Readiness · DPDP readiness

The DPDP readiness checklist

34 items, in the order we would actually do them. Nothing here establishes whether you comply with anything; it establishes what is true about your systems, which is the thing a lawyer will ask you for. Print it, mark it up, give it an owner.

1. Locate it

  • List every system holding personal data.Done when a new person could find all of them from the list alone.
  • Include the informal ones: spreadsheets, WhatsApp, shared inboxes, exports.This is where the list usually doubles.
  • Include vendors who hold it on your behalf.Hosting, CRM, analytics, courier, payment, agency logins.
  • Note who inside the business can reach each one.
  • Note where each one physically stores the data.
  • Mark anything you cannot explain the purpose of.Candidates for deletion, not documentation.

2. Describe it

  • Write the specific purpose next to every row."Analytics" is not a purpose. "To show a customer their past orders" is.
  • Write the categories of personal data each row holds.
  • Check your notice is a standalone document, not a clause.
  • Check the notice is in plain language a customer would follow.
  • Check it itemises categories and purposes, and the services that depend on them.
  • Check it explains withdrawal, grievance, and complaint to the Board.
  • Delete from the notice anything you do not actually do.Copied clauses about cookies you do not set are a written record of a promise you are not keeping.
  • Name a real person for grievances and publish a route that reaches them.

3. Make the rights executable

  • Trace one real record through every system on the inventory.
  • Write down every place it survives a deletion attempt.Backups, warehouses, vendor systems, exports, logs.
  • Decide what deletion means for each of those, and write it down.
  • Build or document the access route: everything you hold about one person.
  • Set a target response time for both, before the first request.
  • Establish whether any of your users are under eighteen.Establish, not assume.
  • If yes, treat verifiable parental consent as a product change.
  • Build withdrawal of consent into the product, not into an inbox.
  • Confirm withdrawal actually stops the processing, not just records the request.

4. Secure it

  • Encrypt, mask, obfuscate or tokenise personal data at rest.
  • Put access controls on the systems that hold it.
  • Enable logs good enough to detect unauthorised access.
  • Set log retention to at least one year for personal data systems.CERT-In separately requires 180 days of ICT logs, kept in India.
  • Read what each vendor contract says about safeguards.The gap is usually the smallest vendor.
  • Set a retention period per row of the inventory, and enforce it.
  • Confirm backups exist and are separated from the systems they protect.

5. Rehearse the bad day

  • Write the incident sequence down, with a named owner.
  • Put both reporting routes in it: CERT-In within six hours, the Board within 72.
  • Draft the message to affected people before you need it.
  • Walk it through out loud, once, with the people who would be on the call.