90-Day DPDP Readiness Plan
Implement DPDP readiness in ninety days through legal commencement mapping, data inventory, notices, consent, vendors, access, retention, incidents and governance.
\nFor broader context, see the Data Privacy, DPDP and Cyber Law — Full Compliance Hub.
A small business does not need a hundred-page privacy programme before it can fix its biggest risks.
Quick View
Use ninety days to create evidence-backed controls and a longer roadmap for phased legal dates.
Appoint executive owner.
Ninety-day plan.
Starting with policy copy.
For the connected rule, example or next step, see 30-60-90 Day DPDP Implementation Plan for SMEs.
\nWhy It Matters
The final Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 with phased commencement. As of 25 June 2026, organisations should distinguish provisions already commenced from operational duties scheduled for later dates, while continuing to comply with the IT Act, CERT-In directions and sectoral rules already in force.
The plan should not claim every DPDP obligation is currently enforceable. It should build controls against the final framework while closing existing CERT-In, security and sectoral gaps.
Prioritise data that can cause financial, identity, health, employment or child harm.
For the connected rule, example or next step, see DPDP Rules 2025: A Finance-Team Readiness Calendar from 2025 to 2027.
\nControl Framework
| Area | What to establish | Operating rule |
|---|---|---|
| Days 1–30 | Scope, owners, data map and incidents. | Find reality. |
| Days 31–60 | Notices, consent, vendors and access. | Build controls. |
| Days 61–90 | Rights, deletion, testing and board pack. | Prove operation. |
| Beyond | Phased dates and mature assurance. | Fund roadmap. |
Action Checklist
- Appoint executive owner.
- Map critical data and vendors.
- Fix open access and logging.
- Draft actual notices.
- Create incident and request workflows.
- Run tabletop and board review.
Practical Example
Evidence to Keep
- Ninety-day plan.
- Data inventory.
- Risk register.
- Notice and consent versions.
- Vendor and access records.
- Exercise and board minutes.
Warning Signs
- Starting with policy copy.
- Treating software as compliance.
- No executive owner.
- Ignoring shadow spreadsheets.
- Claiming completion without tests.
Detailed Review
Privacy governance should connect the personal data, individual, purpose, collection point, system, owner, recipient, access role, retention trigger and incident dependency. A policy that cannot be traced to this chain is difficult to operate.
Create a dated legal matrix rather than one status label. Record the DPDP provision, commencement date, present readiness action, current IT or sectoral obligation and the evidence owner.
Design controls in the product and system. A written rule cannot stop an SDK from firing, a shared folder from exposing payroll, or a vendor from retaining deleted users unless technology and operations enforce it.
Evidence should be generated during normal work: versioned notices, event logs, access approvals, request tickets, deletion reports, vendor registers, incident chronologies and management decisions.
Use proportionate identity and security checks. Excess verification creates more personal data, while weak verification can expose another person’s records or permit account takeover.
Every product release should trigger a privacy change review covering new fields, vendors, permissions, purposes, regions and retention.
Management reporting should show overdue evidence and control failures, not only the existence of policies.
Control Test
Test the control using a real user journey from collection to deletion. Capture the notice shown, data stored, vendors called, employees with access, retention period and response if the user withdraws or complains.
Run a negative scenario: the vendor is breached, the user is a child, the employee exits, the phone is stolen, the data was inaccurate or the regulator asks for proof. Record which control fails.
Check that system records and public wording agree. Product forms, privacy notice, CRM fields, SDK behaviour, vendor contracts and support scripts should describe the same processing.
Assign a named owner and internal deadline for every gap. A risk register without funded action and closure evidence becomes an archive of known failures.
Retain the rejected alternatives and decision basis. This is especially important where the law is in phased commencement or a proportionate technical method is selected.
Escalation Route
Start with the system owner, privacy or security owner and the documented data flow. Preserve records before making changes, and separate current statutory reporting from future DPDP readiness.
For a breach, financial fraud, rights dispute, children’s-data issue or regulated-sector event, involve qualified legal, cyber, forensic and sector specialists and use the applicable official reporting or grievance channel.
Frequently Asked Questions
Source and review trail
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
- Primary category
- Data Protection, Cyber & IT Law
- Official starting point
- www.meity.gov.in