DPDP NavigatorAct 2023 · Rules 2025
All templates
Internal Registers & Trackers

Compliance Evidence Index Template

A master index linking every DPDP compliance obligation to the evidence document that proves it has been met.

Template
COMPLIANCE EVIDENCE INDEX

Organization: [Organization Name]
Maintained By: [DPO]
Purpose of Index: To provide a single, auditable map from each DPDP Act obligation to the evidence artifact demonstrating compliance, for use in internal audits, Board inquiries, or Significant Data Fiduciary independent audits.

1. HOW TO USE THIS INDEX

Each row identifies an obligation, the artifact that evidences compliance, its storage location, and the date it was last verified as current. This index does not replace the underlying documents - it points to them so nothing is misplaced or forgotten when evidence is requested on short notice.

2. INDEX

Column headers: Obligation | DPDP Reference | Evidence Artifact | Location / System | Last Verified | Verified By | Status

Example Row 1:
Obligation: Notice given before or at the time of seeking consent
DPDP Reference: Section 5
Evidence Artifact: Consent notice templates (all versions) and change log
Location / System: [Document Management System, folder path]
Last Verified: [DD-MM-YYYY]
Verified By: [Legal Lead]
Status: Current

Example Row 2:
Obligation: Valid contracts with all Data Processors
DPDP Reference: Section 8(2)
Evidence Artifact: Vendor Risk Register and executed Data Processing Addendums
Location / System: [Contract repository]
Last Verified: [DD-MM-YYYY]
Verified By: [Procurement Lead]
Status: Current

Example Row 3:
Obligation: Reasonable security safeguards against breach
DPDP Reference: Section 8(5), DPDP Rules 2025
Evidence Artifact: Security policy, encryption standard, access log retention configuration, latest penetration test report
Location / System: [Security wiki / GRC tool]
Last Verified: [DD-MM-YYYY]
Verified By: [CISO]
Status: Current

Example Row 4:
Obligation: Breach intimation to Board and Data Principals
DPDP Reference: Section 8(6)
Evidence Artifact: Data Breach Log and copies of all intimation letters sent
Location / System: [Incident management system]
Last Verified: [DD-MM-YYYY]
Verified By: [DPO]
Status: Current

Example Row 5:
Obligation: Published business contact information of DPO / grievance contact
DPDP Reference: Section 8
Evidence Artifact: Screenshot and URL of privacy policy page listing DPO contact
Location / System: [Public website]
Last Verified: [DD-MM-YYYY]
Verified By: [DPO]
Status: Current

Example Row 6:
Obligation: Verifiable parental consent for children's data
DPDP Reference: Section 9
Evidence Artifact: Parental consent flow design document and sample verification logs
Location / System: [Product documentation repository]
Last Verified: [DD-MM-YYYY]
Verified By: [Product Compliance Lead]
Status: In progress - flow update pending

Example Row 7:
Obligation: Annual DPIA and independent audit (if Significant Data Fiduciary)
DPDP Reference: Section 10
Evidence Artifact: Annual DPIA Summary Report and independent auditor's report
Location / System: [Board reporting archive]
Last Verified: [DD-MM-YYYY]
Verified By: [DPO]
Status: Current

3. GAP TRACKING

Any obligation marked "In progress" or "Gap Identified" must have a remediation owner and target date recorded in the Board Reporting Template for Privacy Metrics until closed.

4. REVIEW CADENCE

This index is reviewed [quarterly] ahead of any scheduled Board or leadership privacy update. Last Full Review: [DD-MM-YYYY]. Next Review: [DD-MM-YYYY].

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.