DPDPA Compliance Guide: Step-by-Step Roadmap for Organizations
A step-by-step educational roadmap outlining key areas organizations may consider when working toward compliance with the Digital Personal Data Protection Act, 2023.
✓Immediate Action Checklist
Key steps organisations should prioritise based on the notified DPDP Rules, 2025:
- Appoint a responsible person for data protection and grievance redressal
- Map all personal data processing activities across the organisation
- Review and update consent mechanisms to meet R.3 standards (independent, self-sufficient, itemised notices)
- Implement security safeguards per R.6 - encryption, masking, virtual tokenisation, access controls, and maintain processing logs for a minimum of 1 year
- Establish two-tier breach response per R.7 - Level 1 notification without unreasonable delay, Level 2 within 72 hours
- Set up grievance redressal within 90-day SLA per R.14 with a web-based submission mechanism
B2B Compliance Considerations
The DPDPA applies to all processing of digital personal data, including in B2B contexts. Even where the primary relationship is between businesses, personal data of employees, representatives, and contact persons of business clients may be processed. Organisations engaged in B2B transactions should assess whether they process any personal data and ensure compliance accordingly.
- 1
Applicability Assessment
The first step is determining whether and how the DPDPA applies to your organisation. The Act applies to any entity processing digital personal data within India, or processing data outside India in connection with offering goods or services to individuals in India.- Determine whether your organisation processes digital personal data
- Assess if B2B data processing involves any personal data (e.g., contact details of employees of business clients)
- Evaluate extraterritorial applicability if processing data of individuals in India from outside India
- Identify any exemptions that may apply to your organisation's processing activities
- 2
Data Mapping and Inventory
Organizations may consider identifying and cataloging all personal data they collect, process, and store to understand the scope of their data processing activities.- Inventory all data collection touchpoints
- Classify data by type and sensitivity
- Document data flows across systems and third parties
- 3
Consent Mechanism Review
Reviewing existing consent mechanisms to ensure they meet the Act's requirements for free, specific, informed, and unambiguous consent.- Audit existing consent notices and forms
- Implement granular, purpose-specific consent collection
- Establish processes for consent withdrawal
- 4
Privacy Notices and Transparency
Data Fiduciaries must provide clear and accessible notices to Data Principals before or at the time of collecting personal data, detailing the data sought, the purpose of processing, and the manner in which rights may be exercised.- Draft or update privacy notices to comply with the Act's requirements
- Ensure notices are available in English and all languages specified in the Eighth Schedule
- Implement mechanisms to deliver notices at or before the point of data collection
- Review and update notices when processing purposes change
- 5
SDF Designation Review
Organisations should evaluate whether they may be designated as a Significant Data Fiduciary (SDF) by the Central Government, based on factors such as the volume and sensitivity of data processed, potential risk to Data Principals, and impact on sovereignty and public order.- Assess your organisation against the SDF criteria outlined in the DPDP Rules
- If designated, prepare for additional obligations including periodic DPIAs and independent audits
- Establish processes for periodic Data Protection Impact Assessments
- 6
Data Protection Officer Appointment
Significant Data Fiduciaries are required to appoint a Data Protection Officer based in India who acts as the point of contact for the Data Protection Board.- Assess whether your organization qualifies as a Significant Data Fiduciary
- Define the DPO's roles and responsibilities
- Ensure the DPO has direct reporting access to the board of directors
- 7
Data Protection Impact Assessment
Significant Data Fiduciaries may be required to undertake periodic Data Protection Impact Assessments to evaluate risks associated with data processing activities.- Identify high-risk processing activities
- Assess potential impact on Data Principal rights
- Document risk mitigation measures
- 8
Grievance Redressal Mechanism
Data Fiduciaries are required to establish an accessible grievance redressal mechanism. Under Rule 14 of the DPDP Rules, 2025, a designated responsible person must be appointed and a web-based submission mechanism provided. Grievances must be resolved within a maximum of 90 days from the date of receipt.- Designate a responsible person for grievance redressal as required by R.14
- Implement a web-based grievance submission mechanism
- Establish 90-day SLA for grievance resolution with structured response format
- Implement tracking and reporting for Data Principal requests
- 9
Security Safeguards
Rule 6 of the DPDP Rules, 2025 mandates specific technical security measures beyond the Act's general 'reasonable security safeguards' standard. Measures must be commensurate with the nature and volume of data processed.- Implement encryption of personal data as required by R.6
- Deploy obfuscation, masking, and virtual tokenisation measures
- Establish access controls limiting access to authorised personnel
- Maintain logs of personal data processing activities for a minimum of 1 year
- Implement two-tier breach notification per R.7: Level 1 without delay, Level 2 within 72 hours
- Conduct periodic security assessments and audits
- 10
Record-Keeping and Governance
Maintaining comprehensive records of data processing activities, consent records, and compliance measures is essential for demonstrating accountability and supporting audits or inquiries by the Data Protection Board.- Establish a register of processing activities documenting purposes, data categories, and retention periods
- Maintain records of consent obtained, withdrawn, and renewed
- Document all Data Principal requests and responses within prescribed timelines
- Implement governance structures for periodic compliance reviews and internal audits
- 11
Periodic Audit
Conducting periodic compliance audits helps organisations verify that their data processing activities continue to align with DPDPA requirements and that policies and safeguards remain effective over time.- Plan and execute regular internal compliance audits
- Review policies, procedures, and technical controls for adequacy
- Document findings, gaps, and remediation actions
- Engage independent auditors where required for Significant Data Fiduciaries
- 12
Training and Awareness
Building a culture of data protection within the organisation through training programmes ensures that employees understand their obligations under the DPDPA and handle personal data responsibly.- Develop role-specific data protection training programmes
- Cover employee obligations, data handling procedures, and breach reporting
- Conduct periodic refresher training and awareness campaigns
- Maintain training records for audit and compliance purposes
Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
