Start Here

Where should your organisation start with DPDP compliance?

The right starting point depends on what you do not yet know. If you are unsure whether the Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you, start with applicability. If you know it applies but not how exposed you are, start with a readiness assessment. If the real question is whether to appoint a Data Protection Officer, start with that decision, not with buying tools or drafting policies.

Decision-support first. Specialist introductions only when requested.

India · DPDP Act 2023Answer-first, not sales-firstDecision-support, not legal advice
The path most programmes follow

The privacy decision flow

Most DPDP programmes move through the same six stages. Knowing which stage you are on tells you where to start.

  1. Applicability

    Confirm whether the DPDP Act applies and which obligations to investigate.

  2. Readiness

    Assess existing controls and find the gaps that matter most.

  3. Decision

    Decide the operating model: internal, fractional, consultant or software-led.

  4. Implementation

    Close prioritised gaps in data mapping, notices, rights handling and vendors.

  5. Evidence

    Produce records that show the controls actually operate.

  6. Ongoing governance

    Keep the programme current as data, systems and rules change.

Three questions decide your starting point

Answer these before you spend anything

01

Are you processing digital personal data covered by the DPDP Act?

If you are not sure, applicability comes first. It decides whether any obligation applies at all, and stops you buying controls you may not need.

02

Do you know what personal data you hold and where it flows?

Without a data map you cannot scope consent, honour data-principal rights, or evidence most controls. Discovery usually comes before tooling.

03

Can you produce evidence that your privacy controls actually operate?

Readiness is judged on evidence, not intentions. If you cannot show controls working, your first move is remediation, not more policies.

Your likely next step

A quick way to place yourself

Follow the questions top to bottom. This is guidance to orient you, not a legal determination.

  1. Do you know whether you are in scope?
    NoApplicabilityYes ↓ continue
  2. Have you completed a structured gap assessment?
    NoReadiness assessmentYes ↓ continue
  3. Do you have major implementation gaps?
    YesServicesNo ↓ continue
  4. Do you need continuing privacy ownership?
    YesCompare operating modelsNo → maintain internally + use resources
Avoid this

What not to do first

The most common early mistakes waste budget and delay real readiness.

Buy consent software before mapping your processing

You cannot configure consent for data flows you have not mapped. Discovery comes before tooling.

Appoint a DPO purely because of employee count

Under the DPDP Act the mandatory DPO obligation follows Significant Data Fiduciary designation, not headcount.

Treat a privacy policy as a compliance programme

A published notice is one output. On its own it evidences almost nothing about how your controls actually operate.

Commission twenty policies before you know your gaps

Policies written before a gap assessment usually describe controls you do not yet operate, which is worse than having none.

Illustrative first month

Your first 30 days

A sensible way to sequence the start. This is an illustrative starting sequence, not a statutory schedule.

Week 1

Scope & ownership

Confirm applicability and name an accountable owner for privacy.

Week 2

Data & process discovery

Map what personal data you hold, why, and where it flows.

Week 3

Gap prioritisation

Rank gaps by risk and regulatory exposure, not by ease.

Week 4

90-day roadmap

Turn the priorities into a sequenced implementation plan.

FAQ

Common starting-point questions

Where should a company start with DPDP compliance?

Start with your biggest unknown. If you are unsure the DPDP Act applies, confirm applicability first. If it clearly applies, run a readiness (gap) assessment before buying tools or drafting policies; it tells you what to fix and in what order.

Does every Indian company need a DPO?

No. Under the DPDP Act, a mandatory Data Protection Officer applies to organisations designated as Significant Data Fiduciaries. Many companies instead appoint a voluntary privacy owner or an accountable point of contact. Headcount alone does not trigger the requirement.

Should we start with a DPDP gap assessment?

Usually yes, once applicability is clear. A structured gap assessment turns “we should do privacy” into a prioritised list of what you actually lack, and prevents spending on tools or policies that do not address your real exposure.

Can our existing security or legal team manage DPDP?

Often partly. Security and legal cover important pieces, but DPDP readiness also needs data mapping, records of processing, data-principal request handling and evidence that controls operate. Whether your team can own all of that depends on bandwidth and experience, not job titles.

How long does a DPDP readiness assessment take?

For a mid-sized company a focused readiness assessment typically runs a few weeks, depending on how many systems and data flows are in scope and how quickly stakeholders respond. The output is a prioritised gap list and a roadmap.

What happens after the assessment?

You get a prioritised set of gaps and a sequenced roadmap. From there you decide what to fix internally, where you need specialist help, and whether ongoing privacy ownership such as a fractional DPO makes sense. Where specialist delivery is required, we can introduce independent partners.

Sources & scope

  • Digital Personal Data Protection Act, 2023 (Ministry of Electronics and Information Technology / India Code).
  • Digital Personal Data Protection Rules, 2025 (notified 13 November 2025); core duties commence 13 May 2027.
  • DPO obligation applies to organisations designated as Significant Data Fiduciaries under Section 10 of the DPDP Act.

Last reviewed: August 2026. This page is decision-support, not legal advice. Confirm current obligations against official notifications before acting.

Not sure which starting point is yours?

Take the free readiness assessment for a prioritised picture, or talk it through with an advisor first.

Follow DPOIndia in Google SearchAdd as a preferred source on Google