Free resource · DPDP Act 2023 · India

DPDP Act Compliance Checklist

Every Data Fiduciary obligation under India’s Digital Personal Data Protection Act 2023 — notice & consent, Data Principal rights, security, breach notification, children’s data and cross-border. Work through it below, or download the CSV.

Notice & consent

  • Clear, itemised notice at or before collection (plain language, incl. 8th Schedule languages)
  • Free, specific, informed, unambiguous consent — as easy to withdraw as to give
  • Consent Manager support where used; processing tied to a lawful purpose

Data Principal rights

  • Right to access a summary of personal data processed
  • Right to correction, completion, updating and erasure
  • Right of grievance redressal (readily available mechanism)
  • Right to nominate another individual

Data Fiduciary obligations

  • Reasonable security safeguards to prevent a personal data breach
  • Personal data breach notification to the Data Protection Board and affected principals
  • Retention limitation — erase when purpose served or consent withdrawn
  • Accuracy and completeness; process personal data only under a valid contract with processors

Children’s data

  • Verifiable parental / guardian consent for under-18s
  • No tracking, behavioural monitoring or targeted advertising directed at children

Significant Data Fiduciary & cross-border

  • Appoint a Data Protection Officer based in India (if classified as an SDF)
  • Periodic Data Protection Impact Assessment and independent audit (SDF)
  • Cross-border transfer only to countries not restricted by the Central Government

Summarised from the Digital Personal Data Protection Act 2023 (India) — see meity.gov.in for the authoritative text; rules are still being operationalised. Not legal advice.

DPDP Act checklist FAQ

What is the DPDP Act?
The Digital Personal Data Protection Act 2023 is India’s data-protection law. It governs how organisations (Data Fiduciaries) may process the digital personal data of individuals (Data Principals) — built around notice and consent, a set of Data Principal rights, and obligations including security safeguards, breach notification and purpose/retention limits. This checklist turns those obligations into a working tracker.
Who is a Data Fiduciary?
A Data Fiduciary is any person or organisation that, alone or with others, determines the purpose and means of processing personal data — broadly equivalent to a "controller" under GDPR. If you decide why and how personal data is processed, the Fiduciary obligations in this checklist apply to you. A Significant Data Fiduciary (SDF), designated based on volume and sensitivity, carries extra duties like a DPO and DPIA.
How does the DPDP Act compare to GDPR?
The DPDP Act shares GDPR’s core structure — notice, consent, data-principal rights, breach notification and accountability — but is more consent-centric, has fewer explicit legal bases, and adds India-specific elements like the Consent Manager and the Data Protection Board. If you already run a GDPR programme, much of it maps across; this checklist highlights the DPDP-specific obligations.
Can CATAAM help with DPDP?
Yes. CATAAM supports the DPDP Act as a framework, reusing the security and privacy controls you may already run for GDPR or ISO 27001 and mapping them to DPDP obligations — so security safeguards, breach readiness and evidence are proven continuously rather than assembled by hand.

Reuse what you already run for DPDP

CATAAM maps your existing GDPR / ISO 27001 security and privacy controls to DPDP obligations and proves them continuously — so India readiness rides on evidence you already collect.