DPIA Trigger and Completion Checklist
Section 10(2)(c) of the DPDP Act requires Significant Data Fiduciaries to undertake Data Protection Impact Assessments, and Rule 13(1) of the DPDP Rules 2025 makes the DPIA an annual obligation alongside the independent audit. For non-SDF Data Fiduciaries, the DPIA obligation is triggered by the nature and risk of the processing — not by designation. A DPIA is not a one-time form. It documents the activity, justifies its lawful basis under Section 4, tests its necessity and proportionality, rates the risks to data principal rights, maps mitigations one-to-one, accepts residual risk with a named owner, and locks for audit. For a mid-tier Indian bank, the master list of high-risk processing activities typically runs to 40–80 items — KYC, lending, fraud monitoring, marketing, partner data sharing, AI-driven decisioning, regulatory reporting — and each one needs its own DPIA on an annual cycle. The checklist below covers the trigger test, the DPIA's minimum mandatory content, the stakeholder loop, and the lock-and-track that makes the DPIA defensible under audit.