DPDP Readiness Audit: A 12-Point Self-Assessment for Indian SMEs
Most Indian SMEs handle far more personal data than they realise: website leads, customer accounts, employee and applicant records, WhatsApp enquiries, CRM contacts and analytics data. Under India’s data protection framework, how that data is collected, used, stored and shared is becoming an operational question for every function, not just IT or legal.
A DPDP readiness audit is a structured review of how your business collects, uses, stores, shares and protects personal data, measured against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. This 12-point self-assessment helps an SME find its gaps and prioritise fixes before the main obligations of the law come into force in May 2027.
A DPDP readiness audit checks 12 areas: your data inventory, processing purposes, privacy notices, consent mechanisms, rights handling, breach response, security safeguards, vendors, retention, internal access, accountability and documentation. Most Data Fiduciary obligations under the DPDP Act and Rules apply from May 2027, so SMEs can use the time now to identify and close gaps.
DPDP readiness is not the same as publishing a privacy policy. It means knowing what data you have, why you have it, who can access it and how you protect it. This article is a readiness self-assessment, not legal certification or a determination of compliance.
Where Things Stand: The DPDP Commencement Timeline
The DPDP Rules, 2025 were notified on 13 November 2025 and come into force in phases:
| Phase | When | What it covers |
|---|---|---|
| Phase 1 In force | 13 November 2025 | Definitions and provisions establishing and operating the Data Protection Board of India (Rules 1, 2 and 17 to 21) |
| Phase 2 Upcoming | One year after notification (November 2026) | Registration and obligations of Consent Managers (Rule 4) |
| Phase 3 Upcoming | Eighteen months after notification (May 2027) | Most Data Fiduciary obligations: notice, security safeguards, breach intimation, erasure, contact details, children’s data, Significant Data Fiduciaries and Data Principal rights (Rules 3, 5 to 16, 22 and 23) |
Swipe the table sideways to see all columns.
In this article, each checklist point is labelled to show whether it reflects an obligation that applies from May 2027 or a recommended readiness step. MeitY has publicly discussed shortening the eighteen-month window; as of writing, no amendment has been notified, so check the official position before relying on any date.
What Is a DPDP Readiness Audit?
For an SME, a readiness assessment reviews data collection, processing purposes, notices, consent, access, security controls, vendors, retention, rights processes, incident response, documentation and governance. It is a practical first-level review carried out internally.
It is different from a formal legal audit or a professional assurance engagement. The checklist helps you spot and prioritise gaps; it does not, by itself, determine whether your business complies with the law.
Before You Start: Does DPDP Apply to Your Business?
The DPDP Act applies to the processing of digital personal data within India, whether collected digitally or collected offline and later digitised. It also applies to processing outside India if it is connected with offering goods or services to individuals in India. Personal data processed by an individual for personal or domestic purposes, and data made publicly available by the individual, are among the exclusions. The Act also allows the government to exempt certain classes of Data Fiduciaries, including startups, from specified provisions, so check for any notified exemption rather than assume one.
Key terms in plain language:
- Data Principal: the individual the personal data relates to, such as a customer, employee or applicant. For a child, this includes the parent or lawful guardian.
- Data Fiduciary: the person or business that decides the purpose and means of processing.
- Data Processor: a person or business that processes personal data on behalf of a Data Fiduciary.
- Processing: almost any operation on digital personal data, including collection, storage, use, sharing and erasure.
- Consent: the individual’s free, specific, informed, unconditional and unambiguous agreement, given by a clear affirmative action.
Roles depend on the activity. Your SME is usually a Data Fiduciary for its own customer and employee data. A payroll vendor processing salaries on your instructions is typically your Data Processor. A digital agency running campaigns for clients may be a processor for some activities and a fiduciary for others.
The 12-Point DPDP Readiness Self-Assessment
For each point, mark your status: ✅ Ready, ⚠️ Needs Attention, ❌ Not Started or N/A.
1. Have You Mapped the Personal Data You Collect? Readiness step
2. Do You Know Why You Collect Each Type of Personal Data? From May 2027
3. Is Your Privacy Notice Clear and Appropriate? From May 2027
4. Are Your Consent Mechanisms Properly Designed? From May 2027
5. Can You Handle Data Principal Rights Requests? From May 2027
6. Do You Have a Data Breach Response Process? From May 2027
7. Are Your Security Measures Adequate? From May 2027
8. Do You Know Which Vendors Handle Personal Data? From May 2027
9. Do You Have a Data Retention and Deletion Process? From May 2027
10. Have You Reviewed Employee and Internal Access? Readiness step
11. Is There a Clear Grievance and Privacy Responsibility Structure? From May 2027
12. Have You Documented Your DPDP Readiness? Readiness step
DPDP Self-Assessment Scorecard
| Assessment area | ✅ Ready | ⚠️ Needs Attention | ❌ Not Started |
|---|---|---|---|
| 1. Data inventory | |||
| 2. Processing purposes | |||
| 3. Privacy notices | |||
| 4. Consent mechanisms | |||
| 5. Rights requests | |||
| 6. Breach response | |||
| 7. Security safeguards | |||
| 8. Vendors and processors | |||
| 9. Retention and deletion | |||
| 10. Internal access | |||
| 11. Accountability and grievances | |||
| 12. Documentation |
Swipe the table sideways to see all columns.
This is a risk-prioritisation tool, not a legal compliance score. A practical way to prioritise (our recommendation, not a statutory classification):
- High priority: unauthorised access, missing security safeguards, uncontrolled third-party access, no breach response process, or no clear picture of what personal data you process.
- Medium priority: inconsistent notices, incomplete vendor documentation, poor retention practices, weak access reviews.
- Improvement: better documentation, staff awareness, process automation, periodic privacy reviews.
Common DPDP Readiness Mistakes SMEs Make
- Treating a privacy policy as the whole programme. Policies describe practices; they do not replace them.
- Collecting data without knowing where it goes. Fix: start with the data inventory.
- Generic consent checkboxes. Fix: specific, unbundled consent with an easy withdrawal option.
- Keeping data indefinitely. Fix: a retention schedule tied to purpose and legal requirements.
- Too many people with access. Fix: role-based access and regular reviews.
- Ignoring SaaS tools. Fix: include every platform in the vendor register.
- No breach plan. Fix: a short, tested incident response procedure.
- Assuming cybersecurity equals privacy. Security is one part; notices, purposes, rights and retention matter too.
- Copying another website’s privacy policy. Fix: write notices that describe your actual data and purposes.
- Ignoring the phased timeline. Fix: plan against the notified dates, and watch for official changes.
30-Day DPDP Readiness Action Plan for an SME
This is a recommended implementation roadmap, not a statutory requirement.
| Week | Focus | Actions |
|---|---|---|
| Week 1 | Discover | Identify personal data, map systems, list vendors, record purposes |
| Week 2 | Review | Review notices, consent, access controls and retention; list gaps |
| Week 3 | Build | Create rights-request and incident processes, update vendor documents, strengthen security, assign owners |
| Week 4 | Test | Run a mock rights request and breach drill, review access, test deletion, document open risks, set a review cycle |
Swipe the table sideways to see all columns.
When Should an SME Seek Professional DPDP Advice?
A self-assessment is enough for many small businesses to get started. Professional help is worth considering if you process large volumes of personal data, handle health, financial, HR or children’s data, rely on a complex vendor ecosystem, operate across borders, share data with partners, suspect a breach, are unsure whether you are a Data Fiduciary or Data Processor for an activity, or are making significant changes to your systems.
For the full picture of obligations, read our DPDP Act 2023 compliance guide and our explainer on DPDP Act penalties.
Frequently Asked Questions
What is a DPDP readiness audit?
A DPDP readiness audit is a structured review of how a business collects, uses, stores, shares and protects personal data, measured against the DPDP Act, 2023 and DPDP Rules, 2025. It identifies gaps and priorities. A self-assessment is a starting point, not a legal certification of compliance.
Does the DPDP Act apply to small businesses in India?
Yes. The Act has no general size or turnover threshold. Any business processing digital personal data of individuals in India is generally covered, although the government can notify exemptions for certain classes of Data Fiduciaries, including startups, for specified provisions.
What should an SME check for DPDP compliance?
Its data inventory, processing purposes, privacy notices, consent mechanisms, rights handling, breach response, security safeguards, vendor contracts, retention and deletion, internal access, accountability structure and documentation.
Is a privacy policy enough for DPDP compliance?
No. A privacy policy alone does not meet notice, consent, security, breach, rights or retention obligations. The Rules require clear, itemised notices at the point of collection, and the business must actually operate the processes the policy describes.
What is a Data Fiduciary under DPDP?
A Data Fiduciary is any person or business that, alone or with others, decides the purpose and means of processing personal data. Most SMEs are Data Fiduciaries for their own customer and employee data.
Do SMEs need consent to collect personal data?
Not always. Personal data can be processed either with valid consent or for specific “legitimate uses” listed in Section 7 of the Act, such as legal obligations or certain employment purposes. Where consent is the basis, it must be free, specific, informed and unambiguous.
What are the rights of a Data Principal?
The right to access information about their personal data; to correction, completion, updating and erasure; to grievance redressal; and to nominate another person to exercise their rights in case of death or incapacity.
What should a company do after a personal data breach?
Contain the incident, preserve evidence and assess impact. Once the breach provisions apply in May 2027, Rule 7 requires informing affected individuals without delay, and the Board without delay with a detailed report within 72 hours of becoming aware. Take legal advice on the specific facts.
Do small businesses need a Data Protection Officer?
Generally no. Only Significant Data Fiduciaries notified by the government must appoint a DPO. Other Data Fiduciaries must publish the contact details of a person who can answer questions about their processing.
When does the DPDP Act become applicable to businesses?
In phases. Board-related provisions came into force on 13 November 2025, Consent Manager provisions apply from November 2026, and most Data Fiduciary obligations apply eighteen months after notification, in May 2027. Check MeitY’s official notifications for any changes.
Make DPDP Readiness an Ongoing Habit
DPDP readiness is a business process, not a one-time document exercise. The pattern is simple: know your data → know your purpose → control access → manage vendors → protect data → respond to requests → prepare for breaches → document everything.
This article is a readiness self-assessment for general information. It is not legal advice and does not certify compliance.
Want a Structured DPDP Readiness Review?
AAPT & Associates offers DPDP Act compliance services for Indian businesses, from gap assessments to notices, vendor contracts and breach response planning.
Sources & References: MeitY: DPDP Act, 2023 and Rules · DPDP Rules, 2025 (Gazette, G.S.R. 846(E)) · Mondaq: MeitY proposal on compliance timeline






