Zuber & Partners LLP - Technology-native law firm logo
All Insights

Practical Guide · Data Protection

DPDP Act compliance checklist for companies

What the Digital Personal Data Protection Act, 2023 actually requires an Indian enterprise or capability centre to have in place, and the order to build it in.

By Zuber Syed|Founder & Managing Partner, Zuber & Partners|Published 23 August 2026|~13 min read

Quick Answer

DPDP compliance rests on eight things a company must be able to produce on demand: a current data inventory, a lawful basis recorded for every processing activity, notices in clear language with a working withdrawal route, valid contracts with every processor and sub-processor, security safeguards that are documented and tested, retention periods with actual deletion, a functioning rights and grievance process, and a breach process that can notify the Data Protection Board and affected individuals quickly. Everything else follows from the inventory, which is why discovery comes first.

Get a DPDP gap assessment

This guide is general information. For advice on your specific facts, speak with the team.

Before You Start

Most DPDP programmes fail at discovery, not at drafting.

Policies are quick to write and easy to audit against. The hard part is knowing what personal data the organisation actually holds, in which systems, under which vendor contracts, for how long. Companies that start with documents rather than discovery end up with a compliant-looking file and an uncontrolled data estate.

1. Who is actually in scope

The Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India, including data collected in non-digital form and later digitised. It also reaches processing carried out outside India where that processing is connected with offering goods or services to data principals in India. The practical effect is that scope questions are rarely close: if a company employs people in India, sells to people in India, or processes Indian personal data anywhere, it is in scope.

Two categories of organisation regularly and wrongly conclude they are outside the Act. The first is the capability centre that processes only the parent's foreign customer data. It still processes employee, candidate, contractor and vendor personal data in India, and it is a data fiduciary for that data in its own right. The second is the business-to-business enterprise that believes it holds only company data. Contact names, work emails, procurement approvers and support tickets are personal data.

Certain processing falls outside the Act, including processing for personal or domestic purposes and personal data that a data principal has made publicly available in prescribed circumstances. These are narrow exclusions, not a general carve-out, and they should be relied on only where the facts clearly fit.

The scope question is not whether the Act applies. It is which of your processing activities you have never mapped.

2. Data fiduciary, data processor and the GCC question

A data fiduciary determines the purpose and means of processing and carries the substantive obligations: lawful basis, notice, accuracy, security safeguards, retention limits, rights handling, breach intimation and accountability for the processors it appoints. A data processor processes on the fiduciary's behalf under a valid contract, and its duties flow from that contract rather than directly from most of the statutory obligations. Importantly, a fiduciary remains answerable for processing carried out by its processors, so contractual discipline is a compliance control, not a commercial nicety.

Most enterprises hold both roles simultaneously across different data sets, and the mapping needs to be explicit. A capability centre is typically a processor when it handles the parent group's customer data on instruction, and a fiduciary for its own employee, recruitment, vendor and visitor data. A software provider is a processor for its customers' end-user data and a fiduciary for its own prospect and employee data.

The reason to settle roles early is that they determine who writes the notice, who answers a data principal's request, who reports a breach to whom, and who bears the penalty exposure. Organisations that leave the question unresolved discover it during an incident, which is the worst moment to negotiate it.

Fiduciary duties

Lawful basis, notice, accuracy, security safeguards, retention limits, rights handling, breach intimation, and accountability for appointed processors.

Processor duties

Process only on instruction and under a valid contract, apply agreed security measures, assist with rights requests, notify incidents, and delete or return data on termination.

GCC dual role

Processor for parent-group customer data; fiduciary for its own employee, candidate, contractor and vendor data processed in India.

Group policies

A parent's global privacy programme does not discharge the Indian entity's obligations. The India-facing notice, grievance route and records must exist locally.

3. Data mapping: the step everything else depends on

The inventory is the foundation of a DPDP programme and the deliverable most organisations skip or outsource to a survey. Done properly, it records for every processing activity: the systems and applications involved, the categories of personal data and of data principal, the purpose, the lawful basis relied on, the internal and external recipients including sub-processors, the geographies where the data is stored or accessed, the retention period, and the security controls applied.

Discovery should combine top-down interviews with bottom-up technical evidence. Interviews tell you what the business thinks it does; system inventories, integration logs, vendor lists from procurement and finance, single-sign-on application lists and endpoint scans tell you what it actually does. The gaps between those two views are where the risk lives: the marketing tool nobody registered, the shared drive holding old candidate CVs, the analytics script sending identifiers to a third party, the spreadsheet of employee bank details in a manager's mailbox.

Treat the inventory as a living record with an owner, not a one-off project artefact. Every new vendor, integration or product feature should update it, ideally through a lightweight assessment step in procurement and change management. An inventory that is accurate on the day of the audit and nowhere else provides no protection at all.

You cannot notify a breach you cannot scope

The single most common reason breach notification goes badly is that nobody knows which data sets a compromised system held, whose data was in them or which vendors had copies. That answer has to exist before the incident, in the inventory. Building it afterwards, under a reporting clock, is where disclosure errors and regulator credibility problems begin.

Talk to us about data discovery

4. Lawful basis, notice and consent mechanics

Every processing activity needs a recorded basis. Where consent is relied on, it must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the specified purpose. The notice accompanying it must describe the personal data collected and the purpose, the way to exercise rights, and the route to complain to the Data Protection Board, in clear and plain language, with the option of an Indian language. Withdrawal must be as easy as giving consent, and the consequences of withdrawal must be handled downstream rather than merely acknowledged.

The Act also recognises certain legitimate uses where consent is not required, including specified employment-related purposes such as protecting the employer from loss or providing a service or benefit to an employee, compliance with law or a court order, and medical emergencies. These are useful and finite. Employment processing in particular should be assessed activity by activity, because monitoring, background verification and analytics do not all sit comfortably in the same bucket.

Practical failures cluster in three places. Bundled consent, where one checkbox covers service delivery and marketing, is not specific. Pre-ticked boxes and continued-use notices are not affirmative action. And withdrawal that stops future emails but leaves the profile, the enriched attributes and the vendor copies intact is not withdrawal. Each of these is a design problem in the product or the CRM, which is why privacy work belongs with engineering as much as with legal.

5. Processor contracts and the vendor chain

The Act requires processing by a processor to be under a valid contract. In practice that means every vendor that touches personal data, from payroll and background verification to cloud hosting, support tooling, analytics and marketing platforms, needs terms covering purpose limitation, permitted sub-processing, security measures, incident notification with a timeline that lets the fiduciary meet its own obligations, cooperation on rights requests, audit and information rights, cross-border transfer terms, and deletion or return on termination.

Remediation is a sequencing exercise rather than a drafting exercise. Rank vendors by data sensitivity and volume, start with the ones that hold employee, financial or customer identifying data, and work down. For high-volume, low-risk tools, a standard data-processing addendum applied at renewal is usually sufficient. For critical processors, negotiate specifics: notification hours, encryption standards, sub-processor change controls and deletion evidence.

Intra-group arrangements need the same discipline and are the ones most often overlooked. A parent accessing the Indian entity's employee data, or a shared-services team in another country administering Indian payroll, is a cross-border processing arrangement that requires documented terms, whatever the internal org chart says.

The fiduciary answers for its processors. An unpapered vendor is not a procurement gap; it is a liability transfer that never happened.

6. Rights, grievances and retention

Data principals have the right to access a summary of their personal data and processing activities, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person to exercise their rights in the event of death or incapacity. Each of these needs a working operational route, not a policy sentence: a published channel, identity verification proportionate to the request, a defined internal workflow with named owners, a response timeline, and a log that demonstrates what was done and when.

Grievance redressal deserves particular attention because it is a statutory precondition to a complaint reaching the Data Protection Board. A grievance route that is unmonitored, or that routes to a mailbox nobody owns, converts a resolvable complaint into a regulatory matter. Publish the route, staff it, log it and report on it internally.

Retention is where compliance meets housekeeping. The Act requires erasure when the purpose is no longer served and consent is withdrawn, unless retention is required by law. That obliges a retention schedule per data category, deletion that actually executes across primary systems, backups, exports and vendor copies, and documented exceptions for statutory retention such as tax, payroll and corporate records. Most organisations discover during this exercise that they are holding candidate data from years ago, former employee records without a defined period and customer data in analytics stores nobody owns.

Erasure that does not reach backups and vendors is not erasure

Deleting the record in the primary system while copies persist in a data warehouse, a marketing platform, a support tool and an offsite backup leaves the organisation asserting a compliance position it cannot evidence. Map deletion across the full chain identified in the inventory, and get deletion confirmation from processors in writing.

Review your retention and deletion controls

7. Security safeguards and breach reporting

The Act requires a data fiduciary to take reasonable security safeguards to prevent a personal data breach, and the highest penalty tier attaches to failing to do so. That makes demonstrable controls, rather than documentation alone, the highest-value part of a programme: access control on a least-privilege basis with periodic review, encryption in transit and at rest for sensitive data sets, logging and monitoring sufficient to detect and reconstruct an incident, patch and vulnerability management, secure development practice, endpoint and device controls, backup integrity testing, and vendor security assessment.

Breach response has two distinct legs in India and they run on different clocks. Under the DPDP Act, a fiduciary must give intimation of a personal data breach to the Data Protection Board and to each affected data principal in the prescribed form and manner. Separately, CERT-In directions require reporting of specified cyber incidents within six hours of noticing them, together with log retention and other obligations. A single incident can trigger both, along with sector-regulator reporting for regulated entities and contractual notification duties to customers.

The only reliable preparation is a tested plan: defined roles including a decision-maker, criteria for engaging counsel early so that investigation work can be conducted with privilege considerations in mind, pre-drafted notification templates, a forensic provider on retainer, communication holding statements, and an evidence-preservation protocol. Run it as a tabletop exercise at least annually and fix what the exercise breaks.

01

Build the data inventory

Identify every system, vendor and workflow that touches personal data, the categories held, the purposes, the lawful basis, retention and the geographies involved. Nothing downstream is reliable without this.

02

Fix the lawful basis and notices

Assign each processing activity to consent or a recognised legitimate use, then rewrite notices in clear language with purpose, rights, grievance route and withdrawal mechanics.

03

Remediate processor and vendor contracts

Put valid processing contracts in place with every processor and sub-processor, covering purpose limitation, security, breach notification, deletion, audit and onward transfer.

04

Stand up rights and grievance handling

Build a route for access, correction, erasure, nomination and grievance requests, with identity verification, response timelines, an audit trail and a named owner.

05

Implement retention and deletion

Define retention periods per data category, automate deletion where possible, and document the exceptions required for legal or regulatory retention.

06

Test breach detection and reporting

Run a tabletop exercise against both the DPDP intimation obligation and CERT-In's six-hour incident reporting requirement, and fix the gaps the exercise exposes.

8. Significant data fiduciary obligations

The government may designate a company, or a class of companies, as a significant data fiduciary based on factors including the volume and sensitivity of personal data processed, the risk to data principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, security of the state and public order. Designation brings three additional obligations: appointing a Data Protection Officer based in India who represents the fiduciary and reports to the board or an equivalent governing body, appointing an independent data auditor to evaluate compliance, and undertaking periodic data protection impact assessments and audits along with any other prescribed measures.

Companies that process large volumes of consumer data, sensitive categories such as financial or health data, or children's data should assume they may be designated and build accordingly. The three obligations are also good practice independent of designation: a named accountable officer, independent assurance and impact assessment before high-risk processing begins.

Children's data carries its own strict rules regardless of designation, including verifiable parental consent and prohibitions on tracking, behavioural monitoring and targeted advertising directed at children. Any product with users under eighteen needs an age-assurance design decision made deliberately, not defaulted.

9. A realistic 120-day readiness programme

In the first thirty days, appoint an accountable owner, run data discovery across systems and vendors, and produce a first-pass inventory with a gap assessment against notice, consent, contracts, retention, security and rights handling. Expect this phase to reveal shadow systems and unregistered vendors; that is its purpose.

In days thirty-one to seventy-five, remediate. Rewrite notices and consent flows with engineering, assign lawful bases and record them, paper the priority vendors, define and implement the retention schedule, close the access-control and logging gaps the assessment found, and build the rights and grievance workflow with a named owner and a log.

In days seventy-six to one hundred and twenty, operationalise and test. Run the breach tabletop against both the DPDP intimation obligation and the CERT-In six-hour clock, test a real access and erasure request end to end, complete training for the teams that handle personal data, embed a privacy assessment step into procurement and product change, and report a short compliance dashboard to the board. Then keep the inventory current, because the programme's value decays from the day discovery stops.

The board question is not 'are we compliant' but 'can we evidence it tomorrow'

Regulators, customers and acquirers all ask for the same artefacts: the inventory, the basis records, the vendor contracts, the retention schedule, the access reviews, the incident log and the tabletop results. A programme built to produce those on demand is a programme that holds up. One built to produce a policy set is not.

Request a DPDP readiness review

How Zuber & Partners helps

We run DPDP readiness as an operating programme, not a policy pack.

For enterprises, capability centres and technology companies, we lead data discovery and mapping, assign and document lawful bases, rewrite notices and consent flows with product and engineering teams, remediate processor and intra-group contracts, design retention and deletion, and build rights and grievance handling that actually runs.

We also prepare and test incident response across the DPDP intimation obligation, CERT-In's six-hour reporting requirement and sector-regulator duties, and we advise boards on significant data fiduciary readiness, Data Protection Officer appointment and independent audit.

Talk to us about DPDP readiness

Frequently asked questions

Who does the DPDP Act apply to?

The Digital Personal Data Protection Act, 2023 applies to the processing of digital personal data within India, whether the data was collected digitally or digitised afterwards. It also applies to processing outside India where that processing is connected with offering goods or services to data principals in India. Any company with Indian employees, customers or users is therefore in scope, including a captive capability centre that processes only foreign customer data, because its own employee data is processed in India.

What is the difference between a data fiduciary and a data processor under the DPDP Act?

A data fiduciary is the entity that determines the purpose and means of processing and carries the primary obligations: lawful basis, notice, security safeguards, accuracy, retention limits, rights handling, breach intimation and accountability for its processors. A data processor processes personal data on behalf of a fiduciary under a valid contract and takes its obligations from that contract. A GCC is typically a processor for the parent's customer data and a fiduciary in its own right for employee, candidate and vendor data.

Does the DPDP Act require consent for everything?

No. Consent is the primary basis, and where it is used it must be free, specific, informed, unconditional and unambiguous, obtained with a notice in clear language and with an equally easy route to withdraw. But the Act also recognises certain legitimate uses that do not require consent, including specified employment-related purposes, compliance with law or judgments, and responding to medical emergencies. Most enterprises end up with a mix, and the important discipline is recording which basis supports which processing activity.

How quickly must a personal data breach be reported under the DPDP Act?

The Act requires a data fiduciary to give intimation of a personal data breach to the Data Protection Board and to each affected data principal, in the form and manner prescribed by the rules. Because the obligation extends to notifying individuals and there is no materiality threshold in the statute itself, the practical requirement is a tested process that can determine scope, assemble the required content and notify quickly. This obligation sits alongside CERT-In's separate six-hour reporting requirement for specified cyber incidents, which is a different trigger with a different timeline.

What extra obligations apply to a significant data fiduciary?

Where the government designates a company as a significant data fiduciary based on factors such as the volume and sensitivity of data processed and risk to data principals, additional obligations apply: appointing a Data Protection Officer based in India who reports to the board or its equivalent, appointing an independent data auditor, and conducting periodic data protection impact assessments and audits. Companies close to that threshold should build these functions in advance rather than waiting for a designation.

Can personal data be transferred outside India under the DPDP Act?

The Act adopts a comparatively permissive position: transfers are allowed except to countries or territories the government restricts by notification. Sector regulators can still impose stricter localisation, and existing sectoral rules on payments, banking, insurance and telecom data continue to apply. Practically, this means transfer mapping remains necessary, with contracts that carry the processing obligations through the chain and a record of where data actually sits.

What are the penalties under the DPDP Act?

The Act provides for financial penalties determined by the Data Protection Board, with the highest tier applying to failures to take reasonable security safeguards to prevent a personal data breach, and further tiers for failures to notify breaches, breaches of children's data obligations, breaches of significant data fiduciary obligations and other non-compliance. Because the ceiling for the security-safeguards failure is the highest, demonstrable technical and organisational controls, tested and documented, are the highest-value investment.

How long does DPDP readiness usually take?

For a mid-sized enterprise or GCC, a realistic programme runs ninety to one hundred and twenty days: four to six weeks for data discovery and mapping, running in parallel with a gap assessment against notice, consent, contracts, retention, security and rights handling; six weeks to remediate contracts, notices, retention rules and access controls; and a final phase to build and test the rights and breach processes. Discovery is the phase companies consistently underestimate, and it is the one everything else depends on.

Your question not covered above?

Send us your situation and we will reply with a practical next step.

Ask a question

Sources & primary references

This guide is written against the primary sources below. Where a statute, rule or regulator direction is cited, the official text controls.

Authored by

Zuber Syed

Founder & Managing Partner · Advocate · Cybersecurity & Data Protection

Zuber Syed advises enterprises, boards and capability centres on India's data protection and cybersecurity regime, including DPDP readiness, incident response and regulator engagement. This guide is general information and not legal advice for a specific matter.