Compliance programmes fail when they start with policy documents instead of data. This checklist follows the order that actually works: first know your data, then fix consent, then build the operational muscle. Work through it top to bottom — each step depends on the one above it.
Inventory every place personal data lives: databases, CRM and ERP systems, file shares, email, spreadsheets, cloud drives, WhatsApp exports, paper converted to PDF. For each source record what data it holds, why, who accesses it and where it flows onward.
This is the step organisations most want to skip and least can afford to. Every later obligation queries this inventory: valid consent needs to know what you collect, access responses need to locate a person's data, erasure needs to know every copy, and breach scoping needs it under time pressure. Done manually it is a months-long project that is stale on completion; done with automated discovery it becomes a continuously maintained asset.
Done when: you can name every system holding personal data, and no one on the team can point to a store that isn't on the list.
Tag data by category and purpose. Then delete what you no longer need — data you don't hold is data you can't breach, can't be asked to produce, and can't be penalised over. Purpose limitation and storage limitation are legal duties, not hygiene. Most organisations find years of over-retention here: old exports, superseded backups, departed employees' files, admission records from a decade ago.
Done when: every data store has an owner, a purpose and a retention period.
For each activity in your inventory, identify the basis: consent, or one of the Act's legitimate uses — voluntary provision for a specified purpose, employment purposes, compliance with law, medical emergencies, State functions. Remember there is no general legitimate-interest basis as under GDPR; if your processing doesn't fit a listed use, you need consent.
Two findings recur in assessments: organisations claiming legitimate use for marketing (almost never valid), and organisations collecting fresh consent for HR processing they were already entitled to perform under employment purposes.
Done when: every row in your inventory has a basis and a one-line justification.
Then audit your existing consent base. Consent that wouldn't meet the Act's standard needs either a fresh compliant notice, a re-mapped basis, or the processing stops. See the seven requirements of valid consent.
Done when: you can produce, for any individual, the exact notice they saw and the purposes they agreed to.
Set up an intake channel for access, correction and erasure requests; verify requester identity without collecting excess data; locate the person's data across every system and vendor; respond within timelines; and log everything. Maintain a request register — date received, verification performed, systems searched, action taken, date responded, approver.
Done when: you could fulfil an access request and an erasure request end-to-end this week, with a record of both.
The Rules set the floor: encryption or equivalent protection of personal data, access control on a need-to-know basis, logging and monitoring to detect unauthorised access, backups, and log retention sufficient to investigate a breach. Add protection that persists when files leave your network — the majority of exposure in most organisations sits in unstructured documents, not databases.
The heaviest penalty in the Act — ₹250 crore — attaches to this duty, and it is assessed on whether safeguards existed, not on whether you intended well.
Done when: you could document, with evidence, what controls were operating on a given date.
Write and rehearse an incident playbook: detection, scoping (whose data, what fields), containment, and notification to the Board and every affected individual. Pre-draft notification templates. Run a tabletop exercise annually.
During a live incident is the wrong time to discover you can't tell whose data was exposed. Organisations with a current inventory scope in hours; those without spend days and still submit an estimate to the regulator.
Done when: a tabletop exercise shows you could file the 72-hour report on time.
If you process data of anyone under 18: implement verifiable parental consent — verification that the consenting adult is an identifiable adult, not merely a ticked box — and eliminate tracking, behavioural monitoring and targeted advertising directed at children. Review every third-party app and platform you use with minors for the same. Education institutes, edtech, gaming and consumer platforms should treat this as their highest-priority item given the ₹200-crore tier.
Processors act on your behalf, but liability stays with you. Maintain a register of processors and the data each touches. Update contracts with purpose limitation, security obligations, breach notification to you fast enough to meet your own 72-hour duty, sub-processor disclosure, audit rights, and deletion on exit. Close out dormant vendor accounts holding old exports — a recurring breach source.
Appoint a privacy owner (a DPO if you are a Significant Data Fiduciary — and good practice regardless), publish their contact details, and run role-based training for leadership, IT, HR, sales and front-line staff. Most breaches begin with a person, not a system. Keep training records; they form part of your evidence pack.
| Question | If "no"... |
|---|---|
| Can you list every system holding personal data? | Start at Step 1 |
| Does every processing activity have a documented basis? | Go to Step 3 |
| Are all your consents unbundled and evidenced? | Go to Step 4 |
| Could you fulfil an erasure request in a week? | Go to Step 5 |
| Could you scope a breach within 72 hours? | Go to Step 7 |
| Do your vendor contracts contain DPDP clauses? | Go to Step 9 |
Every "no" is a gap the Data Protection Board could examine. Ranked by exposure, Steps 1, 6 and 7 carry the largest penalties — but Steps 3, 4 and 5 are where most organisations are currently non-compliant.
Privonta Shield helps Companies, Government, SMEs and Education Institutes meet every DPDP obligation — data discovery, consent management, rights workflows and audit trails, deployed inside your own boundary. Book a free DPDP assessment →
Get a personalised compliance assessment — free, no obligation.
Book a Free Assessment →