
What is the DPDP Act 2023? Complete Guide for Indian Companies
15 min read

Quick Answer: Making your business DPDP compliant follows a clear sequence: assign an owner first, map your data second, fix consent and privacy notices third, lock down vendor contracts fourth, build security and breach readiness fifth, then train your team and launch. Most small and mid-size Indian businesses can complete this roadmap in 90 days if they follow the phases in order, instead of jumping around.
Many businesses already have a DPDP checklist. What they don't have is a sequence — a clear answer to "what do we do first, who owns it, and by when." That is what a roadmap gives you. This guide lays out a practical, phase-by-phase plan you can actually follow, week by week.
A checklist tells you every task you need to complete. But most businesses that struggle with DPDP compliance don't struggle because they don't know what to do — they struggle because they start five tasks at once, in the wrong order, with no one clearly responsible for finishing any of them.
A roadmap solves this by grouping tasks into phases, giving each phase a timeframe, and naming an owner for each one. This turns a vague legal obligation into a project your team can actually execute — the same way you would plan a product launch or a system migration.
| Phase | Timeframe | Focus | Typical Owner |
|---|---|---|---|
| Phase 1 | Days 1–15 | Assess & assign ownership | Founder / CEO |
| Phase 2 | Days 16–30 | Map your data | IT / Operations lead |
| Phase 3 | Days 31–45 | Fix consent & privacy notices | Marketing + Legal |
| Phase 4 | Days 46–60 | Lock down vendor contracts | Operations / Procurement |
| Phase 5 | Days 61–75 | Security & breach readiness | IT / Security lead |
| Phase 6 | Days 76–90 | Train, test, and launch | Grievance Officer / DPO |
| Ongoing | Every quarter | Monitor & review | Grievance Officer / DPO |
The sections below walk through each phase in detail.
Direct answer: The first step in any DPDP roadmap is naming one person who owns the project and running a quick gap assessment — before touching any actual compliance task.
Start by appointing a Grievance Officer (or a Data Protection Officer, if your business qualifies as a Significant Data Fiduciary). This person does not need to be a lawyer — they need authority to get other departments to act, and enough time to actually run the project. Our guide to appointing a DPO under DPDP explains how to pick the right person and what the role actually requires.
Next, run a short gap assessment: where does your business currently stand against DPDP's core requirements? A one-page honest answer here saves weeks later, because it tells you which phases below need more time and which ones are mostly already in place.
By day 15, you should have: a named owner, leadership sign-off on the 90-day plan, and a one-page gap assessment.
Direct answer: Data mapping means listing every place personal data enters your business, where it moves after that, and who touches it — this document becomes the foundation for every phase that follows.
This is the phase most businesses want to skip, and the one that causes the most rework later if they do. You cannot write an accurate privacy notice, fix your consent flows, or know which vendors need contracts until you know exactly what data you collect and where it goes.
Walk through every data entry point: signup forms, checkout pages, support tickets, marketing tools, HR systems. For each one, record what data is collected, why, where it's stored, and which third parties (if any) receive it. This becomes your Record of Processing Activities (RoPA). Our full data mapping and RoPA guide gives you a ready template to speed this up.
By day 30, you should have: a completed data map covering every system that touches personal data, and a list of every vendor that receives that data.
Direct answer: With your data map complete, rebuild your consent flows so they are specific and easy to understand, and rewrite your privacy notice in plain language reflecting exactly what you documented in Phase 2.
This is why data mapping comes first — you cannot honestly describe your data practices in a privacy notice until you know what they actually are. Review every place you currently collect consent (signup forms, cookie banners, newsletter opt-ins) and rebuild anything that uses pre-ticked boxes, bundled consent, or vague language. Our consent management implementation guide shows how to do this without hurting your conversion rates.
At the same time, rewrite your privacy notice so an average customer — not a lawyer — can understand what you collect, why, and how long you keep it.
By day 45, you should have: redesigned consent flows across every collection point, and a plain-language privacy notice published and live.
Direct answer: Using the vendor list from Phase 2, sign a Data Processor Agreement (DPA) with every third party that touches your customers' personal data, from cloud hosts to marketing platforms.
This phase depends directly on Phase 2's data map — you cannot contract with vendors you haven't identified. Go through your vendor list and prioritize by data sensitivity: payment processors and cloud hosts first, smaller marketing tools later. Our processor agreements (DPA) guide includes a practical checklist for what each agreement needs to cover.
By day 60, you should have: signed or in-progress DPAs with every vendor handling meaningful volumes of personal data.
Direct answer: Put proportional security safeguards in place — encryption for sensitive data and access controls limiting who can view personal data — and write a breach notification plan before you need one.
Security doesn't need to mean expensive enterprise tools. It means matching protection to risk: encrypting the most sensitive fields, restricting database access to staff who genuinely need it, and removing old access nobody uses anymore.
At the same time, write down exactly what happens if a breach occurs: who gets notified first, how affected users are informed, and when the Data Protection Board needs to be told. Our breach notification playbook gives you a ready-to-adapt response plan — do this now, not during an actual crisis.
By day 75, you should have: documented security safeguards in place and a tested breach response plan.
Direct answer: Train every employee who handles personal data on the basics, run an internal review of everything built in Phases 1 through 5, and formally launch your compliance program.
Most real-world data mishandling comes from human error, not sophisticated attacks — a support agent emailing the wrong attachment, a marketer exporting a customer list carelessly. A short, practical training session for anyone touching customer data closes this gap.
Before calling the roadmap complete, do an internal walk-through: test your consent flow as a real user would, confirm your privacy notice matches your actual data map, and confirm your breach response plan has clear owners for each step.
By day 90, you should have: a trained team, a tested compliance program, and a documented go-live date.
DPDP compliance is not a project with a finish line — it needs a quarterly owner check-in. New vendors, new products, and new marketing tools all change your data footprint. Set a recurring quarterly review where your Grievance Officer or DPO checks whether the data map, consent flows, and vendor list still reflect reality.
Ownership looks different depending on your company size:
Whatever the size, the same rule holds: one clearly named owner per phase, reporting progress to one overall roadmap owner.
| Business Size | Realistic Timeline |
|---|---|
| Small business (under 50 employees, simple data flows) | 60–90 days |
| Mid-size business (multiple systems, several vendors) | 90–150 days |
| Large business / Significant Data Fiduciary | 4–9 months, often longer with audits |
The 90-day version in this guide assumes a small to mid-size business with a reasonably motivated team. Larger organizations should treat each phase above as a workstream, not a fixed two-week sprint — the sequence stays the same, but each step takes longer.
The first step is naming one person to own the compliance project and running a short gap assessment of where your business currently stands. Skipping this step is the most common reason DPDP projects stall, because no task gets finished without someone clearly responsible for it. This should happen before any other compliance task begins, ideally within the first two weeks.
Most small to mid-size Indian businesses can complete a working DPDP compliance roadmap in about 90 days, following six clear phases in sequence. Larger businesses or Significant Data Fiduciaries, with more systems and vendors to cover, typically need 4 to 9 months. The timeline depends less on company size and more on how many systems and vendors touch personal data.
The correct order is: assign an owner, map your data, fix consent and privacy notices, sign vendor agreements, build security and breach readiness, then train your team and launch. Each phase depends on the one before it — for example, you cannot write an accurate privacy notice before completing your data map. Following this sequence avoids the most common cause of rework in DPDP projects.
In a small business, the founder or a senior operations leader typically owns DPDP compliance directly, often as a part-time responsibility alongside their existing role. This person does not need to be a lawyer, but does need the authority to get other team members to complete their assigned tasks. As the business grows, this role often becomes a dedicated Grievance Officer or Data Protection Officer.
Data mapping must come first because you cannot accurately describe your data practices in a privacy notice until you know exactly what data you collect and where it goes. Businesses that skip this step often publish a privacy notice that doesn't match reality, then have to rewrite it once proper data mapping is eventually done. Doing it in the correct order avoids this duplicated work entirely.
Businesses that miss compliance deadlines face financial penalties that scale with the severity of the violation, up to ₹250 crore for serious cases involving sensitive personal data. Beyond fines, non-compliance risks losing B2B contracts and customer trust, since more businesses now ask about data protection practices before signing agreements. Starting the roadmap early avoids the compressed, high-risk timeline of trying to comply right before enforcement.
In a very small business, one person can lead the roadmap, but they will still need input from whoever manages your website, marketing tools, and vendor contracts. For mid-size and larger businesses, a single owner should coordinate the roadmap while department heads own their specific phases, such as marketing owning consent flows. Trying to execute every phase single-handedly in a larger organization usually slows the roadmap down significantly.
Your business needs a full-time, India-based Data Protection Officer if it qualifies as a Significant Data Fiduciary, a classification based on the volume and sensitivity of personal data you process. Smaller businesses can typically start with a part-time Grievance Officer and reassess as their data volume grows. If you are unsure which category applies, a quick data-volume and sensitivity review is the fastest way to check.
A complete DPDP roadmap document should include clear phases with timeframes, a named owner for each phase, specific deliverables to mark each phase complete, and a recurring review schedule after launch. It should read like a project plan, not a legal memo, so that non-legal team members can follow and execute it. Without these elements, a roadmap tends to function as a to-do list rather than something a team can actually track progress against.
Yes — any new vendor that will process personal data on your behalf needs its own Data Processor Agreement before it goes live, not added retroactively after the fact. This is exactly why the quarterly review phase exists in the roadmap, to catch new tools before they become a compliance gap. Treating vendor agreements as a one-time task is one of the most common ways roadmaps quietly go out of date.
A 90-day roadmap is realistic for most small to mid-size businesses with straightforward data flows and a small number of vendors and systems. Businesses with complex, multi-system data flows, international operations, or Significant Data Fiduciary status usually need a longer timeline, often 4 to 9 months. The phase sequence stays identical either way — only the time allotted to each phase changes.
A checklist lists every task that needs to be done, but doesn't specify the order, ownership, or deadlines, which is often why checklists stall inside real companies. A roadmap adds sequence, a named owner per phase, and a realistic timeframe, turning the same tasks into an executable project. For the full list of individual compliance tasks referenced throughout this roadmap, see our complete DPDP implementation guide.
DPDP compliance fails less often because businesses don't know what to do, and more often because tasks happen in the wrong order with no one clearly responsible for finishing them. This roadmap fixes both problems: six phases, each with a clear owner and a realistic deadline, moving from data mapping to consent to vendor contracts to security to training, in an order that avoids rework. Follow it in sequence, and 90 days is enough for most small and mid-size Indian businesses to get there.
Cor Advance Solutions helps Indian businesses build and execute practical DPDP roadmaps like this one — from the initial gap assessment through to ongoing quarterly reviews. Start with our free DPDP compliance assessment or get in touch to build a roadmap for your specific business.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. DPDP Rules and enforcement timelines are subject to government notification and may change. Consult a qualified data protection professional or lawyer for guidance specific to your business.
Let's discuss how these insights apply to your specific challenges.
Get in Touch