DPDP compliance resources

Checklists, DPIA & ROPA templates, data-flow diagrams, and gap assessment frameworks — PDF, Excel, tables, and images. All free to download.

checklist

DPDP Readiness Checklist

Board-ready checklist with 8 expandable modules — notice, consent, rights, security, breach, processors, SDF, and cross-border controls mapped to DPDP Act 2023 and Rules 2025.

8 expandable modules · multi-format downloads below

ChecklistPDFExcelTable

Sample controls (full checklist in downloads)

Control areaEvidence requiredOwnerStatus
Privacy notice (Rule 3)Published notice + version historyLegal / DPOPending
Consent managerGranular consent logs per purposeProductIn progress
Data principal rightsSOP + 30-day SLA trackerGrievance officerPending
Security safeguards (Sec. 8)Encryption + access matrixCISOComplete
Breach notificationPlaybook + Board escalation treeDPOPending
Processor contractsDPDP-aligned DPA registerProcurementIn progress

Expand sections for full depth — 8 modules

1. Governance & Board oversight

Section 10 SDF obligations, DPO independence, and quarterly Board reporting cadence.

ControlEvidenceOwnerFrequencyStatus
DPO appointment & independenceBoard resolution + reporting line to audit committeeBoard / CHROAnnual review
Privacy steering committeeCharter, membership, meeting minutesDPOMonthly
Policy registerPrivacy policy, retention, BYOD, AI useLegalQuarterly
Training & awarenessRole-based LMS + phishing simulationsHR / DPOQuarterly
Regulatory horizon scanMEITY / DPB circular trackerLegal / DPOMonthly
Budget & toolingConsent, discovery, DLP, TPRM line itemsCFO / DPOAnnual
Board pack checklist
  • Executive summary: open gaps vs last quarter
  • Consent withdrawal rate & grievance SLA metrics
  • Material breach register (even near-misses)
  • Processor concentration risk (top 5 vendors)
  • Cross-border transfer status & TIAs pending
2. Notice & transparency (Rules 3–4)

Itemised notice, language accessibility, and change-management when processing evolves.

Notice elementRequirementArtifactOwnerStatus
Purposes of processingSpecific, not bundledNotice v3.2 + diff logLegal
Categories of personal dataIncluding inferred / derivedData inventory mapDPO
Retention schedulesPer purpose, not blanketRetention matrixLegal
Rights & grievance contactOfficer name + channelPublished FAQComms
Processor disclosuresSub-processor list linkVendor register excerptProcurement
Children processingRule 7 carve-out if applicableAge-gating specProduct
3. Consent management (Section 6)

Granular, withdrawable consent with audit trail — CMP integration and product flows.

FlowTest caseExpected outcomeOwnerStatus
First-party signupMarketing opt-in separate from T&CDistinct consent IDs loggedProduct
Cookie / SDK bannerReject all equally prominentNo pre-ticked boxesProduct
Consent refreshPurpose change triggers re-consentBlock processing until refreshDPO
WithdrawalOne-click in account + email linkProcessing stops within SLAProduct
Consent proof exportRegulator / audit requestJSON bundle with timestampsEngineering
Legacy consent migrationPre-DPDP databasesRe-consent campaign planMarketing
CMP evaluation criteria (reference)
  • DPDP-native purpose taxonomy & Hindi UI
  • Webhook to CRM / CDP on consent change
  • SDK coverage: web, iOS, Android, server-side
  • Integration with discovery & ROPA tools (e.g. Complynz)
4. Data principal rights (Sections 11–14)

Access, correction, erasure, grievance — 30-day SLA and nomination support.

RightChannelSLAVerificationStatus
Access / summaryPortal + email30 daysOTP + ID match
CorrectionSelf-serve + agent15 daysAudit trail
ErasureExcept legal retention30 daysLegal hold check
GrievanceDedicated officer30 daysTicket numbering
NominationForm + verification30 daysDeath certificate workflow
Automated decisionOpt-out where applicable15 daysHuman review queue
5. Security safeguards (Section 8)

Encryption, access control, logging, and alignment with CERT-In directions.

SafeguardStandardEvidenceOwnerStatus
Encryption at restAES-256 or equivalentKMS policy + rotation logCISO
Encryption in transitTLS 1.2+Certificate inventoryInfra
RBAC / least privilegeQuarterly access reviewIAM exportCISO
Logging & SIEMPersonal data access logs90-day retention minimumSecOps
PseudonymisationHigh-risk analyticsArchitecture diagramData eng
Backup & DRRPO/RTO for PII systemsDR test reportInfra
6. Breach notification & response

72-hour Board pathway and Data Protection Board notification templates.

StageActionOwnerTarget timeStatus
Detect & containIsolate affected systemsSecOps0–4 hours
Assess harmPrincipal count, data typesDPO + Legal4–24 hours
Board notificationMaterial breach criteriaDPO → Board72 hours
Principal communicationPlain-language noticeCommsAs required
DPB notificationPrescribed formatLegalAs required
Post-incident reviewRoot cause + CAPACISO14 days
7. Processors, vendors & transfers

ROPA-linked DPA register, TPRM tiering, and Section 16 transfer safeguards.

Vendor tierDue diligenceContract clauseReview cycleStatus
Tier 1 — critical PIIOn-site / SOC2 + DPDP DPAAudit + breach notifyAnnual
Tier 2 — moderateQuestionnaire + sample auditSub-processor approval18 months
Tier 3 — low touchStandard DPA addendumLiability cap alignment24 months
Cross-borderTIA + whitelist countrySCC / BCR equivalentPer transfer
Sub-processor change30-day notice to fiduciaryRegister updateEvent-driven
8. SDF programme & DPIA

Significant Data Fiduciary controls: DPIA cadence, audits, and certification readiness.

SDF controlRule / sectionDeliverableOwnerStatus
DPIA for new high-risk processingRule 9Signed DPIA registerDPO
Data auditor engagementRule 10Annual audit planBoard
Consent manager certificationRule 5CMP audit reportProduct
Children safeguardsRule 7Verifiable parental flowProduct
Publication of transparency reportBest practiceAnnual transparency PDFComms

Downloads — full depth workbooks · free, no sign-in

template

DPIA Template (DPDP-aligned)

Structured Data Protection Impact Assessment for high-risk processing — purpose, necessity, proportionality, risks, and mitigation tracker.

4 expandable modules · multi-format downloads below

DPIAPDFExcelTable

DPIA risk register excerpt

Risk IDDescriptionLikelihoodImpactMitigationOwner
R-01Excessive profiling without opt-outMediumHighPurpose limitation + consent refreshDPO
R-02Cross-border transfer without safeguardsLowHighStandard contractual clausesLegal
R-03Children's data without verifiable consentMediumHighAge-gating + parental flowProduct

Expand sections for full depth — 4 modules

Phase A — Scoping & necessity
FieldGuidanceResponse
Project name & IDLink to Jira / change ticket
Processing descriptionPlain language for Board
Lawful basisConsent / legal / contract — cite section
Necessity testWhy less intrusive alternatives fail
ProportionalityData minimisation measures
Phase B — Data mapping
CategorySubjectsVolumeSensitive?Source
IdentityCustomers2.1MNoApp signup
FinancialLoan applicants450KYesCredit bureau
BehaviouralWeb visitors8M/moNoAnalytics SDK
Special categoryHealth (if applicable)YesPartner API
Phase C — Risk register (expandable)
IDRiskLIScoreMitigationOwnerTarget
R-01Profiling without opt-outMH12Purpose limitation + consent refreshDPO
R-02Cross-border without TIALH8Whitelist + SCC packLegal
R-03Children without verifiable consentMH12Age gate + parental flowProduct
R-04Processor subprocessors unknownMM9TPRM + ROPA syncProcurement
R-05Automated loan denial biasLH8Human review + model auditRisk
Phase D — Residual risk & sign-off
Sign-off matrix
  • DPO recommendation: Proceed / Proceed with conditions / Do not proceed
  • CISO security review attachment
  • Legal opinion on lawful basis
  • Board / SDF committee date & minutes reference

Downloads — full depth workbooks · free, no sign-in

template

ROPA Template

Records of Processing Activities aligned to Section 8 and Rule 8 expectations — one row per processing activity with lawful basis and retention.

2 expandable modules · multi-format downloads below

ROPAPDFExcelTable

ROPA sample rows

ActivityPurposeLawful basisData categoriesRetentionRecipients
Customer onboardingKYC & account openingLegal obligationIdentity, contact7 yearsCore banking
Marketing analyticsCampaign personalisationConsentBehavioural, device12 monthsAd platform
HR payrollSalary processingContractEmployment, bank3 years post-exitPayroll vendor

Expand sections for full depth — 2 modules

Core processing activities
Activity IDPurposeLawful basisData categoriesRetentionRecipients
PA-001Customer KYCLegal obligationIdentity, address, PAN7 yearsCore banking, C-KYC
PA-002Marketing personalisationConsentBehavioural, device ID12 monthsCDP, ad network
PA-003HR payrollEmployment contractSalary, bank, tax3y post-exitPayroll SaaS
PA-004Customer supportLegitimate use / contractContact, ticket history24 monthsCRM, BPO
PA-005Fraud detectionLegitimate useTransaction, device fingerprint18 monthsRisk engine
Cross-border & processor annex
ActivityDestinationSafeguardTIA dateDPA ref
PA-002US (CDP)SCC + supplementary measures2025-11-02DPA-2024-088
PA-003Singapore (payroll)Adequacy assessment2026-01-15DPA-2025-012

Downloads — full depth workbooks · free, no sign-in

template

Data Flow Diagram (DFD) Template

Visual template for mapping data sources, processing stages, storage, and third-party transfers — essential for audits and DPIA scoping.

2 expandable modules · multi-format downloads below

DFDImagePDFSVG
DPDP data flow diagram — Indian enterprise context

Expand sections for full depth — 2 modules

DFD layers & notation
Level 0 — Context
  • Data principals (customers, employees, vendors)
  • Your organisation as Data Fiduciary boundary
  • External processors & regulators (DPB, CERT-In)
Level 1 — Processing stages
  • Collection channels: app, web, branch, API, call centre
  • Processing: CRM, core banking, data lake, ML pipeline
  • Storage: primary DB, backups, cold archive, logs
  • Disclosure: analytics, ads, credit bureaus, cloud regions
Audit questions per flow
FlowQuestionEvidenceOwner
App → CRMLawful basis documented in ROPA?ROPA PA-004DPO
CRM → US CDPTIA completed for transfer?TIA-2025-14Legal
Logs → SIEMRetention aligned to policy?Retention matrixCISO

Downloads — full depth workbooks · free, no sign-in

framework

Gap Assessment Framework

Maturity-based gap assessment across governance, people, process, and technology — score your programme before DPO certification or Board review.

5 expandable modules · multi-format downloads below

FrameworkPDFExcelTable

Maturity scoring matrix (1–5)

DomainCurrentTargetGapPriorityRemediation
Governance & board oversight242HighAppoint DPO + quarterly reporting
Notice & consent341MediumRefresh consent manager UX
Data principal rights242HighAutomate grievance SLA
Vendor & transfer controls143CriticalROPA + DPA renewal programme
Security & breach response352HighTabletop + 72h playbooks

Expand sections for full depth — 5 modules

Domain 1 — Governance (weight 20%)
CriterionL1 Ad hocL3 DefinedL5 OptimisedCurrentTargetGap
Board oversightNo privacy reportingQuarterly DPO reportReal-time dashboard4
Policy lifecycleStale PDF on websiteVersion-controlledAutomated attestation4
DPO resourcingPart-time legalDedicated DPO + teamDPO + privacy engineering5
Domain 2 — Notice & consent (weight 25%)
CriterionL1L3L5CurrentTargetGap
Notice qualityGeneric privacy policyItemised Rule 3 noticeDynamic notice API4
Consent granularityBundle acceptPurpose-level CMPReal-time sync to ROPA5
Domain 3 — Data principal rights (weight 20%)
CriterionL1L3L5CurrentTargetGap
Grievance handlingEmail inboxTicketing + SLASelf-serve portal4
Erasure workflowManual spreadsheetsOrchestrated deletionCross-system purge5
Domain 4 — Technology (weight 20%)
CriterionL1L3L5CurrentTargetGap
DiscoveryUnknown data storesQuarterly scanContinuous classification5
DLPEmail DLP onlyEndpoint + cloudML classification + block4
Domain 5 — Vendors & transfers (weight 15%)
CriterionL1L3L5CurrentTargetGap
TPRMSpreadsheetTiered assessmentsIntegrated GRC platform4
Transfer governanceAd hoc legal reviewTIA template libraryAutomated transfer register5

Downloads — full depth workbooks · free, no sign-in

All resources are educational templates aligned to DPDP Act 2023 and Rules 2025. Expand each section for audit-ready depth. Not legal advice — adapt with qualified counsel before Board or regulatory submission.

Privacy journal

Tooling rankings by Alisha Sharma

Privacy Journalist