5 October 2026 · Data Privacy

Are You Ready for DPDP Compliance?

By CA Ratan Singh Tanwar

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) is changing the way organisations collect, use, store and protect personal data.

But the real question is not:

“Have you updated your Privacy Policy?”

The real question is:

Can your organisation prove that personal data is being handled responsibly?

Most businesses today hold far more personal data than they realise—customer names, PAN, Aadhaar details, bank information, employee records, emails, mobile numbers, financial information, CCTV footage, payroll data, website leads and documents stored across laptops, cloud applications, WhatsApp and shared drives.

This is where DPDP compliance begins.

DPDP is not just a legal policy exercise

Many organisations may think compliance means preparing:

That is only the beginning.

True compliance requires organisations to answer some basic questions:

What personal data do we hold?
Why do we need it?
Where is it stored?
Who has access to it?
Which vendors receive it?
How long do we retain it?
How do we delete it?
What happens if it is leaked?

If these questions cannot be answered with evidence, the organisation may still have significant privacy risk.

What should organisations start doing?

The first step should be data discovery and mapping.

Identify personal data across departments, systems, employees, vendors and cloud platforms.

Then build controls around:

Data Inventory → Purpose Mapping → Notice & Consent → Access Control → Vendor Management → Retention → Security → Breach Management → Evidence

Organisations should also establish a clear process for handling Data Principal rights, such as correction, updating, erasure and grievance redressal.

Cybersecurity is now directly connected with privacy

A beautifully drafted privacy policy will not help if:

Privacy therefore cannot remain only with the legal or compliance department.

It requires participation from:

Management + IT + Information Security + HR + Legal + Process Owners + Internal Audit

The most important question

DPDP compliance should not be approached as:

“What is the last date for compliance?”

Instead, management should ask:

“If a customer asks us today what personal data we hold about them, can we identify it?”

And:

“If a data breach happens tomorrow, are we ready to respond?”

If the answer is uncertain, your DPDP journey should begin now.

DPDP compliance is not about creating more paperwork.

It is about creating trust, accountability and evidence that personal data is being handled responsibly.

Is your organisation ready?

— CA Ratan Singh Tanwar
Information Systems Audit | Cybersecurity | Digital Forensics | Data Privacy & DPDP Governance

Need help with DPDP readiness?
Data mapping, gap assessment and privacy governance for your organisation.
Request a Consultation →

← Back to all articles

Discover more from Tanwar Ratan Singh & Associates

Subscribe now to keep reading and get access to the full archive.

Continue reading