DPDP Act Enforcement Begins: Your 90-Day Compliance Playbook

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 have established the framework. What matters now is the enforcement timeline. The Data Protection Board of India is operational, and the phased enforcement approach means different obligations kick in at different dates. For large organizations classified as Significant Data Fiduciaries, the expectations are higher and the timelines shorter. If your organization processes personal data of Indian citizens at scale — through customer databases, employee records, marketing activities, or service delivery — you are a data fiduciary under the Act. The question is not whether you need to comply but how quickly you can operationalize compliance. The common mistake we observe is organizations treating DPDP as a legal compliance exercise handled entirely by the legal team. DPDP has operational, technical, and organizational dimensions that require coordination across IT, security, marketing, HR, product development, and customer service. A legal-only approach will produce policies without processes and consent language without consent management systems.

Days 1-30: Data Discovery and Mapping
Your first thirty days should focus entirely on understanding what personal data you hold, where it lives, how it flows, and who has access. This is not a theoretical exercise — it requires technical data discovery across your databases, file systems, cloud storage, SaaS applications, email systems, and physical records. Start with your customer-facing systems — CRM, customer portals, payment systems, support ticketing, and marketing platforms. These typically hold the highest volume of personal data. Map each data element to its purpose — why are you collecting it, what legal basis supports that collection, and how long do you retain it. Then move to employee data — HR systems, payroll, benefits administration, and internal collaboration tools. Employee data is often overlooked in privacy programs, but the DPDP Act applies equally to employee personal data as it does to customer data. Document your data flows, including transfers to third parties, cross-border transfers, and data shared between group companies. Create a data inventory that captures the data element, the system it resides in, the purpose of processing, the legal basis, the retention period, and any third parties it is shared with. This inventory becomes the foundation for every subsequent compliance activity.

Days 31-60: Consent and Rights Management
With your data map complete, address the two most visible DPDP obligations — consent management and data principal rights. DPDP requires that consent be free, specific, informed, unconditional, and unambiguous. Review every touchpoint where your organization collects personal data and evaluate whether the consent mechanism meets these criteria. This includes website forms, mobile app permissions, customer onboarding flows, marketing opt-ins, and cookie consent banners. For each touchpoint, ensure that the consent request is presented in clear, plain language. The DPDP Act requires that consent notices be available in English and all 22 scheduled languages. While you may not need all languages immediately, your consent infrastructure must be designed to support multilingual notices. Implement a consent management platform that records when consent was given, what it was given for, and provides mechanisms for withdrawal. Consent withdrawal must be as easy as giving consent — this is an explicit requirement under the Act. For data principal rights — access, correction, erasure, and nomination — build internal workflows that can receive, authenticate, process, and respond to rights requests within the prescribed timeframes. This requires coordination between your customer service team, IT department, and legal team. Test these workflows with simulated requests before enforcement begins.

Days 61-90: Security Controls and Governance
The DPDP Act requires data fiduciaries to implement reasonable security safeguards to protect personal data. While the Act does not prescribe specific technical controls, the expectation is that security measures are proportionate to the risk. For organizations already compliant with PCI DSS, ISO 27001, or similar frameworks, your existing security controls likely satisfy this requirement — but you need to document the mapping explicitly. Implement data protection impact assessments for high-risk processing activities. The DPDP Rules require Significant Data Fiduciaries to conduct DPIAs, but all organizations benefit from assessing the privacy impact of new products, services, or processing activities before launch. Appoint your Data Protection Officer if you have not already done so. Significant Data Fiduciaries are required to designate a DPO who is based in India, but even non-SDF organizations should designate a privacy lead with clear responsibilities. Establish your breach notification process. The DPDP Act requires that personal data breaches be reported to the Data Protection Board and affected data principals. Your incident response plan must include privacy-specific procedures for assessing whether a breach involves personal data and triggering notification within the required timeline. Finally, train your organization. Every employee who handles personal data needs to understand the basic obligations under DPDP — what constitutes personal data, how to handle access requests, and when to escalate potential breaches.

Sustaining Compliance Beyond the First 90 Days
The 90-day playbook gets you to a baseline compliance posture. Sustaining compliance requires ongoing operational discipline. Schedule quarterly reviews of your data inventory to capture new data sources, changed processing activities, and updated retention schedules. Conduct annual privacy impact assessments for material changes to your data processing. Monitor your consent management platform for opt-out trends and respond to patterns that might indicate consent fatigue or poor user experience. Review your vendor agreements to ensure data processing agreements are in place with every third party that processes personal data on your behalf. The DPDP Act makes data fiduciaries responsible for their processors' compliance. Build privacy metrics into your organizational reporting — consent rates, rights request volumes and response times, breach incident trends, and training completion rates. These metrics serve dual purposes — they demonstrate compliance to the Data Protection Board and they provide your leadership team with visibility into the privacy program's health. The organizations that will navigate DPDP enforcement successfully are those that treated it as a business process transformation, not a checkbox exercise. Privacy is becoming a differentiator in the Indian market just as it did in Europe following GDPR enforcement.

Q: When does DPDP Act enforcement begin in India?
A: The DPDP Act has a phased enforcement timeline. Different obligations become enforceable at different dates as specified in the DPDP Rules, 2025. Monitor the Data Protection Board of India for specific compliance deadlines.

Q: What are the penalties for non-compliance with the DPDP Act?
A: Penalties range up to Rs 250 crore per instance depending on the nature and severity of the violation. Penalties apply to breaches of consent requirements, data principal rights violations, and failure to implement reasonable security safeguards.

Q: Do we need a Data Protection Officer under DPDP?
A: Significant Data Fiduciaries are required to appoint a DPO based in India. Even if you are not classified as an SDF, designating a privacy lead is strongly recommended.

QRC provides DPDP compliance assessments and implementation support. Contact us to build your data protection program.

LinkedIn Youtube

We use cookies to enhance your user experience. By continuing to browse, you hereby agree to the use of cookies. Know more Privacy Policy & Cookies Policy.

X