The Digital Personal Data Protection (DPDP) Act, 2023, with its implementing Rules notified in late 2025, is now the operative privacy law for every business processing personal data of individuals in India. Penalties reach ₹250 crore per violation. This checklist breaks compliance into concrete steps: what to do first, what the law actually requires, and where most organizations fail.
01 //Who the DPDP Act Applies To
The Act covers processing of digital personal data within India, and processing outside India if it relates to offering goods or services to individuals in India. If you run a SaaS product, an e-commerce store, a hospital chain, or a fintech app with Indian users, you are a Data Fiduciary under the Act. Unlike GDPR, the DPDP Act has no 'legitimate interest' basis. Processing rests almost entirely on consent or a narrow list of 'legitimate uses' (voluntary provision, state functions, medical emergencies, employment purposes). That makes your consent architecture the single most important compliance artifact.
- Data Fiduciary: decides purpose and means of processing (you)
- Data Processor: processes on the Fiduciary's behalf (your vendors)
- Data Principal: the individual the data is about (your users)
- Consent Manager: registered platform letting users manage consent
02 //The Compliance Checklist
Work through these in order. Steps 1–4 are foundational and expose the most risk if skipped; steps 5–8 depend on your data maps being accurate.
- 1. Data mapping: inventory every system holding personal data, its purpose, and retention period
- 2. Consent notices: rewrite for each purpose, in plain language, available in scheduled Indian languages
- 3. Consent records: log what was consented to, when, and provide withdrawal as easily as consent was given
- 4. Breach response plan: notification to the Data Protection Board and affected Data Principals, with drilled playbooks
- 5. Data Principal rights workflow: access, correction, erasure, grievance redressal with defined SLAs
- 6. Vendor contracts: flow DPDP obligations down to every Data Processor
- 7. Children's data: verifiable parental consent; no tracking or behavioural advertising directed at children
- 8. Retention & erasure: delete personal data once its purpose is served; automate where possible
03 //Significant Data Fiduciary Obligations
The government can designate organizations as Significant Data Fiduciaries (SDFs) based on volume and sensitivity of data, risk to rights, and impact on sovereignty and public order. Banks, insurers, hospitals, telecoms, and large consumer platforms should assume they will qualify. SDFs must appoint a Data Protection Officer based in India who reports to the board, engage an independent data auditor for annual audits, and conduct periodic Data Protection Impact Assessments. If you're likely to be designated an SDF, build these functions now. Retrofitting governance under regulatory scrutiny is far more expensive.
04 //Security Safeguards: Where Penalties Actually Land
The largest penalty tier, up to ₹250 crore, attaches to failure to take 'reasonable security safeguards to prevent personal data breach'. The Act doesn't enumerate controls, which means the Data Protection Board will judge you against industry practice: encryption at rest and in transit, access control, logging and monitoring, and, critically, evidence that you actually test your defenses. This is where compliance and offensive security meet. A penetration test report, a vulnerability management program, and breach-response drills are the strongest evidence that your safeguards were 'reasonable'. Faltrox runs DPDP-aligned gap assessments that map your current controls to the Act's obligations and produce an audit-ready remediation roadmap.
- Encrypt personal data at rest and in transit
- Enforce least-privilege access with audit logging
- Test controls: regular VAPT and red team exercises
- Drill the breach-notification workflow before you need it
