DPDP Act 2023 Readiness Checklist
Evaluate your organization's compliance against mandatory statutory requirements under the Digital Personal Data Protection Act 2023.
Notice in 22 Languages (§5(3))
Is your consent notice available in English and all 22 Eighth Schedule languages?
Itemized Purpose Selection (§5(1))
Does your notice present itemized, clear purpose choices without bundled opt-ins?
Grievance Redressal Disclosure (§8(9))
Is your Statutory Grievance Redressal Officer name and email clearly disclosed on every page?
No Pre-Ticked Checkboxes (§6(1))
Are all non-essential consent toggles un-ticked by default before visitor interaction?
Easy Consent Withdrawal (§6(4))
Can Data Principals withdraw consent as easily as it was given via a persistent trigger?
Court-Admissible Proof of Consent (§6(10))
Do you maintain tamper-evident, cryptographically signed consent records?
Data Principal Rights Intake (§11–14)
Do you have an automated portal to handle Access, Correction, Erasure, and Nominee requests?
Statutory Erasure Holds (§12)
Can your system enforce legal retention holds (KYC/PMLA/GST) when erasure is requested?