DPDP Readiness: 6 Steps to Comply by May 2027
A practical DPDP readiness plan in six plain-English steps, so your business meets India's 13 May 2027 data protection deadline without a last-minute scramble.

What it is: DPDP readiness is the work of getting your business ready for India's Digital Personal Data Protection (DPDP) Act and its 2025 Rules - the law that governs how you collect, use, and protect personal data of people in India. Why it matters: the deadlines are real and the penalties are large, up to Rs 250 crore per breach of the Act. When it applies: to every organisation that is a Data Fiduciary - a plain-English term meaning any business that decides why and how personal data is collected and used, which covers almost every company with customers, users, or employees in India. This post lays out a six-step DPDP readiness plan you can start today, well ahead of the 13 May 2027 full-compliance deadline.
Step 1: Discover and inventory
You cannot protect personal data you do not know you have. Start by finding every system, application, spreadsheet, and third-party vendor that touches personal data - names, phone numbers, emails, financial details, health information, location data, and anything else that identifies a person. This discovery step usually surfaces more than expected: marketing tools, old databases, support ticket systems, and vendor integrations that were never formally reviewed for what they store.
Step 2: Build a RoPA and map data flows
Once you know where personal data lives, write it down in a RoPA - a Record of Processing Activities, which is simply a living list of what personal data you hold, why you collect it, where it is stored, who you share it with, and how long you keep it. Alongside the RoPA, map the data flows: how personal data moves from the point of collection (a signup form, a support call) through your systems and out to any vendors or partners. This map becomes the backbone for every other compliance decision, because you cannot assess a gap or write an accurate notice without first knowing the actual flow of data.
Step 3: Run a gap assessment
With your inventory and RoPA in hand, score your current practices against each obligation in the DPDP Act and Rules: notice (do you clearly tell people what data you collect and why), consent (is it clear, specific, and easy to withdraw), security safeguards, breach handling, data retention limits, and individual rights (can a person see, correct, or ask you to delete their data). Rate each area as compliant, partially compliant, or non-compliant, and use this scorecard to prioritise your remediation work - fix the biggest gaps first rather than working alphabetically through a checklist.
Step 4: Check if you are a Significant Data Fiduciary
The DPDP framework has an extra tier of obligations for a Significant Data Fiduciary (SDF) - a larger or higher-risk entity, so classified based on factors like the volume and sensitivity of data it processes. If your business is designated an SDF, you take on additional duties: appointing a Data Protection Officer (a named senior person accountable for data protection), running a yearly independent audit, and carrying out a DPIA - a Data Protection Impact Assessment, which is a structured review of the privacy risk in a new project or system before you launch it. Even if you are not an SDF, review your vendor relationships for the same kind of risk: a vendor that mishandles the personal data you share with them is still your problem to answer for.
Step 5: Implement the controls
This is where the plan turns into engineering and process work. Priorities include: clear, specific consent and notice language that a non-lawyer can actually understand; the Rule 6 security safeguards, which cover encryption of personal data, access controls so only the right people can see it, and logging that is kept for at least one year so you can investigate an incident after the fact; a retention and erasure policy so data is not kept indefinitely once its purpose is served; and a rights portal or process so people can exercise their rights - viewing, correcting, or requesting deletion of their data - without needing to email your legal team.
Step 6: Build a roadmap and operate
DPDP compliance is not a one-time project you finish and file away. Turn your remaining gaps into a dated roadmap, assign owners, and set up a recurring review - because new products, new vendors, and new data types will keep appearing, and each one needs to be checked against the same obligations. Build DPDP checks into your existing product and vendor-onboarding processes so compliance stays current instead of becoming another once-a-year scramble.
Key dates to plan around
- 13 November 2025 - DPDP Rules formally notified, starting the compliance clock.
- 13 November 2026 - registration opens for Consent Managers, platforms that let individuals manage their consent across companies from one place.
- 13 May 2027 - full compliance deadline for all Data Fiduciaries, with penalties of up to Rs 250 crore per breach.
None of these six steps require exotic technology - they require disciplined inventory work, honest gap-scoring, and controls that most mature security programmes already have some version of. The businesses that will struggle in May 2027 are the ones that leave discovery and inventory, step one, until the deadline is already close.