Infosek
INFOSEK

A Practical DPDP Implementation Roadmap, Rule by Rule

Most DPDP plans start with the privacy policy because it is the easiest thing to change. That is the wrong end. Almost every obligation in the Rules depends on knowing where your personal data actually is.

A Practical DPDP Implementation Roadmap, Rule by Rule

Start with the inventory, not the policy

Rewriting the privacy policy is the most common first move and one of the least useful. A notice under Rule 3 has to describe the personal data you process and the purpose you process it for. You cannot write that accurately without knowing what you hold.

Three separate obligations collapse without an inventory. Rule 8 requires erasure once the specified purpose is no longer served, which needs a retention clock per data set. Rule 14 requires a working process for Data Principal rights requests, which means finding one person's data across systems. Rule 7 requires describing the extent of a breach within seventy-two hours, which is impossible if nobody knows what was in the affected system.

Phase one: know what you hold

Phase two: Rule 6 security controls

Rule 6 is a list rather than a principle, which makes the gap assessment concrete. At minimum it requires:

The one year log retention is the item most often missed in budgeting, because it is a storage cost that scales with traffic and has to be provisioned before it is needed, not after.

Phase three: the processes that run on demand

These are the obligations that only reveal whether they work when someone exercises them.

Phase four: notices, consent and governance

Only now is the notice worth writing, because you finally know what it has to describe. Rule 3 requires the notice to be presented and understandable independently of any other information the Data Fiduciary has made or may make available, which most privacy policies fail because they rely on incorporation by reference.

If you expect to be notified as a Significant Data Fiduciary, Rule 13 adds a Data Protection Impact Assessment and an audit once every twelve months, with significant observations reported to the Board, plus due diligence on algorithmic software and restrictions on transferring specified personal data outside India.

Every phase above except the last is engineering work. That is the honest reason eighteen months is not as long as it sounds, and why a plan that begins in 2027 begins too late.

Infosek Team

The sequence in one line

Inventory, then controls, then the processes that run on demand, then the documents that describe all three. Doing it in the reverse order produces a compliant-looking privacy policy attached to systems that cannot honour it.

Common questions

What should a company do first for DPDP compliance?

Map where personal data is held. Rule 8 requires erasure against a retention clock, Rule 14 requires answering Data Principal rights requests, and Rule 7 requires describing the extent of a breach. None of those is possible without a current inventory of what personal data exists and where.

How long does DPDP implementation take?

The government allowed eighteen months between publication of the Rules on 14 November 2025 and the commencement of Rules 3 and 5 to 16 on 14 May 2027. The work is largely engineering change to live systems rather than documentation, so the runway is the estimate.

Want this sequenced against your systems?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment