How to get ready for DPDP enforcement in 90 days
You have 90 days. Here is the most efficient path to DPDP readiness — prioritised by risk, not by exhaustive compliance perfection.
Days 1–20: Conduct your data inventory
Start with a sprint data inventory: run structured interviews with the owners of your top 5–10 data-processing systems (CRM, HRMS, payment, marketing, analytics). Document: what personal data each system holds, the purpose, who has access, and who it is shared with. You will not build a perfect data inventory in 20 days — but you will understand your data risk landscape well enough to prioritise the rest of the sprint. Use a simple spreadsheet template. Assign a project owner and track completion daily.
Days 15–30: Rewrite your privacy notice
Using the data inventory as source material, rewrite your privacy notice to accurately reflect what you actually collect and process. A DPDP-compliant notice: names the specific purposes for each data category; identifies Data Processors by name or category; gives the retention period for each category; and provides a mechanism for individuals to exercise their rights. Publish the updated notice on your website and link it from every data collection point (sign-up forms, checkout, app onboarding). This is the highest-visibility compliance action — customers and regulators can both see it.
Days 20–45: Audit and fix your consent flows
Walk through every point where you collect personal data — registration, checkout, contact forms, email marketing sign-up, app onboarding. Test each: is there a pre-checked box? Is the consent purpose specific? Is there an easy way to withdraw? Is the withdrawal working (does it stop processing)? Fix the broken ones: remove pre-checked boxes; add specific purpose descriptions; add an opt-out mechanism; and ensure withdrawal signals propagate to your marketing tools. Focus first on the highest-traffic collection points.
Days 30–60: Execute your vendor DPA programme
From your data inventory, list every vendor that processes personal data on your behalf. Check which have existing DPAs. For vendors without DPAs, prioritise by risk: first, vendors with access to sensitive personal data (health, financial, biometric); second, vendors with large-volume access; third, vendors with cross-border data transfers. Send DPAs to the top 5–10 vendors immediately. For lower-risk vendors, schedule outreach over the next 30 days. Track DPA execution in a register.
Days 45–75: Build your breach response plan
Draft a one-page breach response runbook: who is in the response team; what triggers a breach response; what the 6-hour CERT-In notification and the DPDP Board notification timelines are; who drafts each notification; and how you notify affected individuals. Test it: run a tabletop exercise where a hypothetical breach (ransomware attack, employee data leak) is presented to your team and you work through the response. Document the exercise and identify gaps. Update the runbook based on what you learned.
Days 60–90: Train your employees and build your rights mechanism
Deliver a 60-minute DPDP awareness session to all employees — cover what personal data is, the key rights under the Act, how to recognise a data request, and how to report a breach. Set up a data rights mechanism: an email address or web form where individuals can submit access, correction, and erasure requests, with a designated responder. Test the mechanism: submit a test request and verify that it is routed, handled, and closed within the target timeline. Document the training completion and the rights mechanism as evidence of compliance.
Frequently asked questions
Is 90 days enough to achieve full DPDP compliance?
90 days is enough to achieve baseline readiness in the highest-risk areas — consent, privacy notice, vendor DPAs, breach response, and training. Full compliance — covering every system, every vendor, every policy, SDF readiness if applicable — is typically a 12–18 month programme. The 90-day sprint gets you to a position where you can demonstrate good-faith effort and have the highest-risk gaps addressed. The remainder is a rolling improvement programme.
What should we do after the 90-day sprint?
After the sprint: continue the vendor DPA programme to cover all remaining vendors; build a formal data retention schedule and implement automated deletion; conduct a full DPDP readiness assessment to identify remaining gaps; establish a quarterly privacy review cycle; and assign ongoing compliance responsibility to a designated privacy owner (internal or external). The 90-day sprint builds the foundation; the quarterly review cycle maintains and improves it.
What is the biggest mistake companies make in DPDP preparation?
The biggest mistake is waiting for the final Rules before starting. Many organisations are holding back compliance programmes pending the government's notification of DPDP Rules — a reasonable precaution for some rule-dependent items, but not for foundational work. A data inventory, consent audit, vendor DPAs, and breach response plan are valuable regardless of how the Rules are finalised. Start now — the 90-day sprint can be run in parallel with Rules monitoring, and you adjust when the Rules are notified.
Start your 90-day DPDP sprint with Niti Bharat
Niti Bharat's DPDP Readiness Assessment is the structured starting point for your 90-day sprint — gap analysis, risk scoring, and a prioritised remediation roadmap in 2 weeks.
Start Your DPDP Sprint