S shape representing Sattrix
We Serve, We Prove, We Repeat
DPDP Act Compliance Checklist for Indian Mid-Sized Enterprises

Most mid-sized companies begin DPDP preparation in the same way. Someone downloads a template, assigns owners, drafts a privacy policy and ticks items off. A few months later, a customer asks what personal data the company holds about them, and nobody can answer with confidence within a week.

The checklist was finished. The capability behind it was not.

That gap is what this guide is about. A DPDP Act compliance checklist is useful only when leaders see data protection as a governance capability, meaning the ongoing ability to know, control and prove how personal data is handled. It is not a documentation exercise. This guide from Sattrix explains how DPDP obligations turn into real operational work, and what mid-sized enterprises should check, own and evidence.

Note: This article is for general education and is not legal advice. Please validate your approach with qualified legal or compliance professionals, especially as the DPDP Rules are phased in.

What DPDP Readiness Means for a Mid-Sized Enterprise

The Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 use some terms that are worth knowing:

  • Data Fiduciary: the organisation that decides why and how personal data is processed. That is usually your company.
  • Data Principal: the individual the data belongs to, such as a customer, employee, job applicant or patient.
  • Data Processor: a third party that processes personal data on your behalf, such as a payroll provider, cloud CRM or call centre.

For a mid-sized enterprise, readiness means being able to answer, with evidence, seven practical questions:

  1. What personal data do we hold?
  2. Where does it reside?
  3. How does it move, internally and to third parties?
  4. Why are we processing it?
  5. Who can access it?
  6. How long do we keep it?
  7. What happens when something goes wrong?

Mid-sized organisations face particular conditions. IT and security teams are often small, SaaS tools multiply faster than anyone tracks them, and vendor relationships build up over years. Those conditions make visibility harder, and they explain why the first step matters so much.

Start with Personal Data Discovery and Mapping

If this article has one central message, it is this: data discovery and mapping come first, because everything else depends on them.

Why Assumptions Are Not Enough

Take a Pune-based manufacturer with 900 employees. The HR head says all employee data sits in the HRMS. A discovery exercise finds something different:

  • Aadhaar and PAN scans in a shared network folder
  • Salary spreadsheets saved on managers’ laptops
  • Candidate CVs forwarded to personal email accounts
  • A former payroll vendor that still has SFTP access

None of this was deliberate. It happened gradually. It does show why organisations need verified visibility across applications, databases, endpoints, cloud storage, SaaS platforms, email, backups and third-party systems.

Data Inventory vs Data Mapping

  • Data inventory records what personal data exists and where it is stored.
  • Data mapping shows how that data flows: where it is collected, which systems process it, which vendors receive it and where it ends up.

Both matter. An inventory without flows tells you where data sits today but not how it got there or where it goes next.

Why Everything Downstream Depends on It

Without a reliable data map, you cannot confidently:

  • Apply consent withdrawals to every system that uses the data
  • Fulfil access or erasure requests completely
  • Identify which processors hold personal data
  • Enforce retention and deletion rules
  • Judge the scope of a breach quickly

Organisations that begin with policy documents instead of data inventories often end up with compliance they cannot evidence. The policy says data is deleted after three years, but no one can show where that data lives, so no one can prove the deletion took place.

Establish Processing Purposes and Consent Mechanisms

Every category of personal data should have a clear, documented purpose. The DPDP Act allows processing based on consent or on certain “legitimate uses” defined in the law, such as some employment-related purposes. Which basis applies to which activity is a question to confirm with legal advisors.

Consent Is a Process, Not a Checkbox

Treating consent as an operational process means:

  • Clear notices that explain what data is collected, why, and how individuals can exercise their rights, in plain language (and in scheduled Indian languages where required)
  • Recorded consent linked to a specific purpose, with a date, version and channel
  • Purpose limitation, so data collected for delivery is not quietly reused for marketing
  • Withdrawal that is as easy as giving consent, and that actually reaches downstream systems

Example: A retail chain runs a loyalty programme. A customer withdraws marketing consent in the app, but the SMS campaigns run through an external agency using a list exported last quarter. The checkbox worked. The process did not.

Prepare for Data Principal Rights

Data Principals have rights that include accessing information about their data, correcting and updating it, requesting erasure, raising grievances and nominating someone to act for them in certain circumstances.

What an Operational Request Process Looks Like

  1. Receive: a clearly published channel such as a web form, email address or in-app option
  2. Authenticate: confirm the requester’s identity without collecting excessive new data
  3. Log and track: assign a reference number, owner and due date
  4. Fulfil: use the data map to locate the data in every system
  5. Escalate: set a defined path for complex or disputed requests
  6. Respond and evidence: keep a record of what was done and when

The DPDP Rules expect organisations to publish response timelines and to resolve grievances within a defined maximum period. Confirm the timelines that apply to you with your advisors.

Where Manual Processes Break

A shared mailbox and a spreadsheet may cope with ten requests a month. After a publicised incident or a large marketing campaign, volumes can jump sharply, and tracking, deadlines and consistency start to slip. Plan for scale before you need it.

Review Processor and Third-Party Relationships

Using a vendor does not transfer your accountability. As the Data Fiduciary, your organisation remains responsible for how processors handle personal data on your behalf.

Mid-sized enterprises should check:

  • Contracts: clear processing instructions, security obligations, breach notification duties, and deletion or return of data when the contract ends
  • Security controls: evidence of reasonable safeguards, not just a signed declaration
  • Access: who at the vendor can reach your data, and whether that access is still needed
  • Sub-processors: whether your vendor passes data on to others
  • Monitoring: periodic reviews, not only a check at onboarding

Example: A managed IT service provider with domain admin rights, a logistics partner receiving customer addresses and an outsourced payroll firm all hold personal data. Many organisations cannot produce a complete list of such parties on request.

Define Retention and Deletion Rules

Keeping personal data indefinitely “just in case” increases the impact of any breach, makes rights requests harder and is difficult to justify under the DPDP Act’s purpose-based approach.

What Good Looks Like

  • Retention schedule: how long each data category is kept, and why
  • Legal alignment: reconciling DPDP expectations with other obligations such as tax, labour or sector-specific rules (for example, RBI requirements for regulated entities)
  • Deletion process: covering production systems, file shares, endpoints, backups and vendors
  • Archival rules: restricted access for data kept only for legal reasons
  • Evidence of disposal: deletion logs, vendor certificates and approvals

Example: A mid-sized IT services firm holds ten years of job applicant CVs across three recruitment platforms. There is no business purpose for most of them, and each one adds risk.

Build a Breach Notification and Response Process

A breach plan that exists only as a PDF will struggle at 2 a.m. on a Saturday. Under the DPDP Rules, organisations are expected to inform affected Data Principals and the Data Protection Board without delay, with a more detailed report to the Board within a defined window (currently 72 hours of becoming aware, unless extended). Separate CERT-In reporting obligations for cyber incidents may also apply.

A Workable Data Breach Response Workflow

  1. Identify: detect and report suspected incidents through a known channel
  2. Escalate: notify a defined response team with named decision-makers
  3. Investigate: determine what data, which individuals and which systems are affected
  4. Decide: assess notification obligations with legal input
  5. Communicate: prepare approved messages for the Board, individuals, regulators and partners
  6. Document: keep a timeline of actions, decisions and evidence

Rehearse Before It Is Real

Run tabletop exercises at least once a year. They quickly expose gaps, such as not knowing who approves external communication or being unable to identify affected individuals because the data map is out of date.

Create an Evidence-Based Governance Model

Privacy governance means someone is accountable, decisions are recorded and claims can be proved. Useful practices include:

  • A named privacy or data protection lead with clear authority
  • A RACI (Responsible, Accountable, Consulted, Informed) matrix across IT, security, legal, HR and business teams
  • Regular reporting to senior management or the board
  • A central evidence repository, so proof is not scattered across inboxes

Practical DPDP Readiness Checklist

Use this table to assess where your organisation stands today. Treat it as a working DPDP Act compliance checklist that you review regularly, not a one-time sign-off.

Area What to Check Evidence to Maintain Typical Owner Common Gap
Personal data inventory All personal data categories and locations identified Data inventory register, discovery scan results IT / Security, with business units Relying on interviews instead of verified discovery
Data flow and mapping Flows between systems, teams and vendors Data flow diagrams, system register IT / Enterprise architecture Maps created once and never updated
Purpose and processing Documented purpose and basis for each activity Processing records, legal assessments Compliance / Legal Purposes too vague to enforce
Consent and notice Clear notices, recorded consent, working withdrawal Consent logs, notice versions Marketing, Product, Legal Withdrawal not reaching vendors
Data Principal requests Channel, authentication, tracking, timelines Request log, response records Privacy lead, Customer service Email-only handling with no tracking
Processor and vendor management Contracts, security, access, sub-processors Vendor register, DPAs, assessments Procurement, Security Unknown vendors with data access
Access control Least-privilege access to personal data Access reviews, role matrices IT / Security Leavers and movers keeping access
Data retention Retention period per data category Retention schedule, approvals Compliance, Business owners “Keep everything” as the default
Secure deletion Deletion across systems, backups and vendors Deletion logs, certificates IT Operations Deleted in the app but not in backups
Incident and breach response Tested workflow and notification decisions Incident plan, exercise reports Security, Legal, Leadership Plan never rehearsed
Documentation and evidence Central, current evidence repository Evidence index, audit trails Privacy lead Evidence scattered or outdated
Awareness and training Role-based training for staff handling data Training records, completion rates HR, Security Generic annual training only
Periodic reviews and governance Scheduled reviews and management reporting Review minutes, dashboards Leadership, Privacy lead No owner once the project ends

Common Mistakes Indian Mid-Sized Enterprises Should Avoid

  1. Starting with policies instead of data. Well-written policies cannot be evidenced without a verified inventory.
  2. Treating DPDP as an IT-only project. HR, marketing, sales, finance and procurement all handle personal data.
  3. Overlooking unstructured data. Spreadsheets, email attachments, WhatsApp exports and scanned documents often hold the most sensitive data.
  4. Ignoring legacy vendors. Old contracts rarely include adequate data protection clauses.
  5. Assuming backups are out of scope. Retention and deletion decisions must account for them.
  6. Declaring the work “done”. Readiness decays quickly without ongoing ownership.

How to Maintain Readiness as the Organisation Changes

Data protection readiness is a starting position, not a finish line. It erodes every time:

  • A new application or SaaS tool is adopted
  • A vendor is onboarded or replaced
  • An employee changes roles or leaves
  • A new form, campaign or product collects fresh data
  • Systems are migrated to the cloud or consolidated
  • Business processes are restructured after growth or acquisition

To keep pace, build privacy checks into existing processes: procurement approvals, change management, employee onboarding and exit, and project kick-offs. Refresh data discovery periodically rather than relying on last year’s map. Review access, vendors and retention on a set schedule, and report the results to leadership.

Conclusion

The DPDP Act asks organisations to do more than write good policies. It asks them to know their data, control how it is used and prove it.

For Indian mid-sized enterprises, the most practical path starts with discovery and mapping, then builds consent, rights handling, vendor oversight, retention and breach response on that foundation. Each area needs an owner, a working process and evidence.

Most importantly, treat readiness as something you maintain. Applications, vendors, people and processes will keep changing. Organisations with continuous visibility, clear accountability, regular review and reliable evidence will be better placed to respond to regulators, customers and incidents, whatever changes next.

Frequently Asked Questions

1. What should a DPDP readiness checklist include?

It should cover personal data inventory, data mapping, processing purposes, consent and notices, Data Principal requests, vendor management, access control, retention, secure deletion, breach response, evidence, training and periodic governance reviews.

2. Why is data discovery important for DPDP readiness?

Every other obligation depends on knowing what personal data exists and where it flows. Without verified discovery, consent handling, access requests, deletion and breach assessments rest on assumptions.

3. How should businesses prepare for Data Principal requests?

Publish a clear request channel, define how identity is verified, track each request with an owner and deadline, use your data map to find all relevant records, and keep evidence of each response.

4. What should companies check when working with data processors?

Check contracts, security safeguards, access levels, sub-processor use, breach notification duties, and data return or deletion at contract end. Maintain a current register of every vendor that handles personal data.

5. Why are retention and deletion policies important?

Holding data longer than needed increases breach impact and makes compliance harder. A defined retention schedule, backed by a verifiable deletion process, reduces risk and supports purpose limitation.

6. How should an organisation prepare for a personal data breach?

Define an escalation path, name decision-makers, prepare notification templates, align DPDP and CERT-In reporting, and run tabletop exercises regularly. Confirm current notification timelines with legal advisors.

7. Is DPDP compliance a one-time project or an ongoing process?

It is ongoing. New systems, vendors, employees and data collection points change your risk continuously, so readiness needs regular review, updated evidence and clear ownership.

Share It Now: