Free resource · DPDP Act 2023 · India
DPDP Act Compliance Checklist
Every Data Fiduciary obligation under India’s Digital Personal Data Protection Act 2023 — notice & consent, Data Principal rights, security, breach notification, children’s data and cross-border. Work through it below, or download the CSV.
Notice & consent
- Clear, itemised notice at or before collection (plain language, incl. 8th Schedule languages)
- Free, specific, informed, unambiguous consent — as easy to withdraw as to give
- Consent Manager support where used; processing tied to a lawful purpose
Data Principal rights
- Right to access a summary of personal data processed
- Right to correction, completion, updating and erasure
- Right of grievance redressal (readily available mechanism)
- Right to nominate another individual
Data Fiduciary obligations
- Reasonable security safeguards to prevent a personal data breach
- Personal data breach notification to the Data Protection Board and affected principals
- Retention limitation — erase when purpose served or consent withdrawn
- Accuracy and completeness; process personal data only under a valid contract with processors
Children’s data
- Verifiable parental / guardian consent for under-18s
- No tracking, behavioural monitoring or targeted advertising directed at children
Significant Data Fiduciary & cross-border
- Appoint a Data Protection Officer based in India (if classified as an SDF)
- Periodic Data Protection Impact Assessment and independent audit (SDF)
- Cross-border transfer only to countries not restricted by the Central Government
Summarised from the Digital Personal Data Protection Act 2023 (India) — see meity.gov.in for the authoritative text; rules are still being operationalised. Not legal advice.
DPDP Act checklist FAQ
- What is the DPDP Act?
- The Digital Personal Data Protection Act 2023 is India’s data-protection law. It governs how organisations (Data Fiduciaries) may process the digital personal data of individuals (Data Principals) — built around notice and consent, a set of Data Principal rights, and obligations including security safeguards, breach notification and purpose/retention limits. This checklist turns those obligations into a working tracker.
- Who is a Data Fiduciary?
- A Data Fiduciary is any person or organisation that, alone or with others, determines the purpose and means of processing personal data — broadly equivalent to a "controller" under GDPR. If you decide why and how personal data is processed, the Fiduciary obligations in this checklist apply to you. A Significant Data Fiduciary (SDF), designated based on volume and sensitivity, carries extra duties like a DPO and DPIA.
- How does the DPDP Act compare to GDPR?
- The DPDP Act shares GDPR’s core structure — notice, consent, data-principal rights, breach notification and accountability — but is more consent-centric, has fewer explicit legal bases, and adds India-specific elements like the Consent Manager and the Data Protection Board. If you already run a GDPR programme, much of it maps across; this checklist highlights the DPDP-specific obligations.
- Can CATAAM help with DPDP?
- Yes. CATAAM supports the DPDP Act as a framework, reusing the security and privacy controls you may already run for GDPR or ISO 27001 and mapping them to DPDP obligations — so security safeguards, breach readiness and evidence are proven continuously rather than assembled by hand.
Reuse what you already run for DPDP
CATAAM maps your existing GDPR / ISO 27001 security and privacy controls to DPDP obligations and proves them continuously — so India readiness rides on evidence you already collect.