Are You Ready for DPDP Compliance?
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) is changing the way organisations collect, use, store and protect personal data.
But the real question is not:
“Have you updated your Privacy Policy?”
The real question is:
Can your organisation prove that personal data is being handled responsibly?
Most businesses today hold far more personal data than they realise—customer names, PAN, Aadhaar details, bank information, employee records, emails, mobile numbers, financial information, CCTV footage, payroll data, website leads and documents stored across laptops, cloud applications, WhatsApp and shared drives.
This is where DPDP compliance begins.
DPDP is not just a legal policy exercise
Many organisations may think compliance means preparing:
- a privacy policy,
- a consent form, and
- a few legal documents.
That is only the beginning.
True compliance requires organisations to answer some basic questions:
What personal data do we hold?
Why do we need it?
Where is it stored?
Who has access to it?
Which vendors receive it?
How long do we retain it?
How do we delete it?
What happens if it is leaked?
If these questions cannot be answered with evidence, the organisation may still have significant privacy risk.
What should organisations start doing?
The first step should be data discovery and mapping.
Identify personal data across departments, systems, employees, vendors and cloud platforms.
Then build controls around:
Data Inventory → Purpose Mapping → Notice & Consent → Access Control → Vendor Management → Retention → Security → Breach Management → Evidence
Organisations should also establish a clear process for handling Data Principal rights, such as correction, updating, erasure and grievance redressal.
Cybersecurity is now directly connected with privacy
A beautifully drafted privacy policy will not help if:
- employees share passwords,
- client documents are stored on personal devices,
- laptops are unencrypted,
- backups are unavailable,
- public AI tools receive confidential information, or
- sensitive information is emailed to the wrong recipient.
Privacy therefore cannot remain only with the legal or compliance department.
It requires participation from:
Management + IT + Information Security + HR + Legal + Process Owners + Internal Audit
The most important question
DPDP compliance should not be approached as:
“What is the last date for compliance?”
Instead, management should ask:
“If a customer asks us today what personal data we hold about them, can we identify it?”
And:
“If a data breach happens tomorrow, are we ready to respond?”
If the answer is uncertain, your DPDP journey should begin now.
DPDP compliance is not about creating more paperwork.
It is about creating trust, accountability and evidence that personal data is being handled responsibly.
Is your organisation ready?
— CA Ratan Singh Tanwar
Information Systems Audit | Cybersecurity | Digital Forensics | Data Privacy & DPDP Governance