Privacy and security

DPDP Act readiness: a practical checklist for IT and engineering teams

What India's Digital Personal Data Protection Act and the DPDP Rules 2025 mean for systems, logs, consent and breach response, with a phased checklist.

Published
Reading time
5 minutes
Written by
Plurentoo Systems

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive data protection law. The DPDP Rules, 2025 were notified in November 2025, and most obligations switch on in phases after that. Legal teams will own the interpretation. IT and engineering teams will own most of the work. This checklist focuses on that work.

The timeline in plain terms

The Rules were published with a staggered start, counted from the date of notification in November 2025:

  • Immediately: provisions that set up the Data Protection Board of India.
  • After about 12 months (around November 2026): the framework for registered Consent Managers.
  • After about 18 months (around May 2027): the core duties of Data Fiduciaries, including notices, consent, security safeguards, breach intimation, retention, children's data and the rights of Data Principals.

Eighteen months sounds generous until you list the systems that hold personal data. Most organizations need that time to find the data, fix the gaps and prove the fixes work.

1. Know what personal data you hold

Everything else depends on an accurate inventory. For each system, record:

  • What personal data it stores, including free-text fields and attachments.
  • Why it is collected, and which business process relies on it.
  • Where it lives: cloud region, data center, SaaS vendor, backups and logs.
  • Who can access it, and through which roles or service accounts.
  • Which processors (vendors) handle it on your behalf.
  • How long it is kept, and what happens at the end of that period.

Start with the systems that face customers and employees: CRM, HR and payroll, support desks, marketing tools, websites and mobile apps. Include analytics tags and data warehouses, which often hold more personal data than anyone expects.

2. Rebuild notices and consent flows

Where consent is the basis for processing, the Rules require a notice that stands on its own and is easy to understand. It should describe the personal data being collected, the specific purposes, and how a person can withdraw consent, exercise their rights and complain to the Board.

  • Replace pre-ticked boxes with a clear affirmative action.
  • Split bundled consents so each purpose can be accepted or declined separately.
  • Make withdrawal as easy as giving consent, in the same channel.
  • Store a record of what was shown, what was chosen and when.
  • Give people the option to read the notice in English or in any language listed in the Eighth Schedule to the Constitution.

Not every processing activity needs consent. The Act also allows certain legitimate uses, such as processing data a person has voluntarily provided for a specified purpose. Map each purpose to its basis with your legal team before redesigning screens.

3. Put the security safeguards in writing and in code

The Rules list reasonable security safeguards that a Data Fiduciary must take. In practice, expect to show:

  • Encryption, masking, obfuscation or tokenization of personal data where appropriate.
  • Access controls on systems and data, with regular reviews.
  • Logging and monitoring that can detect and investigate unauthorized access.
  • Backups and continuity measures so data stays available after an incident.
  • Retention of relevant logs for at least one year.
  • Contracts that require the same safeguards from processors.

If you already follow ISO/IEC 27001 or run a mature security program, much of this exists. The gap is often evidence: documented controls, review records and test results that an auditor or the Board can read.

4. Prepare to report breaches quickly

When a personal data breach happens, the Rules require you to inform affected people without delay and in plain language, and to inform the Board without delay, followed by a detailed report within 72 hours. Separately, CERT-In directions already require many cyber incidents to be reported within six hours.

  • Write an incident response plan that covers both timelines.
  • Pre-draft notification templates for individuals and regulators.
  • Make sure logs, clock synchronization and forensics access are in place before you need them.
  • Run a tabletop exercise at least once a year.

5. Handle rights requests as a workflow

Data Principals can ask to access information about their data, correct or erase it, nominate someone to act for them, and raise grievances. You must publish how to make these requests, and grievances must be resolved within a maximum of 90 days.

  • Provide a simple request form and a monitored mailbox.
  • Define how you verify identity without collecting more data than needed.
  • Build search and export scripts for your main systems.
  • Track every request with dates, owners and outcomes.

You can see how we handle this on our own privacy request page.

6. Set retention and erasure rules

Personal data should be erased once the purpose is served or consent is withdrawn, unless the law requires you to keep it. The Rules also set a minimum one-year retention for certain data and logs, and they add specific erasure timelines for some large platforms. Translate all of this into retention schedules that systems can enforce automatically, including in backups and data warehouses.

7. Treat children's data with extra care

Under the Act, a child is anyone under 18. Processing their data generally needs verifiable consent from a parent or lawful guardian, and tracking, behavioral monitoring and targeted advertising directed at children are restricted. Education, health and consumer platforms should review sign-up flows and age assurance early.

8. Publish a contact point and name owners

Every Data Fiduciary must publish the business contact details of a person who can answer questions about its processing. Significant Data Fiduciaries must also appoint a Data Protection Officer based in India, carry out periodic impact assessments and audits, and meet additional obligations.

A phased plan that fits most organizations

  1. Now: complete the data inventory, name owners and fix obvious security gaps such as shared accounts and missing logs.
  2. Next six months: redesign notices and consent flows, sign processor contracts, and build the rights request workflow.
  3. Before May 2027: automate retention, rehearse breach response and collect evidence that each control works.

Penalties are significant

The schedule to the Act sets penalties of up to INR 250 crore for failing to take reasonable security safeguards, up to INR 200 crore for failing to notify breaches or meet the obligations for children's data, and up to INR 150 crore for breaching the additional obligations of Significant Data Fiduciaries. Other breaches can attract penalties of up to INR 50 crore.

How we can help

Plurentoo runs data inventories, security assessments and remediation programs, and builds the consent, logging and request workflows the Act expects. See our cybersecurity and data governance services, or talk to us about a readiness review.

Keep reading

More insights

Want to apply this to your own systems?

Tell us where you are starting from and what you need to decide. A real person from our delivery team will reply with questions and options.