The DPDP readiness checklist for IT/SaaS vendors

DPDP Readiness Checklist for IT and SaaS Vendors
Stage 2 — Define Need

DPDP Readiness Checklist for IT and SaaS Vendors

A pass/fail self-assessment across 18 controls in 9 domains — use this to score your compliance posture before your next enterprise questionnaire arrives.

This DPDP readiness checklist covers 18 controls across nine domains — legal basis and consent, privacy notice, data inventory, breach response, vendor contracts, data subject rights, retention and deletion, grievance officer, and documentation. Each item includes a "done looks like" description so you can score yourself honestly. A vendor passing 14 or more of these controls is meaningfully compliant; passing all 18 is audit-ready.

One of the most common questions from IT and SaaS vendors preparing for DPDP compliance is: "Where do we actually stand?" The problem is that without a structured frame of reference, internal assessments tend to be optimistic. The CTO says "our security is solid," the founding team says "we have a privacy policy," and the conclusion is "we're probably fine." Then the enterprise questionnaire arrives and exposes the gaps.

This checklist gives you an honest, structured view of where you stand across nine control domains. It is not exhaustive — a full gap assessment covers more ground — but it covers the controls that matter most for vendor questionnaire responses, enterprise procurement, and the core DPDP Act obligations. Score yourself honestly: pass means the control is genuinely in place and demonstrable; fail means it is absent, undocumented, or untested.

How to use this checklist:

Read each item. Mark pass only if you could demonstrate the control to a third-party auditor today — not if you intend to implement it, or if it exists informally somewhere.

14–18 passes: Meaningfully compliant — you can respond to most enterprise questionnaires with confidence.
9–13 passes: Partial compliance — you will struggle with enterprise procurement. Prioritise the fails.
0–8 passes: Significant exposure — a structured compliance programme is needed before your next major deal.

Domain 1: Legal Basis and Consent
  • 1. Every processing activity has a documented legal basis. Done looks like: A data inventory or RoPA that lists each processing activity with the corresponding legal basis (consent, legitimate use, legal obligation, etc.) — not "TBD" or "contract."
  • 2. Where consent is relied upon, you have a technical mechanism to record and honour consent withdrawal. Done looks like: A user can withdraw consent in-product or by request, and the withdrawal is logged with a timestamp and actioned within your stated timeframe.
Domain 2: Privacy Notice
  • 3. Your privacy notice is current, accurate, and written in plain language. Done looks like: The notice accurately describes what data you collect, why, who you share it with, retention periods, and how individuals can exercise their rights — with no placeholder text, no GDPR-only language, and a review date within the last 12 months.
  • 4. Your privacy notice is accessible at every point where personal data is collected. Done looks like: A link to the privacy notice is present on the sign-up form, any data collection page, and the footer. It is not buried in terms and conditions.
Domain 3: Data Inventory
  • 5. You have a data inventory covering all personal data processed by your organisation. Done looks like: A maintained document (spreadsheet, GRC tool, or data flow diagram) listing data categories, systems, owners, legal basis, and retention periods. It has been reviewed in the last six months.
  • 6. You can locate any individual's data across all systems on request within 5 business days. Done looks like: You have tested this capability at least informally. You know which databases, backups, and logs would need to be searched, and someone is responsible for executing that search.
Domain 4: Breach Response
  • 7. You have a documented personal data breach response plan. Done looks like: A written procedure covering detection, internal escalation, containment, assessment, and notification — with named individuals responsible for each step. It is accessible to the people who need it, not just saved on a hard drive.
  • 8. The breach response plan has been tested in the last 12 months. Done looks like: A tabletop exercise, a drill, or at minimum a walkthrough meeting where the team talked through a hypothetical breach scenario and confirmed they understand the steps and timelines.
  • 9. You have defined breach notification timelines and can meet them. Done looks like: Your DPAs and internal procedures specify when you will notify clients (e.g., within 24 hours of confirmed detection), and your technical monitoring is capable of detecting breaches fast enough to meet that timeline.
Domain 5: Vendor Contracts
  • 10. You have a signed Data Processing Agreement with every client that sends you personal data. Done looks like: A DPA library with a signed agreement for every active client engagement. No major client relationships are running without a DPA in place. New client onboarding includes DPA execution as a standard step.
  • 11. You have reviewed and documented your sub-processors, and have appropriate agreements with them. Done looks like: A sub-processor register listing every third-party tool or service that processes personal data on your behalf, with a DPA or equivalent contractual protection in place for each. You know which ones have access to client data specifically.
Domain 6: Data Subject Rights
  • 12. You have a process to receive and respond to data subject rights requests. Done looks like: A published mechanism (email address, web form, or in-product portal) for individuals to submit requests. A named owner internally. A documented workflow for processing requests with a response timeline (30 days is standard).
  • 13. You have a technical mechanism to delete or return an individual's data on request. Done looks like: A tested, repeatable process to locate all data relating to a specific individual and delete or export it — including primary databases, logs, backups, and any data held by sub-processors. You have done this at least once, even in a test scenario.
Domain 7: Retention and Deletion
  • 14. You have documented retention periods for each category of personal data. Done looks like: Specific retention periods (not "we keep data as long as necessary") for each data category in your inventory, aligned to business need and any applicable legal requirements.
  • 15. You have a functioning data deletion mechanism and run it at least quarterly. Done looks like: Automated or manual deletion of data that has reached its retention limit. Deletion covers primary stores, backups, and archived data. There is a deletion log. Sub-processors are instructed to delete on the same schedule.
Domain 8: Grievance Officer
  • 16. You have a named Grievance Officer with published contact details. Done looks like: A real name and a monitored contact email or phone number published on your website's privacy page. The individual is aware of their responsibilities and has read the DPDP Act. Their contact details are also included in your privacy notice and DPA templates.
Domain 9: Documentation and Governance
  • 17. You have a Grievance Register and keep it current. Done looks like: A log (spreadsheet or simple GRC tool) recording every data principal contact — date received, nature of request, action taken, resolution date, and outcome. Even if the log is empty (no requests received), the register structure exists and is ready to use.
  • 18. Employees who handle personal data have received DPDP awareness training in the last 12 months. Done looks like: A training session, an internal document review, or an e-learning module covering what personal data is, what the DPDP Act requires, how to handle data subject requests, and what to do if a breach is suspected. Attendance is recorded.

Interpreting Your Score — What to Do Next

If you scored 14 or more, your immediate priority is documentation: making sure that everything you are doing informally is written down and demonstrable. The gap between "we do this" and "we can prove we do this" is the most common failure point in enterprise audits.

If you scored 9–13, you have the foundations but meaningful gaps remain. The highest-priority fixes are typically: breach response testing (item 8), sub-processor agreements (item 11), data subject rights processes (items 12–13), and the Grievance Register (item 17). These are the controls most commonly flagged in enterprise questionnaire reviews.

If you scored below 9, a structured compliance programme is the right next step — not because the DPDP Act will penalise you tomorrow, but because every enterprise deal you pursue is at risk until you have these foundations in place. The good news is that the programme is buildable in 8–12 weeks for most vendors of this size.

For a deeper understanding of how each domain is assessed professionally, see our post on what a vendor DPDP gap assessment covers. For cost planning on the compliance programme, see what DPDP compliance costs a mid-size IT vendor. For context on the DPA vs. readiness distinction underlying several of these controls, see DPA only or full DPDP readiness. Background on DPDP requirements for IT companies is in our earlier post on DPDP compliance for IT companies.

Frequently Asked Questions

Is this checklist based on the final DPDP Rules 2025?

This checklist is based on the DPDP Act 2023 and the draft DPDP Rules 2025 as available in June 2026. Some specific requirements (exact notification timelines, thresholds for Significant Data Fiduciary designation) may be refined when the final Rules are notified. The eight control domains and core obligations covered here are unlikely to change materially, but we recommend reviewing against the final Rules once published.

How often should we run this self-assessment?

At minimum, annually — and additionally after any significant change: a new product line, a major infrastructure migration, an acquisition, or a new category of personal data being processed. The most common trigger for a formal reassessment is a new enterprise client demanding a vendor security review.

What if we pass this checklist but still fail a client's questionnaire?

Client questionnaires vary in depth and sometimes include technical controls (specific encryption standards, penetration testing frequency, certifications) that go beyond the DPDP Act's requirements. Passing this checklist covers the DPDP-specific baseline; clients in financial services, healthcare, or with ISO 27001 requirements may ask additional questions. The answer is not to build a separate framework — it is to layer DPDP compliance on top of (or alongside) your existing information security programme.

Want the Full DPDP Rules 2025 Checklist?

Our free DPDP Rules 2025 Checklist covers all 23 rules with plain-language action items, a compliance timeline, and a penalty reference grid — download it free.

Get the Full Checklist — Free
Previous Post Next Post

Get Free DPDP Checklist