DPDPA 2023 — From Awareness to Compliance
Module 8 of 9 · 8 min read

The 90-day plan — what to do first

A sequenced programme for a mid-size Indian organisation, by function.

Guiding principle

You cannot serve rights, notify breaches or answer the Board without a data inventory keyed by purpose. Everything else is downstream of it. Spend the first 30 days there.

Days 1–30 — Discover and decide

Governance

  • Board resolution: accountable executive, budget, reporting cadence.
  • Decide whether you are likely to be notified an SDF; if yes, plan for a DPO and independent auditor now.

Inventory

  • Interview each function (Product, HR, Sales/Marketing, Finance, IT, Customer Support). For every process: data elements, purpose, source, storage, sharing (internal, Processors, third parties, abroad), retention.
  • Tag children's data and employee data explicitly.

Quick wins

  • Kill pre-ticked boxes and bundled consents in live forms.
  • Publish a grievance channel (email + form) and start the log.

Days 31–60 — Design

Legal / Privacy

  • Purpose taxonomy; notice templates per purpose; language list (English + Scheduled languages you serve).
  • Decide which employment purposes rely on "legitimate use" vs consent.
  • Processor contract addendum: safeguards, breach notification "immediately", sub-processor flow-down, erasure on instruction, audit rights.

Engineering

  • Consent ledger schema; withdrawal event; erasure fan-out; access-report generator.
  • Map the six Rules safeguards to existing ISO 27001 / sectoral controls; close the gaps (most common: 1-year log retention, masking in non-production).

Security / IR

  • Add DPDPA + CERT-In clocks to the IR runbook; draft notification templates; rehearse once.

HR

  • Employee privacy notice; interns under 18 flagged; background-check vendors as Processors.

Days 61–90 — Implement and evidence

  • Ship the new notices and consent flows on the top-3 customer journeys.
  • Serve the notice to legacy consented data (batch email/SMS with withdrawal link).
  • Run a table-top breach exercise; time yourself against 72 hours and 6 hours.
  • Produce the evidence pack: inventory, purpose taxonomy, notices, consent ledger extract, Processor addenda signed, safeguards mapping, grievance log, IR test report.
  • If SDF-likely: engage the independent auditor and schedule the first DPIA.

Metrics the board should see quarterly

MetricTarget
Processes inventoried with purpose + retention100%
Live forms with compliant notice/consent100% of customer-facing
Rights requests closed within SLA≥ 95%
Processors with signed DPDPA addendum100% of those handling personal data
Breach drill — time to Board intimation draft< 24 h
Personal data in non-production masked100%