DPDPA docs, drafted for you.
Twelve editable Word and Excel documents for India’s Digital Personal Data Protection Act, with a walkthrough video for every step. Every document is checked against the official text of the Act and Rules, and the toolkit’s own choices are labelled as ours.
Launch price ₹29,999 incl. GST one time
Key dates
- 13 Nov 2025DPDP Rules notified
- 13 Nov 2026Consent Manager registration rule in force
- 13 May 2027Data Fiduciary duties and penalties apply
For the people who run the business, not a legal department.

Founders and owners who decide what data the business collects and why.

IT and operations leads who run the systems and the vendors.

Compliance and support leads who answer people’s requests about their data.
Stock photographs for illustration. They are not our team or our customers.
Up to ₹250 crore. A ceiling, not a bill.
The Act sets a maximum penalty for each kind of breach; the main ones for a business are below. The Data Protection Board can impose one only if, at the end of an inquiry, it finds the breach significant and the person has been given an opportunity of being heard, and it sets the amount by weighing the factors the Act lists.
The Board acts on a breach intimation, a complaint, a government reference or a court direction. The duties start on 13 May 2027.
The real risk isn’t the number. It’s not knowing where your gaps are.Step 01 lists 19 legal duties and 1 good-practice item, with a citation and penalty category for each duty, and shows which ones you already cover.
- ₹250croreFailing to take reasonable security safeguards
- ₹200croreFailing to notify the Board or people affected by a breach
- ₹200croreBreaching the additional duties for children’s data
- ₹150croreBreaching the additional duties of a Significant Data Fiduciary
- ₹50croreBreaching any other provision of the Act or Rules
“May extend to”: each figure is the most the Board may impose, not a fixed fine.
Twelve documents. Each one does one job.
Word documents you edit and Excel workbooks that calculate: dropdowns with the law’s own options, due dates worked out for you, and a Dashboard tab in eight of the ten workbooks. Numbered by the step that fills them in.
01Reality Check self-assessmentExcel · how-to 01
02Compliance TimelineExcel · how-to 02
03RoPA trackerExcel · how-to 03
04Data Protection PolicyWord · how-to 04
05Consent NoticeWord · how-to 05
06Retention ScheduleExcel · how-to 06
07Rights Request Form + TrackerWord + Excel · how-to 07
08DPIA + Risk RegisterExcel · how-to 08
09Vendor Risk AssessmentExcel · how-to 09
09bData Processing AgreementWord · how-to 09b
10Cross-Border Transfer RegisterExcel · how-to 10
11Breach Register + both noticesExcel + Word · how-to 11
Badges show the step that uses each document. Step 12 adds three bonus tools: a cost-of-inaction brief, a roles guide and a five-framework crosswalk.
One spotlight on exactly what to fill in.
Each video moves through the real document, one section at a time, and says where every input comes from. Here is page one of the Data Protection Policy, the way step 04 walks it.

-
1Every bracket is yours
Type your company name into the header and the title. The worked example uses a fictional online store.
-
2Four fields, filled from your plan
Effective date, owner, approver and next review. The dates and owners come from your Compliance Timeline in step 02.
A DPO is required only for a notified Significant Data Fiduciary -
3Scope and roles
The policy opens with its scope, then defines the roles and asks whether you are a Significant Data Fiduciary, a status only the Central Government can give by notification.
-
4Seven principles
From lawful basis to accountability. Five cite the Act; two are your own commitments. Keep all seven.
Lawful basis: consent, or a legitimate use the Act lists
Twelve steps, in the order you need them.
Step 09 has two parts, so there are 13 walkthroughs. Each step builds on the one before; the videos say what to bring over and where it goes next, so the same activity IDs, vendors and dates run through every file.
- Step 01:
Start here
Find out whether the Act applies, then see which duties you already cover.
00-does-this-apply-to-you.docxdpdpa-reality-check-self-assessment.xlsx - Step 02:
Plan the work
Turn your gaps into a dated plan, with each task tied to a document.
compliance-timeline.xlsx - Step 03:
Know your data
Map every way your business uses personal data. Most other documents build on this one.
ropa-tracker.xlsx - Step 04:
Set the rules
The Data Protection Policy your business commits to, in 17 sections.
data-protection-policy.docx - Step 05:
Ask properly
The notice that must come with, or before, every request for consent.
consent-notice-template.docx - Step 06:
Keep only as long as needed
Turn retention periods into deletion dates, and track every erasure.
data-retention-schedule.xlsx - Step 07:
Answer people on time
A form for people to ask about their data, and a tracker so you answer on time.
rights-request-form.docxrights-request-tracker.xlsx - Step 08:
Check risky processing
Score the risk to people's rights before and after your fixes.
dpia-template-risk-register.xlsx - Step 09:
Control your vendors
Screen each vendor before you sign, and see who still needs work.
vendor-risk-assessment.xlsx - Step 09b:
Sign the vendor contract
The Data Processing Agreement: 15 clauses, plus Schedules A and B.
data-processing-agreement-template.docx - Step 10:
Data leaving India
Log every transfer abroad and re-check it against the gazette.
cross-border-transfer-register.xlsx - Step 11:
When something goes wrong
Log a breach, file both Board reports on time, and tell the people affected.
breach-register.xlsxbreach-notification-to-board.docxbreach-notification-to-data-principal.docx - Step 12:
Bonus tools
A budget brief, a roles guide for messy org charts, and a five-framework crosswalk.
cfo-cost-of-inaction-onepager.docxdpdpa-roles-in-a-hairball-org.docxdpdpa-multi-framework-crosswalk.xlsx
Numbers traced to the official text.
Sections, rules, dates and legal figures are traced to the Act, the Rules as notified, and the notification that sets when each part of the Act starts. A few of the numbers the toolkit gets right:
The longest grievance response period you may publish; you then answer within it. It applies to grievances only; the toolkit says so instead of stretching it to every request.
For the detailed breach report to the Board, within 72 hours of becoming aware, after a first intimation sent without delay. Two filings, not one.
The minimum time to keep personal data, traffic data and logs of each processing.
For data sent abroad, the Central Government may restrict transfers to countries it notifies, stricter Indian law still applies, and the Rules let it set requirements about making data available to a foreign State. The register lists no “safe” countries.
Read against the primary text
The Act of 2023, the Rules as notified on 13 November 2025, and the notification that sets when each part of the Act starts. Not summaries, not drafts.
Our choices are labelled as ours
A 24-hour vendor breach notice, a 180-day transfer review, a 90-day target for every request type: each is marked as a contract or internal choice, not as law.
Reviewed against the text
Each document was reviewed against the official text when its walkthrough was prepared.
How we arrived here: how each document is built, what we checked, and which provisions it rests on
One price. Every document.
Buy once and keep the files. Watch a free preview of every walkthrough before you decide.
Before 14 Nov!
No subscription.
- 12 core documents in Word and Excel
- 3 bonus tools and the “Does this apply to you?” guide
- Workbooks with live formulas and dropdowns; eight include a Dashboard tab
- Full walkthrough videos for every step (26 min); free previews on this site
The price includes GST. To get a GST invoice, email us your billing name, address and GSTIN. No refunds: the toolkit is digital and delivered right after payment.
Refund policy · Terms · Delivery · Contact
Your steps and program invitation arrive by email after payment. Check spam too.
Straight answers
Does the DPDP Act apply to my business?
Ask two questions. Do you collect personal information digitally, such as names, phone numbers or emails, even in a spreadsheet on a laptop? Is any of it stored on a computer, phone, app or the cloud? If yes, and you process it in India or to offer goods or services to people in India, the law is built to cover you, unless an exemption applies, such as data an individual processes for a personal or domestic purpose, data the person has made public, or one of the other exemptions the Act lists. Step 01 starts with exactly these two questions.
Do we need a Data Protection Officer?
A DPO is mandatory only for a business the Central Government notifies as a Significant Data Fiduciary. Every Data Fiduciary must publish the contact of someone able to answer questions about its processing. Steps 04 and 12 cover both.
Do we have to do a DPIA?
The Act requires a periodic Data Protection Impact Assessment only from Significant Data Fiduciaries. The toolkit recommends one for any high-risk activity and step 08 shows how to run it.
How long do we have to answer a request?
The Rules cap the grievance response period you publish at ninety days. The rights tracker applies the same 90-day target to every request type as its own choice, and turns a request red when fewer than 15 days remain.
Is this legal advice?
No. It is a drafting aid that helps you prepare your own documents. Have counsel review them before you adopt them.
Three ways in
Map what you process
Tick what you collect and the tools you use. See the duties and documents that match. Answers stay in your browser.
Build your mapSelling online?
Typical personal data for a Shopify, Wix or WordPress store, and the documents to start with.
See the store checkHow we arrived here
Why these documents, how each is built from the official text, and which choices are ours.
See how