What documents do I need to be DPDP compliant?
The core document set that demonstrates DPDP accountability.
The baseline set
Every Data Fiduciary should hold: a privacy notice and policy; evidence of consent; a data inventory and processing register; a retention schedule; vendor DPAs; a breach-response plan; and a documented grievance process with a named contact. These are your accountability backbone.
Extra for SDFs
If you're designated a Significant Data Fiduciary, add Data Protection Impact Assessments for high-risk processing, periodic independent audit reports, and records of your DPO's oversight. These are continuing, not one-time, documents.
Documents are evidence
The point of the document set isn't bureaucracy — it's that, if a complaint or audit lands, these are what demonstrate you acted reasonably. Keep them current and consistent with what you actually do.
Frequently asked questions
What's the minimum documentation for DPDP?
Privacy notice and policy, consent records, data inventory, processing register, retention schedule, vendor DPAs, breach plan and grievance process.
Do small businesses need all of this?
The set scales with your data, but the core artifacts apply to everyone. SDF-specific documents (DPIAs, audits) only apply if you're designated.
Why keep all these documents?
They're your evidence of accountability if the Board investigates a complaint or breach.
See your full document checklist
Use the DPDP Compliance Checklist to track which documents you have and which are missing.
DPDP Compliance Checklist