NOTICE Β· CONSENT Β· DATA RIGHTS

India DPDP Act Checklist

A practical checklist for mapping personal data, consent, retention, security safeguards, processors, and incident response under India's DPDP Act.

Use this as an operational starting point, not legal advice. Map the personal data you handle, then make notice, consent, safeguards, and response practices real.

PHASE 01

Map data and purpose

Identify personal data, collection points, purposes, systems, processors, retention periods, and who can access it.

  • Keep a current data inventory.
  • Separate essential processing from optional uses.
  • Assign a business owner for each purpose.

PHASE 02

Implement notice and consent

Use clear notices and consent flows that match the actual purpose. Make withdrawal and data-rights handling operational.

  • Test consent capture and withdrawal records.
  • Verify processors follow documented instructions.
  • Avoid collecting data just in case.

PHASE 03

Prepare safeguards and response

Apply access control, encryption where appropriate, logging, vendor checks, retention controls, and an incident response path.

  • Practice a personal-data incident escalation.
  • Review access and retention on a schedule.
  • Get legal review for applicability and obligations.

Frequently asked questions

Is this a substitute for legal advice?

No. It is a practitioner checklist. Confirm obligations and implementation decisions with qualified counsel.