The DPDP readiness checklist
34 items, in the order we would actually do them. Nothing here establishes whether you comply with anything; it establishes what is true about your systems, which is the thing a lawyer will ask you for. Print it, mark it up, give it an owner.
1. Locate it
- List every system holding personal data.Done when a new person could find all of them from the list alone.
- Include the informal ones: spreadsheets, WhatsApp, shared inboxes, exports.This is where the list usually doubles.
- Include vendors who hold it on your behalf.Hosting, CRM, analytics, courier, payment, agency logins.
- Note who inside the business can reach each one.
- Note where each one physically stores the data.
- Mark anything you cannot explain the purpose of.Candidates for deletion, not documentation.
2. Describe it
- Write the specific purpose next to every row."Analytics" is not a purpose. "To show a customer their past orders" is.
- Write the categories of personal data each row holds.
- Check your notice is a standalone document, not a clause.
- Check the notice is in plain language a customer would follow.
- Check it itemises categories and purposes, and the services that depend on them.
- Check it explains withdrawal, grievance, and complaint to the Board.
- Delete from the notice anything you do not actually do.Copied clauses about cookies you do not set are a written record of a promise you are not keeping.
- Name a real person for grievances and publish a route that reaches them.
3. Make the rights executable
- Trace one real record through every system on the inventory.
- Write down every place it survives a deletion attempt.Backups, warehouses, vendor systems, exports, logs.
- Decide what deletion means for each of those, and write it down.
- Build or document the access route: everything you hold about one person.
- Set a target response time for both, before the first request.
- Establish whether any of your users are under eighteen.Establish, not assume.
- If yes, treat verifiable parental consent as a product change.
- Build withdrawal of consent into the product, not into an inbox.
- Confirm withdrawal actually stops the processing, not just records the request.
4. Secure it
- Encrypt, mask, obfuscate or tokenise personal data at rest.
- Put access controls on the systems that hold it.
- Enable logs good enough to detect unauthorised access.
- Set log retention to at least one year for personal data systems.CERT-In separately requires 180 days of ICT logs, kept in India.
- Read what each vendor contract says about safeguards.The gap is usually the smallest vendor.
- Set a retention period per row of the inventory, and enforce it.
- Confirm backups exist and are separated from the systems they protect.
5. Rehearse the bad day
- Write the incident sequence down, with a named owner.
- Put both reporting routes in it: CERT-In within six hours, the Board within 72.
- Draft the message to affected people before you need it.
- Walk it through out loud, once, with the people who would be on the call.