concrete steps: what to do first, what the law actually requires, and where most organizations fail.

    01Who the DPDP Act Applies To

    The Act covers processing of digital personal data within India, and processing outside India if it relates to offering goods or services to individuals in India. If you run a SaaS product, an e-commerce store, a hospital chain, or a fintech app with Indian users, you are a Data Fiduciary under the Act. Unlike GDPR, the DPDP Act has no 'legitimate interest' basis. Processing rests almost entirely on consent or a narrow list of 'legitimate uses' (voluntary provision, state functions, medical emergencies, employment purposes). That makes your consent architecture the single most important compliance artifact.

    • 01Data Fiduciary: decides purpose and means of processing (you)
    • 02Data Processor: processes on the Fiduciary's behalf (your vendors)
    • 03Data Principal: the individual the data is about (your users)
    • 04Consent Manager: registered platform letting users manage consent

    02The Compliance Checklist

    Work through these in order. Steps 1–4 are foundational and expose the most risk if skipped; steps 5–8 depend on your data maps being accurate.

    • 011. Data mapping: inventory every system holding personal data, its purpose, and retention period
    • 022. Consent notices: rewrite for each purpose, in plain language, available in scheduled Indian languages
    • 033. Consent records: log what was consented to, when, and provide withdrawal as easily as consent was given
    • 044. Breach response plan: notification to the Data Protection Board and affected Data Principals, with drilled playbooks
    • 055. Data Principal rights workflow: access, correction, erasure, grievance redressal with defined SLAs
    • 066. Vendor contracts: flow DPDP obligations down to every Data Processor
    • 077. Children's data: verifiable parental consent; no tracking or behavioural advertising directed at children
    • 088. Retention & erasure: delete personal data once its purpose is served; automate where possible

    03Significant Data Fiduciary Obligations

    The government can designate organizations as Significant Data Fiduciaries (SDFs) based on volume and sensitivity of data, risk to rights, and impact on sovereignty and public order. Banks, insurers, hospitals, telecoms, and large consumer platforms should assume they will qualify. SDFs must appoint a Data Protection Officer based in India who reports to the board, engage an independent data auditor for annual audits, and conduct periodic Data Protection Impact Assessments. If you're likely to be designated an SDF, build these functions now. Retrofitting governance under regulatory scrutiny is far more expensive.

    04Security Safeguards: Where Penalties Actually Land

    The largest penalty tier, up to ₹250 crore, attaches to failure to take 'reasonable security safeguards to prevent personal data breach'. The Act doesn't enumerate controls, which means the Data Protection Board will judge you against industry practice: encryption at rest and in transit, access control, logging and monitoring, and, critically, evidence that you actually test your defenses. This is where compliance and offensive security meet. A penetration test report, a vulnerability management program, and breach-response drills are the strongest evidence that your safeguards were 'reasonable'. Faltrox runs DPDP-aligned gap assessments that map your current controls to the Act's obligations and produce an audit-ready remediation roadmap.

    • 01Encrypt personal data at rest and in transit
    • 02Enforce least-privilege access with audit logging
    • 03Test controls: regular VAPT and red team exercises
    • 04Drill the breach-notification workflow before you need it

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us