DPDP Compliance by Sector: BFSI, Fintech, Healthcare, E-commerce, SaaS
One Act. Seven industries. Seven playbooks.
Nine things every Indian business gets wrong
Patterns we see in 9 out of 10 readiness assessments — regardless of industry, size, or how far along a team thinks it is.
Treating it like 'just a privacy policy update'
DPDP requires real operational change — consent infrastructure, DSAR fulfilment, breach response, vendor flow-down. A polished notice without the engineering behind it creates more risk, not less.
Waiting for 'final rules' before starting
The Rules are notified. Phase 3 substantive obligations crystallise on 13 May 2027. Substantive work takes 9–12 months. The clock has been running for months already.
Underestimating vendor remediation
You're liable under Section 8(2) for processor failures. Updating DPAs across 30–100+ vendors is the single longest-pole activity in most programmes. Start it now.
Confusing lawful basis with consent
Section 7 gives seven legitimate uses that don't require consent. Many teams seek consent for data they were always entitled to process, creating brittle, over-consented architectures that collapse when consent is withdrawn.
Building consent capture but not withdrawal
Section 6(4) requires withdrawing consent to be exactly as easy as giving it. Most organisations bury the withdrawal link three menus deep. That asymmetry alone is an enforcement trigger — regulators check it first.
Ignoring children's data until it's a crisis
If any part of your platform can be accessed by a user under 18, Section 9 applies. Age-verification and verifiable parental consent are among the most demanding obligations, and the ban on behavioural tracking of children is absolute.
No breach response runbook before a breach
The 72-hour DPBI window under Rule 7 starts at detection, not at complete information. Organisations that start drafting their process after discovering a breach are already in breach of the notification obligation.
Mapping data flows once — then never again
A RoPA completed in Q1 is obsolete by Q3. New features, vendors, acquisitions and pivots all create new flows. Treat data mapping as a continuous discipline, not a one-time project.
Leaving DPDP as a legal team problem
The highest-penalty obligations — security (₹250 Cr), breach notification (₹200 Cr), children (₹200 Cr) — are owned by Engineering, Security and Product, not Legal. Legal-only programmes run out of mandate exactly when they need engineering.
Pick your sector playbook.
Expand a sector to see its overlapping frameworks and the friction points specific to it.
Want the playbook tailored to your stack?
We map DPDP obligations onto your sector, systems and vendors.