← Back to insights

Data privacy

DPDPA Compliance Checklist 2026: Score Your Business in 30 Minutes

A structured self-assessment across eight areas: governance, data inventory, consent, Data Principal rights, security controls, vendors, breach response and documentation.

Score every item 0, 1 or 2, add it up out of 100, and you instantly know whether you are audit-ready or exposed. Most organisations we assess land between 35 and 55 on their first attempt.

Why 2026 is the year nobody gets a free pass

The Digital Personal Data Protection Act (DPDPA) 2023 stopped being a ‘we'll deal with it later’ law when the DPDP Rules established real enforcement machinery, complaint channels and penalties.

The first failure point is rarely encryption or firewalls. It is evidence: a consent log, a retention schedule, or a signed DPA with a long-standing vendor. Regulators audit what you can prove.

How to score yourself

Use this scale on every line item in your data protection review.

  • 2 points — done, documented and tested
  • 1 point — partly built or on the roadmap
  • 0 points — does not exist
ScoreWhat it meansYour next move
80–100Audit-readyMove to continuous monitoring
60–79Solid, with visible gapsClose vendor and rights gaps first
40–59Real exposureBuild a 90-day compliance roadmap
0–39CriticalAppoint a DPO this month

The 8 pillars of your DPDPA compliance checklist

Governance and leadership
Name a Data Protection Officer, create a board-level reporting rhythm, document policy and DPIA processes, and train staff every year.
Data inventory and mapping
Map each dataset to its purpose, legal basis, recipients and retention period. Flag sensitive and legacy data.
Legal basis and consent
Consent must be free, specific, informed and unbundled. Keep timestamped records and make withdrawal easy.
Data Principal rights
Give access, correction, erasure, portability and grievance requests a working channel, owner and SLA.
Technical and organisational measures
Use encryption, RBAC, audit logging, minimisation, tested backups and breach detection.
Third-party management
Every processor needs a signed DPA covering data location, sub-processing, audit rights and breach timelines.
Incident response
Document roles, notification templates and a tested breach process.
Accountability and documentation
Maintain a clear privacy notice, processing record, evidence archive and annual internal audit.

Your 90-day roadmap

Days 1–30
Appoint a DPO, run a data inventory, rewrite the privacy notice and publish a retention schedule.
Days 31–60
Deploy consent management, turn on encryption and RBAC, build rights-request workflow and send DPAs to vendors.
Days 61–90
Complete DPIAs for high-risk processing, stand up audit logging, run a breach drill and book an internal audit.