{"id":3133,"date":"2026-09-28T09:45:45","date_gmt":"2026-09-28T09:45:45","guid":{"rendered":"https:\/\/www.sattrix.com\/blog\/?p=3133"},"modified":"2026-09-28T09:49:19","modified_gmt":"2026-09-28T09:49:19","slug":"dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises","status":"publish","type":"post","link":"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/","title":{"rendered":"DPDP Act Compliance Checklist for Indian Mid-Sized Enterprises"},"content":{"rendered":"<p>Most mid-sized companies begin DPDP preparation in the same way. Someone downloads a template, assigns owners, drafts a privacy policy and ticks items off. A few months later, a customer asks what personal data the company holds about them, and nobody can answer with confidence within a week.<\/p><div id=\"ez-toc-container\" class=\"ez-toc-v2_0_69 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title \" >Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#What_DPDP_Readiness_Means_for_a_Mid-Sized_Enterprise\" title=\"What DPDP Readiness Means for a Mid-Sized Enterprise\">What DPDP Readiness Means for a Mid-Sized Enterprise<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Start_with_Personal_Data_Discovery_and_Mapping\" title=\"Start with Personal Data Discovery and Mapping\">Start with Personal Data Discovery and Mapping<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Why_Assumptions_Are_Not_Enough\" title=\"Why Assumptions Are Not Enough\">Why Assumptions Are Not Enough<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Data_Inventory_vs_Data_Mapping\" title=\"Data Inventory vs Data Mapping\">Data Inventory vs Data Mapping<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Why_Everything_Downstream_Depends_on_It\" title=\"Why Everything Downstream Depends on It\">Why Everything Downstream Depends on It<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Establish_Processing_Purposes_and_Consent_Mechanisms\" title=\"Establish Processing Purposes and Consent Mechanisms\">Establish Processing Purposes and Consent Mechanisms<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Consent_Is_a_Process_Not_a_Checkbox\" title=\"Consent Is a Process, Not a Checkbox\">Consent Is a Process, Not a Checkbox<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Prepare_for_Data_Principal_Rights\" title=\"Prepare for Data Principal Rights\">Prepare for Data Principal Rights<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#What_an_Operational_Request_Process_Looks_Like\" title=\"What an Operational Request Process Looks Like\">What an Operational Request Process Looks Like<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Where_Manual_Processes_Break\" title=\"Where Manual Processes Break\">Where Manual Processes Break<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Review_Processor_and_Third-Party_Relationships\" title=\"Review Processor and Third-Party Relationships\">Review Processor and Third-Party Relationships<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Define_Retention_and_Deletion_Rules\" title=\"Define Retention and Deletion Rules\">Define Retention and Deletion Rules<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#What_Good_Looks_Like\" title=\"What Good Looks Like\">What Good Looks Like<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Build_a_Breach_Notification_and_Response_Process\" title=\"Build a Breach Notification and Response Process\">Build a Breach Notification and Response Process<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#A_Workable_Data_Breach_Response_Workflow\" title=\"A Workable Data Breach Response Workflow\">A Workable Data Breach Response Workflow<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Rehearse_Before_It_Is_Real\" title=\"Rehearse Before It Is Real\">Rehearse Before It Is Real<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Create_an_Evidence-Based_Governance_Model\" title=\"Create an Evidence-Based Governance Model\">Create an Evidence-Based Governance Model<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Practical_DPDP_Readiness_Checklist\" title=\"Practical DPDP Readiness Checklist\">Practical DPDP Readiness Checklist<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Common_Mistakes_Indian_Mid-Sized_Enterprises_Should_Avoid\" title=\"Common Mistakes Indian Mid-Sized Enterprises Should Avoid\">Common Mistakes Indian Mid-Sized Enterprises Should Avoid<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#How_to_Maintain_Readiness_as_the_Organisation_Changes\" title=\"How to Maintain Readiness as the Organisation Changes\">How to Maintain Readiness as the Organisation Changes<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Conclusion\" title=\"Conclusion\">Conclusion<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#Frequently_Asked_Questions\" title=\"Frequently Asked Questions\">Frequently Asked Questions<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#1_What_should_a_DPDP_readiness_checklist_include\" title=\"1. What should a DPDP readiness checklist include?\">1. What should a DPDP readiness checklist include?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#2_Why_is_data_discovery_important_for_DPDP_readiness\" title=\"2. Why is data discovery important for DPDP readiness?\">2. Why is data discovery important for DPDP readiness?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#3_How_should_businesses_prepare_for_Data_Principal_requests\" title=\"3. How should businesses prepare for Data Principal requests?\">3. How should businesses prepare for Data Principal requests?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#4_What_should_companies_check_when_working_with_data_processors\" title=\"4. What should companies check when working with data processors?\">4. What should companies check when working with data processors?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#5_Why_are_retention_and_deletion_policies_important\" title=\"5. Why are retention and deletion policies important?\">5. Why are retention and deletion policies important?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#6_How_should_an_organisation_prepare_for_a_personal_data_breach\" title=\"6. How should an organisation prepare for a personal data breach?\">6. How should an organisation prepare for a personal data breach?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"https:\/\/www.sattrix.com\/blog\/dpdp-act-compliance-checklist-for-indian-mid-sized-enterprises\/#7_Is_DPDP_compliance_a_one-time_project_or_an_ongoing_process\" title=\"7. Is DPDP compliance a one-time project or an ongoing process?\">7. Is DPDP compliance a one-time project or an ongoing process?<\/a><\/li><\/ul><\/li><\/ul><\/nav><\/div>\n\n<p>The checklist was finished. The capability behind it was not.<\/p>\n<p>That gap is what this guide is about. A DPDP Act compliance checklist is useful only when leaders see data protection as a governance capability, meaning the ongoing ability to know, control and prove how personal data is handled. It is not a documentation exercise. This guide from Sattrix explains how DPDP obligations turn into real operational work, and what mid-sized enterprises should check, own and evidence.<\/p>\n<p>Note: This article is for general education and is not legal advice. Please validate your approach with qualified legal or compliance professionals, especially as the DPDP Rules are phased in.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"What_DPDP_Readiness_Means_for_a_Mid-Sized_Enterprise\"><\/span>What DPDP Readiness Means for a Mid-Sized Enterprise<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The Digital Personal Data Protection Act, 2023 (DPDP Act) and the <strong><a href=\"https:\/\/www.sattrix.com\/blog\/data-protection-laws-india-dpdp-rules-2025\/\">DPDP Rules, 2025<\/a><\/strong> use some terms that are worth knowing:<\/p>\n<ul>\n<li><strong>Data Fiduciary:<\/strong>\u00a0the organisation that decides why and how personal data is processed. That is usually your company.<\/li>\n<li><strong>Data Principal:<\/strong>\u00a0the individual the data belongs to, such as a customer, employee, job applicant or patient.<\/li>\n<li><strong>Data Processor:<\/strong>\u00a0a third party that processes personal data on your behalf, such as a payroll provider, cloud CRM or call centre.<\/li>\n<\/ul>\n<p>For a mid-sized enterprise, readiness means being able to answer, with evidence, seven practical questions:<\/p>\n<ol>\n<li>What personal data do we hold?<\/li>\n<li>Where does it reside?<\/li>\n<li>How does it move, internally and to third parties?<\/li>\n<li>Why are we processing it?<\/li>\n<li>Who can access it?<\/li>\n<li>How long do we keep it?<\/li>\n<li>What happens when something goes wrong?<\/li>\n<\/ol>\n<p>Mid-sized organisations face particular conditions. IT and security teams are often small, SaaS tools multiply faster than anyone tracks them, and vendor relationships build up over years. Those conditions make visibility harder, and they explain why the first step matters so much.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Start_with_Personal_Data_Discovery_and_Mapping\"><\/span>Start with Personal Data Discovery and Mapping<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>If this article has one central message, it is this:\u00a0data discovery and mapping come first, because everything else depends on them.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Why_Assumptions_Are_Not_Enough\"><\/span><span style=\"font-size: 70%;\">Why Assumptions Are Not Enough<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Take a Pune-based manufacturer with 900 employees. The HR head says all employee data sits in the HRMS. A discovery exercise finds something different:<\/p>\n<ul>\n<li>Aadhaar and PAN scans in a shared network folder<\/li>\n<li>Salary spreadsheets saved on managers&#8217; laptops<\/li>\n<li>Candidate CVs forwarded to personal email accounts<\/li>\n<li>A former payroll vendor that still has SFTP access<\/li>\n<\/ul>\n<p>None of this was deliberate. It happened gradually. It does show why organisations need verified visibility across applications, databases, endpoints, cloud storage, SaaS platforms, email, backups and third-party systems.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Data_Inventory_vs_Data_Mapping\"><\/span><span style=\"font-size: 70%;\">Data Inventory vs Data Mapping<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Data inventory<\/strong>\u00a0records\u00a0what\u00a0personal data exists and<em>\u00a0<\/em>where\u00a0it is stored.<\/li>\n<li><strong>Data mapping<\/strong>\u00a0shows\u00a0how\u00a0that data flows: where it is collected, which systems process it, which vendors receive it and where it ends up.<\/li>\n<\/ul>\n<p>Both matter. An inventory without flows tells you where data sits today but not how it got there or where it goes next.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Why_Everything_Downstream_Depends_on_It\"><\/span><span style=\"font-size: 70%;\">Why Everything Downstream Depends on It<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Without a reliable data map, you cannot confidently:<\/p>\n<ul>\n<li>Apply consent withdrawals to every system that uses the data<\/li>\n<li>Fulfil access or erasure requests completely<\/li>\n<li>Identify which processors hold personal data<\/li>\n<li>Enforce retention and deletion rules<\/li>\n<li>Judge the scope of a breach quickly<\/li>\n<\/ul>\n<p>Organisations that begin with policy documents instead of data inventories often end up with compliance they cannot evidence. The policy says data is deleted after three years, but no one can show where that data lives, so no one can prove the deletion took place.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Establish_Processing_Purposes_and_Consent_Mechanisms\"><\/span>Establish Processing Purposes and Consent Mechanisms<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Every category of personal data should have a clear, documented purpose. The <strong><a href=\"https:\/\/www.sattrix.com\/blog\/data-protection-laws-in-india\/\">DPDP Act<\/a><\/strong> allows processing based on consent or on certain &#8220;legitimate uses&#8221; defined in the law, such as some employment-related purposes. Which basis applies to which activity is a question to confirm with legal advisors.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Consent_Is_a_Process_Not_a_Checkbox\"><\/span><span style=\"font-size: 70%;\">Consent Is a Process, Not a Checkbox<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Treating consent as an operational process means:<\/p>\n<ul>\n<li><strong>Clear notices<\/strong>\u00a0that explain what data is collected, why, and how individuals can exercise their rights, in plain language (and in scheduled Indian languages where required)<\/li>\n<li><strong>Recorded consent<\/strong>\u00a0linked to a specific purpose, with a date, version and channel<\/li>\n<li><strong>Purpose limitation,<\/strong>\u00a0so data collected for delivery is not quietly reused for marketing<\/li>\n<li><strong>Withdrawal that is as easy as giving consent,<\/strong>\u00a0and that actually reaches downstream systems<\/li>\n<\/ul>\n<p class=\"example\"><strong>Example:<\/strong>\u00a0A retail chain runs a loyalty programme. A customer withdraws marketing consent in the app, but the SMS campaigns run through an external agency using a list exported last quarter. The checkbox worked. The process did not.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Prepare_for_Data_Principal_Rights\"><\/span>Prepare for Data Principal Rights<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Data Principals have rights that include accessing information about their data, correcting and updating it, requesting erasure, raising grievances and nominating someone to act for them in certain circumstances.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_an_Operational_Request_Process_Looks_Like\"><\/span><span style=\"font-size: 70%;\">What an Operational Request Process Looks Like<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ol>\n<li><strong>Receive:<\/strong>\u00a0a clearly published channel such as a web form, email address or in-app option<\/li>\n<li><strong>Authenticate:<\/strong>\u00a0confirm the requester&#8217;s identity without collecting excessive new data<\/li>\n<li><strong>Log and track:<\/strong>\u00a0assign a reference number, owner and due date<\/li>\n<li><strong>Fulfil:<\/strong>\u00a0use the data map to locate the data in every system<\/li>\n<li><strong>Escalate:<\/strong>\u00a0set a defined path for complex or disputed requests<\/li>\n<li><strong>Respond and evidence:<\/strong>\u00a0keep a record of what was done and when<\/li>\n<\/ol>\n<p>The DPDP Rules expect organisations to publish response timelines and to resolve grievances within a defined maximum period. Confirm the timelines that apply to you with your advisors.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Where_Manual_Processes_Break\"><\/span><span style=\"font-size: 70%;\">Where Manual Processes Break<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A shared mailbox and a spreadsheet may cope with ten requests a month. After a publicised incident or a large marketing campaign, volumes can jump sharply, and tracking, deadlines and consistency start to slip. Plan for scale before you need it.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Review_Processor_and_Third-Party_Relationships\"><\/span>Review Processor and Third-Party Relationships<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Using a vendor does not transfer your accountability. As the Data Fiduciary, your organisation remains responsible for how processors handle personal data on your behalf.<\/p>\n<p>Mid-sized enterprises should check:<\/p>\n<ul>\n<li><strong>Contracts:<\/strong>\u00a0clear processing instructions, security obligations, breach notification duties, and deletion or return of data when the contract ends<\/li>\n<li><strong>Security controls:<\/strong>\u00a0evidence of reasonable safeguards, not just a signed declaration<\/li>\n<li><strong>Access:<\/strong>\u00a0who at the vendor can reach your data, and whether that access is still needed<\/li>\n<li><strong>Sub-processors:<\/strong>\u00a0whether your vendor passes data on to others<\/li>\n<li><strong>Monitoring:<\/strong>\u00a0periodic reviews, not only a check at onboarding<\/li>\n<\/ul>\n<p class=\"example\"><strong>Example:<\/strong>\u00a0A <strong><a href=\"https:\/\/www.sattrix.com\/managed-cybersecurity-services.php\">managed IT service provider<\/a><\/strong> with domain admin rights, a logistics partner receiving customer addresses and an outsourced payroll firm all hold personal data. Many organisations cannot produce a complete list of such parties on request.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Define_Retention_and_Deletion_Rules\"><\/span>Define Retention and Deletion Rules<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Keeping personal data indefinitely &#8220;just in case&#8221; increases the impact of any breach, makes rights requests harder and is difficult to justify under the DPDP Act&#8217;s purpose-based approach.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_Good_Looks_Like\"><\/span><span style=\"font-size: 70%;\">What Good Looks Like<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Retention schedule:<\/strong>\u00a0how long each data category is kept, and why<\/li>\n<li><strong>Legal alignment:<\/strong>\u00a0reconciling DPDP expectations with other obligations such as tax, labour or sector-specific rules (for example, RBI requirements for regulated entities)<\/li>\n<li><strong>Deletion process:<\/strong>\u00a0covering production systems, file shares, endpoints, backups and vendors<\/li>\n<li><strong>Archival rules:<\/strong>\u00a0restricted access for data kept only for legal reasons<\/li>\n<li><strong>Evidence of disposal:<\/strong>\u00a0deletion logs, vendor certificates and approvals<\/li>\n<\/ul>\n<p class=\"example\"><strong>Example:<\/strong>\u00a0A mid-sized IT services firm holds ten years of job applicant CVs across three recruitment platforms. There is no business purpose for most of them, and each one adds risk.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Build_a_Breach_Notification_and_Response_Process\"><\/span>Build a Breach Notification and Response Process<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A breach plan that exists only as a PDF will struggle at 2 a.m. on a Saturday. Under the DPDP Rules, organisations are expected to inform affected Data Principals and the Data Protection Board without delay, with a more detailed report to the Board within a defined window (currently 72 hours of becoming aware, unless extended). Separate CERT-In reporting obligations for cyber incidents may also apply.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"A_Workable_Data_Breach_Response_Workflow\"><\/span><span style=\"font-size: 70%;\">A Workable Data Breach Response Workflow<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ol>\n<li><strong>Identify:<\/strong>\u00a0detect and report suspected incidents through a known channel<\/li>\n<li><strong>Escalate:<\/strong>\u00a0notify a defined response team with named decision-makers<\/li>\n<li><strong>Investigate:<\/strong>\u00a0determine what data, which individuals and which systems are affected<\/li>\n<li><strong>Decide:<\/strong>\u00a0assess notification obligations with legal input<\/li>\n<li><strong>Communicate:<\/strong>\u00a0prepare approved messages for the Board, individuals, regulators and partners<\/li>\n<li><strong>Document:<\/strong>\u00a0keep a timeline of actions, decisions and evidence<\/li>\n<\/ol>\n<h3><span class=\"ez-toc-section\" id=\"Rehearse_Before_It_Is_Real\"><\/span><span style=\"font-size: 70%;\">Rehearse Before It Is Real<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Run tabletop exercises at least once a year. They quickly expose gaps, such as not knowing who approves external communication or being unable to identify affected individuals because the data map is out of date.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Create_an_Evidence-Based_Governance_Model\"><\/span>Create an Evidence-Based Governance Model<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Privacy governance means someone is accountable, decisions are recorded and claims can be proved. Useful practices include:<\/p>\n<ul>\n<li>A named privacy or data protection lead with clear authority<\/li>\n<li>A RACI (Responsible, Accountable, Consulted, Informed) matrix across IT, security, legal, HR and business teams<\/li>\n<li>Regular reporting to senior management or the board<\/li>\n<li>A central evidence repository, so proof is not scattered across inboxes<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Practical_DPDP_Readiness_Checklist\"><\/span>Practical DPDP Readiness Checklist<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Use this table to assess where your organisation stands today. Treat it as a working DPDP Act <strong><a href=\"https:\/\/www.sattrix.com\/managed-services\/managed-compliance-services.php\">compliance checklist<\/a><\/strong> that you review regularly, not a one-time sign-off.<\/p>\n<div class=\"table-wrap\">\n<table class=\"table table-bordered\">\n<thead>\n<tr style=\"height: 13.8438px;\">\n<th style=\"height: 13.8438px;\">Area<\/th>\n<th style=\"height: 13.8438px;\">What to Check<\/th>\n<th style=\"height: 13.8438px;\">Evidence to Maintain<\/th>\n<th style=\"height: 13.8438px;\">Typical Owner<\/th>\n<th style=\"height: 13.8438px;\">Common Gap<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Personal data inventory<\/td>\n<td style=\"height: 26px;\">All personal data categories and locations identified<\/td>\n<td style=\"height: 26px;\">Data inventory register, discovery scan results<\/td>\n<td style=\"height: 26px;\">IT \/ Security, with business units<\/td>\n<td style=\"height: 26px;\">Relying on interviews instead of verified discovery<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Data flow and mapping<\/td>\n<td style=\"height: 26px;\">Flows between systems, teams and vendors<\/td>\n<td style=\"height: 26px;\">Data flow diagrams, system register<\/td>\n<td style=\"height: 26px;\">IT \/ Enterprise architecture<\/td>\n<td style=\"height: 26px;\">Maps created once and never updated<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Purpose and processing<\/td>\n<td style=\"height: 26px;\">Documented purpose and basis for each activity<\/td>\n<td style=\"height: 26px;\">Processing records, legal assessments<\/td>\n<td style=\"height: 26px;\">Compliance \/ Legal<\/td>\n<td style=\"height: 26px;\">Purposes too vague to enforce<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Consent and notice<\/td>\n<td style=\"height: 26px;\">Clear notices, recorded consent, working withdrawal<\/td>\n<td style=\"height: 26px;\">Consent logs, notice versions<\/td>\n<td style=\"height: 26px;\">Marketing, Product, Legal<\/td>\n<td style=\"height: 26px;\">Withdrawal not reaching vendors<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Data Principal requests<\/td>\n<td style=\"height: 26px;\">Channel, authentication, tracking, timelines<\/td>\n<td style=\"height: 26px;\">Request log, response records<\/td>\n<td style=\"height: 26px;\">Privacy lead, Customer service<\/td>\n<td style=\"height: 26px;\">Email-only handling with no tracking<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Processor and vendor management<\/td>\n<td style=\"height: 26px;\">Contracts, security, access, sub-processors<\/td>\n<td style=\"height: 26px;\">Vendor register, DPAs, assessments<\/td>\n<td style=\"height: 26px;\">Procurement, Security<\/td>\n<td style=\"height: 26px;\">Unknown vendors with data access<\/td>\n<\/tr>\n<tr style=\"height: 13px;\">\n<td style=\"height: 13px;\">Access control<\/td>\n<td style=\"height: 13px;\">Least-privilege access to personal data<\/td>\n<td style=\"height: 13px;\">Access reviews, role matrices<\/td>\n<td style=\"height: 13px;\">IT \/ Security<\/td>\n<td style=\"height: 13px;\">Leavers and movers keeping access<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Data retention<\/td>\n<td style=\"height: 26px;\">Retention period per data category<\/td>\n<td style=\"height: 26px;\">Retention schedule, approvals<\/td>\n<td style=\"height: 26px;\">Compliance, Business owners<\/td>\n<td style=\"height: 26px;\">&#8220;Keep everything&#8221; as the default<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Secure deletion<\/td>\n<td style=\"height: 26px;\">Deletion across systems, backups and vendors<\/td>\n<td style=\"height: 26px;\">Deletion logs, certificates<\/td>\n<td style=\"height: 26px;\">IT Operations<\/td>\n<td style=\"height: 26px;\">Deleted in the app but not in backups<\/td>\n<\/tr>\n<tr style=\"height: 13px;\">\n<td style=\"height: 13px;\">Incident and breach response<\/td>\n<td style=\"height: 13px;\">Tested workflow and notification decisions<\/td>\n<td style=\"height: 13px;\">Incident plan, exercise reports<\/td>\n<td style=\"height: 13px;\">Security, Legal, Leadership<\/td>\n<td style=\"height: 13px;\">Plan never rehearsed<\/td>\n<\/tr>\n<tr style=\"height: 13px;\">\n<td style=\"height: 13px;\">Documentation and evidence<\/td>\n<td style=\"height: 13px;\">Central, current evidence repository<\/td>\n<td style=\"height: 13px;\">Evidence index, audit trails<\/td>\n<td style=\"height: 13px;\">Privacy lead<\/td>\n<td style=\"height: 13px;\">Evidence scattered or outdated<\/td>\n<\/tr>\n<tr style=\"height: 13px;\">\n<td style=\"height: 13px;\">Awareness and training<\/td>\n<td style=\"height: 13px;\">Role-based training for staff handling data<\/td>\n<td style=\"height: 13px;\">Training records, completion rates<\/td>\n<td style=\"height: 13px;\">HR, Security<\/td>\n<td style=\"height: 13px;\">Generic annual training only<\/td>\n<\/tr>\n<tr style=\"height: 26px;\">\n<td style=\"height: 26px;\">Periodic reviews and governance<\/td>\n<td style=\"height: 26px;\">Scheduled reviews and management reporting<\/td>\n<td style=\"height: 26px;\">Review minutes, dashboards<\/td>\n<td style=\"height: 26px;\">Leadership, Privacy lead<\/td>\n<td style=\"height: 26px;\">No owner once the project ends<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"Common_Mistakes_Indian_Mid-Sized_Enterprises_Should_Avoid\"><\/span>Common Mistakes Indian Mid-Sized Enterprises Should Avoid<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ol>\n<li><strong>Starting with policies instead of data.<\/strong>\u00a0Well-written policies cannot be evidenced without a verified inventory.<\/li>\n<li><strong>Treating DPDP as an IT-only project.<\/strong>\u00a0HR, marketing, sales, finance and procurement all handle personal data.<\/li>\n<li><strong>Overlooking unstructured data.<\/strong>\u00a0Spreadsheets, email attachments, WhatsApp exports and scanned documents often hold the most sensitive data.<\/li>\n<li><strong>Ignoring legacy vendors.<\/strong>\u00a0Old contracts rarely include adequate data protection clauses.<\/li>\n<li><strong>Assuming backups are out of scope.<\/strong>\u00a0Retention and deletion decisions must account for them.<\/li>\n<li><strong>Declaring the work &#8220;done&#8221;.<\/strong>\u00a0Readiness decays quickly without ongoing ownership.<\/li>\n<\/ol>\n<h2><span class=\"ez-toc-section\" id=\"How_to_Maintain_Readiness_as_the_Organisation_Changes\"><\/span>How to Maintain Readiness as the Organisation Changes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Data protection readiness is a starting position, not a finish line. It erodes every time:<\/p>\n<ul>\n<li>A new application or SaaS tool is adopted<\/li>\n<li>A vendor is onboarded or replaced<\/li>\n<li>An employee changes roles or leaves<\/li>\n<li>A new form, campaign or product collects fresh data<\/li>\n<li>Systems are migrated to the cloud or consolidated<\/li>\n<li>Business processes are restructured after growth or acquisition<\/li>\n<\/ul>\n<p>To keep pace, build privacy checks into existing processes: procurement approvals, <strong><a href=\"https:\/\/www.sattrix.com\/blog\/ai-change-management-reduce-risk-it-transitions\/\">change management<\/a><\/strong>, employee onboarding and exit, and project kick-offs. Refresh data discovery periodically rather than relying on last year&#8217;s map. Review access, vendors and retention on a set schedule, and report the results to leadership.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Conclusion\"><\/span>Conclusion<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The DPDP Act asks organisations to do more than write good policies. It asks them to know their data, control how it is used and prove it.<\/p>\n<p>For Indian mid-sized enterprises, the most practical path starts with discovery and mapping, then builds consent, rights handling, vendor oversight, retention and breach response on that foundation. Each area needs an owner, a working process and evidence.<\/p>\n<p>Most importantly, treat readiness as something you maintain. Applications, vendors, people and processes will keep changing. Organisations with continuous visibility, clear accountability, regular review and reliable evidence will be better placed to respond to regulators, customers and incidents, whatever changes next.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"1_What_should_a_DPDP_readiness_checklist_include\"><\/span><span style=\"font-size: 70%;\">1. What should a DPDP readiness checklist include?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>It should cover personal data inventory, data mapping, processing purposes, consent and notices, Data Principal requests, vendor management, access control, retention, secure deletion, breach response, evidence, training and periodic governance reviews.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"2_Why_is_data_discovery_important_for_DPDP_readiness\"><\/span><span style=\"font-size: 70%;\">2. Why is data discovery important for DPDP readiness?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Every other obligation depends on knowing what personal data exists and where it flows. Without verified discovery, consent handling, access requests, deletion and breach assessments rest on assumptions.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"3_How_should_businesses_prepare_for_Data_Principal_requests\"><\/span><span style=\"font-size: 70%;\">3. How should businesses prepare for Data Principal requests?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Publish a clear request channel, define how identity is verified, track each request with an owner and deadline, use your data map to find all relevant records, and keep evidence of each response.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"4_What_should_companies_check_when_working_with_data_processors\"><\/span><span style=\"font-size: 70%;\">4. What should companies check when working with data processors?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Check contracts, security safeguards, access levels, sub-processor use, breach notification duties, and data return or deletion at contract end. Maintain a current register of every vendor that handles personal data.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"5_Why_are_retention_and_deletion_policies_important\"><\/span><span style=\"font-size: 70%;\">5. Why are retention and deletion policies important?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Holding data longer than needed increases breach impact and makes compliance harder. A defined retention schedule, backed by a verifiable deletion process, reduces risk and supports purpose limitation.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"6_How_should_an_organisation_prepare_for_a_personal_data_breach\"><\/span><span style=\"font-size: 70%;\">6. How should an organisation prepare for a personal data breach?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Define an escalation path, name decision-makers, prepare notification templates, align DPDP and CERT-In reporting, and run tabletop exercises regularly. Confirm current notification timelines with legal advisors.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"7_Is_DPDP_compliance_a_one-time_project_or_an_ongoing_process\"><\/span><span style=\"font-size: 70%;\">7. Is DPDP compliance a one-time project or an ongoing process?<\/span><span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>It is ongoing. New systems, vendors, employees and data collection points change your risk continuously, so readiness needs regular review, updated evidence and clear ownership.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most mid-sized companies begin DPDP preparation in the same way. Someone downloads a template, assigns<\/p>\n","protected":false},"author":1,"featured_media":3134,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[128,106],"tags":[],"_links":{"self":[{"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/posts\/3133"}],"collection":[{"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/comments?post=3133"}],"version-history":[{"count":2,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/posts\/3133\/revisions"}],"predecessor-version":[{"id":3136,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/posts\/3133\/revisions\/3136"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/media\/3134"}],"wp:attachment":[{"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/media?parent=3133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/categories?post=3133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sattrix.com\/blog\/wp-json\/wp\/v2\/tags?post=3133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}