DPDP Act 2025 Compliance Checklist for Indian Businesses

Key Takeaways:
- The DPDP Rules were notified on 13 November 2025 and the Data Protection Board is already operational and full compliance is mandatory by 13 May 2027.
- Every Indian business that collects digital personal data qualifies as a Data Fiduciary, regardless of size or industry.
- Breach notification to the Data Protection Board must happen within 72 hours without an incident response playbook, this deadline is impossible to meet.
- Penalties for non-compliance reach ₹250 crore per violation, making the cost of preparation far lower than the cost of a breach.
- Mobile app penetration testing in India directly supports DPDP Rule 6 compliance by validating your technical security safeguards.
What Is the DPDP Act and Why Does It Apply to Your Business?
Your company’s mobile app collects names, phone numbers, and location data from users across India. Your SaaS platform processes employee records for enterprise clients. Your fintech product handles KYC documents.
Until 13 November 2025, India had no comprehensive, enforceable data protection law governing any of this.
That changed when MeitY formally notified the Digital Personal Data Protection Rules, 2025, operationalising the DPDP Act, 2023. India now has a binding privacy regime that applies to every organisation processing the digital personal data of Indian residents whether headquartered in Bengaluru, Mumbai, or globally.
The hard compliance deadline is 13 May 2027. The Data Protection Board is already established and operational today. Penalties are already on the books.
This DPDP compliance checklist covers every obligation your business must meet before that deadline.
Key Definitions Every Indian Business Must Know
Before working through the DPDP compliance checklist, your team needs to understand the legal definitions that shape your obligations.
Data Principal is the individual whose personal data is being processed. For children or persons with disabilities, this includes their parent or lawful guardian.
Data Fiduciary is any organisation that determines the purpose and means of processing personal data.If your business collects and uses personal data and determines how it is processed, it qualifies as a Data Fiduciary. The full DPDP compliance checklist applies to you.
Data Processor is any entity that processes data on behalf of a Data Fiduciary. Even when a processor handles the data, the Data Fiduciary remains primarily liable for compliance.
Significant Data Fiduciary (SDF) is a government designation applied to high-volume or high-sensitivity processors. SDFs carry the heaviest compliance obligations under the Act.
The Three-Phase DPDP Compliance Timeline
Understanding when each obligation activates is foundational to any DPDP compliance checklist for Indian businesses.
| Phase | Date | What Goes Live |
| Phase 1 | 13 Nov 2025 | Data Protection Board established, penalty framework active |
| Phase 2 | 13 Nov 2026 | Consent Manager registration opens |
| Phase 3 | 13 May 2027 | Full compliance mandatory notices, security, breach reporting and rights |
The regulator is operational now. Phase 3 is where businesses without structured programmes will face their first enforcement actions.
DPDP Compliance Checklist for Indian Businesses
1. Consent and Privacy Notice Requirements
The DPDP Act is built on explicit consent as the primary legal basis for processing personal data.
Under Rule 3, a Data Fiduciary must issue a standalone privacy notice separate from your terms and conditions before collecting personal data. The notice must be in plain language, available in English or any of India’s 22 scheduled languages, and must itemise the data being collected, the purpose of processing, and how users can exercise their rights.
Consent must be free, informed, specific, and unambiguous. Pre-ticked boxes, bundled consent, and consent buried in terms of service do not meet the standard.
Data Principals can withdraw consent at any time, and withdrawal must be as easy as giving consent. Once withdrawn, processing must stop unless a separate lawful basis exists.
By November 2026, your systems must also be technically capable of integrating with registered Consent Managers; this is an architecture requirement, not a policy update.
2. Data Principal Rights — 90-Day Response Window
The DPDP Rules require Data Fiduciaries to build accessible channels for every individual right. All requests must be resolved within 90 days.
Right to Access — users can request a summary of what personal data you hold and how it is being used.
Right to Correction — Individuals can request that inaccurate or incomplete data be corrected or updated.
Right to Erasure — when personal data is no longer needed, or consent is withdrawn, users can request deletion. Your systems must be capable of reliably locating and deleting that data.
Right to Nominate — a unique provision of the DPDP Act allowing users to appoint a nominee to exercise their rights in case of death or incapacity.
Grievance Redressal — every Data Fiduciary must publish a grievance officer’s contact details and resolve complaints within 90 days. For Significant Data Fiduciaries, a formally appointed Data Protection Officer is mandatory.
3. Security Safeguards — Technical Controls Under Rule 6
Rule 6 mandates that Data Fiduciaries implement reasonable security safeguards to prevent personal data breaches. Failure carries a penalty of up to ₹250 crore.
The minimum required controls under Rule 6 are:
- Encryption and tokenisation of personal data at rest and in transit — covering databases, APIs, backups, and all data transmission
- Role-based access controls — only those with a legitimate need should access personal data, with all access events logged
- Active monitoring and logging — passive log storage is not sufficient; detection, investigation, and remediation capability is required
- Data backup and business continuity — systems holding personal data must have tested recovery capabilities
- Data Processor contracts (Rule 6(f)) — every vendor agreement must require the processor to implement equivalent safeguards; standard SaaS terms will not meet this requirement
For SaaS and BFSI companies in India, security testing of every data collection surface web applications, APIs, and mobile apps is a practical requirement of demonstrating Rule 6 compliance.
4. Personal Data Breach Notification — The 72-Hour Rule
This is where most Indian businesses are least prepared. The breach notification obligations are dual-tracked, prescriptive, and fast.
Notify affected Data Principals without delay. On becoming aware of a breach, inform each affected user immediately in plain language via their registered communication channel. Describe the breach, its likely consequences, mitigation steps taken, and safety actions they can take.
Submit a detailed report to the Data Protection Board within 72 hours. An initial intimation must go to the Board without delay. Within 72 hours, a full report must follow — covering the nature, extent, cause, mitigation measures, and confirmation of user notifications.
CERT-In dual clock. For SaaS and cloud-hosted businesses, CERT-In’s directive requires a separate 6-hour cyber incident notification simultaneously. Your incident response playbook must handle both clocks at once.
Building and testing an incident response playbook before a breach occurs is not optional. Seventy-two hours is three calendar days from detection to full regulatory reporting. Without automated detection, internal escalation, and pre-written communication templates, this deadline cannot be met in practice.
5. Data Retention and Erasure
Personal data must be erased once the purpose is served and consent has lapsed, unless a legal retention obligation applies.
Also Read : Establishing Data Retention and Erasure Policies: Integrating GRC Frameworks for DPDPA Compliance
Large-scale e-commerce platforms with 20 million+ Indian users, online gaming platforms with 5 million+ users, and social media platforms with 20 million+ users must erase personal data after three years of user inactivity, with a 48-hour erasure notice sent to the user before deletion.
All organisations must retain personal data processing logs for a minimum of one year.
6. Children’s Data
The DPDP Act defines a child as anyone under 18.
Verifiable parental consent is mandatory before processing any data belonging to a minor, using government-recognised identity verification or Digital Locker credentials.
Targeted advertising and profiling of minors is explicitly prohibited. Platforms serving users under 18 must implement age-gating and disable behavioural tracking and ad-targeting for minor users.
7. Significant Data Fiduciary Obligations
Large-scale SaaS platforms, major BFSI entities, healthcare networks, and social media intermediaries are the most likely candidates for SDF designation. While the formal government list has not yet been published, businesses that may qualify should begin readiness planning now.
Annual DPIA — a comprehensive Data Protection Impact Assessment must be conducted every 12 months and submitted to the Data Protection Board by an independent professional.
Annual independent data protection audit — conducted separately from the DPIA and also reported to the Board.
Algorithmic due diligence — technical systems including AI and recommendation engines must not harm the rights of Data Principals.
Data Protection Officer — formally appointed, with contact details publicly published for Data Principals and the Board.
DPDP Act Penalties for Non-Compliance in India
Understanding the penalty structure is essential for communicating the urgency of the DPDP compliance checklist to your leadership and board.
| Violation | Maximum Penalty |
| Failure to maintain reasonable security safeguards | ₹250 crore |
| Failure to notify Board and users of a breach | ₹250 crore |
| Breach of children’s data protection obligations | ₹200 crore |
| Non-compliance by Significant Data Fiduciaries | ₹150 crore |
| Breach of Data Principal rights obligations | ₹10,000 |
In cases of repeated serious non-compliance, the Central Government can direct blocking of access to the Data Fiduciary’s services, the equivalent of an operational shutdown order.
How Mobile App Penetration Testing Supports DPDP Compliance
For most Indian businesses, mobile applications are the primary personal data collection surface. Rule 6’s security safeguard obligations apply fully to your iOS and Android apps.
Mobile app penetration testing in India validates whether your application actually meets the “reasonable security safeguards” standard that Rule 6 requires. A professional assessment tests whether personal data is encrypted at rest and in transit, whether API endpoints are protected against injection and unauthorised access, whether authentication mechanisms are resilient to credential theft, and whether the app leaks data through insecure local storage or third-party SDKs.
Also Read : Ultimate Mobile Application Security Checklist For Indian Businesses
An undetected vulnerability in your mobile app is a breach event waiting to happen. Under the DPDP Act, the financial and regulatory consequences of that breach are now legally and financially quantified.
Wattlecorp’s mobile app penetration testing services in India are conducted by OSCP and CEH-certified professionals and are fully aligned to DPDP Rule 6 requirements, covering both iOS and Android platforms.
Strengthen Your DPDP Compliance Posture with Wattlecorp
A DPDP compliance checklist tells your team what needs to be done. A professional data privacy consulting engagement tells you whether your controls actually meet the standard — and builds the infrastructure to maintain compliance as the regulatory framework continues to evolve.
Wattlecorp‘s data privacy consulting services in India cover gap assessments against the DPDP Act and Rules, privacy notice and consent architecture reviews, breach notification playbook development, security safeguard technical testing, and Significant Data Fiduciary readiness programmes all aligned to RBI, SEBI, and IRDAI frameworks where applicable.
DPDP Compliance Checklist FAQs
1.What is included in a practical DPDP compliance checklist for Indian businesses?
A practical DPDP compliance checklist covers consent and privacy notice requirements under Rule 3, Data Principal rights management with 90-day response SLAs, technical security safeguards under Rule 6 including encryption and access controls, 72-hour breach notification to the Data Protection Board and immediate user notification, purpose-based data retention and erasure policies, verifiable parental consent for children’s data, and Significant Data Fiduciary obligations for high-volume processors. For businesses with mobile apps, the checklist must also include mobile app penetration testing in India to validate that technical controls meet the Rule 6 security standard.
2.What changed after the Digital Personal Data Protection Rules, 2025 were notified?
The DPDP Rules, notified on 13 November 2025, turned the Act from a principles framework into an operational compliance regime. They introduced standalone privacy notice requirements with itemised content, Consent Manager integration standards, 72-hour breach reporting timelines, prescriptive security safeguard measures, purpose-based data retention policies, verifiable parental consent for children, and annual DPIA and audit obligations for Significant Data Fiduciaries with a hard compliance deadline of 13 May 2027.
3.When must a company notify users and the Board about a personal data breach?
Affected Data Principals must be notified without delay immediately upon detection in plain language. The Data Protection Board must receive an initial intimation without delay and a detailed follow-up report within 72 hours. For companies also subject to CERT-In’s 2022 directive, a separate 6-hour cyber incident notification runs concurrently. A mature, automated incident response playbook is the only way to meet both deadlines reliably.
4.Which businesses may face additional obligations as Significant Data Fiduciaries?
SDFs are designated by the Central Government based on data volume, sensitivity, and risk. Likely candidates include large-scale SaaS platforms, major BFSI entities, social media intermediaries with 20M+ Indian users, and healthcare networks processing sensitive data at scale. SDFs must conduct annual DPIAs, independent audits, algorithmic due diligence, appoint a mandatory DPO, and prepare for potential data localisation requirements.
5.How does mobile app penetration testing support DPDP compliance in India?
Mobile app penetration testing in India validates that your application meets the “reasonable security safeguards” standard required by Rule 6. A professional assessment tests encryption at rest and in transit, API security against unauthorised access, authentication resilience to credential theft, and data leakage through insecure storage or third-party SDKs. For BFSI and SaaS companies, it also builds the documented security evidence that enterprise buyers and the Data Protection Board will expect. Wattlecorp’s mobile app penetration testing covers iOS and Android platforms and is fully aligned to DPDP Rule 6.
Third-Party Vendor Security Risk Assessment Under DPDP: A Guide for Indian Enterprises
Key Takeaways: Third-party vendor risk assessment with DPDP practices helps Indian enterprises to verify that external partners handle personal data with adequate safeguards. The Digital Personal Data Protection Act holds data fiduciaries accountable for vendor conduct, which makes due diligence a legal and operational necessity. A structured vendor security questionnaire, covering encryption, access control, and […]
Virtual CISO Services for UAE Free Zone Startups: Affordable Security Leadership for Growing Companies
Key Takeaways: Most startups already hold sensitive data such as customer info, source code, financials, long before they feel big enough to take security seriously, and that’s exactly when the risk starts. A virtual CISO gets you someone who’s done this before, setting up strategy and guiding compliance, without the cost of putting a full-time […]
SOC as a Service for Indian BFSI and FinTech Companies: 24/7 Monitoring for CERT-In Readiness
Key Takeaways: SOC as a Service for BFSI and FinTech India gives banks, NBFCs, insurers and digital lenders continuous security visibility without the cost and hiring effort of building an in-house operations centre. CERT-In directions require regulated entities to report qualifying cyber incidents within six hours of detection, and implementing SOC for BFSI and FinTech […]
SOC as a Service in India: How It Works, Pricing, and Why Businesses Need ItÂ
Key Takeaways: SOC as a Service helps Indian businesses to get 24×7 security monitoring without huge cost and complexity of building a full in-house security operations center. A managed SOC check and analyse beyond basic log monitoring, which combining SIEM, threat intelligence, analyst-led alert triage, incident escalation, reporting, and security response support. SOC as a […]
Mobile App Security Testing for Indian Digital Lending Apps RBI, DPDP and API Risk Checklist
Key Takeaways: Mobile app security testing forms an important part of meeting RBI cybersecurity expectations, secure application development practices, and periodic security assessment requirements for digital lending platforms. APIs in lending apps are constantly under attack. Broken object-level authorization, data leaking where it shouldn’t, weak token validation, and missing rate limiting, these aren’t edge cases, […]
Cybersecurity Risk Assessment for Saudi Supply Chain Vendors Under Aramco and NCA ExpectationsÂ
Key Takeaways: Cybersecurity risk assessment becomes a practical requirement for proving security maturity, with protecting vendor relationships, and moving forward in procurement processes with Aramco and critical infrastructure clients. Vendors will need to provide evidence of access review documentation, patch deployment, monitoring artifacts, technical assessment results and more that demonstrates the controls in place are […]