Industry News

DPDP Act Compliance Checklist: 12 Jobs Before May 2027

EDWartens Engineering Team
10 min read
DPDP Act Compliance Checklist: 12 Jobs Before May 2027

The short answer

A DPDP Act compliance checklist turns India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 into a list of jobs: map your personal data, pick a lawful ground for each use, rewrite notices to rule 3, set up consent records, rights and grievance handling, protect children's data, meet the rule 6 security safeguards, rehearse breach reporting, fix retention, sign processor contracts and train staff. Most of these duties start on 13 May 2027, eighteen months after the Rules were published in the Gazette on 13 November 2025. One duty is already live: the CERT-In directions of 2022 require many incidents, including data breaches, to be reported within 6 hours. Start now, because a programme of this size takes months.

Dates and penalties were checked on 11 October 2026 against the Gazette text of the Rules, the Act and the CERT-In directions (October 2026). This is a practical guide, not legal advice.

Who must follow the DPDP Act?

The Act applies to digital personal data processed in India, whether it was collected online or collected on paper and digitised later. It also reaches processing outside India when it is connected with offering goods or services to people in India. The organisation that decides why and how data is processed is the Data Fiduciary; a vendor that processes on its behalf is a Data Processor; the person the data is about is the Data Principal.

Purely personal or domestic use is outside the Act, and so is data a person has made publicly available herself. Almost every business, hospital, school, NGO and app in India that holds customer, patient, student or employee data in digital form is a Data Fiduciary.

The DPDP compliance checklist

#
Checklist item
Where it comes from
Done when
1
Inventory every place personal data enters, lives and leaves
Needed to prove everything else
Every system and vendor listed
2
Keep a processing register, one row per activity
Good practice; the Act needs the answers
Each row names owner, data, purpose, ground
3
Choose consent or a section 7 legitimate use for each purpose
Sections 4, 6, 7
No row without a lawful ground
4
Rewrite notices to rule 3
Section 5, rule 3
Notice stands alone, itemises data and purposes
5
Record consent and make withdrawal as easy as giving it
Section 6, rule 3
Proof of every consent is retrievable
6
Set up access, correction, erasure and grievance handling
Sections 11 to 13, rule 14
Published process; grievances closed within 90 days at most
7
Handle children's data with verifiable parental consent
Section 9, rules 10 to 12
Age and parent checks designed and tested
8
Meet the rule 6 security safeguards
Section 8(5), rule 6
Encryption, access control, logs, backups, contracts
9
Build one breach plan for CERT-In, the Board and people
Section 8(6), rule 7, CERT-In directions
Notification matrix rehearsed
10
Fix retention and erasure, with one-year logs
Section 8(7), rule 8
Every row has a retention period and trigger
11
Sign processor contracts and check transfers abroad
Sections 8(2), 16, rule 6(1)(f), rule 15
Every vendor contract has security and breach terms
12
Publish a contact person; train staff; prove it works
Section 8(9), rule 9
Contact published; training and audit records kept
Checklist of the first eight DPDP Act compliance jobs, from data inventory to breach plan
Checklist of the first eight DPDP Act compliance jobs, from data inventory to breach plan

The DPDP Rules 2025 (Gazette text, G.S.R. 846(E)) say a notice must be understandable on its own, not buried in terms of service. It must list the personal data collected and the specific purposes, and show how to withdraw consent, exercise rights and complain to the Data Protection Board. A privacy clause numbered 47 in a 30-page agreement fails that test.

Consent must be free, specific, informed, unconditional and unambiguous, and withdrawing it must be as easy as giving it. Keep evidence: which notice version the person saw, when and through which channel. Section 6(10) says that where consent is the basis and it is questioned, the Data Fiduciary must prove that notice was given and consent obtained.

Security safeguards and breach response

Rule 6 sets a minimum: secure data by encryption, masking or tokens; control access; keep logs and monitor them; make sure processing can continue after a loss, through tested backups; keep logs and personal data for one year for investigation; and put security terms into processor contracts.

Breach reporting runs on two clocks. The CERT-In directions of 28 April 2022 already require listed incidents to be reported to CERT-In within 6 hours of noticing them, and ICT logs to be kept for a rolling 180 days within India. From 13 May 2027, rule 7 adds a first intimation to the Board without delay, a detailed report within 72 hours of becoming aware, and a notice to every affected person.

Worked example: the breach clock. A hospital's IT team notices at 21:15 on a Friday that a misconfigured storage bucket exposed patient records.

  1. CERT-In: 21:15 + 6 hours = 03:15 on Saturday
  2. Board detailed report (from May 2027): 21:15 Friday + 72 hours = 21:15 on Monday
  3. Board first intimation and notices to patients: without delay, long before Monday

Weekends stop neither clock, so the on-call rota must be able to file the CERT-In report at night.

Penalties: what is at stake

The Schedule to the Act sets maximum penalties by type of breach. The Data Protection Board fixes the actual amount after an inquiry, weighing factors such as gravity, duration, mitigation and proportionality.

Breach
Maximum penalty
Failure to take reasonable security safeguards
₹250 crore
Failure to notify a personal data breach
₹200 crore
Breach of the additional duties for children
₹200 crore
Breach of Significant Data Fiduciary duties
₹150 crore
Breach of any other provision
₹50 crore
Breach of a Data Principal's own duties
₹10,000

Each breach type has its own ceiling. A company that failed to take safeguards and then failed to notify the resulting breach faces up to ₹250 crore + ₹200 crore = ₹450 crore in total, though the amount actually imposed is set case by case.

Worked example: will the gap assessment finish in time?

Score each of twelve duties 0 (not started), 1 (partial) or 2 (in place with evidence). Suppose a mid-sized company scores 8 out of 24.

  1. Points to close: 24 - 8 = 16
  2. The team can close about one point a week, so it needs 16 weeks
  3. Starting on 2 November 2026, 16 weeks (112 days) ends on 22 February 2027
  4. Days from 2 November 2026 to 13 May 2027: 28 + 31 + 31 + 28 + 31 + 30 + 13 = 192
  5. Spare: 192 - 112 = 80 days, about 11 weeks

That margin matters. In January 2026 MeitY asked industry for views on cutting the eighteen-month period to twelve months (Storyboard18, 28 January 2026). No amending notification had been published when we checked on 11 October 2026, but close the highest-risk gaps first in case the date moves. Our DPDP Rules 2025 timeline explains each stage.

Steps for running a DPDP gap assessment and roadmap before 13 May 2027
Steps for running a DPDP gap assessment and roadmap before 13 May 2027

Marketing and sales teams: a special case

Marketing lists are where many Indian firms hold the most personal data with the weakest records. Every lead needs a lawful ground, a notice and a way to withdraw, and withdrawn consent means the data must be erased unless a law requires you to keep it. If your sales team uses AI tools for prospecting, read our guide to AI tools for sales prospecting, which covers the data rules too.

Learn the whole programme, free

The free DPDP Act Compliance: India's Data Protection Law in Practice course works through every item on this checklist in thirteen study modules: scope and dates, roles, lawful grounds, rule 3 notices and Consent Managers, rights, children's data, safeguards and breach response, retention, processors and transfers, Significant Data Fiduciaries, the Board and penalties, the RBI, SEBI and IRDAI overlays, and building a programme with a register, gap assessment and roadmap.

It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not a government or Data Protection Board certification, and it is not legal advice. Start the DPDP Act compliance course and build your register as you go.

If you want to learn this alongside PLCs, SCADA and drives in a classroom, see our industrial automation course in Bangalore.

Frequently asked questions

Q: What is a DPDP Act compliance checklist?
A: It is a list of the jobs an organisation must finish to meet the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025: data inventory, lawful grounds, rule 3 notices, consent records, rights and grievances, children's data, security safeguards, breach response, retention, processor contracts and training.

Q: When do the DPDP Rules 2025 take effect?
A: In three stages counted from publication in the Gazette on 13 November 2025: the Board and core definitions that day, the Consent Manager rules on 13 November 2026, and the main duties on 13 May 2027. Check the e-Gazette for any amendment.

Q: What is the maximum penalty under the DPDP Act?
A: Up to ₹250 crore for failing to take reasonable security safeguards. Failing to notify a breach and breaching the children's data duties can each attract up to ₹200 crore, and the Board sets the actual amount after an inquiry.

Q: How fast must a data breach be reported in India?
A: To CERT-In within 6 hours of noticing it, under directions in force since 2022. From 13 May 2027 the DPDP Rules add a first intimation to the Data Protection Board without delay, a detailed report within 72 hours and notice to each affected person.

Q: Does every company need a Data Protection Officer?
A: No. Only a Significant Data Fiduciary, notified by the Government, must appoint a DPO based in India. Every other Data Fiduciary must publish the contact of a person who can answer questions about its processing.

Q: Is there a free DPDP Act course with a certificate?
A: Yes. EDWartens' DPDP Act Compliance course is a free course with a verifiable certificate of completion, covering the Act, the DPDP Rules 2025, CERT-In reporting and a compliance programme step by step.

Learn this, free

The courses that teach this

Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.

Start Your Engineering Career at EDWartens

Join as a Junior Engineer at Wartens Automation Pvt Ltd. Learn PLC and SCADA in our Electronic City classroom on wired PLC panels, and earn a Wartens Experience Certificate. Job guarantee or programme fee refunded (conditions apply). It runs for the six months after you complete the programme. See the placement policy.