Skip to main content
Version: 2.1.1-preview

DPDP Act 2023 Compliance Tests

These tests verify Microsoft 365 tenant configurations against the statutory obligations and security safeguards under India's Digital Personal Data Protection Act, 2023.

Tests

Test IDTitleSeverityCategory
DPDP.1.1Purview Sensitivity Labels SHALL be configured to discover and classify Indian PII/SPII data (Rule 3(i)).UnknownIndiaDPDP
DPDP.1.2Processing activities SHALL map to explicit purpose specification and lawful basis (Rule 5(1)).UnknownIndiaDPDP
DPDP.1.3Anonymous (UnknownIndiaDPDP
DPDP.1.4Default sharing link permissions SHALL be restricted to Specific People or Internal Users (Rule 3(ii)).UnknownIndiaDPDP
DPDP.1.5DPO and Data Fiduciary contact info SHALL be published in tenant policy metadata (Rule 3(vi)).UnknownIndiaDPDP
DPDP.2.1Consent Manager & Service Principal API authentication SHALL enforce TLS transport security (Rule 4(3)(d)).UnknownIndiaDPDP
DPDP.2.2User consent to third-party apps SHALL be disallowed requiring Admin Consent Workflow (Rule 8(2)).UnknownIndiaDPDP
DPDP.2.3User-owned application registrations SHALL be restricted to authorized developers (Rule 8(2)).UnknownIndiaDPDP
DPDP.2.4Third-party applications SHALL be disallowed from accessing personal data without valid DPA (Rule 5(4)).UnknownIndiaDPDP
DPDP.3.1Multi-Factor Authentication (MFA) SHALL be enforced for all users handling personal data (Rule 8(5)-Sec-1).UnknownIndiaDPDP
DPDP.3.2Legacy and weak authentication protocols SHALL be disabled tenant-wide (Rule 8(5)-Sec-1).UnknownIndiaDPDP
DPDP.3.3Global Admin count SHALL be limited to 5 or fewer with PIM Just-In-Time access (Rule 8(5)-Sec-1).UnknownIndiaDPDP
DPDP.3.4Data Loss Prevention (DLP) policies SHALL block outbound transfer of Indian PII/SPII (Rule 8(5)-Sec-9).UnknownIndiaDPDP
DPDP.3.5Exchange Online attachment and file filtering policies SHALL be active (Rule 8(5)-Sec-9).UnknownIndiaDPDP
DPDP.3.6Safe Links and Safe Attachments anti-malware policies SHALL be enabled (Rule 8(5)-Sec-6).UnknownIndiaDPDP
DPDP.3.7BitLocker Encryption SHALL be enforced on endpoints processing personal data (Rule 8(5)-Sec-3).UnknownIndiaDPDP
DPDP.3.8TLS 1.2+ mandatory transport encryption SHALL be enforced for Exchange Online (Rule 8(5)-Sec-2).UnknownIndiaDPDP
DPDP.3.9Backup and recovery procedures SHALL be encrypted and periodically verified (Rule 8(5)-Sec-4).UnknownIndiaDPDP
DPDP.3.10Inactive account block threshold and smart lockout baselines SHALL be enforced (Rule 8(5)-Sec-6).UnknownIndiaDPDP
DPDP.3.11Phishing protection and anti-spoofing DMARC/DKIM records SHALL be active (Rule 8(5)-Sec-6).UnknownIndiaDPDP
DPDP.4.1Automated retention and deletion policies SHALL purge data when purpose is fulfilled (Rule 8(7)(a)).UnknownIndiaDPDP
DPDP.4.2Inactivity period thresholds SHALL be configured to auto-delete stale personal data (Rule 8(8)).UnknownIndiaDPDP
DPDP.4.3Workflows SHALL exist to verify data processors erase supplied personal data (Rule 8(7)(b)).UnknownIndiaDPDP
DPDP.4.4Legacy unlinked datasets SHALL be audited and purged from tenant stores (Rule 8(7)).UnknownIndiaDPDP
DPDP.4.5Direct sign-in to Shared Mailboxes SHALL be disabled (Rule 8(5)).UnknownIndiaDPDP
DPDP.4.6Creation of unauthorized or unmanaged shadow tenants SHALL be disallowed (Rule 8(1)).UnknownIndiaDPDP
DPDP.5.1Verifiable parental consent mechanisms SHALL be configured for child accounts (Rule 9(1)).UnknownIndiaDPDP
DPDP.5.2Tracking, behavioral monitoring, and targeted ads to children SHALL be disabled (Rule 9(3)).UnknownIndiaDPDP
DPDP.5.3Detrimental processing assessments SHALL restrict unmanaged 3rd-party services (Rule 9(2)).UnknownIndiaDPDP
DPDP.6.1Purview eDiscovery SHALL be operational for Data Principal Access Requests (Rule 11(1)(a)).UnknownIndiaDPDP
DPDP.6.2Third-party processor recipient lists SHALL be log-accessible for DSAR summaries (Rule 11(1)(b)).UnknownIndiaDPDP
DPDP.6.3Customer Lockbox SHALL be enabled for explicit approval of Microsoft support access (Rule 11-12-Req-1).UnknownIndiaDPDP
DPDP.6.4Technical erasure workflows SHALL exist for Exchange, SharePoint, and Teams data (Rule 12(3)).UnknownIndiaDPDP
DPDP.6.5Right to Data Portability SHALL support structured CSV/JSON data exports (Rule 11-12-Req-4).UnknownIndiaDPDP
DPDP.6.6Grievance redressal ticketing SLA channels SHALL be monitored and accessible (Rule 13(1)).UnknownIndiaDPDP
DPDP.6.7Nominee access assignment settings SHALL be enabled for post-death/incapacity rights (Rule 14(1)).UnknownIndiaDPDP
DPDP.7.1M365 Multi-Geo Data Residency SHALL be configured with India primary region (Rule 16-XB-3).UnknownIndiaDPDP
DPDP.7.2Cross-border data transfers to notified prohibited countries SHALL be blocked (Rule 16(1)).UnknownIndiaDPDP
DPDP.7.3External Teams communication with unmanaged users SHALL be restricted (Rule 16-XB-2).UnknownIndiaDPDP
DPDP.8.1Unified Audit Logging (UAL) SHALL be enabled with minimum 180+ days retention (Rule 8(5)-Sec-5).UnknownIndiaDPDP
DPDP.8.2Real-time alert notifications SHALL trigger upon suspicious mass downloads or exfiltration (Rule 6(1)).UnknownIndiaDPDP
DPDP.8.3Outbound exfiltration and spam filter policies SHALL be configured (Rule 6(2)).UnknownIndiaDPDP
DPDP.8.4Hosted connection filter and IP access rules SHALL be documented (Rule 6(2)).UnknownIndiaDPDP
DPDP.9.1DPO role assignment and India residency designation SHALL be documented in Entra ID (Rule 10(2)(a)).UnknownIndiaDPDP
DPDP.9.2Microsoft Purview Compliance Manager DPDP 2023 assessment template SHALL be active (Rule 10(2)(c)).UnknownIndiaDPDP
DPDP.Sec.04.1Ensure Admin Consent Workflow is enabled to prevent unconsented 3rd-party access to personal dataUnknownGeneral
DPDP.Sec.04.2Ensure user consent to third-party applications is disallowed to enforce consent unbundlingUnknownGeneral
DPDP.Sec.04.3Ensure user-owned and unregistered third-party application access is restrictedUnknownGeneral
DPDP.Sec.05.1Ensure tenant creation and self-service authorization are restricted to authorized administratorsUnknownGeneral
DPDP.Sec.06.4Ensure external guest user directory permissions are strictly restrictedUnknownGeneral
DPDP.Sec.06.5Ensure guest users are dynamically categorized for automated lifecycle governanceUnknownGeneral
DPDP.Sec.08.1Ensure Global Administrator accounts are restricted to 4 or fewer to minimize breach surfaceUnknownGeneral
DPDP.Sec.08.2Ensure weak and legacy authentication protocols are disabled across the tenantUnknownGeneral
DPDP.Sec.08.3Ensure dedicated emergency break-glass cloud administrator accounts existUnknownGeneral
DPDP.Sec.08.4Ensure passwords are not configured to expire unnecessarily, mitigating weak password cyclingUnknownGeneral
DPDP.Sec.08.5Ensure Customer Lockbox is enabled for administrative approvals on support escalationsUnknownGeneral
DPDP.Sec.08.6Ensure no unapproved public Microsoft 365 Groups expose sensitive organizational conversationsUnknownGeneral
DPDP.Sec.08.7Ensure SharePoint default sharing link is not set to anonymous AnyoneUnknownGeneral
DPDP.Sec.08.8Ensure default sharing link permissions are restricted to View OnlyUnknownGeneral
DPDP.Sec.08.9Ensure guest access expiration is configured for SharePoint Online document librariesUnknownGeneral
DPDP.Sec.08.10Ensure external guests cannot share unowned SharePoint documentsUnknownGeneral
DPDP.Sec.08.11Ensure downloading malicious files is blocked in SharePoint OnlineUnknownGeneral
DPDP.Sec.08.12Ensure Entra B2B collaboration integration restricts unvetted cross-tenant sharingUnknownGeneral
DPDP.Sec.08.13Ensure Teams communication with unmanaged external users is restrictedUnknownGeneral
DPDP.Sec.08.14Ensure Teams meeting lobby prevents unauthorized participants from bypassing verificationUnknownGeneral
DPDP.Sec.08.15Ensure third-party storage services are restricted across Microsoft 365UnknownGeneral
DPDP.Sec.08.16Ensure third-party file sharing in Teams is restrictedUnknownGeneral
DPDP.Sec.08.17Ensure Zero-Hour Auto Purge (ZAP) for phishing and malware is enabled in Exchange OnlineUnknownGeneral
DPDP.Sec.08.18Ensure Safe Links protection is active to prevent credential-harvesting phishingUnknownGeneral
DPDP.Sec.08.19Ensure Safe Attachments ATP policy is active to block zero-day malicious payloadsUnknownGeneral
DPDP.Sec.08.20Ensure Anti-Phishing protection policies are enabled for internal data principalsUnknownGeneral
DPDP.Sec.08.21Ensure DKIM signing is enabled on all custom mail domains to prevent spoofingUnknownGeneral
DPDP.Sec.08.22Ensure Outbound Spam policies block automatic external email forwardingUnknownGeneral
DPDP.Sec.08.23Ensure direct interactive sign-in on shared mailboxes is blockedUnknownGeneral
DPDP.Sec.08.24Ensure Unified Audit Logging is enabled for statutory personal data breach readinessUnknownGeneral
DPDP.Sec.08.25Ensure internal malware and threat notifications are configured for security personnelUnknownGeneral
DPDP.Sec.08.26Ensure Exchange connection filter safe-lists are not configured with 0.0.0.0 bypassesUnknownGeneral