India's Digital Personal Data Protection Act and the DPDP Rules notified in November 2025 phase in over 18 months, with the main operating obligations arriving in mid-May 2027. This checklist is for product, engineering, compliance and security leads at fintech platforms who need to turn the law into concrete work items, and who want to know where RBI rules still apply on top.

It is a working checklist, not legal advice. Confirm the final reading of each item with your counsel, especially where RBI, SEBI or other sector rules overlap.

Before you start

  • [ ] Confirm your role for each processing activity: Data Fiduciary (you decide purpose and means) or Data Processor (you process on someone else's behalf). Lending partners, KYC providers and payment gateways often differ per flow.
  • [ ] Note the phased dates: Data Protection Board provisions are already in force (November 2025), consent manager registration follows in November 2026, and substantive obligations apply from mid-May 2027. Work backwards from that date.
  • [ ] Name one accountable owner (compliance or product) and one technical owner (engineering or security).
  • [ ] Check whether you may be designated a Significant Data Fiduciary (SDF) based on data volume and sensitivity. If so, plan for a Data Protection Officer, an annual impact assessment and an annual independent audit.

1. Data inventory and mapping

  • [ ] List every category of personal data you collect: identity, KYC documents, contact details, bank and UPI identifiers, transaction history, device and location data, bureau data.
  • [ ] For each category, record the purpose, the system of record, who can access it, and which third parties receive it.
  • [ ] Mark data that is collected but never used. Stop collecting it; the Act is built around collecting only what the stated purpose needs.
  • [ ] Map data flows to processors and partners (KYC, payments, collections, analytics, support tooling, cloud regions).
  • [ ] Record where each store physically sits, so you can answer cross-border and RBI localisation questions quickly.
  • [ ] Write a standalone privacy notice in plain language that itemises the personal data and the specific purpose for each use.
  • [ ] Make consent specific, informed and unambiguous. No pre-ticked boxes, and no bundling optional uses (marketing, profiling) into the core service consent.
  • [ ] Provide notice and consent in English and in the Indian languages your users actually use.
  • [ ] Make withdrawing consent as easy as giving it, and wire withdrawal through to every downstream system.
  • [ ] Store a consent record per user: what they saw, what they agreed to, when, and which version of the notice.
  • [ ] Decide whether you will integrate a registered consent manager, and design your consent store so you can.
  • [ ] Review the "legitimate uses" the Act permits (for example, certain regulatory and legal obligations) and document which of your processing relies on them rather than on consent.

3. Data principal rights

  • [ ] Build a request channel for access, correction, completion, erasure and grievance redress.
  • [ ] Publish the contact details of the person who handles grievances.
  • [ ] Set an internal SLA well inside the response window set in the Rules (confirm the current maximum with counsel).
  • [ ] Support nomination of another person to exercise rights on a user's behalf.
  • [ ] Define what you must keep despite an erasure request (for example, records required by financial regulation) and how you explain that to the user.

4. Retention and erasure

  • [ ] Set a retention period per data category tied to its purpose and to the regulatory minimum for financial records.
  • [ ] Automate deletion or anonymisation when the purpose ends, including in backups, analytics copies and vendor systems.
  • [ ] Retain the security logs the Rules require (the Rules set a minimum retention period for logs, so confirm the exact scope with counsel).
  • [ ] Define how inactive accounts are handled and what notice users get before data is erased.

5. Security safeguards

  • [ ] Encrypt personal data in transit and at rest, with managed keys and a documented rotation process.
  • [ ] Enforce least-privilege access with role-based controls, MFA for staff and a periodic access review.
  • [ ] Log access to personal data and keep logs tamper-resistant.
  • [ ] Mask or tokenise sensitive fields (PAN, Aadhaar-linked data, account numbers) in non-production and support tooling.
  • [ ] Test backup restore and keep a business-continuity plan for systems holding personal data.
  • [ ] Align this work with your existing PCI DSS, ISO 27001 or SOC 2 controls so you extend rather than duplicate them.

6. Breach response

  • [ ] Write a breach playbook with severity levels, decision rights and a named incident lead.
  • [ ] Be able to notify the Data Protection Board within the Rules' deadlines (an initial intimation without delay and a detailed report within 72 hours of becoming aware) and to notify affected users plainly.
  • [ ] Prepare templates for the Board report and the user message: what happened, what data, likely impact, what you did, who to contact.
  • [ ] Run a tabletop exercise at least once a year, including a vendor-caused breach.
  • [ ] Check how your incident process lines up with RBI and CERT-In reporting so one event does not produce three uncoordinated responses.

7. Children's data

  • [ ] Decide whether your product is open to anyone under 18 (for example, student or family wallets, teen accounts).
  • [ ] If so, build verifiable parental or guardian consent into onboarding.
  • [ ] Switch off tracking, behavioural monitoring and targeted advertising for children's accounts.

8. Vendors and cross-border transfers

  • [ ] Keep a register of every processor with the data they touch, their location and their sub-processors.
  • [ ] Put a data processing agreement in place covering security standards, breach notice to you, deletion on exit and audit rights.
  • [ ] Remember that you remain accountable for processors acting on your behalf.
  • [ ] Treat RBI payment-data storage rules as separate and still binding: payment system data must be stored only in India, with limited offshore processing allowed only if the data is deleted abroad and brought back within the RBI-specified window. DPDP does not replace this.
  • [ ] Watch for any government notification restricting transfers to specific countries, and make sure your architecture can move or pin data by region.

9. Governance and evidence

  • [ ] Run a gap assessment against each section above and rank gaps by regulatory exposure and effort.
  • [ ] Keep a living record of decisions: purposes, legal basis, retention, vendors and exceptions.
  • [ ] If you are or may be an SDF: appoint a DPO based in India, schedule the annual data protection impact assessment and the independent audit.
  • [ ] Train customer support, collections and product staff on handling personal data and rights requests.
  • [ ] Set a quarterly review: new data fields, new vendors, new features that change purposes.

Red flags that mean you are behind

SignalWhat it usually means
No one can say which systems hold a customer's dataInventory is missing, so erasure and access requests will fail
One consent checkbox covers everythingConsent is bundled and unlikely to be "specific"
Deleting a user removes only the main database rowBackups, analytics and vendors still hold the data
Vendor contracts say nothing about breach noticeYou may learn about an incident after your own deadline has started
Breach plan has no named ownerThe 72-hour clock will be spent finding who decides

How to use this

Run through the checklist with product, engineering and compliance in one room. Mark each item done, in progress or gap, and assign an owner and date to every gap. Tackle sections 1, 2 and 6 first, because the inventory feeds everything else, consent design takes the longest to change in product, and breach response is the one with a hard clock. Work backwards from mid-May 2027 and revisit the checklist as the Rules are clarified.

Next step

If you would like to see how this checklist maps to your own stack and customer flows, we can walk through it together in a 30-minute call.

Book a 30-minute call