Most "DPDP compliance checklists" are a lead-gen form wearing a listicle's clothes — ten vague bullet points and a "get your free assessment" button. This one names the section for every item, so you can go read the actual text instead of taking our word for it.
DPDP §5 requires a notice that names what personal data you're collecting, what for, and how someone exercises their rights and reaches the Data Protection Board — given in plain, understandable terms, not buried in a general privacy policy written for lawyers. A notice that lists "your data, for our business purposes" isn't itemised, and an itemised notice is what the section asks for.
§6 sets the bar: free, specific, informed, unconditional and unambiguous, given through clear affirmative action — no pre-ticked boxes, no bundling six purposes behind one checkbox. And it has to be withdrawable at least as easily as it was given (§6(4)), which is a specific, checkable requirement most consent banners fail quietly. We wrote a separate post on exactly how that one gets missed: as easily as you gave it →
§8(5) requires reasonable security safeguards to prevent a breach in the first place. §8(6) covers what happens when one happens anyway: the Board and the affected people have to be told. The Rules set out the mechanics of that notification in more detail than fits in a checklist item — worth reading directly rather than trusting a paraphrase, this one included.
§8(7) requires erasing personal data once its purpose is no longer being served and retention isn't required by some other law — not "eventually," not "when someone asks." The common failure here isn't malice, it's architecture: data that's easy to write and hard to find again tends to just stay, because nothing forces the question.
§9 requires verifiable parental consent before processing a child's personal data, and bars behavioural tracking, targeted advertising, and any processing likely to cause harm to a child — categorically, not "unless the parent consented to that too." The Rules carve out narrow exemptions for specific categories of processing; check whether you actually qualify before assuming you do.
If the Central Government has notified you as one under §10 — based on factors like the volume and sensitivity of what you process — you carry more: a Data Protection Officer, an independent data auditor, and periodic impact assessments. It's a specific legal status, not a synonym for "big company," and it's easy to use loosely. We wrote up that distinction and two others worth getting right: the glossary post →
§§11–14 give people the right to a summary of what's processed about them and who it's shared with, the right to correction and erasure, a grievance-redressal mechanism, and the right to nominate someone to exercise these rights if they die or become incapacitated. A working checklist item here isn't "we have a privacy policy" — it's "someone can ask, and something answers."
§16 lets the Central Government restrict transfer of personal data to specific countries by notification, rather than requiring a country-by-country adequacy finding before any transfer at all. That's a different mechanism from what GDPR uses, and worth checking directly rather than assuming the two work the same way.
This names the sections; it doesn't tell you which apply to your specific data flows, or reproduce every sub-clause and Rule that sits underneath each one. The Act and Rules are the actual source — this is a map to them, not a substitute for reading them, and it isn't legal advice.