
The Digital Personal Data Protection Act, 2023 applies to any organisation that decides why and how personal data of individuals in India is processed. The Act calls that organisation a data fiduciary. Here is a checklist we use with clients to find the gaps before an auditor or a customer does.
1. Can you list every purpose for which you process personal data?
Consent is tied to a purpose. If you cannot enumerate the purposes, you cannot show that consent covers them. Start with a purpose register, not a technology choice.
2. Is a notice shown at the point of collection?
The notice must describe the personal data collected, the purpose, how the person can exercise their rights, and how to complain. It has to appear before or with the consent request, in clear language, and the Act contemplates notices in Indian languages.
3. Is consent specific, and can it be withdrawn as easily as it was given?
Bundled consent across unrelated purposes is not specific. A withdrawal path that is harder than the opt-in path is not compliant. Test both journeys as a user would.
4. Can you prove consent for one individual on one date?
Pick a customer at random and try to produce the notice they saw, the purposes they agreed to and when. If the answer lives in application logs that an engineer can edit, the proof is weak. A tamper-evident ledger is the fix.
5. What happens when consent is withdrawn?
Processing for that purpose has to stop within a reasonable time, and any processors you share the data with have to stop too. Map the downstream systems now.
6. Can a person get their data corrected or erased?
Correction, completion, updating and erasure are rights of the data principal. You need an intake channel, an approval step, an execution step that actually purges the data, and a record that it happened.
7. Who is the Grievance Officer, and is the contact published?
Grievances must go to a named officer, and the response has to be within the prescribed period. Publish the contact, and give the officer a queue rather than an inbox.
8. Do you have reasonable security safeguards?
The Act requires safeguards to prevent personal data breaches. Encryption, access control, monitoring and backup are the usual evidence. If you run Microsoft 365, immutable backup with in-country residency is part of that answer.
9. Do you know what you would do in the first hours of a breach?
The Act requires breaches to be reported to the Data Protection Board and to affected individuals. A rehearsed runbook matters more than a policy document.
10. Are your processors under contract?
A fiduciary may engage a processor only under a valid contract. Inventory every vendor that touches personal data and check the paperwork.
Most organisations pass questions 1, 8 and 10 and fail 4, 5 and 6. Those three are exactly what a consent manager exists to fix.
Third Octopus advises on the programme and builds OctoCred, a consent management platform that covers the notice, consent, ledger, erasure and grievance steps. Either way, start with the checklist.

