Home › Insights › Cybersecurity
DPDP lands on 13 May 2027. Three things that usually are not started
Eighteen months sounds comfortable until you try to answer the first question: where is personal data actually held?
- Published
- 18 August 2026
- Reading
- 5 min
- Topic
- Cybersecurity
- Deadline
- 13 May 202718-month runway
The Digital Personal Data Protection Rules were notified in November 2025 with an eighteen-month runway. The Data Protection Board is already operating. Consent-manager registration provisions switch on at twelve months. The substantive obligations (notice, consent, data-principal rights, grievance redressal and breach reporting) land on 13 May 2027, and the government has indicated the timeline could be pulled in rather than pushed out.
Eighteen months sounds comfortable. It stops sounding comfortable at the first question.
1 · Where is the personal data, actually
Not where the policy says. For most mid-market organisations the honest answer involves a CRM nobody owns, a few spreadsheets, an export somebody set up for a campaign in 2023, and a WhatsApp group.
What is needed is an inventory of systems, exports and third parties: the places data goes, not the places it is supposed to go. This is unglamorous and it is the foundation for everything else, because you cannot write a notice describing processing you have not mapped.
A questionnaire circulated to department heads will not produce it. People answer honestly about the systems they remember.
2 · Would you notice a breach
Breach reporting duties are meaningless if nothing in the environment would have raised its hand. Plenty of organisations have a documented incident-response process and no detection worth the name, which means the first notification of a breach arrives from a customer, a researcher, or a regulator.
This is the item most likely to need budget, and the one most likely to be deferred because it produces nothing visible when it is working.
3 · Who is the named person
Grievance redressal needs a route a data principal can actually use, with somebody accountable at the end of it. A role mailbox that forwards to three people and is watched by none does not qualify in practice, whatever the policy says.
This one costs nothing. It requires a decision, which is why it is often the last thing done.
What is worth doing now, and what is not
A large amount of what is currently sold as DPDP readiness is a policy pack. Policy documents are necessary and they are not sufficient: a set of well-drafted policies describing controls you do not have is a liability rather than an asset, because it documents the gap.
The order we would suggest: map the data, then fix detection, then write the policies that describe what is actually true. Notices and consent flows are easier to write once the first step is done, and much harder to write convincingly before it.
Of the three above, one needs budget and two need a decision. Worth knowing which is which before the runway shortens.
Want to know what you are actually carrying?
Two weeks across identity, endpoints and cloud configuration, scored by the risk you carry rather than by how alarming each item sounds. Includes a DPDP data map where it applies.