The DPDP compliance checklist.

Fourteen steps that take an Indian business from unprepared to DPDP-ready — each one tied to the exact section of the DPDP Act 2023 or DPDP Rules 2025 it satisfies. Tick items off as you go; your progress is saved on this device.

14 steps
Grouped into four phases
13 May 2027
Most operational obligations commence
₹250 Cr
Maximum penalty under the Act
0 / 14 done

Phase 1 · Map & Document

01

Take the free EasyDP DPDP Checker — it takes 2 minutes and tells you exactly which section of the Act applies to you and what your penalty exposure is. As a rule of thumb: the Act applies to personal data collected in digital form, or collected on paper and then digitised (Section 3). If you store customer details in any software — billing, WhatsApp, a spreadsheet — you're likely covered, but the details depend on what you collect and how. Read our guide on whether the DPDP Act applies to your business for the edge cases, including the exemption for purely personal or household use.

DPDP Act 2023, Section 3
02

Before you can protect data, you need to know where it lives — it's the first-month job in our 90-day DPDP implementation plan. Create a simple inventory:

  • What personal data do you collect? (Name, phone, address, payment, medical, biometric)
  • Where is it stored? (WhatsApp, CRM, Excel, Shopify, physical files that get scanned)
  • Who has access to it? (Owner, staff, delivery partners, accountant)
  • Who do you share it with? (Payment gateway, courier, email tool, WhatsApp Business)

A simple spreadsheet is fine. This becomes your Data Register — keep it updated.

Groundwork for Sections 5–8
03

List every third-party tool or service that handles customer data: Razorpay, Shiprocket, Google Analytics, Mailchimp, Tally, your billing software. Under DPDP, you are the Data Fiduciary and they are your Data Processors — you are responsible for their compliance. Check if they have a privacy policy and data processing terms.

DPDP Act 2023, Section 8(2)
04

Draft a privacy notice that covers: what data you collect, why, who you share it with, how long you keep it, and how customers can exercise their rights. Keep it simple — one A4 page in plain language. Publish it on your website footer, Instagram bio link, or WhatsApp pinned message.

Section 5(1); Rules 2025, Rule 3

Phase 2 · Build Processes

05

Define how you'll get consent from customers before collecting their data. For a WhatsApp business, this might be a standard message you send to all new customers. For a Shopify store, it's a checkbox at checkout. For a physical store, it could be a QR code at the counter that opens a digital consent form.

Consent must be explicit, specific, and documented. "They gave me their number so it's fine" is not consent under the DPDP Act.

DPDP Act 2023, Section 6
06

Create a way for customers to ask about their data, request corrections, or ask for deletion. Minimum viable: a dedicated email address (privacy@yourbusiness.in) and a documented process for what to do when a request arrives. The DPDP Rules don't fix a single statutory deadline for responding — instead, they require you to publish how customers can exercise their rights and the time period within which you'll respond (Rule 14). Pick a target you can actually meet — many businesses commit to 30 days — and state it in your privacy notice.

Sections 11–13; Rules 2025, Rule 14
07

"Reasonable security safeguards" is the legal standard — one of the core responsibilities every business carries. For an SMB, this means:

  • Two-factor authentication on any account or device containing customer data
  • Password-protect spreadsheets containing customer lists
  • Limit staff access to only the data they need
  • Secure Wi-Fi in your office (WPA2 minimum)
  • Regular backups of customer data
  • A clear policy about not copying customer data to personal devices
Section 8(5); Rules 2025, Rule 6

Phase 3 · People & Partners

08

Every person who handles customer data needs to know the basics: what data you collect, why, how to handle customer requests, and what to do if there's a potential breach. A one-hour team session with a written summary is sufficient for most SMBs. Document that you did it. Our staff training guide includes a ready-made session plan.

Supports Section 8 obligations
09

Your contracts with Data Processors (delivery partners, payment gateways) should include data protection clauses. These are often called Data Processing Agreements (DPAs) — our guide to what your contracts must say covers them in detail. Most large providers (Google, Meta, Razorpay) already offer these. Review and sign them.

DPDP Act 2023, Section 8(2)
10

If any of your customers might be under 18 — schools, coaching centres, apps, gaming, children's products — you must implement parental consent verification. This is non-negotiable and carries the highest penalty (₹200 Crore). If you're in this category, contact EasyDP specifically about the parental consent flow.

Section 9; Rules 2025, Rule 10
11

Write down: what you'll do if customer data is compromised. Who to call, what to tell customers, how to notify the Data Protection Board. Keep this document somewhere everyone on your team can find it. Under Rule 7 of the DPDP Rules 2025, you must inform affected customers and the Board without delay on becoming aware of a breach, and then file the detailed breach information with the Board within 72 hours. Our guide to breach notification timelines under the DPDP Rules explains exactly what each notification must contain — you don't have time to figure out the process after a breach happens.

Section 8(6); Rules 2025, Rule 7

Phase 4 · Prove & Maintain

12

For customers whose data you collected before the law takes effect, the Act requires you to send them a DPDP-compliant notice as soon as reasonably practicable (Section 5(2)) — covering what data you hold, why, and how they can exercise their rights or withdraw consent. Their earlier consent continues to be valid until they withdraw it, so this is a notification exercise rather than a fresh consent drive — but you need a plan to reach your existing database before enforcement begins in May 2027. EasyDP's multilingual notices can run that re-noticing batch in each customer's own language.

DPDP Act 2023, Section 5(2)
13

Decide how long you'll keep different types of data and when you'll delete it. The DPDP Act's principle is simple: keep personal data only as long as it's needed for the purpose you collected it for, or as long as another law requires you to keep it (Section 8(7)). The fixed three-year erasure timelines in the Rules apply only to very large platforms — e-commerce, social media, and gaming companies above user thresholds set in the Third Schedule — not to typical SMBs.

In practice, that means writing your own retention policy and being able to justify it. For example: tax and transaction records stay as long as GST and income-tax law require (roughly six years); marketing contacts stay until the person opts out; inactive customer accounts get deleted after a period you set and state in your privacy notice. Then actually implement deletion — if you're using Shopify, use their built-in anonymization feature. If it's a spreadsheet, set a calendar reminder to clean it annually.

Section 8(7); Rules 2025, Rule 8
14

The DPB can ask for evidence of your compliance efforts. Keep records of: when you updated your privacy notice, consent records for customers, DSRs received and resolved, breach incidents (even minor ones), staff training sessions, and third-party DPAs signed. EasyDP's audit logs build this evidence file automatically. This documentation is your defence if a complaint is ever filed against you.

Sections 6 & 8 — burden of proof

Sources

  1. Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 (Sections 3, 5, 6, 8, 9, 11–13; the Schedule).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 3 (notice), Rule 6 (security safeguards), Rule 7 (breach intimation), Rule 8 and the Third Schedule (retention and erasure), Rule 10 (children's data), Rule 14 (Data Principal rights); core obligations from May 13, 2027.
  3. India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.

This checklist is general information about the DPDP Act 2023 and DPDP Rules 2025, not legal advice. Verify obligations and deadlines against the current notified text for your specific business.

Not sure the Act applies to you?

The free DPDP checker asks six questions about your business and tells you which obligations — and which penalties — apply to you. It's the fastest way to complete Step 1.

Take the 2-minute checker

Prefer it on paper?

Download the one-page PDF companion to this checklist — the same 14 steps in four quadrants, with a QR code back to this page. Pin it up next to the billing desk.

Download the PDF ↓

The checklist, answered.

Yes — the core obligations of the DPDP Rules 2025 apply from May 13, 2027, and each step maps to an obligation that will be enforceable from that date. Start with the Map & Document phase now: consent processes, staff training, and re-noticing your existing customer base take months, not days.

Want the reasoning behind each step? Read the long-form guides linked inside every step above, or start with the whole DPDP Act in plain English.

Built on India's official DPDP framework.

DPDP Act 2023No. 22 of 2023 · In force Nov 13, 2025
DPDP Rules 2025G.S.R. 846(E) · staged: 2025 → May 2027
MeitY governedMinistry of Electronics & Information Technology