Interactive DPDP Compliance Checklist Registry
Every checklist in this catalog is grounded in enforceable statutory provisions under the Digital Personal Data Protection Act 2023 and DPDP Rules 2025. Search, filter by role or domain, export the master matrix, or launch a dedicated interactive self-audit engine for each asset.
| ID | Checklist Title & Objective | Domain & Role | Statutory Anchor | Systems | Items | Action |
|---|---|---|---|---|---|---|
| C-01 | The 13-Point Notice Content Checklist Does your notice clear r.3? Most don't itemise | Notice & Consent Product Manager & UX Designer | s.5(1)(i)–(iii) + r.3 itemised-data/specific-purpose/independent-comprehensibility; Appendix A.8 notice row Section 5(1)Section 5(2)+4 | 13 | Open→ | |
| C-02 | The 7-Adjective Consent Audit Seven tests every consent screen must survive | Notice & Consent Product Manager & UX Designer | s.6(1): free, specific, informed, unconditional, unambiguous, affirmative action, necessity-limited (Ch. 9 §1) Section 6(1)Section 6(2)+3 | 8 | Open→ | |
| C-03 | Are You Ready for the Cliff? (20-Point Readiness) Score yourself against the commencement date | Executive Governance Board & Executive Sponsor | Ch. 1/23: the pre-13-May-2027 gate criteria — register, inventory, consent, withdrawal machine, breach drill, processor contracts Section 1(2)Section 4+8 | 20 | Open→ | |
| C-04 | The Exemption Trap Checklist Before you claim an exemption, run this | Legal & Regulatory Legal Counsel & DPO | Ch. 3 §4: the s.17 exemptions — what lifts, what survives (s.8(1)/(5) always), 'necessary for' as a test Section 17(1)Section 17(2)+5 | 7 | Open→ | |
| C-05 | The Withdrawal Parity Test If withdrawal is harder than consent, you fail s.6(4) | Notice & Consent Product Manager & UX Designer | Ch. 10 §5: give-path vs withdraw-path, channels, language, confirmation (s.6(4)) Section 6(4)Section 6(1)+2 | 6 | Open→ | |
| C-06 | The Breach Intimation Checklist The two-step clock, itemised — before the incident, not during | Security & Incident Response Chief Security Officer (CSO / CISO) | s.8(6) + r.7 content set: nature/extent/timing, consequences, mitigation, self-protection, contact (Ch. 16; A.8 row) Section 8(6)Rule 7+1 | 8 | Open→ | |
| C-07 | The Children's Product Gate Five gates for anything a child can touch (₹200 cr exposure) | Child Safety & Verification Product Manager & UX Designer | Ch. 13: verify, well-being, no-tracking/no-targeting, SDK-gate, necessity Section 9(1)Section 9(2)+5 | 6 | Open→ | |
| C-08 | The Monthly Regulatory Watch Checklist The loop a compliance team should run every month | Legal & Regulatory Legal Counsel & DPO | Ch. 2 §7, Ch. 36: Gazette, MeitY, Board, sector channels, corrigendum check, designation powers Section 1(2)Section 10(1)+3 | 6 | Open→ | |
| C-09 | The Full Compliance Calendar Checklist The Register's Enterprise-tier sample | Executive Governance Board & Executive Sponsor | The calendar document's recurring cycles + rhythms, as a tick-list per entity class (SDF/non-SDF/sector) Section 10Section 8(5)+4 | 6 | Open→ | |
| C-10 | The Legal Register Row Checklist Build-your-own-register starter (the template is LEGAL_REGISTER_TEMPLATE.csv) | Legal & Regulatory Legal Counsel & DPO | Ch. 2 §4: provision, instrument, source+SHA-256, effective date, status, applicability, control link, review date Section 1(2)Section 2+1 | 6 | Open→ | |
| C-11 | The Rights Request Response Checklist The rights-service operating procedure as a checklist | Data Principal Rights Legal Counsel & DPO | Ch. 12 + r.14 manner/identifiers/windows: intake → identity → scope → decision gates → service → evidence Section 11Section 12+3 | 6 | Open→ | |
| C-12 | The Grievance Response Checklist The front-door discipline itemised | Data Principal Rights Legal Counsel & DPO | s.13: response within the prescribed period, exhaustion before the Board, escalation records (Ch. 12) Section 13Section 28(1)+2 | 6 | Open→ | |
| C-13 | The Erasure Everywhere Checklist The deletion-plane reach, ticked store by store | Data Lifecycle & Deletion Privacy Engineer & Enterprise Architect | Ch. 14 §5: source of record, processors+acks, caches/logs, derived features, backups, receipts, irreversible-effect disclosure Section 8(7)Section 12(2)+2 | 8 | Open→ | |
| C-14 | The Processor Contract Schedule Checklist The RFP annexex for any data vendor | Third-Party & Supply Chain Procurement & Sourcing Lead | s.8(2) + Ch. 17: flow-down clauses, location-change notice, audit rights, deletion verification, ack artefacts Section 8(1)Section 8(2)+3 | 7 | Open→ | |
| C-15 | The Transfer Flow Checklist Per-flow residency discipline | Cloud & Cross-Border Privacy Engineer & Enterprise Architect | Ch. 18 §4: where, s.3(b) scope, s.16(1) position, r.15 conditions, s.16(2) sector check, evidence Section 16(1)Section 16(2)+2 | 6 | Open→ | |
| C-16 | The Security Safeguard Decision Checklist The safeguard catalogue build list | Security & Access Control Chief Security Officer (CSO / CISO) | s.8(4)/(5) + r.6 + Ch. 15: the safeguard-control map rows, reasonableness decision records, log retention Section 8(5)Rule 6+1 | 7 | Open→ | |
| C-17 | The SDF Readiness Checklist For the 'likely SDF' cohort pre-designation | Significant Data Fiduciary Chief Risk Officer (CRO) | Ch. 19 + r.13: the six factors self-assessed, DPO mandate, auditor independence, DPIA/audit cycle Section 10(1)Section 10(2)+2 | 6 | Open→ | |
| C-18 | The Sector Overlay Application Checklist (BFSI) BFSI assessment deliverable | Sector Specific (BFSI) Sector & Business Unit Lead | Ch. 31 + calendar layer 4: dual clocks, KYC retention minima, outsourcing boundaries, examiner artefacts Section 5Section 6+3 | 6 | Open→ | |
| C-19 | The Sector Checklist Set (Retail / Health / Employment) Per-sector assessment deliverables (pack #2+ pipeline) | Sector Specific Sector & Business Unit Lead | Ch. 32/33/34: each playbook's journey control points condensed Section 5Section 6+4 | 6 | Open→ | |
| C-20 | The DPIA Checklist The DPIA template's working checklist | Risk & Impact Assessment Chief Risk Officer (CRO) | Ch. 20 + s.10(2)(c)(i)/r.13: rights description, purpose, risk-to-rights assessment, management, approval authority Section 10(2)(c)(i)Rule 13 | 6 | Open→ | |
| C-21 | The Control-Test Acceptance Checklist The Harness's engagement checklist | Assurance & Audit Assurance Lead & Auditor | Ch. 22 + A.9: per-obligation audit question → artefact; pass criteria reviewable by a stranger Section 10(2)(b)Section 8(1)+1 | 5 | Open→ | |
| C-22 | The Vendor PoV Checklist RFP engagements; also our own sales methodology | Procurement & Sourcing Procurement & Sourcing Lead | Ch. 30: identical test data, pass criteria published, exportability, lock-in, hosting, processor terms, TCO, failure recovery Section 8(2)Section 8(5)+1 | 6 | Open→ | |
| C-23 | The Consent Manager Integration Checklist The CM-boundary decision aid | Notice & Consent Privacy Engineer & Enterprise Architect | Ch. 11: r.4 registration check, interop boundary per surface, evidence reconciliation, grievance coordination Section 6(7)Section 6(8)+2 | 5 | Open→ | |
| C-24 | The AI/Model Registry Checklist The AI-workload assessment deliverable | AI & Advanced Analytics Privacy Engineer & Enterprise Architect | Ch. 21: provenance, purpose/ground, consent-state inheritance, erasure reach, s.8(3) accuracy flags Section 4Section 6+3 | 5 | Open→ | |
| C-25 | The Incident Simulation Checklist The breach-drill facilitation guide | Security & Incident Response Chief Security Officer (CSO / CISO) | Ch. 16/35: the two-step drill, elapsed-time logging, dual-clock parallel run, case-record completeness Section 8(6)Rule 7+1 | 5 | Open→ |