Knowledge base
DPDP Act: documentation and compliance requirements
Everything DPDP Act requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
Prem Kumar Dvivedi · 12 September 2026
This is what DPDP Act requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 58 requirements across 8 areas.
It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free DPDP Act readiness assessment, which scores you out of 100.
Where you stand under the Act
Clauses s.2, s.10, s.3, s.8.
You must be able to answer: For each thing you do with personal data, are you the one who decides why and how it is used, or are you doing it on someone else's instructions?
Evidence: A written note per activity saying whether you are a Data Fiduciary, a Data Processor, or both. Your duties differ a lot, so settle this before answering anything else.
You must have checked whether you might be named a Significant Data Fiduciary.
Evidence: An assessment against the factors: how much and how sensitive the data is, the risk to people's rights, and the effects on sovereignty, the electoral process, security of the State and public order. Any notification received from the Government.
You must know which of your activities the Act covers.
Evidence: Where your processing happens. Note the Act also covers processing outside India connected with offering goods or services to people in India.
You must have identified any data that falls outside the Act because the person made it public themselves.
Evidence: The reasoning, recorded. Do not assume — this exemption is narrower than people think.
You must have a list of everything you do with personal data.
Evidence: A record of processing activities: what data, whose, why, where it came from, who you share it with, and how long you keep it.
Telling people, and getting their agreement
Clauses s.5, s.6, s.7.
You must give people a notice before or when you ask for their personal data.
Evidence: The notice as it actually appears in the customer journey. Screenshots.
The notice must list the actual data you want, item by item — not just a general description.
Evidence: The itemised list in the notice. 'Your personal details' is not enough.
It must say exactly what you will use it for.
Evidence: The specified purpose stated.
It must tell people how to use their rights and how to complain to the Data Protection Board.
Evidence: Both routes given in the notice.
The must be notice available in English and in the other languages listed in the Eighth Schedule, if the person wants.
Evidence: Translated notices, or a working language selector. Evidence the choice is offered clearly.
You must keep old versions of the notice, so you know what each person was actually shown.
Evidence: Version history with the dates each was in use. Consent is only valid against the notice given at the time.
People must have to take a clear action to agree — ticking a box or clicking, not just staying silent.
Evidence: The consent screen or form. No pre-ticked boxes.
You must only ask for the data you actually need for the stated purpose.
Evidence: Evidence of minimisation. Anything beyond what is necessary is not validly consented to.
You must avoid making a service conditional on data you do not need for it.
Evidence: Evidence consent is not bundled with the terms and conditions.
You must be able to show, for any person, what they agreed to and when.
Evidence: Consent records with the date, the method and the notice version.
People must be able to withdraw their agreement as easily as they gave it.
Evidence: The withdrawal route. Compare how easy it is against how easy it was to give.
When someone withdraws, you must stop using the data within a reasonable time — everywhere.
Evidence: Withdrawal records with the date processing stopped. Evidence it reached processors, analytics stores, backups and third parties.
You must tell people the consequences of withdrawing.
Evidence: How the consequences are communicated.
If you use a Consent Manager, they must be registered with the Board, and you must be able to produce the consent record.
Evidence: The agreement and their registration. Ability to retrieve any consent on request. N/A with a reason if you use none.
Where you rely on a legitimate use rather than consent, you must have named which one.
Evidence: The specific ground per activity. Note this is a closed and narrow list — there is no general 'legitimate interests' ground in DPDP, unlike GDPR.
Where you rely on the employment ground, it must be really within what that ground allows.
Evidence: The reasoning. This ground is the one most often over-claimed.
Looking after the data
Clauses s.8, Third Sch..
You must keep personal data accurate and complete, especially where it is used to make a decision about someone.
Evidence: Data quality controls. Extra care where the data leads to a decision affecting the person or is shared with another Fiduciary.
You must have put security measures in place to stop a breach.
Evidence: The measures actually in place: encryption, masking or tokens, access control, monitoring, backups and continuity.
You must keep logs of who accessed what, for at least a year.
Evidence: Log retention configuration showing at least twelve months.
Your processors must be contractually required to keep the same standard of security.
Evidence: Contract terms with each processor.
You must have chosen the measures based on an assessment, rather than assuming.
Evidence: The reasoning behind the measures chosen.
You must delete personal data once the purpose is finished and no law requires you to keep it.
Evidence: A retention schedule by data category. Evidence deletion actually happens, including in backups, archives, analytics stores and test systems.
You must tell your processors to delete it too.
Evidence: The instruction and evidence it was carried out.
You must be able to answer: If you are an e-commerce, online gaming or social media business over the user thresholds, do you follow the erasure timelines in the Third Schedule?
Evidence: The timelines applied. The 48-hour advance notice to the person before erasure. N/A with a reason if the thresholds do not apply to you.
Where you use a processor, there must be a valid written contract.
Evidence: The contract. The Act only allows processing by a processor under one.
You must accept that you stay responsible for compliance, whatever the contract says.
Evidence: Evidence you monitor processors rather than relying on the contract alone.
When something goes wrong
Clause s.8.
You must have a plan for a personal data breach, with the clock starting when you become aware.
Evidence: The breach plan naming roles and the reporting deadlines. Awareness means becoming aware, not confirming the impact.
You must record every breach, including small ones you decided not to escalate.
Evidence: A breach register with the facts and the reasoning for each.
You must tell each affected person, in plain language, what happened and what they can do.
Evidence: Notification content covering the nature and extent, the timing, the likely consequences, what you have done, what they should do, and who to contact.
You must tell the Data Protection Board — first without delay, then in detail within the required period.
Evidence: Both notifications with timestamps.
People's rights and complaints
Clauses s.11, s.12, s.14, s.13, s.8.
A person must be able to get a summary of the data you hold about them, and what you do with it.
Evidence: A request procedure with identity checks. A register with response times. A sample response.
That summary must name the other Fiduciaries and Processors you have shared their data with, and what you shared.
Evidence: The sharing detail in the response. This goes further than most privacy laws.
A person must be able to get their data corrected, completed or updated.
Evidence: Correction records, and evidence corrections reached third parties.
A person must be able to get their data erased, unless a law requires you to keep it.
Evidence: Erasure records showing the data actually went, not just a flag. Refusals recorded with the legal ground.
A person must be able to nominate someone to act for them if they die or become incapable.
Evidence: The nomination route and records. This right has no equivalent in GDPR and is usually missing from systems built to a GDPR design.
There must be a complaints route, and you must answer within the required time.
Evidence: The published route. A register with response times. People must use this before going to the Board, so it has to work.
You must be able to answer: Are the contact details of your Data Protection Officer, or of whoever answers questions, published and easy to find?
Evidence: The details on the website, in the app and in the notice. Evidence the channel is monitored and answers.
Children and people with a guardian
Clause s.9.
You must know whether any of your users are under 18.
Evidence: An age check at the right point in the journey. An untested assumption that no children use your service is not a basis for answering N/A.
You must get verifiable consent from a parent or guardian before processing a child's data.
Evidence: The verification method and evidence it is reliable. Records linking the child's data to the verified consent.
That apply must to people already using your service, not just new sign-ups.
Evidence: Evidence the check was applied to the existing user base.
You must avoid tracking, behavioural monitoring and targeted advertising aimed at children.
Evidence: Controls that switch these off for child users. Third-party trackers, SDKs and ad integrations checked — this is where the duty usually fails.
You must avoid anything likely to harm a child's wellbeing.
Evidence: An assessment with the conclusion recorded. Any exemption you rely on, and the basis for it.
You must treat people with a lawful guardian the same way.
Evidence: The same arrangements applied.
Extra duties if you are named a Significant Data Fiduciary
Clause s.10.
You must have appointed a Data Protection Officer who is based in India and reports to the board.
Evidence: The appointment with the location and reporting line. Evidence of actual reporting to the board. N/A if you are not an SDF — record the assessment from the first section.
You must have appointed an independent data auditor to check your compliance with the Act.
Evidence: The appointment. Evidence of independence. The audit scope, report and findings. Note this is a compliance audit against the Act, not an information security audit under another name.
You must carry out a Data Protection Impact Assessment periodically.
Evidence: Completed assessments covering people's rights, the purpose, and how you manage the risk to them.
You must audit yourself periodically, as well as having the independent audit.
Evidence: Periodic audit records.
You must have checked that any algorithms you use do not put people's rights at risk.
Evidence: Due diligence on the algorithmic software deployed.
You must observe any restriction on sending specified personal data outside India.
Evidence: The restrictions notified, and how you comply.
Being able to prove it
Clauses s.8, 14 May 2027, Schedule.
If the Board asked tomorrow, you must be able to produce the evidence for everything above.
Evidence: A compliance file indexed to the duties. Consent records, notices, registers, breach records, erasure logs and access logs, all retrievable quickly.
You must review your own compliance, rather than waiting to be checked.
Evidence: Internal review or self-audit records.
For anything not yet in place, there must be a plan with an owner and a date that finishes before 14 May 2027.
Evidence: An implementation plan with owners, dates and dependencies. Budget allocated. System and supplier changes booked with realistic lead times.
Senior management must know what the penalties are.
Evidence: Evidence the board has been told. Penalties reach ₹250 crore for failing to take reasonable security safeguards, and ₹200 crore for breach notification and children's data failures.
Using this document
Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.
Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for DPDP Act Compliance, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- India's DPDP consent manager rules bite in November 2026
Rule 4 of the DPDP Rules comes into force on 13 November 2026, with full compliance due by May 2027. What Indian businesses have to have ready.
12 September 2026
- GDPR: documentation and compliance requirements
Everything GDPR requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
- HIPAA: documentation and compliance requirements
Everything HIPAA requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
12 September 2026
