The owner of a chain of four clinics in West Delhi is asked by a hospital group it wants to partner with to confirm, in writing, that it complies with the Digital Personal Data Protection Act. She knows the clinics keep patient records in software, send reminders by SMS, and have a receptionist who photographs prescriptions on her phone. She does not know where the backups are, which vendors can see the data, how long anything is kept, or what would happen if a laptop were stolen. A compliance review answers those questions in a few weeks, ranks what needs fixing, and gives her something truthful to sign. This page explains how such a review works, what it tests, and what it should produce.
For most Indian businesses, personal data grew by accident. A customer list started in a notebook moved to a spreadsheet, then to a CRM; a WhatsApp group became the main channel for client documents; a marketing agency added a few tracking tags; a payroll vendor was engaged by email. Nobody decided, at any point, how the business as a whole should handle personal data. The Digital Personal Data Protection Act, 2023 now requires that decision to be made and written down.
The law itself — what it requires of a data fiduciary, the rights of individuals, the penalties — is set out in our DPDP privacy policy guide. This page is about the practical exercise that turns the law into a business’s own to-do list: the compliance review. Its value is that it replaces guesswork with facts. Before the review, the owner believes the data is “safe with us”; after it, the owner knows which systems hold it, which people and vendors can see it, what was promised to customers, and what must change first.
There are three good reasons to do it now rather than later. The main obligations have a fixed start date, and fixing systems takes months, not days. Larger clients, hospitals, banks and foreign customers are already asking their suppliers for evidence of compliance. And businesses that raise funds or sell themselves find that investors now ask about personal data in due diligence.
The Act was passed in August 2023, and the Digital Personal Data Protection Rules were notified in November 2025. The rules did not take effect all at once. As notified, they provide broadly for three stages:
| Stage | What comes into force | What a business should be doing |
|---|---|---|
| On notification (November 2025) | Provisions constituting the Data Protection Board and its procedure | Understanding the law; starting the inventory |
| After about twelve months | Registration and obligations of consent managers | Designing consent records that can work with consent managers |
| After about eighteen months | Most obligations of data fiduciaries: notice, consent, security safeguards, breach intimation, erasure, rights, children, significant data fiduciary duties | Having the fixes in place and working |
Businesses should check the notified text for the precise date on which each provision takes effect, and watch for amendments and clarifications. The practical lesson is simple: the months before the main obligations begin are the time for the review and the remediation, because after that date the Board can act on complaints and breaches.
The Act applies to processing of digital personal data in India, and to processing outside India connected with offering goods or services to people in India, as our guide on whether the Act applies explains. There is no turnover or headcount threshold for ordinary data fiduciaries. In practice, a review is most urgent for businesses that:
Even a small professional office — a CA firm, a law office, a clinic, a coaching centre — benefits from a short review, because the fixes it identifies are usually simple and cheap if found early.
A review should leave the business with things it can use, not only an opinion. At minimum:
The report should say plainly what was not reviewed, and why, so nobody later mistakes a partial review for a complete one.
| Phase | What happens | Typical output |
|---|---|---|
| 1. Scoping | Agree entities, products, systems, departments and data subjects; name contacts | Scope note and information request |
| 2. Discovery | Interviews with owners of customer service, sales, marketing, HR, IT and finance; review of documents; walk-through of systems | Interview notes, screenshots |
| 3. Inventory | Record each processing activity and data flow | Data inventory |
| 4. Testing | Check each obligation against evidence, including practical tests | Gap register with evidence |
| 5. Scoring | Rank gaps by likelihood and impact | Risk ratings |
| 6. Reporting | Write findings and recommendations | Report and action plan |
| 7. Walk-through | Explain results to owners, agree priorities and owners | Agreed plan |
| 8. Follow-up | Check progress after the first milestones | Updated gap register |
Most of the useful information comes from conversations with the people who do the work, not from policies. The receptionist who scans identity documents, the marketing executive who exports leads to a new tool, and the accountant who emails salary files know where the data goes.
A review goes faster, and costs less time for everyone, when the business gathers a few things in advance. None of them needs to be perfect; the point is to show the reviewer what exists.
| Gather | Why |
|---|---|
| List of software, apps and cloud services in use, with who administers each | Starting point for the inventory and access review |
| Current privacy policy, website terms and any consent wording | To compare promises with practice |
| Vendor list with contracts or order forms | For the vendor register |
| Employee handbook, offer letter and employment contract templates | For HR data and confidentiality |
| Any security policy, certification or test report | Evidence of existing controls |
| Records of past incidents, complaints or data requests | To see how issues were handled |
| Organisation chart and names of department heads | To plan interviews |
The business should not send bulk copies of customer data to the reviewer. Screenshots, field lists and a handful of redacted samples are enough to understand how data is held, and avoid creating a new copy that itself needs protecting.
A review that tries to cover everything at once usually covers nothing well. Scoping decides:
Where a business is large, the first review can focus on the highest-risk activities — usually the core customer database, the website and apps, and the vendors that hold the most data — with other areas in a second phase. The scope note should also name one person inside the business who coordinates the review and can open doors.
The inventory is the heart of the review. It records each processing activity — a distinct use of personal data — in a consistent form. A practical template:
| Column | Example entry |
|---|---|
| Activity | Online appointment booking |
| Whose data | Patients, including minors |
| Data fields | Name, phone, age, reason for visit, appointment time |
| Source | Website form, phone calls entered by reception |
| Purpose | Scheduling and reminders |
| Legal basis | Consent at booking; reminders part of the service |
| System and location | Booking software, cloud servers in India |
| Access | Reception staff, doctors, clinic manager |
| Vendors | Booking software provider, SMS provider |
| Transfers abroad | None known; support team location to confirm |
| Retention | Not defined — gap |
| Security notes | Shared reception login — gap |
A small business may have fifteen to forty activities; a larger one, hundreds. The inventory need not be perfect on day one, but it must be honest and kept up to date, because every other step depends on it. It also makes it possible to answer an individual who asks for a summary of the personal data held about them and the processing activities it is used for, which the Act allows them to request.
For each activity in the inventory, the review asks two questions: what is the specific purpose, and what is the basis for processing? Under the Act, processing is lawful either with consent or for one of the legitimate uses the Act lists — for example, where an individual voluntarily provides data for a specified purpose and has not objected, for employment purposes, or to comply with law. Those bases are explained in our guide on legitimate uses.
Common findings at this stage are uses with no clear purpose (“we keep everything in case it is useful”), purposes that grew beyond what customers were told (booking data now used for marketing), and consent relied on where the business could not actually honour a withdrawal. Each such finding goes into the gap register with a recommended basis and any change needed to notices or systems.
The simplest way to reduce risk is to hold less. A review should look at every form, every document request and every export, and ask whether each field is needed for the stated purpose. Typical quick wins are removing date of birth from enquiry forms, masking all but the last digits of identity numbers, not storing copies of identity documents once verification is done, not exporting full customer lists to marketing tools, and deleting old files from shared drives and messaging groups.
Collecting less is also cheaper: fewer fields to secure, fewer records to delete later, fewer answers to give when someone asks what is held about them. The review report should list each field recommended for removal, with the reason.
A notice is only compliant if it matches what the business actually does and reaches people at the right moment. The review tests this in practice rather than by reading the privacy policy alone:
The content of a good notice is set out in our guide on the notice; where it should appear on a website is covered in our website legal pack guide.
Consent under the Act must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and as easy to withdraw as to give; the requirements are explained in our consent guide and our note on withdrawal. The review tests the reality:
A practical test is to sign up with a test identity, withdraw consent, and see whether messages stop. Businesses are often surprised to find that an unsubscribe removes a customer from one tool but not from the others to which the list was copied. The review should also note whether consent records could be shared with a registered consent manager if the business chooses to use one.
The Act treats anyone under eighteen as a child, requires verifiable consent of a parent or lawful guardian before processing a child’s data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the rules for particular kinds of processing such as by educational institutions and health services in defined circumstances. The details are in our guide on children.
The review asks where children’s data might enter the business, including by accident: a coaching centre’s students, a clinic’s young patients, a game’s players, a toy shop’s loyalty programme. For each, it checks how age is established, how parental consent is obtained and verified, whether any exemption genuinely applies, and whether analytics or advertising tools run on pages children use. This is frequently the area with the largest gap between practice and law.
The Act applies to digital personal data, including data collected on paper and later digitised. In practice, the review cannot ignore paper files, because they are usually scanned, photographed or typed into systems at some point, and because the same staff handle both.
Messaging apps are the hidden database of many Indian businesses. Client documents are sent by customers on WhatsApp, forwarded between staff, saved to phone galleries and backed up to personal cloud accounts. The review should find out which groups and numbers are used for work, what is shared in them, who is in them — including former staff — and where the phones back up. Usual fixes are a business account for customer communication, a rule that documents are moved into the proper system and deleted from phones, removal of former staff from groups, and turning off personal cloud backup of work chats. Paper files need locked storage, a record of who takes them out, and proper shredding.
The Act requires reasonable security safeguards to prevent personal data breaches, and the rules describe the kinds of measures expected, including encryption, masking or tokenisation where appropriate, access control, logging and monitoring, backups and contractual safeguards with processors. The review does not need to be a full technical audit, but it should check the basics with evidence:
| Control | How it is checked |
|---|---|
| Individual logins and multi-factor authentication | Screenshots of user lists and settings for key systems |
| Encryption of laptops, phones and backups | Device settings, backup configuration |
| Access limited by role | Who can export customer lists; test with a junior account |
| Logs of access to personal data, kept for the required period | Log settings and retention in key systems |
| Backups tested | Date of last successful restore test |
| Software updated | Update status of website, plugins, servers |
| Staff leaving | Access removal records for recent leavers |
| Physical records | Storage of paper files and their disposal |
Where the business holds a security certification or has a recent penetration test, those are good evidence. Where it has neither, the review identifies the few controls that give the most protection for the least cost.
Most data incidents in small and mid-sized Indian businesses involve people rather than hackers: a shared password, a customer list forwarded to a personal email, a former employee who still has access, a phone with client documents lost in an auto-rickshaw. The review therefore looks at:
The fixes are often organisational: a written rule on use of personal devices, an exit checklist, and removing shared logins. Our HR policy guide shows how these rules fit into the staff handbook.
The review builds a vendor register from the inventory: every outside party that receives personal data, what it receives, its role, where it stores the data, and whether the contract is adequate. The Act permits a data fiduciary to engage a processor only under a valid contract and keeps the fiduciary responsible for the processor’s processing, as explained in our data processing agreement guide.
For each significant vendor, the review checks the contract against the points in that guide’s addendum checklist, notes gaps, and recommends either a new agreement, an amendment, or — where a global vendor will not negotiate — compensating steps. It also identifies vendors that act as independent fiduciaries, such as payment gateways and couriers, whose role should be reflected in the notice rather than in a processing contract.
The Act requires a data fiduciary to intimate a personal data breach to the Board and to each affected person, and the rules set out the content and a fixed period for the detailed report to the Board; many cyber incidents must also be reported to CERT-In within a few hours. These duties are explained in our breach guide. A business cannot meet those timelines by improvising.
The most revealing part of a review is often a short tabletop exercise. The reviewer describes a realistic scenario — a receptionist’s laptop with patient files is stolen on Friday evening; a vendor reports that a database was exposed; a customer says their details appeared in a WhatsApp group — and the team talks through what they would do, hour by hour:
Gaps revealed by the drill go straight into the action plan, usually as a one-page breach procedure, a contact list, templates, and changes to vendor contracts.
Individuals have rights to a summary of their personal data and its processing, to correction, completion, updating and erasure, to grievance redressal and to nominate someone to act for them, as set out in our rights guide. The review tests whether the business can actually respond:
A useful practical test is a “mystery request”: with the business’s agreement, a test request is sent through the published channel, and the reviewer observes what happens. The result usually shows in a day what a policy never would. The fix is a short procedure, a request log and, for businesses with many customers, a simple self-service page.
The Act requires erasure once the purpose is no longer served or consent is withdrawn, unless the law requires the data to be kept, and requires the fiduciary to cause its processors to erase too; our guide on retention explains the rule. The rules also set specific periods for certain large classes of platforms, and a minimum period for keeping logs.
In a review, retention is usually the largest gap, because almost no Indian small business deletes anything. The deliverable is a retention schedule: for each category in the inventory, how long it is kept, what event starts the period, what law requires retention (tax, company law, labour law, medical records rules, professional rules), and how deletion happens in each system and at each vendor. The plan then sets out a first clean-up — old enquiry lists, former employees’ files, closed customer records beyond their period — and a routine to repeat it.
The Act permits transfer of personal data outside India except to countries the government notifies as restricted, while preserving stricter sectoral rules, as our transfer guide explains. The review’s job is factual: to find out where data actually goes. Cloud services, email platforms, analytics and advertising tools, customer support software and AI tools frequently store or process data abroad, and vendors’ support teams may access it from other countries.
The inventory should record the location of storage and access for each system, and the report should flag any sector rule requiring storage in India, any vendor whose location is unknown, and whether the business would be affected if a destination were restricted.
HR data is often the most sensitive data a business holds — salaries, bank details, identity numbers, health information for insurance, background checks, disciplinary records — and the least reviewed. The Act allows processing for employment purposes as a legitimate use, as our guide on employee data explains, but every other duty applies.
The review covers recruitment (what applicants are asked for and how long unsuccessful applications are kept), onboarding documents, payroll and attendance vendors, monitoring of email and devices, background verification, medical and insurance data, and exit records. Common recommendations are an employee privacy notice, processing terms with HR vendors, restricted access to salary and medical files, and a retention period for former employees’ records. Our HR policy and employment agreement services can carry these into staff documents.
Marketing is where data most often goes further than customers expect. The review traces how leads are captured, where lists are stored, which tools send messages, what tracking tags and pixels run on the website and app, whether customer lists are uploaded to advertising platforms, and whether any data is used to train or feed AI tools. For each, it checks the notice, the consent and the opt-out.
AI tools deserve a specific question: are staff pasting customer data, documents or conversations into public AI services? A short rule on approved tools and prohibited data, and a check of the terms of any AI vendor, are usually needed. For websites and apps, the review can use the tag and SDK checks described in our app compliance guide and the cookie approach in our website legal pack guide.
A review looks at what exists; the business also needs a habit for what is coming. Before launching a new product, app, form, marketing campaign or AI tool, a short check — a page or two — asks: what personal data will this collect, why, on what basis, who will receive it, where it will be stored, how long it will be kept, whether children could be affected, and what could go wrong. Only significant data fiduciaries are required by the Act to carry out formal impact assessments, but the same questions asked early save redesigns later.
The review can supply a simple template for this check and name who must complete it. Building the answer into the project plan — as a step before the developer is briefed — is what “privacy by design” means in a small business.
The government may notify a data fiduciary or class of fiduciaries as significant, considering the volume and sensitivity of data, risk to individuals and wider factors; such fiduciaries must appoint a Data Protection Officer based in India, an independent data auditor, and carry out periodic impact assessments and audits, as our guide on significant data fiduciaries explains.
Most businesses reading this will not be notified. A review should still record whether the business could plausibly be, given its volume and type of data, and whether large clients are asking it to meet similar standards by contract. Where either is likely, the review can be structured so that it later serves as the baseline for a formal data protection impact assessment.
The DPDP Act is general, and stricter sectoral rules continue to apply. The review should identify which apply to the business and check them alongside the Act:
| Sector | Additional areas to check |
|---|---|
| Banks, NBFCs, payment and lending businesses | RBI directions on IT outsourcing, digital lending, payment data storage and cyber security |
| Securities market intermediaries | SEBI cyber security and resilience framework |
| Insurers and intermediaries | IRDAI information and cyber security guidelines |
| Hospitals, clinics, labs | Confidentiality of medical records, telemedicine rules, digital health standards |
| Schools and coaching | Children’s data, education regulators’ guidance |
| Telecom and internet businesses | Licence conditions, intermediary rules, CERT-In directions |
| Government contractors | Contract terms on data location, security and audit |
Where a sector regulator’s rule is stricter than the Act, the stricter rule generally sets the standard for that activity.
Not every gap is equally urgent. A clear scoring method helps a busy owner decide what to fix first. A simple approach rates each finding for likelihood and impact on a three-point scale and combines them:
| Rating | Likelihood means | Impact means |
|---|---|---|
| High | Happening now, or very likely within a year | Sensitive data, many people, or a legal duty directly breached |
| Medium | Plausible within a year | Moderate harm, limited numbers, or a weak control |
| Low | Unlikely | Minor inconvenience, documentation only |
High-high findings — for example, patient records on staff phones with no lock, or a vendor holding sensitive data with no contract — go into the first thirty days. Documentation gaps with low impact can wait for the ninety-day stage. The score should be explained in words, so that it can be understood without the table.
A useful report is short at the front and detailed at the back. A structure that works:
The report is itself confidential and may contain sensitive findings. It should be shared only with those who need it, and marked accordingly. If the business intends to share a summary with clients or investors, a separate short statement of the steps taken is more appropriate than the full report.
| Period | Typical tasks |
|---|---|
| First 30 days | Fix high-risk security gaps (shared logins, unencrypted devices); stop the riskiest data uses; appoint an owner; adopt a breach procedure and contact list; sign processing terms with the most sensitive vendors |
| 31–60 days | Publish accurate notices and consent wording; separate marketing consent; set up a request channel and log; begin the retention clean-up; train staff |
| 61–90 days | Complete vendor contracts; adopt the retention schedule in each system; employee privacy notice; children’s data controls; follow-up review of progress |
Each task should have one named owner and a date. Tasks that depend on outside parties — a software vendor adding a deletion feature, a global provider’s contract — should have an interim measure, so the plan does not stall. Documents the plan calls for, such as a privacy policy, data processing agreements or a website legal pack, can be prepared in parallel.
Compliance lasts only if someone owns it. Even where the Act does not require a Data Protection Officer, the business should name a person responsible for data protection decisions, give that person time and authority, and publish a contact for questions and grievances. In a company, the board or partners should receive the review summary and a short progress update each quarter until the plan is complete.
The business should also keep an evidence file: the inventory, the notices and their versions, consent records, vendor contracts, training records, the request log, the breach log, and the review reports. If the Board ever inquires, the question will be what the business did and when; the evidence file is the answer.
Businesses that supply larger companies increasingly receive data protection questionnaires: do you have a privacy policy, who is your data protection contact, where is data stored, do you encrypt it, which sub-processors do you use, how would you notify us of a breach, do you have a certification. A review produces most of the answers. Keeping a standard response pack — the inventory summary, security description, sub-processor list, breach commitment and contact — lets the business answer quickly and consistently, and avoids the temptation to tick “yes” to everything. Our guide for processors explains how to prepare it.
Every answer given to a client is a representation. If it is untrue, it can become a breach of contract, and possibly misrepresentation. It is better to answer “planned by March, in progress” than to claim a control that does not exist.
An individual with a complaint must usually first use the business’s own grievance mechanism, and may then complain to the Data Protection Board. The Board can also act on a reference from the government or a court, or on a breach intimation. It is designed as a digital office, and it may inquire, direct urgent measures, and impose penalties after hearing the business. During proceedings the business may offer a voluntary undertaking — for example, to take specified steps within a time — which the Board may accept. Appeals from the Board’s orders go to the Appellate Tribunal within the time the Act allows.
A business that has done a review and followed its plan is in a far better position in any of these steps: it can show the inventory, the notices, the vendor contracts, the training and the steps taken after the incident. The Act itself directs the Board, when deciding a penalty, to consider matters such as the nature and gravity of the breach and the mitigating action taken. Representation before the Board or the Tribunal is for your advocate.
Rules on paper change nothing until staff know them. Training should be short, practical and role-specific: reception and customer service on notices, identity checks and requests; sales and marketing on consent and opt-outs; HR on employee data; IT on access and incidents; everyone on spotting and reporting a breach, safe use of phones and messaging apps, and what never to paste into public tools. A one-page summary on the notice board and a ten-minute refresher each quarter work better than an annual lecture.
A review is a snapshot. After the first review, a lighter annual review should update the inventory, check the plan’s results, test the breach and request procedures again, and pick up changes in law and in the business. A fresh review is also sensible whenever the business launches a new product or app, adopts a major new system or AI tool, expands abroad, acquires another business, or suffers an incident. Tying the annual review to an existing calendar event — the financial year end or the security review — makes it more likely to happen.
Where a business operates through several companies, branches or franchisees, the review must decide who is the data fiduciary for each activity. A group company that runs a shared CRM for its sister companies may be a processor for them, or they may be joint fiduciaries; a franchisor that runs a central booking app may hold customers’ data for itself as well as for franchisees. The answers decide whose notice customers see, who handles their requests, and which contracts are needed between the entities.
A practical approach is to review the central systems once, then use a short checklist for each branch or franchisee covering local practices — paper files, phones, local vendors — and to put intra-group data sharing and processing on written terms.
A shop, clinic, coaching centre or professional office can do a useful review in a few days:
This does not remove any duty under the Act, but it covers the areas where small businesses are most exposed, and it is far better than nothing.
The West Delhi clinic chain from the top of this page asked for a review before signing the hospital group’s partnership agreement. The scope covered its four clinics, the website, the booking and records software, and HR. Interviews with the clinic manager, two receptionists, the IT freelancer and the accountant produced an inventory of twenty-three activities.
The high-risk findings were a shared login to the records software at every reception desk, prescriptions photographed on a receptionist’s personal phone and sent over a messaging app, no processing contract with the SMS provider, backups kept on an unencrypted external drive taken home by the freelancer, and no retention period for anything. The breach drill showed that nobody knew whom to call if a laptop was stolen. Medium findings included a privacy policy copied from a foreign template and booking forms asking for full date of birth. The thirty-day plan gave every receptionist a personal login with a second factor, replaced phone photographs with a scanner feeding the records system, encrypted the backup and moved it to the software provider’s India-hosted service, adopted a one-page breach procedure, and signed processing terms with the SMS and software providers. The owner then signed the hospital group’s confirmation, describing accurately what had been done and what was scheduled.
A coaching institute in Laxmi Nagar with three thousand students, most of them under eighteen, wanted to launch an app for recorded lectures and tests. Its review focused on children’s data, marketing and the new app.
The inventory showed that students’ phone numbers, parents’ numbers, test scores and photographs were held in a spreadsheet shared with six counsellors, uploaded to an advertising platform for “lookalike” campaigns, and posted in results announcements on social media. The app’s draft design included an analytics SDK with advertising features. The review recommended enrolment by parents with a consent step, ending the upload of student lists to advertising platforms, removing the advertising features from the SDK, limiting results announcements to students whose parents agreed, moving the spreadsheet into the student management system with role-based access, and a retention period for former students. The app’s privacy policy and store disclosures were prepared from the updated inventory, using the approach in our app compliance guide.
Our DPDP Act compliance review costs ₹14,999 and takes 7 – 21 days, depending on the size of the business and how quickly information is available. The fee covers a business of ordinary size with one entity; for groups, multiple branches or complex systems, we agree the scope and tell you the total before we start.
| Included | Why it helps |
|---|---|
| Scoping and interviews with your team | Facts, not assumptions |
| Data inventory and vendor register | A map you own and can keep updated |
| Gap assessment with practical tests | Notices, consent, children, security, vendors, breach, rights, retention, transfers |
| Risk-ranked written report | Clear priorities for the owner or board |
| 30-60-90 day action plan and draft procedures | Breach, requests and retention ready to adopt |
| Walk-through meeting and one follow-up check | The plan starts moving |
Documents the review recommends — privacy policies, processing agreements, HR documents — are quoted separately. Technical security testing is for specialist security firms, whose reports we use as evidence. Representation before the Data Protection Board, an appellate tribunal or a court is for your advocate, whose fee is engaged and paid by you directly; we do not quote, collect or share it. You can find an advocate through our directory.
A client, an investor, a customer or the Data Protection Board may one day ask what your business does with personal data. A review gives you a truthful answer, a map you can keep, and a short list of the fixes that matter most. Tell us about your business and we will scope the review.
Two doors, both free. Clients search a factual directory of enrolled advocates. Advocates apply to be listed on it — no fee, no commission, nothing paid in either direction.
Search Bar Council enrolled advocates by what your matter is about, by court, or by city. Searching and sending a request are both free.
Enrolled advocates anywhere in India can apply to be listed. Your entry is published only after we verify your enrolment number with your State Bar Council.
This directory carries no ratings, no reviews, no rankings and no fees — only the factual particulars the Bar Council of India permits, published at each advocate's own request. Browse the network · Terms for Advocates