In short
These documents were built to help you address the legal and statutory requirements of the DPDP Act and Rules. They are not just our ideas: each one starts from the official text, every line is labelled as a legal duty, a contract term or our own recommendation, and the Excel workbooks make their decisions with fixed rating rules instead of opinion. You should still have your own legal advisor review them before you adopt them, but you start with a head start on the page.
The rest of this site says things in plain words. This page is where the basis lives: how the documents were built from the official text, what we checked, which parts are our own choice, and the sections and rules each document rests on.
Why these documents
In our view, a lecture or tutorial course on the DPDP Act can cost anywhere from ₹1 lakh to ₹3 lakh, and a course alone does not hand you the baseline documents to start with. You can finish with a good understanding of the Act and still have no policy, notice, data record or breach register. We have not surveyed prices, so read this as our view.
The toolkit is the set of documents a business needs to begin: a data record (RoPA), a policy, a consent notice, a retention schedule, a rights-request form and tracker, a breach register and notices, a risk assessment (DPIA), a vendor assessment and processing agreement, and a register for data leaving India. They are in the order you use them.
How we built each document
- Start from the official text. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), the DPDP Rules, 2025 as notified on 13 November 2025 (G.S.R. 846(E)), and the commencement notification (G.S.R. 843(E)) that sets when each part of the Act applies.
- List what the law asks. The duties a business carries are written out in plain words: nineteen legal duties, each with its section or rule, and one good-practice item. The free duties list shows them.
- Give each document one job. Each document carries out part of that list, in the order a business uses them. The table further down names the provisions each one rests on.
- Check, label and test. Sections, rules and dates are checked against the official text, labelled by what it is (a legal duty, a contract term or a recommendation), and the workbooks run it through decision rules in Excel.
Why you can build on them
- Built the way standards are built. International security and privacy standards have asked organisations for decades to keep the same kinds of record: a policy, a notice, a register, a procedure and a record of decisions. These documents follow that structure, and a mapping workbook relates the requirements to widely used frameworks.
- Labelled like a standard. Each requirement is labelled the way standards label controls, so you can see what it is, where it comes from and how it relates to other frameworks.
- Decision rules in Excel. In the workbooks you answer and the sheet rates and flags: the Reality Check rates your readiness against each duty, and the rights tracker flags a request when fewer than 15 days remain. The same answers give the same result every time.
- Drafted from the published text. The statements in the documents are drafted from the published text of the DPDP Act and Rules, with the sections and rules they rely on cited. You still need to run them past your own legal advisor, but you have a head start.
- Records you can stand behind. When a customer, auditor or the Board asks what you decided and why, these are the records that help you explain and defend it, and they build trust before that day. They do not decide any outcome. Get legal advice for your situation.
What we checked, and against what
Sections, rules and dates in the documents are checked against those official texts. Where we cannot trace a point to them, we do not state it as fact. Each article on this site also shows the date it was last checked and lists the sections and rules it relies on.
The law was changed on the way, which is why the check matters. The January 2025 draft Rules (G.S.R. 02(E)) were superseded by the notified Rules (G.S.R. 846(E), 13 November 2025), and commencement is staged across 13 November 2025, 13 November 2026 and 13 May 2027. A summary built on the draft, or one that treats the dates as a single date, gets numbers wrong.
Which provisions each document rests on
| Step | Files | Rests on |
|---|---|---|
| 01 · Start here | 00-does-this-apply-to-you.docx, dpdpa-reality-check-self-assessment.xlsx | G.S.R. 843(E), para (c); Act s.10(1); Act Schedule, Sl. 1 and 2; Act s.33(1) |
| 02 · Plan the work | compliance-timeline.xlsx | Rule 1(4); Rule 1(3) |
| 03 · Know your data | ropa-tracker.xlsx | Act s.4(1), s.6, s.7(a) to (i); Act s.9(1) |
| 04 · Set the rules | data-protection-policy.docx | Act s.10(2)(a); Act s.6(1); Rule 14(3); Rule 8(3); Rule 7(2) |
| 05 · Ask properly | consent-notice-template.docx | Act s.5(1); Rule 3(b); Rule 3(c); Act s.6(4); Act s.5(3) |
| 06 · Keep only as long as needed | data-retention-schedule.xlsx | Act s.8(7)(a); Rule 8(1), Third Schedule; Rule 8(2); Rule 8(3); Act s.8(7)(b) |
| 07 · Answer people on time | rights-request-form.docx, rights-request-tracker.xlsx | Rule 14(1)(a); Rule 14(3); Act s.12(3) |
| 08 · Check risky processing | dpia-template-risk-register.xlsx | Act s.10(2)(c)(i); Rule 13(1); Rule 13(2) |
| 09 · Control your vendors | vendor-risk-assessment.xlsx | Act s.8(1); Act s.8(2) |
| 09b · Sign the vendor contract | data-processing-agreement-template.docx | Rule 6(1)(f); Rule 7(2); Act s.8(7)(b); Act s.16(1) |
| 10 · Data leaving India | cross-border-transfer-register.xlsx | Act s.16(1); Act s.16(2); Rule 15; G.S.R. 843(E) para (c); Rule 1(4) |
| 11 · When something goes wrong | breach-register.xlsx, breach-notification-to-board.docx, breach-notification-to-data-principal.docx | Act s.8(6); Rule 7(1); Rule 7(2); Act Schedule, Sl. 1 and 2 |
| 12 · Bonus tools | Three bonus tools (see the step page) | Act s.33(1); Act s.33(2)(a) to (g); Act s.10(2)(a) |
Read the law yourself
The free duties list gives every duty in plain words with its section or rule. The articles go deeper on one topic each. The processing map labels each duty in its result with its section or rule.
What this is not
The documents are a drafting aid. Get legal advice for your situation. The Significant Data Fiduciary risk rating only flags risk; the Central Government decides who is one. Cynor Sense is not part of, or endorsed by, the Ministry of Electronics and Information Technology or the Data Protection Board of India.
Who is behind this
Arun R M
Cynor Sense, Hyderabad
CISO · CRISC · DPO · Cyberlaw (as listed on his LinkedIn profile)
Cynor Sense publishes these documents. Connect on LinkedIn
If demand is high, we will also publish podcasts and videos on how each sector can use these documents.