# The DPDPA Countdown: 9 Compliance Gaps Every DPO Must Close Before 13 May 2027

The waiting is over, and it has been over for a while. The Digital Personal Data Protection Rules were notified on 13 November 2025, converting a two-year-old Act into an operational compliance obligation with dates attached. Penalties and appeals commence on 13 November 2026. Full compliance is due on 13 May 2027.

If your DPDPA programme is still framed as "monitoring developments," you have roughly nine months to build what most organisations need eighteen to complete. This is the gap list, in the order the effort actually bites.

## Where the Clock Actually Stands

The phased commencement is the single most important planning input, and it is widely misread as a single 2027 deadline.

| Phase | Date | What becomes operative |
|---|---|---|
| Phase 1 | 13 November 2025 | Rules notified. Data Protection Board of India established. Definitions and foundational provisions in force. |
| Phase 2 | 13 November 2026 | Consent Manager registration framework and the penalty and appeals machinery become operative. |
| Phase 3 | 13 May 2027 | Full compliance. Consent, notice, Data Principal rights, fiduciary obligations, breach reporting and retention all enforceable. |

Two planning consequences follow. First, the enforcement body already exists and has existed since November 2025 - there is no longer a regulator-shaped hole to hide in. Second, the work that takes longest, which is consent architecture and data discovery, has to be substantially complete well before May 2027, because you cannot test a consent flow you have not built and you cannot map data you have not found.

![A gavel and open statute - the Rules are notified and the phased commencement dates are now fixed](/assets/blog-images/dpdpa-compliance-gaps-dpo-checklist/dpdpa-statutory-obligations.jpg)

## The Obligations in One Page

Before the gaps, a compressed recap of what the Act actually requires of a Data Fiduciary.

**Notice and consent (Sections 5 and 6).** Every request for consent must be accompanied by a notice describing the personal data sought, the purpose, how to exercise rights, and how to complain to the Board. Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to the data necessary for the stated purpose. Withdrawal must be as easy as giving.

**Certain legitimate uses (Section 7).** A narrow set of grounds where consent is not required - voluntary provision for a stated purpose, State functions and benefits, legal obligations, medical emergencies, disaster response, and specified employment purposes. Note the terminology: the 2022 draft bill used "deemed consent" and the enacted 2023 Act replaced it with "certain legitimate uses." The distinction matters because the enacted grounds are narrower than the draft's, and a programme designed against the older draft will over-claim.

**Fiduciary duties (Section 8).** Accuracy, reasonable security safeguards, erasure when purpose is served or consent withdrawn, a published grievance mechanism, and breach intimation. Accountability rests with the Fiduciary even where a Processor does the work.

**Children (Section 9).** Verifiable parental consent before processing a child's data, and a prohibition on tracking, behavioural monitoring, and targeted advertising directed at children.

**Significant Data Fiduciaries (Section 10).** Additional duties for entities the Government notifies as significant: a Data Protection Officer based in India reporting to the board, an independent data auditor, periodic Data Protection Impact Assessments and audits, and algorithmic due diligence.

**Data Principal rights (Sections 11 to 14).** Access to a summary of processing, correction and erasure, grievance redressal, and nomination.

**Cross-border (Section 16).** Transfer is permitted by default, subject to the Central Government restricting transfer to notified countries, and subject to any stricter sectoral law continuing to apply.

## The Nine Gaps

### Gap 1: No valid consent architecture

The most common failure is technical, not legal. Organisations have consent language but no consent *record*: no immutable log of which version of which notice was shown to which Data Principal at what timestamp for which purposes, and no mechanism to prove it later.

Bundled consent is the second failure. A single checkbox covering account creation, marketing, analytics and third-party sharing does not meet the specificity requirement, and unbundling it usually means rebuilding a signup flow that product will not prioritise unless you start asking now.

**Close it by:** versioning every notice, storing a consent receipt per purpose per principal, and separating each purpose into its own affirmative action.

### Gap 2: No DPIA process

A Data Protection Impact Assessment is an explicit obligation for Significant Data Fiduciaries and a practical necessity for anyone processing at scale or processing children's data. Most organisations have neither a template nor a trigger.

The trigger is the harder half. A DPIA performed once at launch and never revisited is evidence of a process that existed, not of a process that works.

**Close it by:** defining trigger events - new data category, new vendor, new jurisdiction, new purpose, model retraining - and binding the assessment to those events rather than to a calendar.

### Gap 3: No breach notification SOP

Section 8(6) requires intimation of a personal data breach to the Board and to each affected Data Principal. The Rules give this shape and timing, including notification to the Board within 72 hours.

Seventy-two hours is not a documentation deadline. It is a detection, triage, legal-assessment, drafting, approval and dispatch deadline, and organisations that have not rehearsed it consistently discover that the approval step alone consumes two days.

**Close it by:** writing the SOP with named roles and a pre-approved notification template, then running a tabletop against a realistic scenario before the deadline is real.

### Gap 4: No Data Principal rights portal

Sections 11 to 14 create rights that require an intake channel, an identity verification step, a fulfilment workflow across every system holding the data, and a response within a defined period.

The binding constraint is almost never the portal. It is fulfilment. An erasure request is unanswerable if you do not know every system where that person's data lives, which is why Gap 4 and Gap 8 are the same problem wearing different clothes.

**Close it by:** building intake and verification first, but resourcing the downstream discovery work in parallel.

### Gap 5: Undefined purpose limitation tags

Purpose limitation is a data model problem. If personal data is stored without a machine-readable record of the purpose it was collected for and the consent that authorises it, then every downstream question - can we use this for analytics, can we share it with this vendor, must we delete it now - becomes a manual investigation.

**Close it by:** tagging at ingestion with purpose, consent basis, retention class and sensitivity, and treating untagged personal data as a defect.

### Gap 6: No DPO appointment or Board-facing contact

Significant Data Fiduciaries must appoint a DPO based in India who reports to the board or equivalent governing body. Every Data Fiduciary must publish contact details for the person able to answer questions about processing.

The subtler gap is independence. A DPO who reports into the function whose processing they review has a conflict that an auditor will identify immediately.

**Close it by:** appointing, publishing the contact, and documenting the reporting line to the governing body rather than to engineering or marketing.

### Gap 7: Missing vendor data processing agreements

The Act makes the Fiduciary accountable for processing carried out by a Processor on its behalf, and requires that engagement to rest on a valid contract. Most vendor estates contain agreements signed before the Act that lack purpose limitation, sub-processor disclosure, deletion guarantees, breach notification timelines aligned to your own 72-hour obligation, and audit rights.

The AI angle makes this urgent. A vendor that has quietly added a model-powered feature may now be sending your data to a sub-processor you have never assessed.

**Close it by:** ranking vendors by data sensitivity and volume, then repapering top-down rather than attempting the whole estate at once.

### Gap 8: No retention and deletion schedule

Erasure when the purpose is served or consent is withdrawn is an affirmative obligation, and the Rules specify retention limits for certain classes of large platform. Indefinite retention "in case we need it" is now a documented violation rather than an untidy habit.

**Close it by:** defining a retention class per data category, implementing automated deletion, and - critically - extending it to backups, analytics warehouses, logs and any dataset used to train a model.

### Gap 9: Absent employee training logs

Training is the control that everyone claims and nobody evidences. When the Board asks how you ensured staff handling personal data understood their obligations, an assertion is not evidence. A dated completion record per employee per module is.

**Close it by:** running role-specific training rather than one generic module, and retaining per-person completion records with dates.

![A pen resting on a stack of documents, representing a structured readiness sprint](/assets/blog-images/dpdpa-compliance-gaps-dpo-checklist/120-day-readiness-sprint.jpg)

## What "Significant Data Fiduciary" Changes

The Government may notify an entity or class as a Significant Data Fiduciary based on volume and sensitivity of data processed, risk to Data Principal rights, potential effects on India's sovereignty and integrity, risk to electoral democracy, security of the State, and public order.

If you are notified, four obligations attach that do not otherwise apply: an India-based DPO reporting to the board, an independent data auditor, periodic DPIAs and audits, and due diligence on algorithmic software used for processing that may risk Data Principal rights.

The planning advice for large enterprises is to assume the designation rather than wait for it. Every one of those four obligations has a lead time measured in months, and the ones that do not receive the designation will have built a defensible programme anyway.

## A 120-Day Readiness Sprint

Nine months is enough time if the first 120 days are spent on the work that everything else depends on.

| Days | Focus | Exit criteria |
|---|---|---|
| 1-15 | Applicability and scoping. Determine likely SDF status, map jurisdictions and sectoral overlays, appoint the DPO. | Named DPO, documented scope, board-approved mandate. |
| 16-45 | Data discovery. Automated scanning across cloud, SaaS, on-prem and AI training sets. Build the first RoPA. | RoPA covering systems accounting for the large majority of personal data volume. |
| 46-70 | Consent and notice audit. Inventory every collection point, version the notices, design the receipt schema. | Gap list per collection point with owners and dates. |
| 71-95 | Vendor repapering wave one. Top vendors by sensitivity and volume. | Signed addenda for the highest-risk tier. |
| 96-110 | Rights portal and breach SOP. Intake, verification, fulfilment routing, notification templates. | Working intake, one completed tabletop exercise. |
| 111-120 | Board reporting and residual plan. Quantify what remains, cost it, get it funded. | Board-approved plan through May 2027. |

The sequencing is deliberate. Discovery precedes consent work because you cannot audit collection points you have not found, and vendor repapering precedes the rights portal because erasure requests you cannot fulfil at a Processor are worse than no portal at all.

## Conclusion

The DPDPA is no longer a forecasting exercise. The Rules are notified, the Board exists, penalties commence in November 2026, and full compliance is due in May 2027. The organisations that will be ready are the ones treating discovery and consent architecture as engineering projects with sprints and owners, not as policy documents awaiting sign-off.

The nine gaps above are ranked roughly by how long they take to close, not by how serious they are. That ordering is the useful one when the deadline is fixed and the resource is not.

**Actionable recommendations:**

- **Work backwards from 13 May 2027, not forwards from today.** Consent architecture and data discovery need six to nine months. Starting them in 2027 means missing the date regardless of budget.
- **Assume Significant Data Fiduciary status if you are large.** The four additional obligations have long lead times and building them is not wasted if the designation never arrives.
- **Fix data discovery before consent tooling.** Every other gap - rights fulfilment, retention, purpose tagging, breach scoping - depends on knowing where personal data actually lives.
- **Rehearse the 72-hour breach clock now.** The approval path, not the drafting, is what fails under time pressure. Find that out in a tabletop rather than in an incident.
- **Repaper vendors in risk order.** A full-estate repapering effort will stall. The top tier by data sensitivity and volume covers most of the exposure.

> **Run a DPDPA gap assessment in 48 hours, not 48 days.** Pre-built control libraries mapped to every Section of the Act, automated data discovery, and a live readiness score you can take to the board. See how [Dedups.ai](https://dedups.ai) turns the nine gaps into a tracked, evidenced programme.
