Back to The DPDP Act Section B

Implementation & Documentation

The evidence trail required by an auditor or the Board.

A complete DPDP programme requires the following documentation:

  • Privacy Policy and Data Protection Policy
  • Standalone privacy notices and consent artefacts
  • Record of Processing Activities (RoPA) and data-flow maps
  • Data Retention and Erasure Policy with retention schedule
  • Incident Response and Breach Notification Plan
  • Data Principal Rights Request Handling Procedure
  • Data Processing Agreements and vendor addenda
  • Children's Data and Age-Assurance Policy
  • Cross-Border Transfer Policy and transfer register
  • DPIA framework, templates and completed assessments
  • Access Control, Encryption and Logging Standards
  • Employee training modules and attendance records

A Note on Evidence

  • The burden of demonstrating compliance rests with the Data Fiduciary.
  • A consent record that cannot be retrieved is, in practice, no consent at all.
  • Documentation should be maintained in a form capable of being produced on demand.

Speak With Our Data Protection & Privacy Team