Are you processing digital personal data covered by the DPDP Act?
If you are not sure, applicability comes first. It decides whether any obligation applies at all, and stops you buying controls you may not need.
The right starting point depends on what you do not yet know. If you are unsure whether the Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you, start with applicability. If you know it applies but not how exposed you are, start with a readiness assessment. If the real question is whether to appoint a Data Protection Officer, start with that decision, not with buying tools or drafting policies.
Decision-support first. Specialist introductions only when requested.
Pick the statement closest to where you are. Each route takes you to the next useful step, not to a sales page.
Determine scope and obligations before buying anything.
Check applicability →ReadinessGet a structured picture of controls, gaps and priorities.
Start readiness assessment →DPO decisionDetermine whether appointment is required, voluntary or unnecessary.
Make the DPO decision →ImplementationUnderstand the programme and implementation support required.
Explore services →ToolsUse decision tools, checklists and implementation resources.
Browse resources →Operating modelEvaluate internal, fractional, consulting and software-led models.
Compare options →Most DPDP programmes move through the same six stages. Knowing which stage you are on tells you where to start.
Confirm whether the DPDP Act applies and which obligations to investigate.
→Assess existing controls and find the gaps that matter most.
→Decide the operating model: internal, fractional, consultant or software-led.
→Close prioritised gaps in data mapping, notices, rights handling and vendors.
→Produce records that show the controls actually operate.
→Keep the programme current as data, systems and rules change.
→If you are not sure, applicability comes first. It decides whether any obligation applies at all, and stops you buying controls you may not need.
Without a data map you cannot scope consent, honour data-principal rights, or evidence most controls. Discovery usually comes before tooling.
Readiness is judged on evidence, not intentions. If you cannot show controls working, your first move is remediation, not more policies.
Follow the questions top to bottom. This is guidance to orient you, not a legal determination.
The most common early mistakes waste budget and delay real readiness.
You cannot configure consent for data flows you have not mapped. Discovery comes before tooling.
Under the DPDP Act the mandatory DPO obligation follows Significant Data Fiduciary designation, not headcount.
A published notice is one output. On its own it evidences almost nothing about how your controls actually operate.
Policies written before a gap assessment usually describe controls you do not yet operate, which is worse than having none.
A sensible way to sequence the start. This is an illustrative starting sequence, not a statutory schedule.
Confirm applicability and name an accountable owner for privacy.
Map what personal data you hold, why, and where it flows.
Rank gaps by risk and regulatory exposure, not by ease.
Turn the priorities into a sequenced implementation plan.
Start with your biggest unknown. If you are unsure the DPDP Act applies, confirm applicability first. If it clearly applies, run a readiness (gap) assessment before buying tools or drafting policies; it tells you what to fix and in what order.
No. Under the DPDP Act, a mandatory Data Protection Officer applies to organisations designated as Significant Data Fiduciaries. Many companies instead appoint a voluntary privacy owner or an accountable point of contact. Headcount alone does not trigger the requirement.
Usually yes, once applicability is clear. A structured gap assessment turns “we should do privacy” into a prioritised list of what you actually lack, and prevents spending on tools or policies that do not address your real exposure.
Often partly. Security and legal cover important pieces, but DPDP readiness also needs data mapping, records of processing, data-principal request handling and evidence that controls operate. Whether your team can own all of that depends on bandwidth and experience, not job titles.
For a mid-sized company a focused readiness assessment typically runs a few weeks, depending on how many systems and data flows are in scope and how quickly stakeholders respond. The output is a prioritised gap list and a roadmap.
You get a prioritised set of gaps and a sequenced roadmap. From there you decide what to fix internally, where you need specialist help, and whether ongoing privacy ownership such as a fractional DPO makes sense. Where specialist delivery is required, we can introduce independent partners.
Last reviewed: August 2026. This page is decision-support, not legal advice. Confirm current obligations against official notifications before acting.
Take the free readiness assessment for a prioritised picture, or talk it through with an advisor first.