Data privacy
DPDPA Compliance Checklist 2026: Score Your Business in 30 Minutes
A structured self-assessment across eight areas: governance, data inventory, consent, Data Principal rights, security controls, vendors, breach response and documentation.
Score every item 0, 1 or 2, add it up out of 100, and you instantly know whether you are audit-ready or exposed. Most organisations we assess land between 35 and 55 on their first attempt.
Why 2026 is the year nobody gets a free pass
The Digital Personal Data Protection Act (DPDPA) 2023 stopped being a ‘we'll deal with it later’ law when the DPDP Rules established real enforcement machinery, complaint channels and penalties.
The first failure point is rarely encryption or firewalls. It is evidence: a consent log, a retention schedule, or a signed DPA with a long-standing vendor. Regulators audit what you can prove.
How to score yourself
Use this scale on every line item in your data protection review.
- 2 points — done, documented and tested
- 1 point — partly built or on the roadmap
- 0 points — does not exist
| Score | What it means | Your next move |
|---|---|---|
| 80–100 | Audit-ready | Move to continuous monitoring |
| 60–79 | Solid, with visible gaps | Close vendor and rights gaps first |
| 40–59 | Real exposure | Build a 90-day compliance roadmap |
| 0–39 | Critical | Appoint a DPO this month |
The 8 pillars of your DPDPA compliance checklist
- Governance and leadership
- Name a Data Protection Officer, create a board-level reporting rhythm, document policy and DPIA processes, and train staff every year.
- Data inventory and mapping
- Map each dataset to its purpose, legal basis, recipients and retention period. Flag sensitive and legacy data.
- Legal basis and consent
- Consent must be free, specific, informed and unbundled. Keep timestamped records and make withdrawal easy.
- Data Principal rights
- Give access, correction, erasure, portability and grievance requests a working channel, owner and SLA.
- Technical and organisational measures
- Use encryption, RBAC, audit logging, minimisation, tested backups and breach detection.
- Third-party management
- Every processor needs a signed DPA covering data location, sub-processing, audit rights and breach timelines.
- Incident response
- Document roles, notification templates and a tested breach process.
- Accountability and documentation
- Maintain a clear privacy notice, processing record, evidence archive and annual internal audit.
Your 90-day roadmap
- Days 1–30
- Appoint a DPO, run a data inventory, rewrite the privacy notice and publish a retention schedule.
- Days 31–60
- Deploy consent management, turn on encryption and RBAC, build rights-request workflow and send DPAs to vendors.
- Days 61–90
- Complete DPIAs for high-risk processing, stand up audit logging, run a breach drill and book an internal audit.