A Practical DPDP Implementation Roadmap, Rule by Rule
Most DPDP plans start with the privacy policy because it is the easiest thing to change. That is the wrong end. Almost every obligation in the Rules depends on knowing where your personal data actually is.
Start with the inventory, not the policy
Rewriting the privacy policy is the most common first move and one of the least useful. A notice under Rule 3 has to describe the personal data you process and the purpose you process it for. You cannot write that accurately without knowing what you hold.
Three separate obligations collapse without an inventory. Rule 8 requires erasure once the specified purpose is no longer served, which needs a retention clock per data set. Rule 14 requires a working process for Data Principal rights requests, which means finding one person's data across systems. Rule 7 requires describing the extent of a breach within seventy-two hours, which is impossible if nobody knows what was in the affected system.
Phase one: know what you hold
- Inventory every system holding personal data, including the ones outside engineering — support tools, spreadsheets, marketing platforms, analytics.
- For each data set, record the purpose it was collected for, the lawful basis, who can access it, where it is stored, and how long it is kept.
- Identify what came from Data Processors acting on your behalf, since Rule 6(1)(f) requires contractual provisions binding them to safeguards.
- Flag children's data specifically. Section 9 obligations and Rule 10 verifiable parental consent are separate, stricter, and carry a ₹200 crore head.
Phase two: Rule 6 security controls
Rule 6 is a list rather than a principle, which makes the gap assessment concrete. At minimum it requires:
- Encryption, obfuscation, masking or virtual tokens protecting the personal data.
- Access control on the computer resources used by you or your Data Processor.
- Logs, monitoring and review giving visibility on access to personal data, to enable detection, investigation and prevention of recurrence.
- Backups sufficient for continued processing if confidentiality, integrity or availability is compromised.
- Retention of those logs and the personal data for one year, unless another law requires otherwise.
- Contractual provisions requiring reasonable security safeguards from Data Processors.
- Technical and organisational measures ensuring the safeguards are actually observed.
The one year log retention is the item most often missed in budgeting, because it is a storage cost that scales with traffic and has to be provisioned before it is needed, not after.
Phase three: the processes that run on demand
These are the obligations that only reveal whether they work when someone exercises them.
- Rule 7 breach response. A defined trigger for becoming aware, a named responder with contact details ready to publish, templates for both the Data Principal intimation and the two Board intimations, and a path to request an extension in writing.
- Rule 14 rights requests. A route for a Data Principal to make a request and a process that can find, correct or erase her data across every system in the inventory.
- Rule 8 erasure. Retention enforced in code rather than stated in a policy. The Third Schedule sets a three year clock for specified classes, including e-commerce entities and social media intermediaries with not less than two crore registered users, and online gaming intermediaries with not less than fifty lakh.
Phase four: notices, consent and governance
Only now is the notice worth writing, because you finally know what it has to describe. Rule 3 requires the notice to be presented and understandable independently of any other information the Data Fiduciary has made or may make available, which most privacy policies fail because they rely on incorporation by reference.
If you expect to be notified as a Significant Data Fiduciary, Rule 13 adds a Data Protection Impact Assessment and an audit once every twelve months, with significant observations reported to the Board, plus due diligence on algorithmic software and restrictions on transferring specified personal data outside India.
Every phase above except the last is engineering work. That is the honest reason eighteen months is not as long as it sounds, and why a plan that begins in 2027 begins too late.
Infosek Team
The sequence in one line
Inventory, then controls, then the processes that run on demand, then the documents that describe all three. Doing it in the reverse order produces a compliant-looking privacy policy attached to systems that cannot honour it.
Common questions
What should a company do first for DPDP compliance?
Map where personal data is held. Rule 8 requires erasure against a retention clock, Rule 14 requires answering Data Principal rights requests, and Rule 7 requires describing the extent of a breach. None of those is possible without a current inventory of what personal data exists and where.
How long does DPDP implementation take?
The government allowed eighteen months between publication of the Rules on 14 November 2025 and the commencement of Rules 3 and 5 to 16 on 14 May 2027. The work is largely engineering change to live systems rather than documentation, so the runway is the estimate.
Want this sequenced against your systems?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment