DPDP Implementation Roadmap: 9 Months to Phase 3 Enforcement
Your runway, mapped, sequenced, built.
The 9-month DPDP runway, sequenced.
Procedural provisions in force. DPBI established. The window to prepare.
Consent Manager registration and obligations come into force.
All substantive obligations enforceable. Penalties live.
Eleven build-outs that cover everything.
Data Discovery & Mapping
Build a RoPA covering every system, data category, purpose, recipient and retention rule.
Notice & Consent Re-engineering
Redesign notices to be standalone, itemised, plain-language and translated; rebuild consent for granularity and easy withdrawal.
Lawful Basis Classification
For every activity, decide between consent and a Section 7 legitimate use. Document the basis; build change-control to keep it accurate.
Reasonable Security Safeguards
Build the seven Rule 6 safeguards: encryption, access control, backups, 1-year logging, detection, processor contracts and TOMs.
Breach Response Playbook
Design the runbook for the first 72 hours: detection, classification, containment, DPBI intimation, Principal notification and post-mortem.
DPIA Methodology
Build the framework, templates and governance for annual Data Protection Impact Assessments — mandatory for SDFs, recommended for all.
Vendor & Processor Governance
Renegotiate every processor contract for DPDP clauses. Build a vendor inventory, risk-tier it, instrument continuous monitoring.
Children's Data Flows
Map every under-18 flow. Build verifiable parental consent (DigiLocker). Audit for prohibited tracking, monitoring or targeted ads.
Cross-Border Transfer Assessment
Inventory cross-border flows. Map each destination to risk. Build readiness for sectoral localisation (RBI, IRDAI overlays).
DPO Appointment & Operating Model
Define the DPO charter, board reporting line, India-based requirement, and operating model for grievances, breaches and audit liaison.
Grievance Redressal Mechanism
Stand up a published grievance channel with a named officer and the 90-day SLA, integrated with your DSAR and breach workflows.
Every function gets a clear plan.
DPDP fails when accountability is fuzzy. Each playbook tells one role what they own, their top three priorities this quarter, and how to measure progress.
CEO & Board
Tone from the top. Risk appetite. Resourcing decisions. Quarterly DPDP exposure review.
- 01Designate accountable executive
- 02Approve budget & timeline
- 03Quarterly metrics review
General Counsel / CCO
Owns the legal framework. Policies. Notice and consent design. Vendor contracts. DPBI liaison.
- 01Privacy policy framework
- 02Master DPA template
- 03Lawful basis register
CISO / Head of Security
Owns Rule 6 safeguards. The ₹250 Cr exposure sits here. Breach response. Log retention.
- 01Rule 6 gap closure
- 0272-hour breach runbook
- 031-year log retention
Data Protection Officer
Mandatory if SDF. Reports to board. Single point of contact for grievances and DPBI.
- 01Annual DPIA programme
- 02Independent audit liaison
- 03Grievance oversight
Head of Engineering
Owns the build. Consent infra. DSAR platform. Erasure pipelines. Privacy-by-design in SDLC.
- 01DSAR fulfilment system
- 02Consent management infra
- 03Erasure automation
Head of Marketing
Owns consent capture in customer journeys. Martech audit. Suppression lists. No targeted ads to children.
- 01Audit all consent points
- 02Withdraw flow parity
- 03Children-targeting controls
Head of HR
Owns employee data flows. Section 7(i) legitimate-use scope. Background checks. Workforce training.
- 01Employee data RoPA
- 02Notice in joining kit
- 03Annual workforce training
Head of Procurement
Owns vendor onboarding. Risk tiering. DPA enforcement. Sub-processor inventory. Continuous due diligence.
- 01Vendor inventory & tier
- 02Mandatory DPA template
- 03Annual vendor reviews
Know exactly where you stand — and what's next.
Initial
Ad-hoc and reactive. No owner, no inventory. Compliance happens — if at all — in response to incidents.
Developing
Foundations forming. A named owner and first artefacts exist, but coverage is partial and inconsistent.
Defined
Documented processes across the core workstreams. Notice, consent, security and breach response are operational.
Managed
Quantitative metrics across the programme. Predictable outcomes. Embedded in product and engineering workflows.
Optimised
Privacy is a competitive moat. Real-time metrics, continuous improvement, sector-leading practices and external recognition.
If you do nothing else for 90 days, do this.
Build the foundation
- Designate an accountable executive and stand up a working group
- Kick off data discovery and a first-pass RoPA
- Inventory processors and start the DPA gap list
Make decisions, draft artefacts
- Classify lawful basis for each processing activity
- Draft the DPDP-compliant privacy notice and consent UX
- Close the highest-risk Rule 6 security gaps
Operationalise the basics
- Stand up DSAR intake and a grievance channel
- Finalise the 72-hour breach runbook and run a tabletop
- Publish the notice and begin vendor DPA remediation
Don't plan in isolation.
Get a roadmap tailored to your organisation in 20 minutes.