Skip to main content

Open resource, CC BY 4.0

DPDP compliance timeline

What the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.

The table itself

This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.

Showing 15 of 15 rows

PhaseWorkBlocked byStart when
1. Start nowData discovery across every system, including analytics copies and exportsNothingImmediately
1. Start nowRecord of processing activities built from what systems actually doDiscoveryAs discovery completes per system
1. Start nowAppoint an accountable owner for DPDPNothingImmediately
1. Start nowVendor and processor inventory with current contract termsNothingImmediately
2. DesignRetention schedule tied to stated purposesRecord of processingOnce the record is broadly complete
2. DesignConsent model, including how consent is evidenced after the factRecord of processingOnce purposes are known
2. DesignNotice content in plain language, per collection pointConsent modelAfter the consent model is agreed
2. DesignRights handling process and grievance routeRecord of processingIn parallel with the consent model
3. BuildConsent capture and withdrawal built into productsConsent modelOnce design is signed off
3. BuildDeletion that reaches analytics copies and backupsRetention scheduleOnce retention is agreed
3. BuildRights request tooling and the response clockRights processOnce the process is agreed
3. BuildProcessor contract addenda issued to vendorsVendor inventoryOnce the inventory is complete
4. OperateBreach detection and notification runbook, rehearsedRights and consent in placeBefore the transition period ends
4. OperateRe-consent for data already held, where the basis is unclearConsent capture builtAfter build
5. If notified as SDFDPIA process, independent audit and a Data Protection OfficerNotification by the Central GovernmentOn notification, not before

Sequenced so nothing waits unnecessarily. The first phase is unblocked today regardless of where the Rules land.

Where the facts come from

Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.

  • Digital Personal Data Protection Act 2023
  • Draft Digital Personal Data Protection Rules as published for consultation

What people use it for

Sequencing a DPDP programme so you are not sitting idle waiting for rules that do not block the work in front of you.

Licence

Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.

Why sequencing matters more than completeness

Nobody implements the DPDP Act in one pass. The question that determines whether a programme succeeds is not what to do but what to do first, and the intuitive order is close to the worst one.

The intuitive order is to write a privacy policy, then build consent, then worry about data. The order that reduces risk fastest is inventory, retention, consent, rights, evidence, with breach notification pulled out and done immediately.

The reason is dependency. You cannot honour erasure against data you have not mapped, you cannot set retention on data you cannot find, and you cannot scope a consent change without knowing what you collect.

What each phase actually involves

Inventory is a discovery exercise across systems, not a questionnaire. The map is almost never complete on the first pass: the analytics warehouse, a CRM export on a shared drive, a vendor's copy, a backup that restores deleted records. Expect it to take longer than planned and to be the most valuable thing you do.

Retention is engineering work: deciding a period per category, and then actually deleting. It is the largest single reduction in exposure available to most organisations and it costs engineering time rather than licence spend.

Consent is a product change with a lead time. Free, specific, informed, unconditional and unambiguous, given by clear affirmative action, withdrawable as easily as given, and propagating to processors. Start it early even though it finishes late.

Rights are workflows with clocks. Volume is usually low at first, so a manual process is defensible while you build something better.

Evidence accumulates rather than being built, which is why it is last and continuous rather than a phase.

The two things that are not sequenced

Breach notification, which is done immediately regardless of where you are on everything else. It is one page and a named decision maker, and the cost of not having it is unbounded. Remember it is separate from the six hour CERT-In duty and triggered differently.

Processor contracts, which should start early because they depend on other organisations' legal teams and therefore have the longest external lead time of anything on the list. Beginning them in month eight is how a programme slips.

Realistic durations

For a mid sized organisation with a moderately complex estate, inventory is typically six to ten weeks, retention six to twelve depending on how much engineering time is available, consent three to six months as a product change, rights four to eight weeks for a workable manual process.

Those overlap. The total is not the sum, and a programme run sequentially will take twice as long as one where consent design starts while inventory is still running.

If your timeline is shorter than this, the honest move is to reduce scope rather than compress phases. Getting inventory, retention and breach notification genuinely right is worth more than getting all five partly done.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.