Godwit AI Labs Talk to us

HomeInsights › Cybersecurity

DPDP lands on 13 May 2027. Three things that usually are not started

Eighteen months sounds comfortable until you try to answer the first question: where is personal data actually held?

Published
18 August 2026
Reading
5 min
Topic
Cybersecurity
Deadline
13 May 202718-month runway

The Digital Personal Data Protection Rules were notified in November 2025 with an eighteen-month runway. The Data Protection Board is already operating. Consent-manager registration provisions switch on at twelve months. The substantive obligations (notice, consent, data-principal rights, grievance redressal and breach reporting) land on 13 May 2027, and the government has indicated the timeline could be pulled in rather than pushed out.

Eighteen months sounds comfortable. It stops sounding comfortable at the first question.

1 · Where is the personal data, actually

Not where the policy says. For most mid-market organisations the honest answer involves a CRM nobody owns, a few spreadsheets, an export somebody set up for a campaign in 2023, and a WhatsApp group.

What is needed is an inventory of systems, exports and third parties: the places data goes, not the places it is supposed to go. This is unglamorous and it is the foundation for everything else, because you cannot write a notice describing processing you have not mapped.

A questionnaire circulated to department heads will not produce it. People answer honestly about the systems they remember.

Where the notice says it is, and where it is The gap a data map closes, and the reason a notice cannot be written first WHAT THE NOTICE DESCRIBES CRMthe system of record One system, one owner, one lawful purpose. WHAT THE ESTATE ACTUALLY HOLDS CRMowner unclear Spreadsheetsa few, shared by link Campaign exportset up in 2023 WhatsApp groupnames, numbers, photos Third-party processorseach one a transfer you must be able to describe Five owners, or none. This is the inventory the Rules assume you already have.
Contents from the article · typical mid-market estate, not a specific client

2 · Would you notice a breach

Breach reporting duties are meaningless if nothing in the environment would have raised its hand. Plenty of organisations have a documented incident-response process and no detection worth the name, which means the first notification of a breach arrives from a customer, a researcher, or a regulator.

This is the item most likely to need budget, and the one most likely to be deferred because it produces nothing visible when it is working.

3 · Who is the named person

Grievance redressal needs a route a data principal can actually use, with somebody accountable at the end of it. A role mailbox that forwards to three people and is watched by none does not qualify in practice, whatever the policy says.

This one costs nothing. It requires a decision, which is why it is often the last thing done.

What is worth doing now, and what is not

A large amount of what is currently sold as DPDP readiness is a policy pack. Policy documents are necessary and they are not sufficient: a set of well-drafted policies describing controls you do not have is a liability rather than an asset, because it documents the gap.

The order we would suggest: map the data, then fix detection, then write the policies that describe what is actually true. Notices and consent flows are easier to write once the first step is done, and much harder to write convincingly before it.

Of the three above, one needs budget and two need a decision. Worth knowing which is which before the runway shortens.

Want to know what you are actually carrying?

Two weeks across identity, endpoints and cloud configuration, scored by the risk you carry rather than by how alarming each item sounds. Includes a DPDP data map where it applies.

How a posture review works