No Payment Now — Pay Only After the Work Is Done · Delhi & All India · Online + Offline · +91 98913 43962
Legal Space Services (LSS) logoLegal Space Services
Login
Legal Space ServicesLegal Services & Documentation Company
Free Consultation
No payment now · Pay after work
Login
+91 98913 43962 WhatsApp Chat
HomeDocumentsDocument Guides › DPDP Act Compliance Review

DPDP Act compliance review — know what your business does with personal data before anyone asks

The owner of a chain of four clinics in West Delhi is asked by a hospital group it wants to partner with to confirm, in writing, that it complies with the Digital Personal Data Protection Act. She knows the clinics keep patient records in software, send reminders by SMS, and have a receptionist who photographs prescriptions on her phone. She does not know where the backups are, which vendors can see the data, how long anything is kept, or what would happen if a laptop were stolen. A compliance review answers those questions in a few weeks, ranks what needs fixing, and gives her something truthful to sign. This page explains how such a review works, what it tests, and what it should produce.

From ₹14,999 7 – 21 days Data map, gap report, action plan Nothing payable in advance
What is a DPDP Act compliance review, and what does it involve?A DPDP Act compliance review is a structured check of how a business handles personal data against the Digital Personal Data Protection Act, 2023 and the rules notified in November 2025, whose main obligations apply in phases, most of them about eighteen months after notification. It starts by agreeing the scope — the entities, products, systems and people covered — and building a data inventory that records, for each kind of personal data, whose it is, why it is collected, the legal basis, where it is stored, who can see it, which vendors receive it, whether it leaves India and how long it is kept. It then tests each obligation in practice: whether notices are accurate and consent is valid and withdrawable, whether children’s data is handled correctly, whether security safeguards and logs are adequate, whether every processor is under a proper contract, whether the business could detect a breach and inform the Board and affected people in time, whether individuals’ requests are answered, and whether data is deleted when its purpose ends. Each gap is scored by likelihood and impact, and the review ends with a written report and a 30-60-90 day action plan with named owners, followed by a lighter review each year and after any major change.

Why review now

For most Indian businesses, personal data grew by accident. A customer list started in a notebook moved to a spreadsheet, then to a CRM; a WhatsApp group became the main channel for client documents; a marketing agency added a few tracking tags; a payroll vendor was engaged by email. Nobody decided, at any point, how the business as a whole should handle personal data. The Digital Personal Data Protection Act, 2023 now requires that decision to be made and written down.

The law itself — what it requires of a data fiduciary, the rights of individuals, the penalties — is set out in our DPDP privacy policy guide. This page is about the practical exercise that turns the law into a business’s own to-do list: the compliance review. Its value is that it replaces guesswork with facts. Before the review, the owner believes the data is “safe with us”; after it, the owner knows which systems hold it, which people and vendors can see it, what was promised to customers, and what must change first.

There are three good reasons to do it now rather than later. The main obligations have a fixed start date, and fixing systems takes months, not days. Larger clients, hospitals, banks and foreign customers are already asking their suppliers for evidence of compliance. And businesses that raise funds or sell themselves find that investors now ask about personal data in due diligence.

The timeline under the rules

The Act was passed in August 2023, and the Digital Personal Data Protection Rules were notified in November 2025. The rules did not take effect all at once. As notified, they provide broadly for three stages:

Swipe to see the full table
StageWhat comes into forceWhat a business should be doing
On notification (November 2025)Provisions constituting the Data Protection Board and its procedureUnderstanding the law; starting the inventory
After about twelve monthsRegistration and obligations of consent managersDesigning consent records that can work with consent managers
After about eighteen monthsMost obligations of data fiduciaries: notice, consent, security safeguards, breach intimation, erasure, rights, children, significant data fiduciary dutiesHaving the fixes in place and working

Businesses should check the notified text for the precise date on which each provision takes effect, and watch for amendments and clarifications. The practical lesson is simple: the months before the main obligations begin are the time for the review and the remediation, because after that date the Board can act on complaints and breaches.

Who needs a review

The Act applies to processing of digital personal data in India, and to processing outside India connected with offering goods or services to people in India, as our guide on whether the Act applies explains. There is no turnover or headcount threshold for ordinary data fiduciaries. In practice, a review is most urgent for businesses that:

Even a small professional office — a CA firm, a law office, a clinic, a coaching centre — benefits from a short review, because the fixes it identifies are usually simple and cheap if found early.

What a good review produces

A review should leave the business with things it can use, not only an opinion. At minimum:

The report should say plainly what was not reviewed, and why, so nobody later mistakes a partial review for a complete one.

The review, step by step

Swipe to see the full table
PhaseWhat happensTypical output
1. ScopingAgree entities, products, systems, departments and data subjects; name contactsScope note and information request
2. DiscoveryInterviews with owners of customer service, sales, marketing, HR, IT and finance; review of documents; walk-through of systemsInterview notes, screenshots
3. InventoryRecord each processing activity and data flowData inventory
4. TestingCheck each obligation against evidence, including practical testsGap register with evidence
5. ScoringRank gaps by likelihood and impactRisk ratings
6. ReportingWrite findings and recommendationsReport and action plan
7. Walk-throughExplain results to owners, agree priorities and ownersAgreed plan
8. Follow-upCheck progress after the first milestonesUpdated gap register

Most of the useful information comes from conversations with the people who do the work, not from policies. The receptionist who scans identity documents, the marketing executive who exports leads to a new tool, and the accountant who emails salary files know where the data goes.

Preparing for the review

A review goes faster, and costs less time for everyone, when the business gathers a few things in advance. None of them needs to be perfect; the point is to show the reviewer what exists.

Swipe to see the full table
GatherWhy
List of software, apps and cloud services in use, with who administers eachStarting point for the inventory and access review
Current privacy policy, website terms and any consent wordingTo compare promises with practice
Vendor list with contracts or order formsFor the vendor register
Employee handbook, offer letter and employment contract templatesFor HR data and confidentiality
Any security policy, certification or test reportEvidence of existing controls
Records of past incidents, complaints or data requestsTo see how issues were handled
Organisation chart and names of department headsTo plan interviews

The business should not send bulk copies of customer data to the reviewer. Screenshots, field lists and a handful of redacted samples are enough to understand how data is held, and avoid creating a new copy that itself needs protecting.

Setting the scope

A review that tries to cover everything at once usually covers nothing well. Scoping decides:

Where a business is large, the first review can focus on the highest-risk activities — usually the core customer database, the website and apps, and the vendors that hold the most data — with other areas in a second phase. The scope note should also name one person inside the business who coordinates the review and can open doors.

Building the data inventory

The inventory is the heart of the review. It records each processing activity — a distinct use of personal data — in a consistent form. A practical template:

Swipe to see the full table
ColumnExample entry
ActivityOnline appointment booking
Whose dataPatients, including minors
Data fieldsName, phone, age, reason for visit, appointment time
SourceWebsite form, phone calls entered by reception
PurposeScheduling and reminders
Legal basisConsent at booking; reminders part of the service
System and locationBooking software, cloud servers in India
AccessReception staff, doctors, clinic manager
VendorsBooking software provider, SMS provider
Transfers abroadNone known; support team location to confirm
RetentionNot defined — gap
Security notesShared reception login — gap

A small business may have fifteen to forty activities; a larger one, hundreds. The inventory need not be perfect on day one, but it must be honest and kept up to date, because every other step depends on it. It also makes it possible to answer an individual who asks for a summary of the personal data held about them and the processing activities it is used for, which the Act allows them to request.

Purpose and legal basis for each use

For each activity in the inventory, the review asks two questions: what is the specific purpose, and what is the basis for processing? Under the Act, processing is lawful either with consent or for one of the legitimate uses the Act lists — for example, where an individual voluntarily provides data for a specified purpose and has not objected, for employment purposes, or to comply with law. Those bases are explained in our guide on legitimate uses.

Common findings at this stage are uses with no clear purpose (“we keep everything in case it is useful”), purposes that grew beyond what customers were told (booking data now used for marketing), and consent relied on where the business could not actually honour a withdrawal. Each such finding goes into the gap register with a recommended basis and any change needed to notices or systems.

Collecting less

The simplest way to reduce risk is to hold less. A review should look at every form, every document request and every export, and ask whether each field is needed for the stated purpose. Typical quick wins are removing date of birth from enquiry forms, masking all but the last digits of identity numbers, not storing copies of identity documents once verification is done, not exporting full customer lists to marketing tools, and deleting old files from shared drives and messaging groups.

Collecting less is also cheaper: fewer fields to secure, fewer records to delete later, fewer answers to give when someone asks what is held about them. The review report should list each field recommended for removal, with the reason.

Testing notices

A notice is only compliant if it matches what the business actually does and reaches people at the right moment. The review tests this in practice rather than by reading the privacy policy alone:

The content of a good notice is set out in our guide on the notice; where it should appear on a website is covered in our website legal pack guide.

Consent under the Act must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and as easy to withdraw as to give; the requirements are explained in our consent guide and our note on withdrawal. The review tests the reality:

A practical test is to sign up with a test identity, withdraw consent, and see whether messages stop. Businesses are often surprised to find that an unsubscribe removes a customer from one tool but not from the others to which the list was copied. The review should also note whether consent records could be shared with a registered consent manager if the business chooses to use one.

Children’s data

The Act treats anyone under eighteen as a child, requires verifiable consent of a parent or lawful guardian before processing a child’s data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the rules for particular kinds of processing such as by educational institutions and health services in defined circumstances. The details are in our guide on children.

The review asks where children’s data might enter the business, including by accident: a coaching centre’s students, a clinic’s young patients, a game’s players, a toy shop’s loyalty programme. For each, it checks how age is established, how parental consent is obtained and verified, whether any exemption genuinely applies, and whether analytics or advertising tools run on pages children use. This is frequently the area with the largest gap between practice and law.

Paper files, phones and messaging groups

The Act applies to digital personal data, including data collected on paper and later digitised. In practice, the review cannot ignore paper files, because they are usually scanned, photographed or typed into systems at some point, and because the same staff handle both.

Messaging apps are the hidden database of many Indian businesses. Client documents are sent by customers on WhatsApp, forwarded between staff, saved to phone galleries and backed up to personal cloud accounts. The review should find out which groups and numbers are used for work, what is shared in them, who is in them — including former staff — and where the phones back up. Usual fixes are a business account for customer communication, a rule that documents are moved into the proper system and deleted from phones, removal of former staff from groups, and turning off personal cloud backup of work chats. Paper files need locked storage, a record of who takes them out, and proper shredding.

Security safeguards

The Act requires reasonable security safeguards to prevent personal data breaches, and the rules describe the kinds of measures expected, including encryption, masking or tokenisation where appropriate, access control, logging and monitoring, backups and contractual safeguards with processors. The review does not need to be a full technical audit, but it should check the basics with evidence:

Swipe to see the full table
ControlHow it is checked
Individual logins and multi-factor authenticationScreenshots of user lists and settings for key systems
Encryption of laptops, phones and backupsDevice settings, backup configuration
Access limited by roleWho can export customer lists; test with a junior account
Logs of access to personal data, kept for the required periodLog settings and retention in key systems
Backups testedDate of last successful restore test
Software updatedUpdate status of website, plugins, servers
Staff leavingAccess removal records for recent leavers
Physical recordsStorage of paper files and their disposal

Where the business holds a security certification or has a recent penetration test, those are good evidence. Where it has neither, the review identifies the few controls that give the most protection for the least cost.

Access and people

Most data incidents in small and mid-sized Indian businesses involve people rather than hackers: a shared password, a customer list forwarded to a personal email, a former employee who still has access, a phone with client documents lost in an auto-rickshaw. The review therefore looks at:

The fixes are often organisational: a written rule on use of personal devices, an exit checklist, and removing shared logins. Our HR policy guide shows how these rules fit into the staff handbook.

Vendors and processors

The review builds a vendor register from the inventory: every outside party that receives personal data, what it receives, its role, where it stores the data, and whether the contract is adequate. The Act permits a data fiduciary to engage a processor only under a valid contract and keeps the fiduciary responsible for the processor’s processing, as explained in our data processing agreement guide.

For each significant vendor, the review checks the contract against the points in that guide’s addendum checklist, notes gaps, and recommends either a new agreement, an amendment, or — where a global vendor will not negotiate — compensating steps. It also identifies vendors that act as independent fiduciaries, such as payment gateways and couriers, whose role should be reflected in the notice rather than in a processing contract.

Breach readiness — the drill

The Act requires a data fiduciary to intimate a personal data breach to the Board and to each affected person, and the rules set out the content and a fixed period for the detailed report to the Board; many cyber incidents must also be reported to CERT-In within a few hours. These duties are explained in our breach guide. A business cannot meet those timelines by improvising.

The most revealing part of a review is often a short tabletop exercise. The reviewer describes a realistic scenario — a receptionist’s laptop with patient files is stolen on Friday evening; a vendor reports that a database was exposed; a customer says their details appeared in a WhatsApp group — and the team talks through what they would do, hour by hour:

  1. Who would hear about it first, and whom would they tell?
  2. Who decides whether it is a personal data breach?
  3. How would the business find out which data and which people were affected?
  4. Who contacts the vendor, and what does the contract require of them?
  5. Who drafts the intimation to the Board and to affected people, and from what template?
  6. Who reports to CERT-In if required, and within what time?
  7. Who talks to customers and the press?
  8. How is the incident recorded, and what is changed afterwards?

Gaps revealed by the drill go straight into the action plan, usually as a one-page breach procedure, a contact list, templates, and changes to vendor contracts.

Requests from individuals — the test

Individuals have rights to a summary of their personal data and its processing, to correction, completion, updating and erasure, to grievance redressal and to nominate someone to act for them, as set out in our rights guide. The review tests whether the business can actually respond:

A useful practical test is a “mystery request”: with the business’s agreement, a test request is sent through the published channel, and the reviewer observes what happens. The result usually shows in a day what a policy never would. The fix is a short procedure, a request log and, for businesses with many customers, a simple self-service page.

Retention and deletion

The Act requires erasure once the purpose is no longer served or consent is withdrawn, unless the law requires the data to be kept, and requires the fiduciary to cause its processors to erase too; our guide on retention explains the rule. The rules also set specific periods for certain large classes of platforms, and a minimum period for keeping logs.

In a review, retention is usually the largest gap, because almost no Indian small business deletes anything. The deliverable is a retention schedule: for each category in the inventory, how long it is kept, what event starts the period, what law requires retention (tax, company law, labour law, medical records rules, professional rules), and how deletion happens in each system and at each vendor. The plan then sets out a first clean-up — old enquiry lists, former employees’ files, closed customer records beyond their period — and a routine to repeat it.

Data leaving India

The Act permits transfer of personal data outside India except to countries the government notifies as restricted, while preserving stricter sectoral rules, as our transfer guide explains. The review’s job is factual: to find out where data actually goes. Cloud services, email platforms, analytics and advertising tools, customer support software and AI tools frequently store or process data abroad, and vendors’ support teams may access it from other countries.

The inventory should record the location of storage and access for each system, and the report should flag any sector rule requiring storage in India, any vendor whose location is unknown, and whether the business would be affected if a destination were restricted.

Employees and applicants

HR data is often the most sensitive data a business holds — salaries, bank details, identity numbers, health information for insurance, background checks, disciplinary records — and the least reviewed. The Act allows processing for employment purposes as a legitimate use, as our guide on employee data explains, but every other duty applies.

The review covers recruitment (what applicants are asked for and how long unsuccessful applications are kept), onboarding documents, payroll and attendance vendors, monitoring of email and devices, background verification, medical and insurance data, and exit records. Common recommendations are an employee privacy notice, processing terms with HR vendors, restricted access to salary and medical files, and a retention period for former employees’ records. Our HR policy and employment agreement services can carry these into staff documents.

Marketing, analytics and AI

Marketing is where data most often goes further than customers expect. The review traces how leads are captured, where lists are stored, which tools send messages, what tracking tags and pixels run on the website and app, whether customer lists are uploaded to advertising platforms, and whether any data is used to train or feed AI tools. For each, it checks the notice, the consent and the opt-out.

AI tools deserve a specific question: are staff pasting customer data, documents or conversations into public AI services? A short rule on approved tools and prohibited data, and a check of the terms of any AI vendor, are usually needed. For websites and apps, the review can use the tag and SDK checks described in our app compliance guide and the cookie approach in our website legal pack guide.

Checking new projects before launch

A review looks at what exists; the business also needs a habit for what is coming. Before launching a new product, app, form, marketing campaign or AI tool, a short check — a page or two — asks: what personal data will this collect, why, on what basis, who will receive it, where it will be stored, how long it will be kept, whether children could be affected, and what could go wrong. Only significant data fiduciaries are required by the Act to carry out formal impact assessments, but the same questions asked early save redesigns later.

The review can supply a simple template for this check and name who must complete it. Building the answer into the project plan — as a step before the developer is briefed — is what “privacy by design” means in a small business.

Significant data fiduciary watch

The government may notify a data fiduciary or class of fiduciaries as significant, considering the volume and sensitivity of data, risk to individuals and wider factors; such fiduciaries must appoint a Data Protection Officer based in India, an independent data auditor, and carry out periodic impact assessments and audits, as our guide on significant data fiduciaries explains.

Most businesses reading this will not be notified. A review should still record whether the business could plausibly be, given its volume and type of data, and whether large clients are asking it to meet similar standards by contract. Where either is likely, the review can be structured so that it later serves as the baseline for a formal data protection impact assessment.

Sector rules on top

The DPDP Act is general, and stricter sectoral rules continue to apply. The review should identify which apply to the business and check them alongside the Act:

Swipe to see the full table
SectorAdditional areas to check
Banks, NBFCs, payment and lending businessesRBI directions on IT outsourcing, digital lending, payment data storage and cyber security
Securities market intermediariesSEBI cyber security and resilience framework
Insurers and intermediariesIRDAI information and cyber security guidelines
Hospitals, clinics, labsConfidentiality of medical records, telemedicine rules, digital health standards
Schools and coachingChildren’s data, education regulators’ guidance
Telecom and internet businessesLicence conditions, intermediary rules, CERT-In directions
Government contractorsContract terms on data location, security and audit

Where a sector regulator’s rule is stricter than the Act, the stricter rule generally sets the standard for that activity.

Scoring the risks

Not every gap is equally urgent. A clear scoring method helps a busy owner decide what to fix first. A simple approach rates each finding for likelihood and impact on a three-point scale and combines them:

Swipe to see the full table
RatingLikelihood meansImpact means
HighHappening now, or very likely within a yearSensitive data, many people, or a legal duty directly breached
MediumPlausible within a yearModerate harm, limited numbers, or a weak control
LowUnlikelyMinor inconvenience, documentation only

High-high findings — for example, patient records on staff phones with no lock, or a vendor holding sensitive data with no contract — go into the first thirty days. Documentation gaps with low impact can wait for the ninety-day stage. The score should be explained in words, so that it can be understood without the table.

The report

A useful report is short at the front and detailed at the back. A structure that works:

  1. Summary for the owner or board: overall position in a paragraph, the five most important findings, and the headline plan.
  2. Scope and method: what was covered, how, and what was not.
  3. Findings by area: notices, consent, children, security, vendors, breach readiness, rights, retention, transfers, HR, marketing — each with evidence, risk rating and recommendation.
  4. Action plan: 30-60-90 day tasks with owners.
  5. Annexes: the data inventory, vendor register, draft procedures and document list.

The report is itself confidential and may contain sensitive findings. It should be shared only with those who need it, and marked accordingly. If the business intends to share a summary with clients or investors, a separate short statement of the steps taken is more appropriate than the full report.

The 30-60-90 day plan

Swipe to see the full table
PeriodTypical tasks
First 30 daysFix high-risk security gaps (shared logins, unencrypted devices); stop the riskiest data uses; appoint an owner; adopt a breach procedure and contact list; sign processing terms with the most sensitive vendors
31–60 daysPublish accurate notices and consent wording; separate marketing consent; set up a request channel and log; begin the retention clean-up; train staff
61–90 daysComplete vendor contracts; adopt the retention schedule in each system; employee privacy notice; children’s data controls; follow-up review of progress

Each task should have one named owner and a date. Tasks that depend on outside parties — a software vendor adding a deletion feature, a global provider’s contract — should have an interim measure, so the plan does not stall. Documents the plan calls for, such as a privacy policy, data processing agreements or a website legal pack, can be prepared in parallel.

Owners, board and evidence

Compliance lasts only if someone owns it. Even where the Act does not require a Data Protection Officer, the business should name a person responsible for data protection decisions, give that person time and authority, and publish a contact for questions and grievances. In a company, the board or partners should receive the review summary and a short progress update each quarter until the plan is complete.

The business should also keep an evidence file: the inventory, the notices and their versions, consent records, vendor contracts, training records, the request log, the breach log, and the review reports. If the Board ever inquires, the question will be what the business did and when; the evidence file is the answer.

Answering clients’ questionnaires

Businesses that supply larger companies increasingly receive data protection questionnaires: do you have a privacy policy, who is your data protection contact, where is data stored, do you encrypt it, which sub-processors do you use, how would you notify us of a breach, do you have a certification. A review produces most of the answers. Keeping a standard response pack — the inventory summary, security description, sub-processor list, breach commitment and contact — lets the business answer quickly and consistently, and avoids the temptation to tick “yes” to everything. Our guide for processors explains how to prepare it.

Every answer given to a client is a representation. If it is untrue, it can become a breach of contract, and possibly misrepresentation. It is better to answer “planned by March, in progress” than to claim a control that does not exist.

Complaints, the Board and what follows

An individual with a complaint must usually first use the business’s own grievance mechanism, and may then complain to the Data Protection Board. The Board can also act on a reference from the government or a court, or on a breach intimation. It is designed as a digital office, and it may inquire, direct urgent measures, and impose penalties after hearing the business. During proceedings the business may offer a voluntary undertaking — for example, to take specified steps within a time — which the Board may accept. Appeals from the Board’s orders go to the Appellate Tribunal within the time the Act allows.

A business that has done a review and followed its plan is in a far better position in any of these steps: it can show the inventory, the notices, the vendor contracts, the training and the steps taken after the incident. The Act itself directs the Board, when deciding a penalty, to consider matters such as the nature and gravity of the breach and the mitigating action taken. Representation before the Board or the Tribunal is for your advocate.

Training the team

Rules on paper change nothing until staff know them. Training should be short, practical and role-specific: reception and customer service on notices, identity checks and requests; sales and marketing on consent and opt-outs; HR on employee data; IT on access and incidents; everyone on spotting and reporting a breach, safe use of phones and messaging apps, and what never to paste into public tools. A one-page summary on the notice board and a ten-minute refresher each quarter work better than an annual lecture.

Keeping it current

A review is a snapshot. After the first review, a lighter annual review should update the inventory, check the plan’s results, test the breach and request procedures again, and pick up changes in law and in the business. A fresh review is also sensible whenever the business launches a new product or app, adopts a major new system or AI tool, expands abroad, acquires another business, or suffers an incident. Tying the annual review to an existing calendar event — the financial year end or the security review — makes it more likely to happen.

Groups, branches and franchises

Where a business operates through several companies, branches or franchisees, the review must decide who is the data fiduciary for each activity. A group company that runs a shared CRM for its sister companies may be a processor for them, or they may be joint fiduciaries; a franchisor that runs a central booking app may hold customers’ data for itself as well as for franchisees. The answers decide whose notice customers see, who handles their requests, and which contracts are needed between the entities.

A practical approach is to review the central systems once, then use a short checklist for each branch or franchisee covering local practices — paper files, phones, local vendors — and to put intra-group data sharing and processing on written terms.

A lean review for small businesses

A shop, clinic, coaching centre or professional office can do a useful review in a few days:

  1. list every place personal data lives — software, spreadsheets, email, WhatsApp, paper files, phones;
  2. for each, write down whose data, why, who can see it and when it can be deleted;
  3. remove shared passwords and switch on phone and laptop locks;
  4. check the website forms and notices;
  5. list vendors and get processing terms from those that hold the most data;
  6. write a one-page breach procedure and a one-page request procedure;
  7. delete what is no longer needed; and
  8. put a date in the calendar to repeat the exercise next year.

This does not remove any duty under the Act, but it covers the areas where small businesses are most exposed, and it is far better than nothing.

An example: a clinic chain

The West Delhi clinic chain from the top of this page asked for a review before signing the hospital group’s partnership agreement. The scope covered its four clinics, the website, the booking and records software, and HR. Interviews with the clinic manager, two receptionists, the IT freelancer and the accountant produced an inventory of twenty-three activities.

The high-risk findings were a shared login to the records software at every reception desk, prescriptions photographed on a receptionist’s personal phone and sent over a messaging app, no processing contract with the SMS provider, backups kept on an unencrypted external drive taken home by the freelancer, and no retention period for anything. The breach drill showed that nobody knew whom to call if a laptop was stolen. Medium findings included a privacy policy copied from a foreign template and booking forms asking for full date of birth. The thirty-day plan gave every receptionist a personal login with a second factor, replaced phone photographs with a scanner feeding the records system, encrypted the backup and moved it to the software provider’s India-hosted service, adopted a one-page breach procedure, and signed processing terms with the SMS and software providers. The owner then signed the hospital group’s confirmation, describing accurately what had been done and what was scheduled.

An example: a coaching institute

A coaching institute in Laxmi Nagar with three thousand students, most of them under eighteen, wanted to launch an app for recorded lectures and tests. Its review focused on children’s data, marketing and the new app.

The inventory showed that students’ phone numbers, parents’ numbers, test scores and photographs were held in a spreadsheet shared with six counsellors, uploaded to an advertising platform for “lookalike” campaigns, and posted in results announcements on social media. The app’s draft design included an analytics SDK with advertising features. The review recommended enrolment by parents with a consent step, ending the upload of student lists to advertising platforms, removing the advertising features from the SDK, limiting results announcements to students whose parents agreed, moving the spreadsheet into the student management system with role-based access, and a retention period for former students. The app’s privacy policy and store disclosures were prepared from the updated inventory, using the approach in our app compliance guide.

Where reviews go wrong

Our fee and what you get

Our DPDP Act compliance review costs ₹14,999 and takes 7 – 21 days, depending on the size of the business and how quickly information is available. The fee covers a business of ordinary size with one entity; for groups, multiple branches or complex systems, we agree the scope and tell you the total before we start.

Swipe to see the full table
IncludedWhy it helps
Scoping and interviews with your teamFacts, not assumptions
Data inventory and vendor registerA map you own and can keep updated
Gap assessment with practical testsNotices, consent, children, security, vendors, breach, rights, retention, transfers
Risk-ranked written reportClear priorities for the owner or board
30-60-90 day action plan and draft proceduresBreach, requests and retention ready to adopt
Walk-through meeting and one follow-up checkThe plan starts moving

Documents the review recommends — privacy policies, processing agreements, HR documents — are quoted separately. Technical security testing is for specialist security firms, whose reports we use as evidence. Representation before the Data Protection Board, an appellate tribunal or a court is for your advocate, whose fee is engaged and paid by you directly; we do not quote, collect or share it. You can find an advocate through our directory.

FAQ

DPDP Act compliance review — questions people ask

What is a DPDP Act compliance review?
A structured check of how a business collects, uses, stores, shares and deletes personal data, measured against the Digital Personal Data Protection Act, 2023 and its rules. It maps the data the business actually holds, tests its notices, consents, security, vendor contracts, breach readiness, retention and handling of individuals’ requests, and ends with a written report of gaps ranked by risk and a practical plan to close them.
When do the DPDP Act obligations start?
The rules under the Act were notified in November 2025 with a phased start. Provisions setting up the Data Protection Board applied at once, the consent manager framework follows after about a year, and most of the obligations on businesses — notices, consent, security, breach intimation, erasure and rights — apply about eighteen months after notification. Businesses should confirm the exact dates for each provision and use the time left to prepare.
Does a small business need a DPDP compliance review?
The Act has no size exemption for ordinary businesses: a clinic, coaching centre, shop with a customer list or small software company is a data fiduciary for the personal data it decides to process. A small business does not need an elaborate audit, but it does need to know what data it holds, why, where it goes and how it is protected. A scaled review gives that answer and a short list of fixes.
How long does a DPDP review take?
For a small business with a website, a few systems and a handful of vendors, one to three weeks, depending on how quickly information and access are provided. Larger organisations with many systems, departments or group companies take longer, and are usually reviewed in phases, starting with the highest-risk processing.
What documents are needed for a DPDP review?
Typically the current privacy policy and notices, forms and consent screens, a list of software and vendors that handle personal data, vendor contracts, employee and HR documents, information security policies if any, any past incidents, and access to the people who run customer service, marketing, HR and IT. The review itself produces a data inventory if none exists.
What is a data inventory or data map?
A record of each category of personal data the business processes: whose data it is, what fields, why it is collected, the legal basis, where it is stored, who can access it, which vendors receive it, whether it leaves India, and how long it is kept. It is the foundation for every other compliance step, and for answering individuals who ask what the business holds about them.
Is a DPDP review the same as an ISO 27001 or security audit?
No. A security audit tests technical and organisational controls against a security standard. A DPDP review asks wider questions — whether the business should hold the data at all, on what basis, what it told people, how it handles their rights and when it deletes data — and includes security as one part. The two support each other, and an existing certification is useful evidence in a DPDP review.
Will the review make us fully compliant?
A review identifies what needs to change and how; compliance comes from making those changes and keeping them working. Some fixes are documents that can be prepared quickly, such as notices and vendor terms. Others involve systems, training and habits, such as deleting old data or handling requests on time. The review report sets priorities so that the most serious risks are addressed first.
Do we need a Data Protection Officer?
The Act requires a Data Protection Officer based in India only for businesses notified as Significant Data Fiduciaries. Every data fiduciary must, however, publish the contact of a person who can answer questions about its processing, and run a grievance mechanism. Most businesses should name a responsible person internally, even if the formal DPO duty does not apply.
How are children’s data handled in a review?
The review checks whether the business is likely to process data of anyone under eighteen — students, young patients, gamers, customers of children’s products — and whether it has a way to obtain verifiable consent of a parent or guardian, avoids tracking and targeted advertising directed at children, and uses any exemptions the rules allow correctly. See our DPDP guide on children.
What is a consent manager?
A consent manager is an entity registered with the Data Protection Board that provides an interoperable platform through which individuals can give, manage, review and withdraw consent given to data fiduciaries. Businesses are not obliged to use one in every case, but should design their consent records so that they can work with consent managers as the framework develops.
What happens if a business ignores the DPDP Act?
The Data Protection Board can inquire into breaches and impose monetary penalties set out in the Schedule to the Act, which run up to two hundred and fifty crore rupees for a failure to take reasonable security safeguards. Beyond penalties, businesses face loss of customer trust, contract problems with larger clients who now ask for DPDP compliance, and difficulty in due diligence when raising funds or selling. Our DPDP penalties table gives the full list.
Does the DPDP Act apply to employee data?
Yes. Employee and applicant data is personal data. The Act allows processing for employment purposes as a legitimate use, but the employer must still protect the data, limit its use, handle requests, control vendors such as payroll providers, and delete data when it is no longer needed. The review covers HR processes alongside customer data.
How often should a DPDP review be repeated?
A full review once the main obligations come into force, then a lighter review every year and whenever the business changes significantly — a new product, a new system, a new country, an acquisition or a serious incident. Many businesses combine the annual review with their security review.
Can you review a vendor’s DPDP compliance for us?
Yes, within the review we can assess key vendors from their contracts, security documents and questionnaires, and recommend contract changes. For processors, the terms in our data processing agreement guide are the benchmark.
Is the review confidential?
Yes. We sign a confidentiality agreement before the review if you wish, see only what is needed, prefer screenshots and samples to bulk copies of personal data, and return or delete what we receive at the end, with confirmation.
Do WhatsApp groups and staff phones count in a DPDP review?
Yes. Customer documents shared on messaging apps, saved to phone galleries and backed up to personal cloud accounts are personal data held by the business. The review finds out which numbers and groups are used for work, who is in them, and where the data ends up, and usually recommends a business account, moving documents into the proper system, removing former staff and switching off personal backups of work chats.
Can a customer complain about us to the Data Protection Board?
Yes, generally after first using the business’s own grievance mechanism. The Board can inquire, direct urgent measures and impose penalties after hearing the business, and may accept a voluntary undertaking to take specified steps. A business that can show its inventory, notices, contracts, training and the steps it took after an incident is in a much stronger position.
What does your DPDP Act compliance review cost?
Our DPDP Act compliance review costs ₹14,999 and takes 7 – 21 days depending on the size of the business. It includes scoping, a data inventory, a gap assessment of notices, consent, security, vendors, breach readiness, retention and rights handling, a risk-ranked written report, a 30-60-90 day action plan, and a walk-through meeting. Drafting the documents the review recommends is quoted separately, and we tell you the total before we start. Representation before the Data Protection Board or any court is for your advocate, whose fee is engaged and paid by you directly.
Related

Data protection documents and guides

Privacy policy Data processing agreement Website legal pack App store compliance documents HR policy Employment agreement Non-disclosure agreement SaaS subscription agreement DPDP privacy policy guide Data processing agreement guide Website legal pack guide Find an advocate All document guides

Find out what you hold before someone asks.

A client, an investor, a customer or the Data Protection Board may one day ask what your business does with personal data. A review gives you a truthful answer, a map you can keep, and a short list of the fixes that matter most. Tell us about your business and we will scope the review.

No payment now · Pay only after the work is done
Tis Hazari Court Complex, New Delhi, Delhi 110054
Keep reading

Related guides

Website Legal Pack — Every Page Your Website Needs, Written to Match How It Works App Store Compliance — The Documents the Stores Ask For, and the Indian Law Behind Them Data Processing Agreement — When Someone Else Handles Your Customers’ Data End User Licence Agreement — What the User Buys When the Software Stays Yours Equipment Lease Agreement — Use the Machine, Protect It, Get It Back Revenue Sharing Agreement — Share the Income, Not the Arguments
82 of 281 document services now have an in-depth guide199 still to be written · see them all →
We are writing these one at a time rather than generating them, which is why it is taking a while. 29% done.
Advocates & Clients

Need an advocate? Or are you one?

Two doors, both free. Clients search a factual directory of enrolled advocates. Advocates apply to be listed on it — no fee, no commission, nothing paid in either direction.

Looking for an advocate?

Search Bar Council enrolled advocates by what your matter is about, by court, or by city. Searching and sending a request are both free.

Are you an advocate?

Enrolled advocates anywhere in India can apply to be listed. Your entry is published only after we verify your enrolment number with your State Bar Council.

  • No listing fee, no subscription, no commission — no money moves in either direction.
  • A directory entry, not an advertisement: only the particulars the Bar Council permits.
  • You keep the client. We do not take instructions for you and take no share of your fee.

This directory carries no ratings, no reviews, no rankings and no fees — only the factual particulars the Bar Council of India permits, published at each advocate's own request. Browse the network · Terms for Advocates

Help