Knowledge base

DPDP Act: Documentation and Compliance Requirements

This guide explains, in simple language, what organisations need to document under the Digital Personal Data Protection (DPDP) Act) and what an auditor may ask to see as evidence.

Prem Kumar Dvivedi · 12. September 2026

It covers 58 requirements across 8 key areas.

This is not just a checklist asking, “Do you have this?” Instead, it explains what you are required to do and what evidence you should be able to show. This is important when you are building a proper data protection system.

If you first want to understand your current level of compliance, you can use a DPDP Act readiness assessment to identify gaps and measure your readiness.

________________________________________

1. Understanding Your Position Under the Act

Relevant clauses: Sections 2, 3, 8 and 10

You must know whether you are a Data Fiduciary or Data Processor

For every activity involving personal data, you should know whether:

• You decide why and how the data will be used — Data Fiduciary

• You process data based on someone else's instructions — Data Processor

• You perform both roles for different activities.

Evidence an auditor may ask for:

A written record for each data-processing activity showing your role and responsibilities.

________________________________________

You must assess whether you could be a Significant Data Fiduciary (SDF)
You must identify which activities are covered by the DPDP Act
You must identify publicly available personal data correctly

You should assess whether your organisation could be classified as an SDF based on factors such as:

• Volume of personal data

• Sensitivity of the data

• Risk to individuals' rights

• Impact on national sovereignty

• Electoral processes

• Security of the State

• Public order

Evidence:

Documented assessment and any Government notification applicable to your organisation.

________________________________________

You should know which of your data-processing activities fall under the Act.

The Act can also apply to processing outside India when it is connected with offering goods or services to individuals in India.

Evidence:

A documented assessment showing where and how your processing activities take place.

________________________________________

If an individual has made their own personal data publicly available, certain provisions may not apply.

Evidence:

Document the reason for treating the data as outside the scope of the Act.

Do not assume that all publicly available information is automatically exempt.

________________________________________

You must maintain a record of your personal-data activities

You should know:

• What personal data you collect

• Whose data it is

• Why you collect it

• Where it comes from

• Who you share it with

• How long you keep it

Evidence:

A Record of Processing Activities or equivalent documentation.

________________________________________

2. Informing People and Taking Consent

Relevant clauses: Sections 5, 6 and 7

You must provide a privacy notice

People should receive a clear notice before or when you collect their personal data.

Evidence:

The actual notice shown to the person, including screenshots of the customer journey.

________________________________________

The notice must clearly identify the data being collected

Instead of saying only "personal information," clearly specify the types of data being collected.

Evidence:

An itemised list of the data included in the notice.

________________________________________

You must explain why the data is being collected

The notice should clearly state the purpose for which the data will be used.

Evidence:

The specific purpose mentioned in the notice.

________________________________________

You must explain how people can exercise their rights

The notice should explain:

• How individuals can exercise their rights

• How they can raise a complaint with the Data Protection Board

Evidence:

Both routes clearly provided in the notice.

________________________________________

Notices should be available in applicable languages

The notice should be available in English and, where applicable, the languages listed in the Eighth Schedule if the individual requests them.

Evidence:

Translated notices or a working language-selection option.

________________________________________

You must keep previous versions of privacy notices

You should maintain records showing which version of the notice was used and when.

This is important because consent is linked to the notice that was provided when consent was obtained.

Evidence:

Version history with dates.

________________________________________

Consent must be clear and affirmative

People must take a clear action to provide consent, such as ticking a box or clicking a button.

Silence or inactivity should not be treated as consent.

Evidence:

Consent forms or screens showing that there were no pre-selected consent options.

________________________________________

Collect only the data you actually need

You should collect only the information necessary for the stated purpose.

Evidence:

Documentation showing how you have applied data minimisation.

________________________________________

Do not make unnecessary data a condition for providing a service

You should not force people to provide unnecessary personal information just to use a service.

Evidence:

Evidence showing that consent is not improperly bundled with general terms and conditions.

________________________________________

You must be able to prove what a person consented to

For each individual, you should be able to show:

• What they consented to

• When they consented

• How they gave consent

• Which privacy notice they saw

Evidence:

Consent records containing these details.

________________________________________

Withdrawal of consent must be easy

People should be able to withdraw consent as easily as they provided it.

Evidence:

The withdrawal process and evidence showing that it is reasonably easy to use.

________________________________________

Stop processing after consent is withdrawn

Once consent is withdrawn, you must stop processing the data within the required or reasonable timeframe.

This should cover relevant systems, processors, analytics platforms, backups and third parties.

Evidence:

Withdrawal records and evidence that processing was stopped.

________________________________________

Explain what happens if consent is withdrawn

People should be told about the consequences of withdrawing consent.

Evidence:

The information provided to individuals about those consequences.

________________________________________

If you use a Consent Manager

Where applicable, the Consent Manager should be registered with the Board, and you should be able to retrieve consent records.

Evidence:

The relevant agreement, registration details and ability to retrieve consent records.

If you do not use a Consent Manager, document why it is not applicable.

________________________________________

If you rely on a lawful use instead of consent

You must clearly identify the specific legal ground on which you are processing the data.

Evidence:

The legal ground documented for each activity.

The DPDP Act provides specific grounds; it does not have a broad "legitimate interests" basis like GDPR.

________________________________________

Employment-related processing must fit the permitted purpose

If you rely on an employment-related ground, you should ensure the processing genuinely falls within that ground.

Evidence:

Documented reasoning supporting the use of that ground.

________________________________________

3. Protecting Personal Data
Relevant clauses: Section 8 and the Third Schedule

Personal data must be accurate

You should take reasonable steps to keep personal data accurate and complete, especially when the information is used to make decisions about an individual.

Evidence:

Data-quality controls and correction processes.

________________________________________

You must have security controls

You need appropriate safeguards to prevent personal-data breaches.

These may include:

• Encryption

• Masking or tokenisation

• Access controls

• Monitoring

• Backups

• Business continuity measures

Evidence:

Records showing that these controls are actually implemented.

________________________________________

Maintain access logs

You should maintain records showing who accessed what data for at least the required period.

Evidence:

System configuration or logs demonstrating the required retention period.

________________________________________

Processors must follow appropriate security requirements

Contracts with Data Processors should require them to maintain appropriate security measures.

Evidence:

Contracts and security clauses with processors.

________________________________________

Security measures should be based on risk

You should be able to explain why particular security controls were selected.

Evidence:

Risk assessments and documented reasoning behind security measures.

________________________________________

Delete data when it is no longer required

When the purpose for collecting personal data is completed, the data should be deleted unless there is a legal requirement to retain it.

Evidence:

• Data-retention schedule

• Deletion records

• Evidence covering backups, archives, analytics systems and test environments

________________________________________

Processors must also delete the data

You should instruct your processors to delete data when required.

Evidence:

Deletion instructions and confirmation that the processor completed them.

________________________________________

Special deletion requirements may apply to certain businesses

If you operate an e-commerce, online gaming or social media service and meet the relevant thresholds, you need to follow the applicable deletion timelines.

Evidence:

The deletion timelines being followed and the required advance communication to individuals.

If this requirement does not apply, document why.

________________________________________

Processor agreements must be in writing

When using a Data Processor, there should be a valid written contract covering the processing.

Evidence:

The processor agreement.

________________________________________

You remain responsible for compliance

Having a contract with a processor does not remove your responsibility for compliance.

Evidence:

Evidence that you monitor and manage processor compliance.

________________________________________

4. When a Data Breach Happens
Relevant clause: Section 8

You must have a data-breach response plan

Your organisation should have a clear process for handling personal-data breaches.

The response timeline starts when you become aware of the breach.

Evidence:

A documented breach-response plan showing responsibilities and reporting timelines.

________________________________________

Record every personal-data breach

Even smaller incidents should be recorded, including incidents that you decide not to escalate.

Evidence:

A breach register containing the facts, actions taken and reasons for the decisions.

________________________________________

Inform affected individuals

Affected individuals should receive information in clear and simple language explaining:

• What happened

• What data was affected

• When it happened

• Possible consequences

• What action you have taken

• What the individual should do

• Who they can contact

Evidence:

Copies of breach notifications.

________________________________________

Notify the Data Protection Board

You must make the required notification to the Data Protection Board within the applicable timelines.

Evidence:

Copies of notifications and timestamps showing when they were submitted.

________________________________________

5. Individual Rights and Complaints
Relevant clauses: Sections 11, 12, 13, 14 and 8

Individuals must be able to access information about their data

A person should be able to request information about:

• What personal data you hold about them

• How you use it

Evidence:

• Request procedure

• Identity-verification process

• Request register

• Response records

________________________________________

You must disclose relevant data-sharing information

Where required, the response should identify the Data Fiduciaries and Data Processors with whom the individual's data has been shared and the relevant information shared.

Evidence:

Data-sharing details included in the response.

________________________________________

Individuals must be able to correct their data

People should be able to request correction, completion or updating of their personal data.

Evidence:

Correction records and evidence that relevant third parties were informed where required.

What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for DPDP Act Compliance, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles