A A P T & ASSOCIATES

AAPT & ASSOCIATES
AAPT Corp Advisors LLP unlock money
  • Home
  • Industry

    • Consumer
    • Automotive
    • Consumer Products
    • Retail, Wholesale & Distribution
    • Transportation, Hospitality & Services

    • Energy, Resources & Industrials
    • Industrial Products & Construction
    • Power, Utilities & Renewables
    • Energy & Chemicals
    • Mining & Metals

    • Financial Services
    • Banking & Capital Markets
    • Investment Management
    • Real Estate
    • Insurance

    • Government & Public Services
    • Defense, Security & Justice
    • Federal health
    • Civil
    • State & Local
    • Higher Education

    • Life Sciences & Health Care
    • Health Care
    • Life Sciences

    • Technology, Media & Telecommunications
    • Technology
    • Telecommunications
    • Media & Entertainment
  • Services

    • Business Advisory
    • Market Assessment
    • India Entry Strategies
    • Corporate Legal & Secretarial Advisory
    • Manufacturing set-up in India
    • Executive Search
    • Employer of Record (EOR) Services
    • Company Registration in India
    • PE Risk Advisory
    • Employee Stock Benefit Advisory
    • Family Office Services
    • Transition Support Services
    • Outbound Expansion Support
    • HR Consulting & Staff Outsourcing Services
    • Wealth Management Advisory

    • Corporate Support Services
    • Accounting & Book Keeping Services
    • Payroll
    • Company Secretarial Services
    • Dematerialization of Securities
    • SOFTEX Compliance Services
    • Labour Law Compliance and POSH Act
    • Virtual CFO Services
    • Ind AS/IFRS/IGAAP Financial Statements
    • Appointment of Independent Directors
    • Registrar and Transfer Agent Services

    • Transaction Advisory Services
    • Business Valuation
    • Due Diligence
    • Mergers & Acquisitions
    • Joint Venture
    • Vendor due Diligence Services
    • Internal Audit
    • Internal Financial Control
    • Statutory Audit Services
    • Forensic Accounting Services
    • audit outsourcing firm India
    • Audit Staffing Services

    • Taxation
    • Direct Tax
    • Indirect Tax
    • Expatriate Services
    • OIDAR Services
    • Goods and Services Tax
    • International Tax Planning
    • Transfer pricing services
    • Income Tax & GST Litigation Services

    US Tax & Accounting Services

    • payroll outsourcing services USA
    • accounting and bookkeeping services USA
    • Outsourced Sales Tax Compliance
    • Sales Tax Nexus Consultant
    • Federal Tax ID Registration & EIN Services USA
    • Form 1041 tax preparation
    • Form 1120-S S-Corp Tax Preparation
    • Form 1120 tax preparation
    • Form 1065 Partnership Tax Preparation
    • Outsourced Bookkeeping & Accounting Services
    • Individual Tax Returns
    • DPDP Act 2023 Compliance Services
  • About Us
    • Our Team
  • Blogs
  • Request Consultation
  • Home
  • Blog
  • DPDP & Data Privacy
  • DPDP Readiness Audit: A 12-Point Self-Assessment for Indian SMEs
October 3, 2026
DPDP & Data Privacy

DPDP Readiness Audit: A 12-Point Self-Assessment for Indian SMEs

Most Indian SMEs handle far more personal data than they realise: website leads, customer accounts, employee and applicant records, WhatsApp enquiries, CRM contacts and analytics data. Under India’s data protection framework, how that data is collected, used, stored and shared is becoming an operational question for every function, not just IT or legal.

A DPDP readiness audit is a structured review of how your business collects, uses, stores, shares and protects personal data, measured against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. This 12-point self-assessment helps an SME find its gaps and prioritise fixes before the main obligations of the law come into force in May 2027.

Quick Answer

A DPDP readiness audit checks 12 areas: your data inventory, processing purposes, privacy notices, consent mechanisms, rights handling, breach response, security safeguards, vendors, retention, internal access, accountability and documentation. Most Data Fiduciary obligations under the DPDP Act and Rules apply from May 2027, so SMEs can use the time now to identify and close gaps.

DPDP readiness is not the same as publishing a privacy policy. It means knowing what data you have, why you have it, who can access it and how you protect it. This article is a readiness self-assessment, not legal certification or a determination of compliance.

Where Things Stand: The DPDP Commencement Timeline

The DPDP Rules, 2025 were notified on 13 November 2025 and come into force in phases:

Phase When What it covers
Phase 1 In force 13 November 2025 Definitions and provisions establishing and operating the Data Protection Board of India (Rules 1, 2 and 17 to 21)
Phase 2 Upcoming One year after notification (November 2026) Registration and obligations of Consent Managers (Rule 4)
Phase 3 Upcoming Eighteen months after notification (May 2027) Most Data Fiduciary obligations: notice, security safeguards, breach intimation, erasure, contact details, children’s data, Significant Data Fiduciaries and Data Principal rights (Rules 3, 5 to 16, 22 and 23)

Swipe the table sideways to see all columns.

In this article, each checklist point is labelled to show whether it reflects an obligation that applies from May 2027 or a recommended readiness step. MeitY has publicly discussed shortening the eighteen-month window; as of writing, no amendment has been notified, so check the official position before relying on any date.

What Is a DPDP Readiness Audit?

For an SME, a readiness assessment reviews data collection, processing purposes, notices, consent, access, security controls, vendors, retention, rights processes, incident response, documentation and governance. It is a practical first-level review carried out internally.

It is different from a formal legal audit or a professional assurance engagement. The checklist helps you spot and prioritise gaps; it does not, by itself, determine whether your business complies with the law.

Before You Start: Does DPDP Apply to Your Business?

The DPDP Act applies to the processing of digital personal data within India, whether collected digitally or collected offline and later digitised. It also applies to processing outside India if it is connected with offering goods or services to individuals in India. Personal data processed by an individual for personal or domestic purposes, and data made publicly available by the individual, are among the exclusions. The Act also allows the government to exempt certain classes of Data Fiduciaries, including startups, from specified provisions, so check for any notified exemption rather than assume one.

Key terms in plain language:

  • Data Principal: the individual the personal data relates to, such as a customer, employee or applicant. For a child, this includes the parent or lawful guardian.
  • Data Fiduciary: the person or business that decides the purpose and means of processing.
  • Data Processor: a person or business that processes personal data on behalf of a Data Fiduciary.
  • Processing: almost any operation on digital personal data, including collection, storage, use, sharing and erasure.
  • Consent: the individual’s free, specific, informed, unconditional and unambiguous agreement, given by a clear affirmative action.

Roles depend on the activity. Your SME is usually a Data Fiduciary for its own customer and employee data. A payroll vendor processing salaries on your instructions is typically your Data Processor. A digital agency running campaigns for clients may be a processor for some activities and a fiduciary for others.

The 12-Point DPDP Readiness Self-Assessment

For each point, mark your status: ✅ Ready, ⚠️ Needs Attention, ❌ Not Started or N/A.

1. Have You Mapped the Personal Data You Collect? Readiness step

QuestionWhat personal data do we collect, from whom, and through which channels: website, app, forms, WhatsApp, HR, CRM, vendors or partners?
Why it mattersEvery other obligation depends on knowing what data you hold. You cannot write an accurate notice, secure data or honour an erasure request for data you have not found.
Evidence to checkA simple data inventory with columns for Data category · Source · Purpose · System · Access · Retention. Start with website leads, customer accounts, employee records, job applicants, newsletter subscribers, CRM contacts and support tickets. Flag any children’s data separately.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

2. Do You Know Why You Collect Each Type of Personal Data? From May 2027

QuestionFor each data category, is the purpose clearly defined, and are we collecting more than we need for it?
Why it mattersUnder Section 4 of the Act, personal data may be processed only for a lawful purpose, either with the individual’s consent or for a “certain legitimate use” listed in Section 7. These include situations such as data voluntarily provided for a specified purpose where the individual has not objected, compliance with a legal obligation, medical emergencies and certain employment purposes. This is a closed list, not a broad “legitimate interests” test like the GDPR.
Evidence to checkA processing-purpose register mapping each data category to its purpose and its basis (consent or a specific Section 7 legitimate use). Remove fields you cannot justify.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

3. Is Your Privacy Notice Clear and Appropriate? From May 2027

QuestionDo our website, app, lead forms, onboarding forms and employee communications give a clear notice before or when we ask for consent?
Why it mattersRule 3 requires the notice to be understandable independently of other information, in clear and plain language, with an itemised description of the personal data and the specified purposes. It must also give a link or means to withdraw consent, exercise rights and complain to the Board. Notices must be available in English or any of the 22 languages in the Eighth Schedule. A long generic policy in the footer may not meet this for every collection point.
Evidence to checkEach collection point mapped to the notice shown there; notice text checked against Rule 3.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

4. Are Your Consent Mechanisms Properly Designed? From May 2027

QuestionAre our forms, marketing opt-ins, newsletter sign-ups, app permissions and cookie or analytics prompts collecting valid consent where consent is the basis?
Why it mattersUnder Section 6, consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, and limited to the data necessary for the purpose. Withdrawal must be as easy as giving consent. Pre-ticked boxes and bundled “I agree to everything” checkboxes are unlikely to qualify. Not all processing needs consent, since Section 7 legitimate uses may apply.
Evidence to checkScreenshots of each consent point, consent records with timestamps, and a working withdrawal option.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

5. Can You Handle Data Principal Rights Requests? From May 2027

QuestionIf a customer asks what data we hold, or asks us to correct or erase it, can we respond properly?
Why it mattersSections 11 to 14 give Data Principals the right to access information about their personal data, to correction, completion, updating and erasure, to grievance redressal, and to nominate another person. Rule 14 requires the means of making requests to be published, and grievances to be responded to within a reasonable period not exceeding ninety days.
Evidence to checkA written procedure, a named owner, and a request log. A simple workflow:
Request received→Verify identity→Locate data→Assess→Act→Communicate→Record
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

6. Do You Have a Data Breach Response Process? From May 2027

QuestionWho receives a suspected breach report, who investigates, who decides on escalation, and who communicates with affected individuals and the Board?
Why it mattersSection 8(6) requires Data Fiduciaries to intimate personal data breaches to the Board and each affected Data Principal. Under Rule 7, affected individuals must be informed without delay, and the Board must receive an initial intimation without delay and a detailed report within seventy-two hours of becoming aware of the breach (or a longer period if the Board allows). That timeline is very hard to meet without a plan prepared in advance.
Evidence to checkAn incident response plan, escalation contacts, notification templates and an incident log.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

7. Are Your Security Measures Adequate? From May 2027

QuestionDo we protect personal data with controls proportionate to its volume, sensitivity and risk?
Why it mattersSection 8(5) requires reasonable security safeguards. Rule 6 sets minimum measures, including encryption, obfuscation, masking or virtual tokens; access controls; logs and monitoring to detect unauthorised access; backups for continued processing after a compromise; retaining logs for a prescribed period; and appropriate contract terms with Data Processors. Broader practices such as MFA, endpoint protection and staff training are strongly recommended on top of these.
Evidence to checkPassword and MFA settings, encryption status, access lists, backup tests, log settings and training records.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

8. Do You Know Which Vendors Handle Personal Data? From May 2027

QuestionWhich CRM, cloud, payroll, HR, email marketing, payment, analytics, support, SaaS, IT and agency providers access our personal data?
Why it mattersUnder Section 8(2), a Data Fiduciary may engage a Data Processor only under a valid contract, and the fiduciary remains responsible for compliance. Not every SaaS tool is automatically a processor; it depends on the actual arrangement.
Evidence to checkA vendor register with columns for Vendor · Data shared · Purpose · Contract · Security review · Access, plus signed contracts with data protection clauses.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

9. Do You Have a Data Retention and Deletion Process? From May 2027

QuestionHow long do we keep customer, former employee and lead data? What happens when an account closes? Are backups covered?
Why it mattersSection 8(7) requires erasure when consent is withdrawn or the specified purpose is no longer served, unless retention is necessary to comply with law. Other laws, such as tax and company law, may require you to keep certain records. Rule 8 also requires certain data and logs to be kept for at least one year for specified purposes. There is no single deletion period that fits all data.
Evidence to checkA retention schedule by data category, with the legal or business reason, and a tested deletion process.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

10. Have You Reviewed Employee and Internal Access? Readiness step

QuestionWho can access, export or download customer and HR data? Are former employees removed promptly?
Why it mattersOver-broad internal access is one of the most common causes of data leaks, and access control is part of the Rule 6 safeguards.
Evidence to checkRole-based access lists, MFA on admin accounts, quarterly access reviews, joiner-mover-leaver checklists and logs of sensitive exports.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

11. Is There a Clear Grievance and Privacy Responsibility Structure? From May 2027

QuestionWho owns privacy, receives grievances, coordinates requests, handles incidents and reports risks to management?
Why it mattersEvery Data Fiduciary must have a grievance redressal mechanism and, under Section 8(9) and Rule 9, publish the business contact information of a person who can answer questions about its processing. Only Significant Data Fiduciaries, a category notified by the government, must appoint a Data Protection Officer, an independent data auditor and carry out periodic impact assessments. Most SMEs are not Significant Data Fiduciaries.
Evidence to checkA named privacy owner, published contact details and a grievance procedure.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

12. Have You Documented Your DPDP Readiness? Readiness step

QuestionIf asked, could we show evidence of our privacy programme?
Why it mattersUndocumented processes are hard to maintain and harder to demonstrate to the Board, customers or auditors.
Evidence to checkData inventory, purpose register, notices, consent records, rights and grievance procedures, breach plan, vendor register and contracts, security policies, retention schedule, access reviews and training records.
Status

✅ Ready⚠️ Needs Attention❌ Not StartedN/A

DPDP Self-Assessment Scorecard

Assessment area ✅ Ready ⚠️ Needs Attention ❌ Not Started
1. Data inventory
2. Processing purposes
3. Privacy notices
4. Consent mechanisms
5. Rights requests
6. Breach response
7. Security safeguards
8. Vendors and processors
9. Retention and deletion
10. Internal access
11. Accountability and grievances
12. Documentation

Swipe the table sideways to see all columns.

This is a risk-prioritisation tool, not a legal compliance score. A practical way to prioritise (our recommendation, not a statutory classification):

  • High priority: unauthorised access, missing security safeguards, uncontrolled third-party access, no breach response process, or no clear picture of what personal data you process.
  • Medium priority: inconsistent notices, incomplete vendor documentation, poor retention practices, weak access reviews.
  • Improvement: better documentation, staff awareness, process automation, periodic privacy reviews.

Common DPDP Readiness Mistakes SMEs Make

  1. Treating a privacy policy as the whole programme. Policies describe practices; they do not replace them.
  2. Collecting data without knowing where it goes. Fix: start with the data inventory.
  3. Generic consent checkboxes. Fix: specific, unbundled consent with an easy withdrawal option.
  4. Keeping data indefinitely. Fix: a retention schedule tied to purpose and legal requirements.
  5. Too many people with access. Fix: role-based access and regular reviews.
  6. Ignoring SaaS tools. Fix: include every platform in the vendor register.
  7. No breach plan. Fix: a short, tested incident response procedure.
  8. Assuming cybersecurity equals privacy. Security is one part; notices, purposes, rights and retention matter too.
  9. Copying another website’s privacy policy. Fix: write notices that describe your actual data and purposes.
  10. Ignoring the phased timeline. Fix: plan against the notified dates, and watch for official changes.

30-Day DPDP Readiness Action Plan for an SME

This is a recommended implementation roadmap, not a statutory requirement.

Week Focus Actions
Week 1 Discover Identify personal data, map systems, list vendors, record purposes
Week 2 Review Review notices, consent, access controls and retention; list gaps
Week 3 Build Create rights-request and incident processes, update vendor documents, strengthen security, assign owners
Week 4 Test Run a mock rights request and breach drill, review access, test deletion, document open risks, set a review cycle

Swipe the table sideways to see all columns.

When Should an SME Seek Professional DPDP Advice?

A self-assessment is enough for many small businesses to get started. Professional help is worth considering if you process large volumes of personal data, handle health, financial, HR or children’s data, rely on a complex vendor ecosystem, operate across borders, share data with partners, suspect a breach, are unsure whether you are a Data Fiduciary or Data Processor for an activity, or are making significant changes to your systems.

For the full picture of obligations, read our DPDP Act 2023 compliance guide and our explainer on DPDP Act penalties.

Frequently Asked Questions

What is a DPDP readiness audit?

A DPDP readiness audit is a structured review of how a business collects, uses, stores, shares and protects personal data, measured against the DPDP Act, 2023 and DPDP Rules, 2025. It identifies gaps and priorities. A self-assessment is a starting point, not a legal certification of compliance.

Does the DPDP Act apply to small businesses in India?

Yes. The Act has no general size or turnover threshold. Any business processing digital personal data of individuals in India is generally covered, although the government can notify exemptions for certain classes of Data Fiduciaries, including startups, for specified provisions.

What should an SME check for DPDP compliance?

Its data inventory, processing purposes, privacy notices, consent mechanisms, rights handling, breach response, security safeguards, vendor contracts, retention and deletion, internal access, accountability structure and documentation.

Is a privacy policy enough for DPDP compliance?

No. A privacy policy alone does not meet notice, consent, security, breach, rights or retention obligations. The Rules require clear, itemised notices at the point of collection, and the business must actually operate the processes the policy describes.

What is a Data Fiduciary under DPDP?

A Data Fiduciary is any person or business that, alone or with others, decides the purpose and means of processing personal data. Most SMEs are Data Fiduciaries for their own customer and employee data.

Do SMEs need consent to collect personal data?

Not always. Personal data can be processed either with valid consent or for specific “legitimate uses” listed in Section 7 of the Act, such as legal obligations or certain employment purposes. Where consent is the basis, it must be free, specific, informed and unambiguous.

What are the rights of a Data Principal?

The right to access information about their personal data; to correction, completion, updating and erasure; to grievance redressal; and to nominate another person to exercise their rights in case of death or incapacity.

What should a company do after a personal data breach?

Contain the incident, preserve evidence and assess impact. Once the breach provisions apply in May 2027, Rule 7 requires informing affected individuals without delay, and the Board without delay with a detailed report within 72 hours of becoming aware. Take legal advice on the specific facts.

Do small businesses need a Data Protection Officer?

Generally no. Only Significant Data Fiduciaries notified by the government must appoint a DPO. Other Data Fiduciaries must publish the contact details of a person who can answer questions about their processing.

When does the DPDP Act become applicable to businesses?

In phases. Board-related provisions came into force on 13 November 2025, Consent Manager provisions apply from November 2026, and most Data Fiduciary obligations apply eighteen months after notification, in May 2027. Check MeitY’s official notifications for any changes.

Make DPDP Readiness an Ongoing Habit

DPDP readiness is a business process, not a one-time document exercise. The pattern is simple: know your data → know your purpose → control access → manage vendors → protect data → respond to requests → prepare for breaches → document everything.

This article is a readiness self-assessment for general information. It is not legal advice and does not certify compliance.

Want a Structured DPDP Readiness Review?

AAPT & Associates offers DPDP Act compliance services for Indian businesses, from gap assessments to notices, vendor contracts and breach response planning.

Book a DPDP Readiness Review

Sources & References: MeitY: DPDP Act, 2023 and Rules · DPDP Rules, 2025 (Gazette, G.S.R. 846(E)) · Mondaq: MeitY proposal on compliance timeline

  • DPDP readiness audi
Share
Previous Post

Search

Categories

  • No categories

Recent Posts

Why US CPA Firms Outsource Bookkeeping to India: A Practical Guide
Sep 30, 2026
7 Red Flags of Financial Fraud Every CFO Should Know
Sep 29, 2026
Consent Manager Under DPDP: Roles, Rules & Registration
Sep 28, 2026

Tags

  • #AccountingServices
  • #bestcafirm
  • #bestcafirminnoida
  • #Bookkeeping
  • #BusinessCompliance
  • #BusinessFinance
  • #BusinessGrowth
  • #BusinessTax
  • #cafirm
  • #cafirminnoida
  • #CapitalGainsTax
  • #CashFlowManagement
  • #CorporateFinance
  • #corporategovernance
  • #CorporateTax
  • #directtax
  • #DueDiligence
  • #FinancialAdvisory
  • #FinancialClarity
  • #FinancialCompliance
  • #FinancialPlanning
  • #FinancialReporting
  • #FinancialStrategy
  • #gstcompliance
  • #GSTIndia
  • #IncomeTax
  • #IndustrialGrowth
  • #InputTaxCredit
  • #InvestmentPlanning
  • #LegalCompliance
  • #mergersandacquisitions
  • #PayrollManagement
  • #poshact
  • #RenewableEnergy
  • #RiskManagement
  • #StartupIndia
  • #StatutoryCompliance
  • #TaxAdvisory
  • #TaxCompliance
  • #TaxPlanning
  • #TaxStrategy
  • #topcafirm
  • #topcafirminnoida
  • #VirtualCFO
  • #WealthManagement

About

  • About Us
  • Our Team
  • Careers
  • Contact Us

Services

  • Business Advisory
  • Taxation
  • Corporate Support Services
  • Transaction Advisory Services

Industries

  • Consumer
  • Energy, Resources & Industrials
  • Financial Services
  • Government & Public Services
  • Life Sciences & Health Care
  • Technology, Media & Telecommunications
Quick Contact
info@aaptcorp.com 0120-4345715, +91-9319922127
Location
Office No-613 & 614, 6th Floor, Vishal Chambers, P Block, Pocket I, Sector 18, Noida, Uttar Pradesh 201301
Mon-Sat:
9:30 AM - 6:30 PM
*Excludes Holidays
Get in Touch

    2026 AAPT & ASSOCIATES, All Rights Reserved. Designed by- G Optimizers