What does DPDP add to a legal team's workload?
Legal leaders: DPDP is now your compliance mandate. Here's the legal checklist.
DPDP policy framework and legal documents
Develop or update company privacy policies (external for customers, internal for employees), data-retention schedules (itemised by data type and purpose), and data-processing impact assessments for high-risk projects. Legal must ensure DPAs with all processors are in place and include DPDP breach-notification clauses. A policy template is good; audit the entire company against it quarterly.
Data Processing Agreements and vendor contracts
Every third-party vendor that accesses company or customer data must be a party to a DPA. DPDP requires that you have explicit vendor agreements covering scope, security, sub-processors and breach notification. For SaaS contracts, many vendors now include DPA addenda; review them carefully. For processors that resist DPA, escalate to business: their compliance risk is your compliance risk.
Board notification and regulatory response
Develop a procedure for breach notification to the Data Protection Board within 72 hours. This includes a documentation template, approval signoff (usually General Counsel or Chief Privacy Officer + CEO), and a timeline that allows drafting within 24 hours of breach discovery. Legal should also prepare templates for regulatory inquiries and adverse Board notices.
Frequently asked questions
What should a DPA cover?
Scope (what data, what processing), security requirements (encryption, access controls), breach notification timelines (24-48 hours to you), sub-processor controls (approval required for new subs), rights support (DSAR, deletion), and audit rights.
How do I audit vendor compliance?
Annual questionnaire covering data handling, security controls, breach history, insurance. For critical processors (payment, cloud), add annual audits (SOC2 Type II, penetration test). Document the audit and follow up on gaps.
What should a breach-notification procedure look like?
Discovery → containment (CTO role) → assessment (does data risk privacy?) → Board notification (legal drafts 24-48h) → individual notifications (business role) → regulatory response. Legal should own the Board and regulatory response.
Build your legal DPDP playbook
Run the DPDP for Legal guide to develop privacy policies, DPA templates and breach-notification procedures.
DPDP for Legal Teams