All resources
Playbook 6 min read

DPDP by 13 May 2027: a readiness checklist

C1The Compliance One team13 September 2026

DPDP readiness is not a single project; it is a set of registers and workflows that have to exist and stay current. Here is the checklist, in the order most teams should tackle it.

Build these first

  • A Record of Processing Activities: every processing activity with its lawful basis (consent or a s.7 use), data categories, recipients, processors and retention.
  • Notices and a consent ledger: an itemised, standalone notice (Rule 3) and a record of every consent given and withdrawn, tied to the notice version shown — because you carry the burden of proof.
  • A rights and grievances queue: access, correction, erasure, nomination and grievance handling, answered within 90 days.
  • A retention schedule and erasure log: erase on withdrawal or purpose-completion, honour the class 3-year rule, and keep the evidence.

Then the higher-risk regimes

  • Breach response: every breach is notifiable — no harm threshold — to each affected person without delay and to the Board with a detailed report within 72 hours.
  • Children's data: verifiable parental consent, age assurance, no tracking or targeted ads.
  • Significant Data Fiduciary duties, if designated: an India-based DPO, an independent auditor, annual DPIAs and audits, algorithmic due diligence, and localisation of specified data.
  • A cross-border transfer register: DPDP allows transfers everywhere except countries the government restricts — but sectoral localisation (RBI, SEBI, IRDAI) still overrides.

See it on your own frameworks

Book a 30-minute walkthrough and we'll map this to your environment.