DPDP
Operational checklist
Practical readiness for DPDP-shaped privacy ops, not a certification.
Operational checklist
Use this as an engineering/ops checklist before treating Erasure as production-ready for consent and erasure workflows. Completing it does not mean you are "DPDP compliant."
Consent (Accord)
- Purposes and notice reviewed with whoever owns legal copy
- Configuration published (not left in draft)
- Publishable key created; raw key stored securely by you
- Allowed origins listed for production hosts
- SDK live on real surfaces; sample receipts present
- Optional: project webhook verified (
X-Accord-Signature) - Optional: withdraw path tested for optional purposes
Mapping & Systems
- Systems connected for every store that must participate in erasure
- Health checks HEALTHY (or known DEGRADED with a plan)
- Data Maps: DELETE entities + identifiers for SQL/document modules
- Dry-run / preview used where available
- Secrets rotated only via product rotate paths
Rights
- Worker process running
- Operational Readiness not blocked
- Test case completed end-to-end (operator path)
- Public intake OTP path tested if subjects will use it
- Evidence exported for a completed (or failed) case
Security & ops
- Owner/Admin/Viewer roles assigned intentionally
- Production mailer configured for OTP (and password reset if used)
- Backups for Postgres owned by your provider/process
- Network egress for worker limited to intended systems