Most mid-sized companies begin DPDP preparation in the same way. Someone downloads a template, assigns owners, drafts a privacy policy and ticks items off. A few months later, a customer asks what personal data the company holds about them, and nobody can answer with confidence within a week.
The checklist was finished. The capability behind it was not.
That gap is what this guide is about. A DPDP Act compliance checklist is useful only when leaders see data protection as a governance capability, meaning the ongoing ability to know, control and prove how personal data is handled. It is not a documentation exercise. This guide from Sattrix explains how DPDP obligations turn into real operational work, and what mid-sized enterprises should check, own and evidence.
Note: This article is for general education and is not legal advice. Please validate your approach with qualified legal or compliance professionals, especially as the DPDP Rules are phased in.
The Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025 use some terms that are worth knowing:
For a mid-sized enterprise, readiness means being able to answer, with evidence, seven practical questions:
Mid-sized organisations face particular conditions. IT and security teams are often small, SaaS tools multiply faster than anyone tracks them, and vendor relationships build up over years. Those conditions make visibility harder, and they explain why the first step matters so much.
If this article has one central message, it is this: data discovery and mapping come first, because everything else depends on them.
Take a Pune-based manufacturer with 900 employees. The HR head says all employee data sits in the HRMS. A discovery exercise finds something different:
None of this was deliberate. It happened gradually. It does show why organisations need verified visibility across applications, databases, endpoints, cloud storage, SaaS platforms, email, backups and third-party systems.
Both matter. An inventory without flows tells you where data sits today but not how it got there or where it goes next.
Without a reliable data map, you cannot confidently:
Organisations that begin with policy documents instead of data inventories often end up with compliance they cannot evidence. The policy says data is deleted after three years, but no one can show where that data lives, so no one can prove the deletion took place.
Every category of personal data should have a clear, documented purpose. The DPDP Act allows processing based on consent or on certain “legitimate uses” defined in the law, such as some employment-related purposes. Which basis applies to which activity is a question to confirm with legal advisors.
Treating consent as an operational process means:
Example: A retail chain runs a loyalty programme. A customer withdraws marketing consent in the app, but the SMS campaigns run through an external agency using a list exported last quarter. The checkbox worked. The process did not.
Data Principals have rights that include accessing information about their data, correcting and updating it, requesting erasure, raising grievances and nominating someone to act for them in certain circumstances.
The DPDP Rules expect organisations to publish response timelines and to resolve grievances within a defined maximum period. Confirm the timelines that apply to you with your advisors.
A shared mailbox and a spreadsheet may cope with ten requests a month. After a publicised incident or a large marketing campaign, volumes can jump sharply, and tracking, deadlines and consistency start to slip. Plan for scale before you need it.
Using a vendor does not transfer your accountability. As the Data Fiduciary, your organisation remains responsible for how processors handle personal data on your behalf.
Mid-sized enterprises should check:
Example: A managed IT service provider with domain admin rights, a logistics partner receiving customer addresses and an outsourced payroll firm all hold personal data. Many organisations cannot produce a complete list of such parties on request.
Keeping personal data indefinitely “just in case” increases the impact of any breach, makes rights requests harder and is difficult to justify under the DPDP Act’s purpose-based approach.
Example: A mid-sized IT services firm holds ten years of job applicant CVs across three recruitment platforms. There is no business purpose for most of them, and each one adds risk.
A breach plan that exists only as a PDF will struggle at 2 a.m. on a Saturday. Under the DPDP Rules, organisations are expected to inform affected Data Principals and the Data Protection Board without delay, with a more detailed report to the Board within a defined window (currently 72 hours of becoming aware, unless extended). Separate CERT-In reporting obligations for cyber incidents may also apply.
Run tabletop exercises at least once a year. They quickly expose gaps, such as not knowing who approves external communication or being unable to identify affected individuals because the data map is out of date.
Privacy governance means someone is accountable, decisions are recorded and claims can be proved. Useful practices include:
Use this table to assess where your organisation stands today. Treat it as a working DPDP Act compliance checklist that you review regularly, not a one-time sign-off.
| Area | What to Check | Evidence to Maintain | Typical Owner | Common Gap |
|---|---|---|---|---|
| Personal data inventory | All personal data categories and locations identified | Data inventory register, discovery scan results | IT / Security, with business units | Relying on interviews instead of verified discovery |
| Data flow and mapping | Flows between systems, teams and vendors | Data flow diagrams, system register | IT / Enterprise architecture | Maps created once and never updated |
| Purpose and processing | Documented purpose and basis for each activity | Processing records, legal assessments | Compliance / Legal | Purposes too vague to enforce |
| Consent and notice | Clear notices, recorded consent, working withdrawal | Consent logs, notice versions | Marketing, Product, Legal | Withdrawal not reaching vendors |
| Data Principal requests | Channel, authentication, tracking, timelines | Request log, response records | Privacy lead, Customer service | Email-only handling with no tracking |
| Processor and vendor management | Contracts, security, access, sub-processors | Vendor register, DPAs, assessments | Procurement, Security | Unknown vendors with data access |
| Access control | Least-privilege access to personal data | Access reviews, role matrices | IT / Security | Leavers and movers keeping access |
| Data retention | Retention period per data category | Retention schedule, approvals | Compliance, Business owners | “Keep everything” as the default |
| Secure deletion | Deletion across systems, backups and vendors | Deletion logs, certificates | IT Operations | Deleted in the app but not in backups |
| Incident and breach response | Tested workflow and notification decisions | Incident plan, exercise reports | Security, Legal, Leadership | Plan never rehearsed |
| Documentation and evidence | Central, current evidence repository | Evidence index, audit trails | Privacy lead | Evidence scattered or outdated |
| Awareness and training | Role-based training for staff handling data | Training records, completion rates | HR, Security | Generic annual training only |
| Periodic reviews and governance | Scheduled reviews and management reporting | Review minutes, dashboards | Leadership, Privacy lead | No owner once the project ends |
Data protection readiness is a starting position, not a finish line. It erodes every time:
To keep pace, build privacy checks into existing processes: procurement approvals, change management, employee onboarding and exit, and project kick-offs. Refresh data discovery periodically rather than relying on last year’s map. Review access, vendors and retention on a set schedule, and report the results to leadership.
The DPDP Act asks organisations to do more than write good policies. It asks them to know their data, control how it is used and prove it.
For Indian mid-sized enterprises, the most practical path starts with discovery and mapping, then builds consent, rights handling, vendor oversight, retention and breach response on that foundation. Each area needs an owner, a working process and evidence.
Most importantly, treat readiness as something you maintain. Applications, vendors, people and processes will keep changing. Organisations with continuous visibility, clear accountability, regular review and reliable evidence will be better placed to respond to regulators, customers and incidents, whatever changes next.
It should cover personal data inventory, data mapping, processing purposes, consent and notices, Data Principal requests, vendor management, access control, retention, secure deletion, breach response, evidence, training and periodic governance reviews.
Every other obligation depends on knowing what personal data exists and where it flows. Without verified discovery, consent handling, access requests, deletion and breach assessments rest on assumptions.
Publish a clear request channel, define how identity is verified, track each request with an owner and deadline, use your data map to find all relevant records, and keep evidence of each response.
Check contracts, security safeguards, access levels, sub-processor use, breach notification duties, and data return or deletion at contract end. Maintain a current register of every vendor that handles personal data.
Holding data longer than needed increases breach impact and makes compliance harder. A defined retention schedule, backed by a verifiable deletion process, reduces risk and supports purpose limitation.
Define an escalation path, name decision-makers, prepare notification templates, align DPDP and CERT-In reporting, and run tabletop exercises regularly. Confirm current notification timelines with legal advisors.
It is ongoing. New systems, vendors, employees and data collection points change your risk continuously, so readiness needs regular review, updated evidence and clear ownership.