The DPDP Act compliance checklist

21 items every Indian website must tick to stay clear of the ₹250 crore penalty. Enter your email and we'll send the printable PDF.

  1. 1.Explicit opt-in consent captured before any tracking cookie fires
  2. 2.Per-category consent (necessary, analytics, marketing, functional)
  3. 3.Withdraw consent as easily as it was given
  4. 4.Timestamped, tamper-proof consent log per visitor
  5. 5.IPs stored as one-way hashes, not raw values
  6. 6.Privacy notice in clear, plain language
  7. 7.Named Data Protection Officer or grievance contact
  8. 8.Data Principal request (DSAR) intake form on your site
  9. 9.Documented SLA to respond to DSAR within statutory window
  10. 10.Deletion workflow that purges related consent logs
  11. 11.Data-sharing agreements with all processors / subprocessors
  12. 12.Retention schedule for each category of personal data
  13. 13.Breach notification playbook and CERT-In readiness
  14. 14.Age gating and verifiable parental consent for children
  15. 15.Cross-border transfer assessment for non-India providers
  16. 16.Cookie inventory reviewed at least quarterly
  17. 17.Consent proof exportable as CSV on demand
  18. 18.Google Consent Mode v2 signals wired for Ads / GA4
  19. 19.Region-aware banner (India opt-in, US opt-out, EU strict)
  20. 20.Employee training log for anyone handling personal data
  21. 21.Annual review of privacy policy against latest DPDP rules

Want this automated? Get a site key — banner, DSAR queue, and audit log ship in one script tag.