Module 8 of 9 · 8 min read
The 90-day plan — what to do first
A sequenced programme for a mid-size Indian organisation, by function.
Guiding principle
You cannot serve rights, notify breaches or answer the Board without a data inventory keyed by purpose. Everything else is downstream of it. Spend the first 30 days there.
Days 1–30 — Discover and decide
Governance
- Board resolution: accountable executive, budget, reporting cadence.
- Decide whether you are likely to be notified an SDF; if yes, plan for a DPO and independent auditor now.
Inventory
- Interview each function (Product, HR, Sales/Marketing, Finance, IT, Customer Support). For every process: data elements, purpose, source, storage, sharing (internal, Processors, third parties, abroad), retention.
- Tag children's data and employee data explicitly.
Quick wins
- Kill pre-ticked boxes and bundled consents in live forms.
- Publish a grievance channel (email + form) and start the log.
Days 31–60 — Design
Legal / Privacy
- Purpose taxonomy; notice templates per purpose; language list (English + Scheduled languages you serve).
- Decide which employment purposes rely on "legitimate use" vs consent.
- Processor contract addendum: safeguards, breach notification "immediately", sub-processor flow-down, erasure on instruction, audit rights.
Engineering
- Consent ledger schema; withdrawal event; erasure fan-out; access-report generator.
- Map the six Rules safeguards to existing ISO 27001 / sectoral controls; close the gaps (most common: 1-year log retention, masking in non-production).
Security / IR
- Add DPDPA + CERT-In clocks to the IR runbook; draft notification templates; rehearse once.
HR
- Employee privacy notice; interns under 18 flagged; background-check vendors as Processors.
Days 61–90 — Implement and evidence
- Ship the new notices and consent flows on the top-3 customer journeys.
- Serve the notice to legacy consented data (batch email/SMS with withdrawal link).
- Run a table-top breach exercise; time yourself against 72 hours and 6 hours.
- Produce the evidence pack: inventory, purpose taxonomy, notices, consent ledger extract, Processor addenda signed, safeguards mapping, grievance log, IR test report.
- If SDF-likely: engage the independent auditor and schedule the first DPIA.
Metrics the board should see quarterly
| Metric | Target |
|---|---|
| Processes inventoried with purpose + retention | 100% |
| Live forms with compliant notice/consent | 100% of customer-facing |
| Rights requests closed within SLA | ≥ 95% |
| Processors with signed DPDPA addendum | 100% of those handling personal data |
| Breach drill — time to Board intimation draft | < 24 h |
| Personal data in non-production masked | 100% |