38 Weeks to DPDP Compliance: Evidence, Not Checklists

Authored by Devansh Awasthi, 3rd Year law student pursuing B.A., LL.B. (Hons.) at Dr Ram Manohar Lohiya National Law University, Lucknow.
DPDP Compliance in 38 Weeks

India has started implementing its new data protection regime with the introduction of the Digital Personal Data Protection Act, 2023 (DPDP Act) and the notification of the Digital Personal Data Protection Rules, 2025 (DPDP Rules). Rule 4 regarding consent managers will become effective one year after the release of the Rules. Most other substantive obligations will begin in 18 months on May 13, 2027. As of August 21, 2026, there are fewer than 38 weeks left.

As a result, companies are breaking down the remaining weeks into activities such as identifying personal data, revising privacy policies, setting up consent mechanisms, and mapping out processes for responding to breaches. While this approach may be beneficial, there tends to be a focus on compliance based on the number of completed activities without having an understanding of whether the controls are effective.

Nonetheless, this approach is not advisable within the DPDP regime. The law does not state which activities should be completed in isolation. Instead, it establishes certain interdependencies among obligations, meaning that compliance with one obligation would depend on the completion of a few other obligations.

The Framework Is Based on Evidence, Not Documentation

As laid out in subsection 6(10) of the DPDP Act, in a scenario where processing is performed based on consent, and the matter is contested in a court of law, the Data Fiduciary will be tasked with providing evidence of proper notification and consent before a judge. Similarly, other duties such as those relating to security, erasure of data, complaint management and the duty of the processor will require a confirmation of the functionality of the respective systems rather than just having the policy on paper.

While the checklist can demonstrate that a privacy notification has been developed or that a processor agreement has been executed, it will be inadequate in proving the actual representation of the data flow in the organisation, that the requests for withdrawal have been conveyed, and that breach notifications were sent to manufacturers/ vendors.

It is plain to see that the above obligations are interconnected. It is impossible to prepare an accurate notification without a data map. Instructions concerning withdrawal will be rendered ineffective if such instructions are not transmitted to the relevant processors. The obligation regarding breach notifications could not occur until the breach is known and communicated to the Data Fiduciary.

The Data Map as an obligation, not a chore

A lot of companies commence the process of preparing the privacy notification, but there is usually a lack of accuracy in the context of the DPDP.

According to Rule 3, the notification must describe the personal data being processed (including the purpose of processing, and how to withdraw one’s consent) as mandatory parameters. The Data Fiduciary has to know its data ecosystem properly before it provides this information accurately.

Thus, the first step for the organisation is to take full account of the personal data it has in its possession.

The company should find out what type of information it has, where the information comes from, for what purpose it can be used, who can access it, who the service providers are which will be the receiving end, for how long the period of the data will be processed by them, and whether there has been any transfer of data outside India. It should also comprise all the systems that are related to customers along with the use of employee information, such as databases dealing with recruitment, customer service calls with all their records, backups, and archives.

Additionally, mapping the existing data is compulsory to make sure that the rights of all data principals are protected. A data fiduciary cannot change or delete any data information that he does not know how to access.

Consent in the process

According to the DPDP Act, consent is not required for all processing actions. Section 7 states that the DPDP Act has made exceptions for a few cases of processing without requiring consent, such as when an employment relation is prevailing.

However, before taking necessary steps for gaining consent, identifying the appropriate bases of law for processing needs to be considered. Consent can be cancelled as stipulated in Section 6(4) of the Act, which states that withdrawal of consent should be made as easy as granting consent. Also, according to Section 6(6), the Data Fiduciary is expected to cease processing of the data.

Should consent be the legitimate basis for processing, it must be provided voluntarily and not under duress. As soon as the provisions become effective, the obligation imposed by Section 5(2) becomes effective since it concerns the processing of personal data only based on consent given before that.

The instructions contained in Rule 6 require the Data Fiduciary to have adequate security measures in place (access control measures, data monitoring, back-ups, and so forth).

Rule 7 presents a two-level notification process in case of a data breach.

However, while it is a legal obligation, it can only take place when there is a breach that needs to be reported. In most cases, the compliance of the data fiduciary depends on the speed of the cloud service provider or payment processor to notify the Data Fiduciary of the incident. It is necessary that all agreements with processors clearly state provisions for incident reporting timelines, logging data retention periods, forensic data access, and investigatory support. Mock scenarios must also be conducted to validate whether legal and technical teams, as well as communication and management teams, can operate effectively in a breach incident.

Two-Way Removal

As per the provisions of Section 8(7), Data Fiduciaries must ensure the removal of personal data. This applies in cases where the consent has been removed from the individual or in situations when the use of the data is no longer valid, although the law may require retention of the data.

According to various laws provided in the rules as well as in the Third Schedule, several classes of large e-commerce companies as well as online gaming intermediaries and social media intermediaries are required to follow a three-year deletion schedule; however, certain data categories must remain in the processing logs for at least a year as required by the law.

Noncompliance can occur in two major areas. An inadequate deletion would lead to a violation of the erasure obligations. On the other hand, excessive deletion may lead to destruction of information that is required to be retained as per the law. Hence, it is essential to have a retention policy in place.

Unique Processing Considerations

Children’s data cannot be processed in the same manner as other types of data. Section 9 maintains that verifiable parental consent must be obtained whenever a child’s data is considered for processing, in addition to preventing tracking, behavioural monitoring, and targeted advertising of children.

Employee information also requires separate assessment. Section 7 acknowledges that certain employers would be able to use employee information; however, it in no way means that the employer has been absolved of the need to ensure data protection. Therefore, biometric data collection systems and workplace surveillance mechanisms must also be separately analysed.

Section 10 has mandatory rules on compliance auditors.

Transitioning From Paperwork to Evidence

Starting 13th May 2027, organisations would be required to create effective documentation that would validate the effectiveness of compliance measures. There must also be documentation relating to consent history, notice history, vendor assessments, access logs, deletion history, and breach-response exercises.

Thus, in the coming weeks, organisations need to develop a working document and not just a checklist. Data mapping must be performed before the drafting of notices, and the legal basis of processing must be established prior to seeking consent from the individual, while oversight of vendors must occur before testing breach-response exercises. All of these responsibilities build upon each other, meaning that these forms of evidence cannot just be built at the last minute.

Leave a Reply

Your email address will not be published. Required fields are marked *

GET IN TOUCH

Collaborate with us for Research and Policy Innovation

We welcome collaborations, research partnerships, and inquiries related to cyber law, governance, and digital policy. Whether you are an academic, policymaker, or institution, we’d be delighted to explore how CRGCL can work with you on impactful research and outreach initiatives.

Why Collaborate with CRGCL:
Reach Out to Our Research Team