Open resource, CC BY 4.0
DPDP compliance timeline
What the DPDP Act asks for, in the order you have to do it, with the dependencies that decide what you can start today.
The table itself
This is the artifact, not a preview of it. Search across every column, filter it down, print what you filtered. Nothing is sent anywhere and there is no email step.
Showing 15 of 15 rows
| Phase | Work | Blocked by | Start when |
|---|---|---|---|
| 1. Start now | Data discovery across every system, including analytics copies and exports | Nothing | Immediately |
| 1. Start now | Record of processing activities built from what systems actually do | Discovery | As discovery completes per system |
| 1. Start now | Appoint an accountable owner for DPDP | Nothing | Immediately |
| 1. Start now | Vendor and processor inventory with current contract terms | Nothing | Immediately |
| 2. Design | Retention schedule tied to stated purposes | Record of processing | Once the record is broadly complete |
| 2. Design | Consent model, including how consent is evidenced after the fact | Record of processing | Once purposes are known |
| 2. Design | Notice content in plain language, per collection point | Consent model | After the consent model is agreed |
| 2. Design | Rights handling process and grievance route | Record of processing | In parallel with the consent model |
| 3. Build | Consent capture and withdrawal built into products | Consent model | Once design is signed off |
| 3. Build | Deletion that reaches analytics copies and backups | Retention schedule | Once retention is agreed |
| 3. Build | Rights request tooling and the response clock | Rights process | Once the process is agreed |
| 3. Build | Processor contract addenda issued to vendors | Vendor inventory | Once the inventory is complete |
| 4. Operate | Breach detection and notification runbook, rehearsed | Rights and consent in place | Before the transition period ends |
| 4. Operate | Re-consent for data already held, where the basis is unclear | Consent capture built | After build |
| 5. If notified as SDF | DPIA process, independent audit and a Data Protection Officer | Notification by the Central Government | On notification, not before |
Sequenced so nothing waits unnecessarily. The first phase is unblocked today regardless of where the Rules land.
Where the facts come from
Nothing here is our opinion dressed up as a rule. Every line traces back to a published source, cited so you can check it.
- Digital Personal Data Protection Act 2023
- Draft Digital Personal Data Protection Rules as published for consultation
What people use it for
Sequencing a DPDP programme so you are not sitting idle waiting for rules that do not block the work in front of you.
Licence
Published under Creative Commons Attribution 4.0. Copy it, cut it about, put it in your own audit pack, sell the work you do with it. Credit Threatsys and you are within the licence. There is no email gate and there never will be.
More open resources
- India compliance registryEvery cyber security obligation an Indian organisation can be held to, in one table, with the regulator and the trigger against each.Open it
- CERT-In directions readiness checklistThe April 2022 directions turned into checks you can actually run, including the log retention and clock sync duties people miss.Open it
- India incident reporting mapOne incident can trigger four different reporting duties on four different clocks. This shows you all of them on one page.Open it
Why sequencing matters more than completeness
Nobody implements the DPDP Act in one pass. The question that determines whether a programme succeeds is not what to do but what to do first, and the intuitive order is close to the worst one.
The intuitive order is to write a privacy policy, then build consent, then worry about data. The order that reduces risk fastest is inventory, retention, consent, rights, evidence, with breach notification pulled out and done immediately.
The reason is dependency. You cannot honour erasure against data you have not mapped, you cannot set retention on data you cannot find, and you cannot scope a consent change without knowing what you collect.
What each phase actually involves
Inventory is a discovery exercise across systems, not a questionnaire. The map is almost never complete on the first pass: the analytics warehouse, a CRM export on a shared drive, a vendor's copy, a backup that restores deleted records. Expect it to take longer than planned and to be the most valuable thing you do.
Retention is engineering work: deciding a period per category, and then actually deleting. It is the largest single reduction in exposure available to most organisations and it costs engineering time rather than licence spend.
Consent is a product change with a lead time. Free, specific, informed, unconditional and unambiguous, given by clear affirmative action, withdrawable as easily as given, and propagating to processors. Start it early even though it finishes late.
Rights are workflows with clocks. Volume is usually low at first, so a manual process is defensible while you build something better.
Evidence accumulates rather than being built, which is why it is last and continuous rather than a phase.
The two things that are not sequenced
Breach notification, which is done immediately regardless of where you are on everything else. It is one page and a named decision maker, and the cost of not having it is unbounded. Remember it is separate from the six hour CERT-In duty and triggered differently.
Processor contracts, which should start early because they depend on other organisations' legal teams and therefore have the longest external lead time of anything on the list. Beginning them in month eight is how a programme slips.
Realistic durations
For a mid sized organisation with a moderately complex estate, inventory is typically six to ten weeks, retention six to twelve depending on how much engineering time is available, consent three to six months as a product change, rights four to eight weeks for a workable manual process.
Those overlap. The total is not the sum, and a programme run sequentially will take twice as long as one where consent design starts while inventory is still running.
If your timeline is shorter than this, the honest move is to reduce scope rather than compress phases. Getting inventory, retention and breach notification genuinely right is worth more than getting all five partly done.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












