DPDP Act 2023 Compliance Checklist Generator India Data Protection Law

Generate a tailored compliance checklist for India's Digital Personal Data Protection Act 2023 based on your organisation profile.

Organisation Profile

Likely SDF
Done Gap Partial
% of applicable items addressed

DPDP Act Penalty Schedule (Reference)

ViolationMax Penalty
Breach of children's data obligations or security safeguards₹250 crore
Failure to notify breach to Board / Data Principals₹200 crore
Non-fulfilment of Significant Data Fiduciary obligations₹150 crore
Breach of duties of Data Processors₹10 crore
Other violations₹50 crore
[ADSENSE SLOT_B]

DPDP Act 2023: A Complete Compliance Guide for Indian Organisations

India's Digital Personal Data Protection Act 2023 (DPDP Act) marks a landmark shift in how personal data of Indian citizens must be handled. Passed in August 2023 after years of deliberation, the Act establishes a comprehensive framework for the processing of digital personal data within India and, in certain cases, outside India when personal data of Indian data principals is involved. Understanding its obligations is essential for any organisation operating in India.

Core Framework and Key Definitions

The DPDP Act applies to Data Fiduciaries — entities that determine the purpose and means of processing personal data. A Data Processor is an entity that processes data on behalf of a Fiduciary. A Data Principal is the individual whose data is being processed. The Act covers only digital personal data (data that is digitised or that is non-digitised but subsequently digitised). It explicitly excludes personal data processed for personal or domestic purposes, and anonymised data.

The Act establishes a consent-forward model: Data Fiduciaries must obtain free, specific, informed, unconditional, and unambiguous consent from Data Principals before processing their personal data. The consent notice must be provided in clear and plain language and, importantly, must be available in all languages listed in the Eighth Schedule to the Constitution (22 scheduled languages) to ensure Indian users can understand it in their preferred language. This multilingual requirement is one of the most operationally demanding aspects of compliance.

Significant Data Fiduciaries: Enhanced Obligations

The DPDP Act creates a higher-accountability class called Significant Data Fiduciaries (SDFs). The Central Government will notify which organisations qualify based on volume of data processed, sensitivity, potential impact, and security risk. SDFs must appoint a Data Protection Officer (DPO) who reports to the board of directors, register with a Consent Manager, conduct periodic Data Protection Impact Assessments (DPIAs), and undergo algorithmic accountability audits. For organisations likely to qualify as SDFs — large e-commerce platforms, health-tech, fintech, and social media companies — building the DPO function and DPIA process should be a priority.

Data Principal Rights

The Act grants Data Principals four core rights: the right to access information about their personal data being processed, the right to correction and erasure of inaccurate or incomplete data, the right to grievance redressal (the fiduciary must acknowledge within 48 hours and resolve within the period prescribed by rules), and the novel right to nominate an individual to exercise data rights on their behalf in case of death or incapacity. Organisations must build user-facing mechanisms to handle these rights requests — a "data request portal" or similar function is now a compliance requirement.

Breach Notification and Security

Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches. In the event of a breach, they must notify both the Data Protection Board and affected Data Principals. The notification timelines will be specified in the Rules. Maintaining a breach log, having an incident response plan, and conducting regular security assessments are essential elements of compliance. The penalty for failing to notify a breach is up to ₹200 crore — the second-highest in the penalty schedule.

Comparison with GDPR and Implementation Roadmap

While inspired by GDPR, the DPDP Act is structurally simpler. It does not enumerate multiple lawful bases for processing (like legitimate interests), does not mandate Data Processing Agreements in GDPR's detailed form, and has a narrower set of rights. For organisations already GDPR-compliant, adapting to DPDP is manageable but requires specific attention to: Indian-language privacy notices, the right to nominate, the Consent Manager registration requirement for SDFs, and the specific children's data obligations. Organisations not previously subject to any privacy law face a more significant compliance lift.

Frequently Asked Questions

The Digital Personal Data Protection Act 2023 received Presidential assent on 11 August 2023. However, most provisions will come into force on a date notified by the Central Government through gazette notification. As of mid-2026, the implementing rules (DPDP Rules 2025) have been published in draft form and are being finalised. Organisations should treat the Act as operative and begin compliance efforts immediately.
The Central Government will notify specific criteria for SDF classification. The DPDP Act specifies that the Government will consider: volume and sensitivity of personal data processed, risk to rights of Data Principals, potential impact on sovereignty, security, public order, and risk to electoral democracy. Practically, organisations processing personal data of more than 1 million individuals and/or processing sensitive personal data categories (health, financial, children's data) are most likely to be designated SDFs. SDFs face additional obligations including DPO appointment, DPIA, and consent manager registration.
The Schedule to the DPDP Act specifies penalties: (1) Breach of obligations for children's data or failure to implement security safeguards — up to ₹250 crore; (2) Failure to notify Data Protection Board and Data Principals of a data breach — up to ₹200 crore; (3) Non-fulfilment of additional obligations of Significant Data Fiduciaries — up to ₹150 crore; (4) Breach of duties of Data Processors — up to ₹10 crore; (5) Other violations of provisions — up to ₹50 crore per instance. These penalties are imposed by the Data Protection Board after due inquiry.
The DPDP Act is similar in spirit to GDPR but simpler in structure. Key similarities: consent-based processing, data minimisation, purpose limitation, data principal rights (access, correction, erasure), breach notification, and penalties. Key differences: DPDP does not require explicit legal bases beyond consent for most processing (legitimate interests concept is absent), has no mandatory DPO for all organisations (only SDFs), no formal data processing agreements required (only contractual obligations on processors), and the right to nominate a representative is unique to DPDP. DPDP also applies only to digital personal data, unlike GDPR which covers all personal data processing.
A Consent Manager is an entity registered with the Data Protection Board that acts as a single point of interface between Data Principals and Data Fiduciaries for managing consent. Data Principals can give, review, withdraw, or refuse consent through the Consent Manager platform. SDFs may be required to link with registered Consent Managers. This is a novel concept not present in GDPR or most other privacy laws, designed to give users a centralised dashboard of all consents they have given.
The Data Protection Board of India (DPBI) is the regulatory body established under the DPDP Act. It will adjudicate complaints from Data Principals, investigate breaches, and impose penalties. The Board is intended to function as a digital-first, quasi-judicial body operating primarily online. It is constituted by the Central Government and is not fully independent — a design feature that has attracted criticism from privacy advocates. The Board has the power to call for information, conduct inquiries, and direct remedial action.
Yes. Section 16 of the DPDP Act restricts transfer of personal data outside India to countries notified by the Central Government. The Government may restrict transfers to countries considered unfriendly to India's interests. As of mid-2026, the list of notified countries has not been published, meaning cross-border transfers remain in a legally uncertain state. Organisations with international data flows should monitor official notifications closely and maintain records of all cross-border transfers for compliance readiness.
Employee data is personal data and is covered by the DPDP Act when processed digitally. However, the Act allows the Government to exempt processing of employee data by employers from certain provisions (such as consent requirements) where processing is necessary for employment purposes. The DPDP Rules 2025 draft provides some exemptions for HR-related processing. Employers should still maintain privacy notices for employees, implement security safeguards, and respect rights to correction and erasure of inaccurate data.
The DPDP Act requires that personal data be retained only for as long as necessary for the purpose for which it was collected. Once the purpose is served and there is no legal obligation to retain the data, it must be erased. Organisations should define and document retention periods for each data category, implement automated deletion workflows, and include retention schedules in their Privacy Policy. Retaining data beyond its purpose without legal basis is a compliance violation subject to penalty.
Processing personal data of children (under 18 years, unless the Government notifies a different age for specific contexts) requires verifiable parental consent before processing. The Act also prohibits tracking, behavioural monitoring, and targeted advertising directed at children. Data Fiduciaries must implement appropriate mechanisms to verify a user's age and obtain parental consent where required. Violation of children's data provisions attracts the highest penalty of up to ₹250 crore.

Related Tools

WCAG 2.2 Compliance Checklist Generator
Interactive WCAG 2.2 compliance checklist with pass/fail tracking, remediation roadmap, and PDF export. ADA, EU Accessibility Act, and Australian DDA compliant.
Use Tool →
HIPAA Risk Assessment Checklist
Annual HIPAA risk assessment checklist generator simulating OCR audit protocol. Generates gap analysis, BAA templates, and remediation priorities for healthcare organizations.
Use Tool →

Automate DPDP compliance with OneTrust

Get Demo →

User Reviews

Loading reviews…

Write a Review

Reviews are moderated and published within 24 hours.

Send Feedback

Found a bug? Wrong result? Have a suggestion? We read every message.