India's Digital Personal Data Protection Act (DPDPA) sets out how organisations must handle the personal data of individuals in India. If your organisation collects, stores or processes personal data — and almost every organisation does — you need a program that satisfies its obligations and, just as importantly, lets you prove you satisfy them. This checklist walks through the essentials.
Know your role and your data
Start by understanding whether you act as a data fiduciary (you determine why and how personal data is processed) and building an accurate picture of the personal data you hold.
- Maintain a data inventory: what personal data you hold, where it lives, and why.
- Map the flows: how data enters, moves through and leaves your systems, including third parties.
- Classify data by sensitivity so protection matches risk.
Consent and notice
DPDPA places weight on lawful processing and clear communication with the individual (the data principal).
- Obtain and record consent where required, with the ability to withdraw it as easily as it was given.
- Provide a clear notice describing what data you collect and the purpose.
- Process data only for the purpose it was collected for (purpose limitation).
Security safeguards
You are expected to protect personal data with reasonable security safeguards. In practice this looks a lot like a sound information-security program.
- Access control, encryption and secure configuration for systems holding personal data.
- Vendor and processor oversight for any third party that touches personal data.
- Logging and monitoring so you can detect and investigate incidents.
Data-principal rights and grievance handling
- Enable individuals to access, correct and erase their data where applicable.
- Stand up a grievance-handling process and, where required, a point of contact for data-protection queries.
Breach handling and retention
- Define a breach response and notification process aligned to regulatory expectations.
- Set and enforce retention limits — don't keep personal data longer than needed.
Evidence it — continuously
As with any regulation, meeting the obligation is only half the job; you also have to demonstrate it. Turning DPDPA obligations into a managed control set, each linked to the evidence that proves it, is what makes compliance sustainable rather than a periodic scramble. Because DPDPA's security expectations overlap heavily with ISO 27001, most of that evidence can be reused across both — which is how Pelta approaches it, with shared control mappings and one connected Evidence Engine.
DPDPA
- Controls mapped
- Evidence collected
- Policies & procedures in place
Adding GDPR
~70% carried overAuto-completed from your existing program
Overlap shown is illustrative — the actual carry-over depends on the maturity of your existing program.
Frequently asked questions
Who does the DPDPA apply to?+
The DPDPA applies to the processing of digital personal data of individuals in India, with specific obligations for data fiduciaries. Confirm your role and the applicable rules for your organisation.
How is DPDPA different from GDPR?+
Both protect personal data and share core principles like consent, purpose limitation and security. DPDPA is India's own law with its own definitions, obligations and enforcement; many controls overlap, so evidence can often be reused across both.
What's the hardest part of DPDPA compliance?+
For most teams it's operationalising and continuously evidencing the obligations — consent records, data-principal requests, vendor oversight and security safeguards — rather than understanding the principles.