Where should we start with DPDP compliance?

Start with discovery. Every other obligation under the DPDP Act is defined against the personal data you actually hold, so an inventory that regenerates rather than a one-off spreadsheet is the prerequisite for making any later step defensible. Only once you know what you hold can you state purposes, record lawful bases, publish accurate notices and answer rights requests completely.

Priya Gupta

The second step is the purpose and lawful-basis register, before any consent interface is designed. Consent screens built on an unexamined model encode the wrong assumptions and have to be rebuilt.

Third is the ability to answer people and incidents in time — a monitored intake for rights requests and grievances, and a defined breach path. Both are time-bound, which is what makes manual handling risky.

Fourth is governance: determine and record whether you are a Significant Data Fiduciary, because that decides whether the DPO, DPIA and audit obligations apply.

General information about the DPDP Act, not legal advice. Obligations depend on your circumstances.

Priya GuptaPriya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.

Where do you stand under DPDP?

Take the free readiness check and find out in 10 minutes.

Start free readiness check →