-
01 · Data mapping
Inventory every processing activity across product, engineering, HR, marketing, support, finance and third-party tools. For each one record what personal data is collected, the purpose, the basis relied on, where it is stored, who it is shared with and how long it is kept. Include the systems nobody owns: the spreadsheet on someone’s drive, the analytics tool marketing signed up for, the support inbox. Then determine your role per activity — Data Fiduciary, Data Processor, or both — because the obligations attach differently to each, and doing this once at company level is the most common and most expensive shortcut in a DPDP programme.
-
02 · Notice and consent
Rewrite notices so they are clear, in plain language, and state what is collected, for what purpose, and how the individual exercises their rights or complains. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action — no pre-ticked boxes, no consent bundled into terms of service. Build withdrawal so that it is as easy as giving consent was, and make sure withdrawal actually stops the processing downstream rather than only setting a flag. Keep consent records that show what was consented to and when, because a consent you cannot evidence is a consent you do not have.
-
03 · Data-principal rights
Publish a mechanism for access, correction and erasure, grievance redressal, and nomination — the right to name another individual to exercise your rights if you die or become incapacitated, which has no equivalent in any framework you have already implemented. Then test it: run a real access request, then a correction, then an erasure, end to end through your own systems, and record how long each took and what broke. A rights process that has only ever been described in a policy will fail the first time a real person uses it, and the first real person may well be a complainant.
-
04 · Breach detection and reporting
The obligation has two clocks. Notify the Data Protection Board and every affected data principal without delay, then file a detailed report with the Board within 72 hours. Work backwards from that: you cannot report inside 72 hours if your logging, alerting and escalation would not tell you inside 72 hours, which makes most of this an engineering task rather than a legal one. Write the playbook — who decides it is a breach, who notifies, what goes to the Board, what goes to individuals — then rehearse it as a tabletop at least once. Failure to notify carries its own maximum penalty of ₹200 crore, separate from any penalty for the failure that caused the breach.
-
05 · Retention and erasure
Set retention periods per processing activity rather than one policy for the whole organisation, and tie each period to the purpose that justifies it. Erase personal data when consent is withdrawn or the purpose is served, unless a law requires you to keep it — and be able to show that erasure happened in backups, logs, analytics and anywhere the data was copied, not only in the primary database. Where the Rules require advance notice to the data principal before deletion, build that notification rather than assuming it will be handled by whoever runs the deletion job.
-
06 · Children’s data
The Indian threshold is 18, not 16 and not 13, so a consent flow designed for GDPR is under-scoped here by several years of users. Establish whether you process the data of anyone under 18 — including through a product that does not target children but does not prevent them either. Where you do, implement verifiable parental or guardian consent, and stop tracking, behavioural monitoring and targeted advertising directed at children. Notified exemptions exist for defined purposes such as healthcare and education; confirm you are actually inside one before relying on it.
-
07 · Processors and contracts
Every vendor that processes personal data on your behalf must do so under a valid contract, and paperwork signed before November 2025 almost certainly does not contain what the Act now requires. Work through the vendor list from the data map, not from the procurement system, because the two do not match. Update the terms to bind processors to security obligations and to breach cooperation on a timeline that lets you meet your own 72-hour deadline — a processor who tells you about an incident on day four has made your compliance failure for you.
-
08 · Security safeguards
This is the limb the largest penalty is attached to: up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach. Encryption in transit and at rest, access control and review, logging and monitoring that would actually surface an incident, patching that happens, and backups that have been restored at least once. If you hold an ISO 27001 certificate this is where it does most of its work for you — but the safeguards are judged against the data you hold and the harm a breach would cause, not against the scope statement of your ISMS.
-
09 · Significant Data Fiduciary duties
Designation is a government decision based on the volume and sensitivity of the personal data processed and the risk it carries — you cannot volunteer for it and you cannot rule it out yourself. Assess whether your volumes put it within reach, and if they do, plan for four additional duties: a Data Protection Officer based in India, an annual Data Protection Impact Assessment, an independent data audit, and algorithmic due diligence over the systems that process personal data. The point of doing this early is that designation should not arrive with a build programme attached.