Identity systems hold more personal data about your workforce than most teams realise: names, work and personal contact details, phone numbers used for codes, device and location traces in sign-in logs, and records of what each person can reach. This checklist helps you map that data and prepare the routines a Data Fiduciary is expected to have. It is general information, not legal advice. The Act, its rules and how they apply to your organisation are for your compliance counsel to confirm.
1. Know what you hold
Start with an inventory. You cannot protect, correct or erase data you have not listed. Write down each system that stores identity data and what it keeps.
2. State the purpose and tell people
Purpose limitation is central to the Act: data collected for one purpose should not quietly be used for another. People should receive a clear notice about what you collect and why.
3. Consent records where you rely on consent
Where consent is the basis for a particular use, keep a record of what was agreed, when, and how it can be withdrawn. AuthMantra includes consent records, which can support this; the policy about when to rely on consent is still yours to decide.
4. Reasonable security safeguards
The Act expects reasonable security safeguards to protect personal data. For identity data, that usually means strong sign-in, tight admin access, encryption, and logs you can examine.
5. Access, correction and erasure requests
People whose data you hold can ask about it, ask for correction, and in many cases ask for erasure, subject to the law's conditions and to other laws that require you to keep records. Decide in advance who handles these and how fast.
6. Grievance redressal
There must be an accessible route for people to raise concerns about their data and a process that responds. A workflow with an owner, a status and a due date is better than a shared mailbox.
7. Retention and deletion
Keep data no longer than the purpose or a legal requirement demands. Sign-in logs may have their own retention duties; CERT-In directions of 28 April 2022 mention keeping certain logs for 180 days. Whether and how that applies to you is a question for counsel.
8. Vendors and where data lives
If a supplier processes employee data for you, your contract and due diligence should reflect your obligations. Ask where data is stored and who can reach it.
9. Be ready for an incident
If personal data is breached, there are duties to inform the regulator and the people affected, and CERT-In has separate reporting directions. Practise before it happens.
About this runbook
AuthMantra provides tools that support these routines: a grievance workflow, data export, consent records, India data residency, audit log export and SIEM streaming. They help you operate your process; they do not by themselves make an organisation compliant.
authmantra.com/praxis/run/dpdp-readiness-checklist/ · info@authmantra.com