Why this matters
The Digital Personal Data Protection Act 2023 was always the easy part — a short, principles-led statute. The Rules notified in 2026 are where the operational burden sits, and most Indian companies are still calibrating to it. With enforcement expected from July 2026, this checklist captures what corporate counsel must have ready for the first audit cycle.
1. Appoint a Data Protection Officer (or a Data Protection Lead)
For Significant Data Fiduciaries the DPO appointment is statutory; for everyone else, designating an accountable lead is an operational necessity even if not a strict legal one. The DPO function needs three things in place: an independent reporting line to the board (or audit committee), a published contact channel for data principals, and a documented escalation matrix for incidents.
2. Map every data-processing activity
The Records of Processing equivalent — what data, what purpose, what lawful ground, what retention period, what processors — is the spine of any compliance defence. Without this, every other requirement (notice, consent, breach-response, principal-rights handling) becomes ad-hoc. Build it once, version it, and review it quarterly.
3. Re-architect the consent layer
DPDP consent must be free, specific, informed, unconditional, and unambiguous. In practice that means moving away from bundled consents and pre-ticked boxes, recording the consent moment with timestamp and version of the notice presented, and providing a withdrawal channel that is at least as easy as the consent channel was. The Rules tighten this further by mandating granularity and a Consent Manager fabric for cross-business consent portability.
4. Set up the 72-hour breach-notification protocol
The Rules require notification to the Board and to affected data principals within tight windows. The 72-hour clock starts when the breach is detected, not when it is fully understood. Counsel must own the playbook: detection, triage, containment, notification copy, regulator submission, principal communication. Tabletop the playbook with engineering and security at least once a quarter. A breach is not the moment to draft your first notice.
5. Get your cross-border transfer posture in writing
The Rules adopt a list-based approach to international transfers — countries on the notified list, transfers permitted; off-list, scrutiny applies. Counsel should map every cross-border data flow (cloud regions, vendor sub-processing, intra-group flows), classify each as on-list or off-list, and document the legal basis. Where the answer is 'off-list, group exception', that is a position counsel must be ready to defend.
6. Children, employees, and the consent-manager edge cases
DPDP imposes a children's-data regime that requires verifiable parental consent and bars targeted advertising at children. Most B2C platforms will need an age-gating mechanism that does not collapse into a privacy violation of its own. Employee data is in scope but with a softened consent regime under the legitimate-uses limb; legal must be the source of truth on which employee processing relies on legitimate uses versus consent.
7. The audit trail is the deliverable
When the Board comes calling, the deliverable is not the policy document — it is the evidence that the policy was applied. Keep the consent receipts, the breach playbook test logs, the principal-rights request logs, the DPIA registers, and the data-processing inventories. A well-run compliance function is a well-run records function.
Tactical takeaways
- Treat the data-processing map as the spine. Every other compliance artefact references it.
- Move away from bundled consent now. Granularity and recording of the consent moment are non-negotiable under the Rules.
- Drill the 72-hour breach playbook quarterly. Speed of response is the part you cannot retrofit during an actual incident.
- Document the cross-border transfer posture explicitly. Auditors and the Board will ask; absence of an explicit position is itself a finding.
- Build the audit trail as you go. Counsel cannot reconstruct a year of compliance after a notice arrives.