Do you have a documented inventory of all personal data your organization collects, including data held by third-party vendors and legacy systems? Is this inventory reviewed and updated regularly?
Are your consent flows , specific, and revocable? Are your privacy notices written in plain language and aligned with your actual data practices, not just legal boilerplate?
Have you implemented reasonable technical and organizational security safeguards? Do you have a documented breach response plan that specifies who is notified, and within what timeframe?
Have you reviewed the data handling practices of your processors and sub-processors? Do your contracts with them include DPDP-aligned data protection clauses?