Guide · 8 min read

DPDPA 2023 Readiness in 90 Days

DPDPA has no certificate and no fixed audit date, which makes it easy to deprioritize and expensive to ignore. Here's a realistic 90-day plan that gets the highest-risk gaps closed first.

Days 1-30: Know what you actually have

You can't protect data you haven't inventoried. This phase is unglamorous and non-negotiable.

Days 31-60: Fix consent and rights

This is the most customer-visible part of DPDPA, and the part most companies get wrong first.

Days 61-90: Safeguards and breach readiness

The part that only matters on the worst day, which is exactly why it needs to be ready before that day arrives.

What "done" actually looks like

DPDPA doesn't hand you a certificate at the end of 90 days. What you get is a defensible position: a current data inventory, consent that would survive scrutiny, a working rights process, and a breach response you've actually tested. That's the bar, and it's a moving one, since the accompanying rules are still phasing in. Treat this as the start of an operating discipline, not a project with a finish line.

Want a clearer starting point?

Get a free preliminary DPDPA readiness score in about three minutes.

← Back to Resources