Knowledge base
DPDP Act: Documentation and Compliance Requirements
This guide explains, in simple language, what organisations need to document under the Digital Personal Data Protection (DPDP) Act) and what an auditor may ask to see as evidence.
Prem Kumar Dvivedi · 12 September 2026
It covers 58 requirements across 8 key areas.
This is not just a checklist asking, “Do you have this?” Instead, it explains what you are required to do and what evidence you should be able to show. This is important when you are building a proper data protection system.
If you first want to understand your current level of compliance, you can use a DPDP Act readiness assessment to identify gaps and measure your readiness.
________________________________________
1. Understanding Your Position Under the Act
Relevant clauses: Sections 2, 3, 8 and 10
You must know whether you are a Data Fiduciary or Data Processor
For every activity involving personal data, you should know whether:
• You decide why and how the data will be used — Data Fiduciary
• You process data based on someone else's instructions — Data Processor
• You perform both roles for different activities.
Evidence an auditor may ask for:
A written record for each data-processing activity showing your role and responsibilities.
________________________________________
You must assess whether you could be a Significant Data Fiduciary (SDF)
You must identify which activities are covered by the DPDP Act
You must identify publicly available personal data correctly
You should assess whether your organisation could be classified as an SDF based on factors such as:
• Volume of personal data
• Sensitivity of the data
• Risk to individuals' rights
• Impact on national sovereignty
• Electoral processes
• Security of the State
• Public order
Evidence:
Documented assessment and any Government notification applicable to your organisation.
________________________________________
You should know which of your data-processing activities fall under the Act.
The Act can also apply to processing outside India when it is connected with offering goods or services to individuals in India.
Evidence:
A documented assessment showing where and how your processing activities take place.
________________________________________
If an individual has made their own personal data publicly available, certain provisions may not apply.
Evidence:
Document the reason for treating the data as outside the scope of the Act.
Do not assume that all publicly available information is automatically exempt.
________________________________________
You must maintain a record of your personal-data activities
You should know:
• What personal data you collect
• Whose data it is
• Why you collect it
• Where it comes from
• Who you share it with
• How long you keep it
Evidence:
A Record of Processing Activities or equivalent documentation.
________________________________________
2. Informing People and Taking Consent
Relevant clauses: Sections 5, 6 and 7
You must provide a privacy notice
People should receive a clear notice before or when you collect their personal data.
Evidence:
The actual notice shown to the person, including screenshots of the customer journey.
________________________________________
The notice must clearly identify the data being collected
Instead of saying only "personal information," clearly specify the types of data being collected.
Evidence:
An itemised list of the data included in the notice.
________________________________________
You must explain why the data is being collected
The notice should clearly state the purpose for which the data will be used.
Evidence:
The specific purpose mentioned in the notice.
________________________________________
You must explain how people can exercise their rights
The notice should explain:
• How individuals can exercise their rights
• How they can raise a complaint with the Data Protection Board
Evidence:
Both routes clearly provided in the notice.
________________________________________
Notices should be available in applicable languages
The notice should be available in English and, where applicable, the languages listed in the Eighth Schedule if the individual requests them.
Evidence:
Translated notices or a working language-selection option.
________________________________________
You must keep previous versions of privacy notices
You should maintain records showing which version of the notice was used and when.
This is important because consent is linked to the notice that was provided when consent was obtained.
Evidence:
Version history with dates.
________________________________________
Consent must be clear and affirmative
People must take a clear action to provide consent, such as ticking a box or clicking a button.
Silence or inactivity should not be treated as consent.
Evidence:
Consent forms or screens showing that there were no pre-selected consent options.
________________________________________
Collect only the data you actually need
You should collect only the information necessary for the stated purpose.
Evidence:
Documentation showing how you have applied data minimisation.
________________________________________
Do not make unnecessary data a condition for providing a service
You should not force people to provide unnecessary personal information just to use a service.
Evidence:
Evidence showing that consent is not improperly bundled with general terms and conditions.
________________________________________
You must be able to prove what a person consented to
For each individual, you should be able to show:
• What they consented to
• When they consented
• How they gave consent
• Which privacy notice they saw
Evidence:
Consent records containing these details.
________________________________________
Withdrawal of consent must be easy
People should be able to withdraw consent as easily as they provided it.
Evidence:
The withdrawal process and evidence showing that it is reasonably easy to use.
________________________________________
Stop processing after consent is withdrawn
Once consent is withdrawn, you must stop processing the data within the required or reasonable timeframe.
This should cover relevant systems, processors, analytics platforms, backups and third parties.
Evidence:
Withdrawal records and evidence that processing was stopped.
________________________________________
Explain what happens if consent is withdrawn
People should be told about the consequences of withdrawing consent.
Evidence:
The information provided to individuals about those consequences.
________________________________________
If you use a Consent Manager
Where applicable, the Consent Manager should be registered with the Board, and you should be able to retrieve consent records.
Evidence:
The relevant agreement, registration details and ability to retrieve consent records.
If you do not use a Consent Manager, document why it is not applicable.
________________________________________
If you rely on a lawful use instead of consent
You must clearly identify the specific legal ground on which you are processing the data.
Evidence:
The legal ground documented for each activity.
The DPDP Act provides specific grounds; it does not have a broad "legitimate interests" basis like GDPR.
________________________________________
Employment-related processing must fit the permitted purpose
If you rely on an employment-related ground, you should ensure the processing genuinely falls within that ground.
Evidence:
Documented reasoning supporting the use of that ground.
________________________________________
3. Protecting Personal Data
Relevant clauses: Section 8 and the Third Schedule
Personal data must be accurate
You should take reasonable steps to keep personal data accurate and complete, especially when the information is used to make decisions about an individual.
Evidence:
Data-quality controls and correction processes.
________________________________________
You must have security controls
You need appropriate safeguards to prevent personal-data breaches.
These may include:
• Encryption
• Masking or tokenisation
• Access controls
• Monitoring
• Backups
• Business continuity measures
Evidence:
Records showing that these controls are actually implemented.
________________________________________
Maintain access logs
You should maintain records showing who accessed what data for at least the required period.
Evidence:
System configuration or logs demonstrating the required retention period.
________________________________________
Processors must follow appropriate security requirements
Contracts with Data Processors should require them to maintain appropriate security measures.
Evidence:
Contracts and security clauses with processors.
________________________________________
Security measures should be based on risk
You should be able to explain why particular security controls were selected.
Evidence:
Risk assessments and documented reasoning behind security measures.
________________________________________
Delete data when it is no longer required
When the purpose for collecting personal data is completed, the data should be deleted unless there is a legal requirement to retain it.
Evidence:
• Data-retention schedule
• Deletion records
• Evidence covering backups, archives, analytics systems and test environments
________________________________________
Processors must also delete the data
You should instruct your processors to delete data when required.
Evidence:
Deletion instructions and confirmation that the processor completed them.
________________________________________
Special deletion requirements may apply to certain businesses
If you operate an e-commerce, online gaming or social media service and meet the relevant thresholds, you need to follow the applicable deletion timelines.
Evidence:
The deletion timelines being followed and the required advance communication to individuals.
If this requirement does not apply, document why.
________________________________________
Processor agreements must be in writing
When using a Data Processor, there should be a valid written contract covering the processing.
Evidence:
The processor agreement.
________________________________________
You remain responsible for compliance
Having a contract with a processor does not remove your responsibility for compliance.
Evidence:
Evidence that you monitor and manage processor compliance.
________________________________________
4. When a Data Breach Happens
Relevant clause: Section 8
You must have a data-breach response plan
Your organisation should have a clear process for handling personal-data breaches.
The response timeline starts when you become aware of the breach.
Evidence:
A documented breach-response plan showing responsibilities and reporting timelines.
________________________________________
Record every personal-data breach
Even smaller incidents should be recorded, including incidents that you decide not to escalate.
Evidence:
A breach register containing the facts, actions taken and reasons for the decisions.
________________________________________
Inform affected individuals
Affected individuals should receive information in clear and simple language explaining:
• What happened
• What data was affected
• When it happened
• Possible consequences
• What action you have taken
• What the individual should do
• Who they can contact
Evidence:
Copies of breach notifications.
________________________________________
Notify the Data Protection Board
You must make the required notification to the Data Protection Board within the applicable timelines.
Evidence:
Copies of notifications and timestamps showing when they were submitted.
________________________________________
5. Individual Rights and Complaints
Relevant clauses: Sections 11, 12, 13, 14 and 8
Individuals must be able to access information about their data
A person should be able to request information about:
• What personal data you hold about them
• How you use it
Evidence:
• Request procedure
• Identity-verification process
• Request register
• Response records
________________________________________
You must disclose relevant data-sharing information
Where required, the response should identify the Data Fiduciaries and Data Processors with whom the individual's data has been shared and the relevant information shared.
Evidence:
Data-sharing details included in the response.
________________________________________
Individuals must be able to correct their data
People should be able to request correction, completion or updating of their personal data.
Evidence:
Correction records and evidence that relevant third parties were informed where required.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for DPDP Act Compliance, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 September 2026
