ErasureDocs
DPDP

Operational checklist

Practical readiness for DPDP-shaped privacy ops, not a certification.

Operational checklist

Use this as an engineering/ops checklist before treating Erasure as production-ready for consent and erasure workflows. Completing it does not mean you are "DPDP compliant."

  • Purposes and notice reviewed with whoever owns legal copy
  • Configuration published (not left in draft)
  • Publishable key created; raw key stored securely by you
  • Allowed origins listed for production hosts
  • SDK live on real surfaces; sample receipts present
  • Optional: project webhook verified (X-Accord-Signature)
  • Optional: withdraw path tested for optional purposes

Mapping & Systems

  • Systems connected for every store that must participate in erasure
  • Health checks HEALTHY (or known DEGRADED with a plan)
  • Data Maps: DELETE entities + identifiers for SQL/document modules
  • Dry-run / preview used where available
  • Secrets rotated only via product rotate paths

Rights

  • Worker process running
  • Operational Readiness not blocked
  • Test case completed end-to-end (operator path)
  • Public intake OTP path tested if subjects will use it
  • Evidence exported for a completed (or failed) case

Security & ops

  • Owner/Admin/Viewer roles assigned intentionally
  • Production mailer configured for OTP (and password reset if used)
  • Backups for Postgres owned by your provider/process
  • Network egress for worker limited to intended systems