The 13-Point Notice Content Checklist
Exhaustive 13-point statutory compliance checklist for digital personal data notice design under Section 5(1) of the DPDP Act 2023 and Rule 3 of the DPDP Rules 2025.
The 13-Point Notice Content Checklist
Does your notice clear r.3? Most don't itemise
Statutory Grounding & Legal Perimeter
Mandatory statutory clauses, rules, and gazette requirements enforceable under this checklist.
Target Architecture & Impacted Systems
Enterprise applications, stores, and integration surfaces evaluated by this checklist.
Public client boundary & untrusted intake surface for notices and consent capture
Domestic production database and primary system of record for loan servicing
Immutable consent event store and Policy Decision Point issuing authority tokens
Associated Operational Controls (54 OBLs)
Control Master Matrix obligations directly tested by this checklist.
Audit & Implementation Guidance
Best practices for establishing evidence, avoiding traps, and conducting periodic assurance.
Do not rely solely on policy documents or statements of intent. Ensure verifiable evidence artifacts (cryptographic logs, test manifests, signed DPA agreements, or automated crawler receipts) are archived for at least 1 year.
Avoid declaring compliance based on frontend UI alone. The Data Protection Board evaluates the full data pipeline, including database persistence, read replicas, cache invalidation, and third-party processor synchronization.