10 min readUpdated

The DPO's First 90 Days: Standing Up a DPDPA Programme from Zero

You have been named Data Protection Officer. The board wants a compliance roadmap, and the deadline that actually matters is 13 May 2027, when full compliance under the Digital Personal Data Protection Rules becomes due. Penalties and appeals commence before that, on 13 November 2026.

Ninety days is enough to build the foundation and earn the credibility to fund the rest. It is not enough to become compliant, and promising otherwise is the fastest way to lose the room in month four.

Here is the week-by-week plan.

Before Week 1: Fix Your Own Mandate

Do this before anything else, because it constrains everything after.

Under Section 10, a Significant Data Fiduciary must appoint a Data Protection Officer based in India who represents the Fiduciary and reports to the board of directors or equivalent governing body. That reporting line is not an organisational preference. It is the structural feature that makes the role capable of functioning.

Establish three things in writing before you start work:

  • Reporting line. To the board or its risk committee. A DPO reporting into the function whose processing they assess has a conflict an auditor will identify on day one.
  • Budget and resourcing. A number, or at minimum a stated process for requesting one. A DPO with responsibility and no budget is an accountability sink.
  • Access rights. To systems, contracts, vendors and people, without needing permission from the function being reviewed.

Get these in the appointment letter. Renegotiating them in month five, after a difficult finding, is a different and much harder conversation.

Reporting line, budget and access rights settled in writing before the programme starts
Reporting line, budget and access rights settled in writing before the programme starts

Weeks 1-2: Stakeholder Mapping and Current State

Objective: Know who owns what, and know honestly how bad it is.

Stakeholder mapping. Identify the people whose cooperation determines success: the CISO, the CTO or engineering leaders, the heads of every function processing personal data at volume, procurement, legal, HR, and the internal audit lead. Meet each one individually. Ask three questions: what personal data does your function handle, what would worry you if it appeared in the news, and what have you been asked to do about privacy before that went nowhere.

That third question is the valuable one. Every organisation has a history of previous compliance initiatives, and understanding why the last one stalled tells you what will stall yours.

Current state assessment. Resist the urge to run a full framework assessment in week one. You need a rapid, honest baseline across eight areas: what personal data exists and where, how consent is currently obtained, what notices are published, which vendors process personal data, what security controls exist, whether any rights request has ever been received and how it was handled, what would happen today if a breach occurred, and what documentation exists.

Score each red, amber or green. Expect mostly red. Resist softening it - your credibility in month six depends on the baseline being honest in month one.

Significant Data Fiduciary applicability. Assess against the statutory factors: volume and sensitivity of personal data processed, risk to Data Principal rights, and the broader public interest considerations the Act names. If you are plausibly in scope, plan as though you are. The four additional obligations - India-based DPO reporting to the board, independent data auditor, periodic DPIAs and audits, algorithmic due diligence - all have long lead times, and none is wasted if the designation never arrives.

Deliverable: A one-page current-state heatmap and a stakeholder map with named owners.

Weeks 3-4: Discovery Sprint

Objective: Find the data. Everything else depends on this, and it takes longer than anyone expects.

Automated discovery across production databases, data warehouses, object storage, SaaS platforms and file shares. Start the tooling procurement or deployment in week one so that scanning begins here.

SaaS inventory from your identity provider's application list and from expense data. In most enterprises this surfaces platforms nobody in IT knew were in use, and it is the highest-yield two hours in the whole ninety days.

AI and ML estate. Training datasets, feature stores, vector databases, prompt logs and fine-tuned models. Ask engineering directly; scanning will not find these reliably.

Consent mechanism audit. Enumerate every point where personal data is collected - web forms, mobile app screens, call centre scripts, paper forms, partner integrations, imports. For each, record what notice is shown, what consent is captured, whether it is bundled, and whether any record persists.

Vendor register review. Every vendor with access to personal data. For each: is there a contract, does it contain data processing terms, does it name sub-processors, does it specify deletion, does it specify breach notification and on what timeline. Rank by data sensitivity and volume.

Deliverable: A first-pass RoPA covering the systems that account for the large majority of personal data volume, plus a ranked vendor list and a collection-point inventory. Not complete. Defensible.

A team working through stakeholder mapping in a workshop
A team working through stakeholder mapping in a workshop

Weeks 5-8: Policies, Notices and the Rights Portal

Objective: Build the visible artefacts, and start the long-lead items.

Draft the core policy set. Four matter first:

  • Privacy notice, aligned to Section 5: what personal data, for what purpose, how to exercise rights, how to complain to the Board. Available in English and, where your user base requires it, in the applicable Eighth Schedule languages.
  • Retention and erasure policy, with a retention class per data category and the trigger that starts each clock.
  • Breach notification SOP, calibrated to the 72-hour Board notification requirement, with named roles and a pre-approved template.
  • Children's data policy, if you process it at all, covering age assurance, verifiable parental consent, and the prohibition on tracking and targeted advertising.

Write these to be operable rather than comprehensive. A four-page policy people follow beats a forty-page policy nobody reads.

Data Principal rights portal. Build intake and identity verification in this window. Do not attempt full automated fulfilment yet - a manual fulfilment process behind a working intake is an acceptable interim state, and it generates the requirement detail that automated fulfilment will need.

Start vendor repapering. Begin with the top tier by sensitivity and volume. Contract negotiation runs on the counterparty's timeline, so starting in week five means concluding in month four or five. Starting in month four means concluding after the deadline.

Deliverable: Four approved policies, a published notice, a working rights intake, and vendor repapering underway on the top tier.

Weeks 9-12: Pilot, Train, Register, Report

Objective: Prove the model works on a small scale and secure funding for the rest.

DPIA pilot. Pick two or three high-risk processing activities and run full assessments. The purpose is to calibrate: how long does a DPIA actually take in this organisation, who needs to be in the room, what data is missing. That calibration is what makes your resourcing estimate credible.

Training programme. Role-specific, not a single generic module. Engineering needs data minimisation and purpose tagging. Support needs what they may and may not paste into tools. Marketing needs consent basis for outreach. HR needs employee and candidate data handling. Procurement needs what to require of vendors. Retain per-person completion records with dates - training you cannot evidence is training you did not do, as far as an auditor is concerned.

Register with the Data Protection Board as applicable to your circumstances, and publish the contact details of the person who can answer questions about processing.

Define the board KPI set. Five numbers, reported quarterly:

MetricWhat it tells the board
Percentage of personal data estate mappedProgress on the foundational dependency
Collection points with compliant consentThe largest engineering workstream, made visible
Top-tier vendors with compliant DPAsThird-party exposure closing
Rights requests received, and percentage fulfilled within targetWhether the process functions in reality
Open high-severity gaps, with owner and dateWhere the risk actually sits

Deliverable: A board-approved plan through May 2027, with a costed resource request grounded in measured effort from the pilot.

Quick Wins That Build Credibility

You need visible progress before month three or the programme loses momentum.

  • Publish the privacy notice. Visible, fast, and demonstrates motion.
  • Kill one genuinely unnecessary data collection. Find a form field nobody uses, remove it, and report the reduction. It signals that privacy work removes burden as well as adding it.
  • Fix the most exposed consent flow. One high-traffic collection point unbundled and properly recorded.
  • Run a breach tabletop and publish the findings. Executives who sit through one understand the 72-hour clock in a way no memo achieves. The approval bottleneck it exposes will fund your SOP work.
  • Give the sales team a security questionnaire answer pack. Nothing buys goodwill faster than reducing the time sales spends chasing compliance answers.

The Five Mistakes

Over-engineering consent. Teams build elaborate consent management before knowing what data exists or what purposes need consenting. Discovery precedes consent architecture, always.

Ignoring employee data. Employee, contractor and candidate data is personal data. HR systems are frequently the least assessed estate in the organisation, and Section 7's employment-related grounds are narrower than most assume.

Treating it as a legal project. The Act's obligations are discharged by engineering: deletion pipelines, consent records, access controls, purpose tagging. A programme run entirely from legal produces documents that describe compliance nobody has built.

Chasing completeness over risk. A perfectly mapped low-risk system while a high-volume customer database goes unassessed is effort spent backwards. Rank by sensitivity and volume, always.

Promising compliance in ninety days. You are building a foundation. Say so at the outset, in writing, with the realistic date. The DPO who sets an honest expectation in month one and meets it survives; the one who promises compliance and misses spends month four defending the schedule instead of running the programme.

Conclusion

The first ninety days determine whether the DPDPA programme becomes an engineering workstream with real resourcing or a documentation exercise that stalls after the policies are signed.

The pattern that works is consistent: fix the mandate before starting, find the data before designing anything, start the long-lead items - vendor repapering and consent architecture - early precisely because they finish late, and set an honest expectation about what ninety days can deliver.

Actionable recommendations:

  • Get the reporting line, budget and access in writing before day one. Renegotiating a mandate after a difficult finding is a much harder conversation.
  • Spend weeks 3 and 4 on discovery, not on policy. Every other obligation depends on knowing where personal data lives, and policies written without that knowledge get rewritten.
  • Start vendor repapering in week five. It runs on the counterparty's timeline, which is the one thing your plan cannot compress.
  • Run a breach tabletop early and let executives feel the 72-hour clock. It is the most efficient way to convert abstract obligation into funded work.
  • Say plainly that ninety days builds a foundation, not compliance. The honest expectation is what earns you the eighteen months you actually need.

Start with a 90-day readiness kit. Pre-built policies mapped to each Section of the Act, automated data discovery, a vendor repapering tracker, and a board-ready KPI dashboard from week one. See how Dedups.ai gets a new DPO to a defensible position faster.

Ready to get started?

Start securing your cloud infrastructure and optimising costs today.