All templates
Internal Registers & Trackers
Compliance Evidence Index Template
A master index linking every DPDP compliance obligation to the evidence document that proves it has been met.
Template
COMPLIANCE EVIDENCE INDEX Organization: [Organization Name] Maintained By: [DPO] Purpose of Index: To provide a single, auditable map from each DPDP Act obligation to the evidence artifact demonstrating compliance, for use in internal audits, Board inquiries, or Significant Data Fiduciary independent audits. 1. HOW TO USE THIS INDEX Each row identifies an obligation, the artifact that evidences compliance, its storage location, and the date it was last verified as current. This index does not replace the underlying documents - it points to them so nothing is misplaced or forgotten when evidence is requested on short notice. 2. INDEX Column headers: Obligation | DPDP Reference | Evidence Artifact | Location / System | Last Verified | Verified By | Status Example Row 1: Obligation: Notice given before or at the time of seeking consent DPDP Reference: Section 5 Evidence Artifact: Consent notice templates (all versions) and change log Location / System: [Document Management System, folder path] Last Verified: [DD-MM-YYYY] Verified By: [Legal Lead] Status: Current Example Row 2: Obligation: Valid contracts with all Data Processors DPDP Reference: Section 8(2) Evidence Artifact: Vendor Risk Register and executed Data Processing Addendums Location / System: [Contract repository] Last Verified: [DD-MM-YYYY] Verified By: [Procurement Lead] Status: Current Example Row 3: Obligation: Reasonable security safeguards against breach DPDP Reference: Section 8(5), DPDP Rules 2025 Evidence Artifact: Security policy, encryption standard, access log retention configuration, latest penetration test report Location / System: [Security wiki / GRC tool] Last Verified: [DD-MM-YYYY] Verified By: [CISO] Status: Current Example Row 4: Obligation: Breach intimation to Board and Data Principals DPDP Reference: Section 8(6) Evidence Artifact: Data Breach Log and copies of all intimation letters sent Location / System: [Incident management system] Last Verified: [DD-MM-YYYY] Verified By: [DPO] Status: Current Example Row 5: Obligation: Published business contact information of DPO / grievance contact DPDP Reference: Section 8 Evidence Artifact: Screenshot and URL of privacy policy page listing DPO contact Location / System: [Public website] Last Verified: [DD-MM-YYYY] Verified By: [DPO] Status: Current Example Row 6: Obligation: Verifiable parental consent for children's data DPDP Reference: Section 9 Evidence Artifact: Parental consent flow design document and sample verification logs Location / System: [Product documentation repository] Last Verified: [DD-MM-YYYY] Verified By: [Product Compliance Lead] Status: In progress - flow update pending Example Row 7: Obligation: Annual DPIA and independent audit (if Significant Data Fiduciary) DPDP Reference: Section 10 Evidence Artifact: Annual DPIA Summary Report and independent auditor's report Location / System: [Board reporting archive] Last Verified: [DD-MM-YYYY] Verified By: [DPO] Status: Current 3. GAP TRACKING Any obligation marked "In progress" or "Gap Identified" must have a remediation owner and target date recorded in the Board Reporting Template for Privacy Metrics until closed. 4. REVIEW CADENCE This index is reviewed [quarterly] ahead of any scheduled Board or leadership privacy update. Last Full Review: [DD-MM-YYYY]. Next Review: [DD-MM-YYYY].
This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.