All resources
Playbook 6 min read
DPDP by 13 May 2027: a readiness checklist
C1The Compliance One team13 September 2026
DPDP readiness is not a single project; it is a set of registers and workflows that have to exist and stay current. Here is the checklist, in the order most teams should tackle it.
Build these first
- A Record of Processing Activities: every processing activity with its lawful basis (consent or a s.7 use), data categories, recipients, processors and retention.
- Notices and a consent ledger: an itemised, standalone notice (Rule 3) and a record of every consent given and withdrawn, tied to the notice version shown — because you carry the burden of proof.
- A rights and grievances queue: access, correction, erasure, nomination and grievance handling, answered within 90 days.
- A retention schedule and erasure log: erase on withdrawal or purpose-completion, honour the class 3-year rule, and keep the evidence.
Then the higher-risk regimes
- Breach response: every breach is notifiable — no harm threshold — to each affected person without delay and to the Board with a detailed report within 72 hours.
- Children's data: verifiable parental consent, age assurance, no tracking or targeted ads.
- Significant Data Fiduciary duties, if designated: an India-based DPO, an independent auditor, annual DPIAs and audits, algorithmic due diligence, and localisation of specified data.
- A cross-border transfer register: DPDP allows transfers everywhere except countries the government restricts — but sectoral localisation (RBI, SEBI, IRDAI) still overrides.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.