The DPDP compliance checklist for small teams (2026)

12 June 2026 · 8 min read

Twelve items between you and DPDP compliance. Work through them in order, tick them off, keep the proof. Print the page or save it as a PDF for your team.

DPDP compliance is not a research project. It is a finite list. The Act and the 2025 Rules ask for specific, checkable things, and for a typical small site there are twelve of them. Work top to bottom. Hard deadline: 13 May 2027, when consent, notice, and data rights obligations become enforceable.

Want this as a PDF?

Print this page and choose "Save as PDF". It renders clean. Pin it in your team channel and assign names to items.

Part 1: know what you collect

1. Map every point where personal data enters

Signup forms, checkout, newsletter boxes, contact forms, chat widgets, lead magnets, analytics scripts, ad pixels. Write each one down with the fields it collects. Most teams find collection points they forgot they had. An old webinar form is still a collection point.

2. Assign a purpose to every field

Why do you collect the phone number? Delivery updates is a purpose. "Might be useful" is not. Under the Act you can only process data for the purpose the person agreed to, so every field needs one, written in words a customer would understand.

3. List your processors

Your CRM, email tool, payment gateway, analytics, cloud host. Data you collect flows to them, and you stay responsible for it. Know where each field goes and check you can delete it there when someone withdraws consent.

Part 2: fix the front door

4. Put up a purpose-wise consent banner

Not a cookie banner. A consent banner that lists each purpose separately, with separate toggles, and equal-weight accept and reject buttons. Pre-ticked boxes and bundled consent fail Section 6. The details live in our guide to consent under the DPDP Act.

5. Publish an itemized privacy notice

The notice must itemize the personal data you collect, state each purpose, and explain how to complain to you and to the Data Protection Board. It must be available in English or any of the 22 Eighth Schedule languages the user prefers. If your notice was copied from a US template in 2019, replace it.

6. Block trackers until consent lands

Google Analytics, Meta Pixel, Hotjar and friends must not fire before the visitor agrees to that purpose. Loading them first and asking later is collection without consent. Autoblocking plus Google Consent Mode v2 handles this without breaking your reporting.

7. Make withdrawal one click

Section 6(4): withdrawing consent must be as easy as giving it. That means a preference center reachable from your site, not an email to support that gets answered on Thursdays.

Part 3: keep the receipts

8. Record every consent event

Who agreed, to which purposes, when, against which version of your notice. Store it where it cannot be quietly edited. When the Board asks, you export and hand it over. No records means no defence, whatever your banner looked like.

9. Version your notices

When you change what you collect or why, the notice changes, and consents taken against the old version need refreshing. Keep every version with dates. This is the item teams most often miss.

Part 4: handle people

10. Open a data rights channel

People can ask what you hold, correct it, erase it, and nominate someone to act for them. You need an address where these requests land and a process that actually executes them, including in your processors' systems.

11. Name a grievance contact

The notice must say who handles complaints and how. A monitored inbox with a response target is enough for a small team. An unmonitored one is a finding waiting to happen.

12. Write the breach playbook

Under the 2025 Rules you notify affected users without delay and file with the Board within 72 hours of becoming aware. Decide now who drafts the notice, who files, and where your consent and processing records live, because 72 hours disappears fast.

The checklist, in one table

DPDP compliance checklist, 2026
#ItemProof it is done
1Data inventoryA list of every form, field, and script
2Purpose per fieldWritten purpose statements
3Processor listVendors mapped to data fields
4Purpose-wise bannerSeparate toggles, equal buttons, live on site
5Itemized noticePublished, language switcher works
6Tracker autoblockNo tracker fires pre-consent
7One-click withdrawalPreference center linked in footer
8Consent recordsTamper-evident log, exportable
9Notice versioningDated versions archived
10Data rights channelRequests land and get executed
11Grievance contactNamed in notice, inbox monitored
12Breach playbookOwners named, 72-hour drill done

Items 4 through 9 are the heavy ones, and they are exactly what tooling automates. Skope closes them in five steps, about 30 minutes for a typical site.

Not legal advice

This checklist covers a typical small website or app. If you process children's data, health data, or large volumes, get counsel to review your setup.

Frequently asked questions

Is there an official DPDP compliance checklist PDF?

The government has not published an official checklist. The obligations come from the DPDP Act, 2023 and the DPDP Rules, 2025. This 12-point list maps to those obligations, and you can print this page to PDF for your team.

How long does DPDP compliance take for a small website?

The inventory and purpose mapping take a few hours of honest work. The technical items, banner, notice, autoblock, records, and withdrawal, take about 30 minutes with a consent kit like Skope, or weeks if you build them yourself.

Do I need a Data Protection Officer?

Only Significant Data Fiduciaries, notified by the government, must appoint a DPO based in India. A typical small business does not, but you still need a named grievance contact in your privacy notice.

What is the deadline to complete this checklist?

Consent, notice, and data rights obligations under the DPDP Rules become enforceable on 13 May 2027. Consent records take time to accumulate, so the earlier your banner is live, the stronger your position.

Check your site against this list, automatically

The free Skope scanner reads your site and scores it against the DPDP checklist: banner, notice, trackers, withdrawal. Results in 60 seconds.

Run the free scan