Knowledge centre · Data privacy

DPDP Compliance Checklist for Startups: 18 Steps Before May 2027

Everything the DPDP Act, 2023 and the DPDP Rules, 2025 expect of a typical startup, in the order we would tackle it, with the section or rule behind each step.

18 steps 5 areas Deadline 13 May 2027
What should a DPDP compliance checklist cover? Five areas: knowing what personal data you hold and who receives it; a proper notice and valid consent; security safeguards and a breach plan that can meet the 72-hour report; erasure, log retention and a way for people to exercise their rights; and the special rules for children, cross-border transfers and Significant Data Fiduciaries.

1. Know your data

  1. List every category of personal data you collect from users, customers and employees, with its source and purpose.Section 8
  2. Identify every vendor that receives personal data (cloud, CRM, payments, analytics, support) and where the data is stored.Section 8(2)
  3. Find out whether any of your users are under 18.Section 9

2. Notice and consent

  1. Give a standalone, plain-language notice at every point of collection that itemises the data and the purposes.Section 5 · Rule 3
  2. In that notice, explain how to withdraw consent, how to exercise rights and how to complain to the Data Protection Board.Rule 3
  3. Make consent free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and not bundled with other terms.Section 6(1)
  4. Make withdrawing consent as easy as giving it, and keep records that let you prove the notice and consent later.Sections 6(4) and 6(10)
  5. Wherever you process data without consent, confirm it fits one of the legitimate uses the Act allows.Section 7

3. Security and breaches

  1. Apply the minimum safeguards: encryption or masking, access control, logs and monitoring, and backups for continuity.Section 8(5) · Rule 6
  2. Put security and deletion duties into every processor contract.Section 8(2) · Rule 6
  3. Write a breach playbook: notify affected users and the Board without delay, and send the Board a detailed report within 72 hours.Section 8(6) · Rule 7

4. Retention and rights

  1. Erase personal data once its purpose is served or consent is withdrawn, and make your processors erase it too.Section 8(7)
  2. Keep personal data, traffic data and processing logs for at least one year from the processing.Rule 8(3)
  3. Publish the business contact of the person who answers questions about your processing (or your DPO, if you have one).Rule 9
  4. Publish how users can access, correct, erase and nominate, and resolve grievances within 90 days.Sections 11 to 13 · Rule 14

5. Special cases

  1. For children, obtain verifiable consent from a parent, and do not track, monitor behaviour or target advertising at them.Section 9 · Rule 10
  2. Before transferring personal data outside India, check any restrictions the government has notified.Section 16 · Rule 15
  3. Check whether your data volume or sensitivity could get you notified as a Significant Data Fiduciary, which brings a DPO, an independent auditor and an annual DPIA.Section 10 · Rule 13
Not sure where you stand? Our DPDP Readiness Check runs this checklist against your actual product in 7 to 10 working days, from ₹25,000. See the DPDP Rules 2025 timeline for when each step becomes mandatory.
FAQs

DPDP compliance checklist: common questions

A data map: a list of every category of personal data you collect, where it comes from, why you use it, where it is stored and which vendors receive it. Every later step depends on it.

Under rule 3, an itemised description of the personal data, the specific purposes and the goods or services involved, and the means to withdraw consent, exercise rights and complain to the Data Protection Board. It must be understandable on its own, in clear and plain language.

Affected users and the Board must be told without delay, and the Board must receive a detailed report within 72 hours of the business becoming aware of the breach, unless the Board allows longer on a written request.

Rule 8(3) requires personal data, associated traffic data and processing logs to be kept for at least one year from the date of processing, for the purposes listed in the Seventh Schedule.

No. Only Significant Data Fiduciaries notified by the government must appoint a Data Protection Officer. Every other business must publish the contact of a person who can answer questions about its processing of personal data.

Get the checklist done, not just read.

Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote for a readiness check.

    Send Us Your Enquiry

    Fill in the form below and our team will respond within 24 hours.

    Prefer chat? WhatsApp us.

    General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.

    Scroll to Top