From the blog · 28 August 2026

A checklist that cites its sections.
Not vibes.

Most "DPDP compliance checklists" are a lead-gen form wearing a listicle's clothes — ten vague bullet points and a "get your free assessment" button. This one names the section for every item, so you can go read the actual text instead of taking our word for it.

1 · Notice, before or at the point of consent

DPDP §5 requires a notice that names what personal data you're collecting, what for, and how someone exercises their rights and reaches the Data Protection Board — given in plain, understandable terms, not buried in a general privacy policy written for lawyers. A notice that lists "your data, for our business purposes" isn't itemised, and an itemised notice is what the section asks for.

2 · Consent that's actually specific

§6 sets the bar: free, specific, informed, unconditional and unambiguous, given through clear affirmative action — no pre-ticked boxes, no bundling six purposes behind one checkbox. And it has to be withdrawable at least as easily as it was given (§6(4)), which is a specific, checkable requirement most consent banners fail quietly. We wrote a separate post on exactly how that one gets missed: as easily as you gave it →

3 · Reasonable security safeguards, and what happens when they fail

§8(5) requires reasonable security safeguards to prevent a breach in the first place. §8(6) covers what happens when one happens anyway: the Board and the affected people have to be told. The Rules set out the mechanics of that notification in more detail than fits in a checklist item — worth reading directly rather than trusting a paraphrase, this one included.

4 · Erasure when the purpose is served

§8(7) requires erasing personal data once its purpose is no longer being served and retention isn't required by some other law — not "eventually," not "when someone asks." The common failure here isn't malice, it's architecture: data that's easy to write and hard to find again tends to just stay, because nothing forces the question.

5 · Children's data gets a stricter bar

§9 requires verifiable parental consent before processing a child's personal data, and bars behavioural tracking, targeted advertising, and any processing likely to cause harm to a child — categorically, not "unless the parent consented to that too." The Rules carve out narrow exemptions for specific categories of processing; check whether you actually qualify before assuming you do.

6 · Extra duties if you're a Significant Data Fiduciary

If the Central Government has notified you as one under §10 — based on factors like the volume and sensitivity of what you process — you carry more: a Data Protection Officer, an independent data auditor, and periodic impact assessments. It's a specific legal status, not a synonym for "big company," and it's easy to use loosely. We wrote up that distinction and two others worth getting right: the glossary post →

7 · The rights a Data Principal can actually exercise

§§11–14 give people the right to a summary of what's processed about them and who it's shared with, the right to correction and erasure, a grievance-redressal mechanism, and the right to nominate someone to exercise these rights if they die or become incapacitated. A working checklist item here isn't "we have a privacy policy" — it's "someone can ask, and something answers."

8 · Cross-border transfer isn't automatically fine, or automatically blocked

§16 lets the Central Government restrict transfer of personal data to specific countries by notification, rather than requiring a country-by-country adequacy finding before any transfer at all. That's a different mechanism from what GDPR uses, and worth checking directly rather than assuming the two work the same way.

Where this checklist stops, on purpose

This names the sections; it doesn't tell you which apply to your specific data flows, or reproduce every sub-clause and Rule that sits underneath each one. The Act and Rules are the actual source — this is a map to them, not a substitute for reading them, and it isn't legal advice.