India's Digital Personal Data Protection Act (DPDPA), 2023 applies to almost every organisation that handles personal data. Most teams know it is coming but are not sure where their gaps are. This is a practical readiness checklist to help you find out.
If you collect, store or process the personal data of individuals in India, DPDPA applies to you as a Data Fiduciary. Readiness comes down to five things: knowing what data you hold, having a lawful basis (usually consent), securing it, being able to honour individuals' rights, and being ready to report a breach. Start with a data-flow map.
Does DPDPA apply to you?
The Act governs the processing of digital personal data in India, and personal data of individuals in India even when processed elsewhere in connection with offering goods or services to them. In practice, if you run a business that holds customer, employee or user data digitally — a fintech, a SaaS product, a healthtech platform, a D2C brand, an agency — you are almost certainly a Data Fiduciary with obligations under the Act.
The core concepts, in plain terms
| Term | What it means for you |
|---|---|
| Data Principal | The individual whose data you hold — your customer, user or employee. |
| Data Fiduciary | You — the organisation deciding why and how personal data is processed. |
| Consent | Must be free, specific, informed and unambiguous, with a clear notice and an easy way to withdraw. |
| Purpose limitation | Use data only for the purpose you collected it for. |
| Data Principal rights | Access, correction, erasure, and grievance redressal — you must be able to action these. |
A practical readiness checklist
1. Map your data
- List every place personal data enters, lives and leaves — forms, apps, CRMs, spreadsheets, third-party tools.
- Record what you collect, why, where it is stored, who can access it, and how long you keep it.
2. Fix your lawful basis
- Review every collection point for a clear notice and genuine, specific consent.
- Provide an easy way to withdraw consent that is as simple as giving it.
- Remove "bundled" or pre-ticked consent.
3. Secure the data
- Apply reasonable security safeguards — access control, encryption in transit and at rest, logging.
- Test your applications and APIs for the flaws that cause data leaks (a VAPT is the direct way to evidence this).
- Extend the same expectations to any Data Processors (vendors) handling data on your behalf.
4. Enable Data Principal rights
- Build a simple process to handle access, correction and erasure requests.
- Publish a grievance-redressal contact and respond within a defined timeframe.
5. Prepare for a breach
- Have an incident-response plan that can detect, contain and report a personal-data breach.
- Know your notification obligations to the Data Protection Board and to affected individuals.
Not sure where your DPDPA gaps are?
XDepthSense runs a fixed-scope DPDPA readiness assessment — a data-flow map, a gap analysis against the Act, and a prioritised remediation plan you can actually work through. Led by a DPDPA-certified consultant in Mumbai.
Frequently asked questions
Is DPDPA in force yet?
The Act was passed in 2023 and is being operationalised through rules. Even ahead of full enforcement, building readiness now is far cheaper than retrofitting under deadline pressure.
Does DPDPA apply to a small startup?
Yes — obligations apply regardless of size if you process personal data, though certain requirements are heavier for entities notified as Significant Data Fiduciaries.
What is the single best first step?
A data-flow map. You cannot protect, or lawfully process, data you have not located.
How does a VAPT relate to DPDPA?
It provides evidence of "reasonable security safeguards" and surfaces the exact flaws — broken access control, exposure — that lead to reportable personal-data breaches.
This article is general information, not legal advice. The DPDPA and its rules are still being operationalised and may change. Confirm your specific obligations with qualified legal counsel before relying on this material.