DPDP annual compliance review: what to do each year

DPDP compliance
DPDP annual compliance review: what to do each year
How-To Guide

DPDP annual compliance review: what to do each year

Compliance decays. Here are the eight things every data fiduciary must review every year — and a month-by-month calendar to make it manageable.

Quick Answer: A DPDP annual compliance review is a structured audit of eight areas — data inventory, consent records, privacy notices, sub-processors, breach logs, Grievance Officer status, employee training, and regulatory updates — conducted once a year to ensure that compliance achieved during initial implementation has not drifted. It also generates the documented evidence that enterprise customers and regulators expect to see. A one-time DPDP implementation exercise is not sufficient; ongoing annual reviews are essential.

Compliance decays — one-time implementation is not enough

There is a pattern that repeats across almost every organisation that goes through an initial DPDP compliance exercise. The first few months are intensive: data inventories are built, consent notices are drafted, privacy policies are updated, Grievance Officers are appointed. Leadership signs off. The compliance team exhales. And then — nothing. The documentation sits untouched for eighteen months while the business moves on.

Meanwhile, three new product features have been shipped that collect new data fields. Two sub-processors have been replaced. The Grievance Officer named in the notice left the company. The privacy policy still references a retention period that was changed eight months ago. And DPDP Rules 2025 introduced a new obligation that nobody has reviewed against the existing documentation.

This is compliance decay — and it is not a theoretical risk. It is the default outcome when annual reviews are not built into the operating calendar. The good news is that a structured annual review is significantly less work than the initial implementation, because the baseline already exists. You are refreshing and verifying, not building from scratch.

If you are still working through the initial implementation and want to understand the full timeline, our guide on the DPDP readiness timeline maps every deliverable from discovery to go-live. This post assumes that baseline is in place and focuses on what happens each year after that.

For context on what a full compliance programme costs, including the annual review component, see our earlier post on DPDP compliance pricing in India.

The eight things to review every year

Step 1: Data inventory refresh
Your data inventory — the record of what personal data you collect, from whom, for what purpose, in which system, with what retention period — is the foundation of every other compliance obligation. It goes stale faster than any other document. Every new product feature, integration, or operational change can add new data flows. Annually, walk through the inventory with the product and engineering teams, compare it against actual data flows in your systems, and update every row that has changed. Pay particular attention to new categories of personal data, new collection points (for example, a mobile app feature that was not in scope last year), and any data that is now being processed by a sub-processor that was previously processed in-house.
Step 2: Consent record audit
For every processing activity that relies on consent as its lawful basis, you must be able to produce a record showing that valid consent was obtained — who consented, when, to what specific purpose, and via which version of the consent notice. Annually, audit your consent management system (or your spreadsheet, if that is what you are using) against your active user base. Identify records where consent was obtained under an older notice version — if the notice has changed materially since consent was given, you likely need to seek fresh consent. Identify any processing that is occurring without a traceable consent record. Both are material compliance gaps.
Step 3: Privacy notice review
Your privacy notice (and any associated consent notices) must accurately reflect your current data practices. If anything in your data inventory has changed since the last review — new purposes, new sub-processors, changed retention periods — your notices must be updated. This is not optional: a privacy notice that does not match actual practice is a misrepresentation to data principals and a regulatory red flag. When updating notices, consider whether the changes are material enough to require active notification to existing data principals rather than a silent web update.
Step 4: Sub-processor update
List every third party that processes personal data on your behalf — cloud providers, analytics tools, payroll processors, background verification firms, email service providers, CRM platforms. For each, verify that a written Data Processing Agreement (DPA) is in place that meets DPDP requirements. Check that the DPA has not expired, that the sub-processor has not changed their data practices in ways that conflict with your obligations, and that you have current contact details for their data protection team. For a template and checklist, see our guide on drafting DPDP-compliant DPAs.
Step 5: Breach log review
Review every personal data breach incident — including near-misses — that occurred in the past twelve months. Verify that each incident was assessed against the DPDP notification threshold and that the appropriate notifications were made (to the Data Protection Board and, where required, to affected data principals) within the prescribed timelines. Identify any pattern in breach causes — repeated incidents involving the same sub-processor, the same data category, or the same system — and document remediation steps taken. The breach log is frequently requested in enterprise RFPs and regulatory examinations.
Step 6: Grievance Officer confirmation
Confirm that your appointed Grievance Officer is still in the role, still reachable at the contact details published in your notices, and has processed all grievances received in the past year within the prescribed timeline. If the Grievance Officer has changed, update all published notices, your privacy policy, and any regulatory filings. Verify that the Grievance Officer is aware of their obligations under DPDP Rules 2025, including the timeline for acknowledging and resolving complaints.
Step 7: Employee training refresh
DPDP compliance depends on every employee who handles personal data understanding their obligations. Annual training is not merely good practice — it is the only way to ensure that new hires, team members in newly data-relevant roles, and existing staff who have forgotten last year's training are up to date. The training should cover the basics of the DPDP Act, your internal data handling policies, how to handle a data subject access request, and what to do if a breach is suspected. Document completion rates — this evidence is valuable in regulatory examinations and enterprise audits.
Step 8: Regulatory update check
The DPDP framework is still maturing. The Rules were notified in 2025, the Data Protection Board is being constituted, and sector-specific guidance from regulators like SEBI, RBI, IRDAI, and DPDP may interact with the Act in ways that were not fully clear at implementation time. Annually, review any new guidance, notifications, or amendments issued by the Ministry of Electronics and Information Technology (MeitY), the Data Protection Board, and your sector regulator. Assess whether any new obligation requires changes to your data practices or documentation. For a structured way to track your response to new requirements, see our post on responding to DPDP compliance questionnaires.

A practical month-by-month review calendar

Trying to do all eight steps in a single intensive week is a recipe for a rushed, superficial review. A better approach is to spread the work across the year, with each quarter owning a specific subset of activities.

Month Activity Owner
January Data inventory refresh — walk through all data flows with product and engineering teams. Update the inventory for any new features shipped in the previous quarter. Privacy Lead + Engineering
February Sub-processor audit — verify DPAs are current for all third-party processors. Renew or update any that have lapsed or changed. Legal / Privacy Lead
March Breach log review — document all incidents from the prior year, confirm notifications were made, identify patterns, and sign off on remediation. CISO / Privacy Lead
April Employee training refresh — run annual DPDP training for all staff. Record completion. Update training content to reflect any regulatory changes from Q1. HR + Privacy Lead
May Grievance Officer confirmation — verify appointment is current, contact details are accurate in all notices, and all grievances from the past year were resolved on time. Privacy Lead
July Mid-year consent audit — sample consent records for the top five processing activities. Identify any gaps or stale records. Initiate fresh consent where needed. Privacy Lead + Product
October Privacy notice review — update notices to reflect any changes in data practices since the last review. Assess whether material changes require active notification to data principals. Legal / Privacy Lead
December Regulatory update check — review MeitY, Data Protection Board, and sector-regulator guidance published in the year. Assess impact on data practices and update the compliance roadmap for the coming year. Privacy Lead + Leadership

How annual review evidence strengthens enterprise RFP responses

Enterprise procurement teams — particularly in banking, insurance, and large-cap IT — have begun including DPDP compliance questionnaires as standard in vendor RFPs. The questions are no longer limited to "are you DPDP compliant?" They now ask for evidence: copies of your privacy notice, your DPA template, your breach notification policy, your training completion records, and your most recent internal audit report.

Organisations that conduct structured annual reviews have this evidence ready. Organisations that completed a one-time implementation exercise three years ago do not — and their answers to these questionnaires are either incomplete or inaccurate, both of which create risk in the procurement process.

A completed annual review also provides the factual basis for your DPDP internal audit report — the formal document that consolidates your compliance status across all eight areas and serves as the primary evidence artefact for enterprise customers and regulators alike. The two documents are designed to work together: the annual review is the process; the audit report is the output.

Organisations that treat DPDP compliance as a living programme — rather than a one-time project — consistently report shorter procurement cycles, fewer follow-up questionnaire rounds, and stronger negotiating positions with enterprise customers. The annual review is the mechanism that makes a living programme possible.

Run your annual DPDP compliance review with a structured framework

Our Annual Compliance Review tool walks you through all eight review areas, generates a dated evidence summary, and produces a board-ready status report you can share with customers and regulators.

Start your annual review — ₹1,499 →

Frequently asked questions

How long does a DPDP annual compliance review take? For a mid-sized organisation with a documented baseline from a prior implementation, a thorough annual review across all eight areas typically takes four to six working days of internal effort spread over the review cycle, plus any remediation work identified. The calendar approach above distributes this across the year so it does not create a concentrated workload. Organisations doing their first annual review after an initial implementation will typically find it takes longer, as they are also documenting processes that existed but were never written down.
Does DPDP legally require an annual review? The DPDP Act and Rules 2025 do not prescribe an annual review cycle by name. However, several obligations are ongoing — the duty to ensure accuracy of personal data, to honour withdrawal of consent within a reasonable time, to maintain records of processing activities, and to notify breaches promptly — and these cannot be met without a systematic periodic review process. Additionally, regulators in analogous frameworks (GDPR, for example) have consistently held that a one-time compliance exercise does not satisfy ongoing obligations. The annual review is the practical mechanism by which ongoing compliance is maintained and demonstrated.
What should we produce at the end of an annual review? At minimum, the annual review should produce: an updated data inventory, a written summary of consent record audit findings and any remediation taken, updated privacy notices (or a documented confirmation that no changes were needed), a refreshed sub-processor list with DPA status, a signed-off breach log, confirmation of Grievance Officer appointment, training completion records, and a regulatory update assessment. These documents collectively form the annual audit evidence package. Many organisations consolidate these into a single internal audit report that can be shared with board members, enterprise customers, and — if requested — the Data Protection Board.
Previous Post Next Post

Get Free DPDP Checklist