Skip to main content
DPDP Implementation Roadmap: 9-Month Plan to May 2027 — page loaded
The phased plan

DPDP Implementation Roadmap: 9 Months to Phase 3 Enforcement

Your runway, mapped, sequenced, built.

11Workstreams
From data discovery to grievance design.
8Role Playbooks
Accountability maps for every function.
90Day Plan
Quick-start sequence for the first three months.
5Maturity Levels
From initial to optimised — know where you stand.
The phased plan

The 9-month DPDP runway, sequenced.

Phase 1Active now
14 Nov 2025 — Now

Procedural provisions in force. DPBI established. The window to prepare.

Phase 2Upcoming
~14 Nov 2026

Consent Manager registration and obligations come into force.

Phase 3Enforcement
13 May 2027

All substantive obligations enforceable. Penalties live.

Workstream library

Eleven build-outs that cover everything.

4–8 weeksFoundational

Data Discovery & Mapping

Build a RoPA covering every system, data category, purpose, recipient and retention rule.

Phase 1
6–10 weeksHigh effort

Notice & Consent Re-engineering

Redesign notices to be standalone, itemised, plain-language and translated; rebuild consent for granularity and easy withdrawal.

Phase 2
3–5 weeksFoundational

Lawful Basis Classification

For every activity, decide between consent and a Section 7 legitimate use. Document the basis; build change-control to keep it accurate.

Phase 1
8–16 weeks₹250 Cr risk

Reasonable Security Safeguards

Build the seven Rule 6 safeguards: encryption, access control, backups, 1-year logging, detection, processor contracts and TOMs.

Phase 1
4–6 weeksHigh priority

Breach Response Playbook

Design the runbook for the first 72 hours: detection, classification, containment, DPBI intimation, Principal notification and post-mortem.

Phase 2
4–8 weeksSDF-only

DPIA Methodology

Build the framework, templates and governance for annual Data Protection Impact Assessments — mandatory for SDFs, recommended for all.

Phase 2
6–10 weeksHigh effort

Vendor & Processor Governance

Renegotiate every processor contract for DPDP clauses. Build a vendor inventory, risk-tier it, instrument continuous monitoring.

Phase 1
4–6 weeks₹200 Cr risk

Children's Data Flows

Map every under-18 flow. Build verifiable parental consent (DigiLocker). Audit for prohibited tracking, monitoring or targeted ads.

Phase 2
3–5 weeksPer region

Cross-Border Transfer Assessment

Inventory cross-border flows. Map each destination to risk. Build readiness for sectoral localisation (RBI, IRDAI overlays).

Phase 2
2–4 weeksSDF mandatory

DPO Appointment & Operating Model

Define the DPO charter, board reporting line, India-based requirement, and operating model for grievances, breaches and audit liaison.

Phase 1
2–4 weeksFoundational

Grievance Redressal Mechanism

Stand up a published grievance channel with a named officer and the 90-day SLA, integrated with your DSAR and breach workflows.

Phase 1
Role playbooks

Every function gets a clear plan.

DPDP fails when accountability is fuzzy. Each playbook tells one role what they own, their top three priorities this quarter, and how to measure progress.

CEO & Board

Tone from the top. Risk appetite. Resourcing decisions. Quarterly DPDP exposure review.

  1. 01Designate accountable executive
  2. 02Approve budget & timeline
  3. 03Quarterly metrics review

General Counsel / CCO

Owns the legal framework. Policies. Notice and consent design. Vendor contracts. DPBI liaison.

  1. 01Privacy policy framework
  2. 02Master DPA template
  3. 03Lawful basis register

CISO / Head of Security

Owns Rule 6 safeguards. The ₹250 Cr exposure sits here. Breach response. Log retention.

  1. 01Rule 6 gap closure
  2. 0272-hour breach runbook
  3. 031-year log retention

Data Protection Officer

Mandatory if SDF. Reports to board. Single point of contact for grievances and DPBI.

  1. 01Annual DPIA programme
  2. 02Independent audit liaison
  3. 03Grievance oversight

Head of Engineering

Owns the build. Consent infra. DSAR platform. Erasure pipelines. Privacy-by-design in SDLC.

  1. 01DSAR fulfilment system
  2. 02Consent management infra
  3. 03Erasure automation

Head of Marketing

Owns consent capture in customer journeys. Martech audit. Suppression lists. No targeted ads to children.

  1. 01Audit all consent points
  2. 02Withdraw flow parity
  3. 03Children-targeting controls

Head of HR

Owns employee data flows. Section 7(i) legitimate-use scope. Background checks. Workforce training.

  1. 01Employee data RoPA
  2. 02Notice in joining kit
  3. 03Annual workforce training

Head of Procurement

Owns vendor onboarding. Risk tiering. DPA enforcement. Sub-processor inventory. Continuous due diligence.

  1. 01Vendor inventory & tier
  2. 02Mandatory DPA template
  3. 03Annual vendor reviews
Maturity model

Know exactly where you stand — and what's next.

L1

Initial

Ad-hoc and reactive. No owner, no inventory. Compliance happens — if at all — in response to incidents.

L2

Developing

Foundations forming. A named owner and first artefacts exist, but coverage is partial and inconsistent.

L3

Defined

Documented processes across the core workstreams. Notice, consent, security and breach response are operational.

L4

Managed

Quantitative metrics across the programme. Predictable outcomes. Embedded in product and engineering workflows.

L5

Optimised

Privacy is a competitive moat. Real-time metrics, continuous improvement, sector-leading practices and external recognition.

90-Day quick start

If you do nothing else for 90 days, do this.

Days 1–30

Build the foundation

  • Designate an accountable executive and stand up a working group
  • Kick off data discovery and a first-pass RoPA
  • Inventory processors and start the DPA gap list
Days 31–60

Make decisions, draft artefacts

  • Classify lawful basis for each processing activity
  • Draft the DPDP-compliant privacy notice and consent UX
  • Close the highest-risk Rule 6 security gaps
Days 61–90

Operationalise the basics

  • Stand up DSAR intake and a grievance channel
  • Finalise the 72-hour breach runbook and run a tabletop
  • Publish the notice and begin vendor DPA remediation

Don't plan in isolation.

Get a roadmap tailored to your organisation in 20 minutes.