Security & Compliance 6 min read

DPDPA readiness is more than a compliance exercise.

Building practical data protection controls starts with understanding how personal data moves through your business, who has access to it, and where the real operational risks exist.

Read featured insight

India's Digital Personal Data Protection framework is changing the way organisations need to think about personal data. But becoming DPDPA-ready should not begin with another policy. It should begin with understanding how the business actually collects, uses, shares, stores and removes personal information.

01

Readiness is an operational question.

When organisations first approach data protection, the conversation often starts with documents.

Do we have a privacy notice? Is consent captured correctly? Do our contracts contain the appropriate clauses?

These are important questions, but they represent only one part of readiness.

The more important questions are operational. Where is personal data collected? Which systems hold it? Who can access it? Where is it shared? How long is it retained? And what happens when it needs to be corrected or removed?

Readiness means making the organisation's actual handling of personal data consistent with the controls it says it follows.

A business may have a carefully written privacy notice while customer information remains distributed across spreadsheets, CRM exports, shared drives, email attachments, ERP systems and third-party applications.

The policy may be correct. The operating environment may not be.

02

Follow the data, not just the application.

Most organisations understand their applications better than they understand the personal information moving between those applications.

They know they operate an HR system, CRM, ERP platform, support application and payroll system.

But personal data rarely remains inside only one system.

Consider a simple customer enquiry. A person enters their name, telephone number and email address through a website. That information may enter a CRM, trigger an email, appear in a spreadsheet, move into an ERP application and later appear in invoices, reports and support systems.

Practical perspective

One business process can create several copies of the same personal information across different teams, systems and technologies.

An effective data discovery exercise therefore needs to follow the complete business process.

Start where the information enters the organisation. Then identify where it is stored, transferred, transformed, exported, backed up, shared and ultimately removed.

The goal is not to build a complex inventory simply for documentation purposes.

The goal is to answer a practical question:

Can the organisation explain the lifecycle of the personal data for which it is responsible?

03

Build controls around the data lifecycle.

Once an organisation understands how personal information moves, regulatory requirements can be translated into practical operational controls.

01 / Collect

Collect with purpose

Understand why information is required and avoid collecting unnecessary data simply because the system allows it.

02 / Access

Control who can use it

Align access with business roles, responsibilities and genuine operational requirements.

03 / Share

Understand where it goes

Identify which vendors, partners, applications and cloud platforms receive personal information.

04 / Retain

Keep it intentionally

Establish retention decisions based on business, contractual and applicable legal requirements.

05 / Protect

Apply appropriate safeguards

Combine identity, endpoint, network, application and process-level security controls.

06 / Remove

Design for deletion

Understand how information can be removed from operational systems and other locations where copies may remain.

Controls become more effective when they are built into everyday business processes rather than managed as disconnected compliance activities.

04

Make accountability part of everyday work.

Technology controls alone cannot make an organisation ready.

Personal data moves because people perform business processes.

  • Sales teams export customer information.
  • HR teams handle employee records.
  • Finance teams process banking information.
  • Support teams access customer details.
  • IT administrators may have privileged access.
  • Marketing teams maintain prospect databases.

Privacy therefore cannot sit entirely with IT, legal or compliance.

Each function should understand what personal information it handles, what it is permitted to do with that information, which systems are involved and who owns the process.

Good data protection is rarely one control. It is a chain of controls working together.

The same principle applies when something goes wrong. Incident management should connect security, IT, business owners, management and other relevant functions.

05

Measure readiness, not document completion.

A readiness programme becomes more valuable when leadership can see measurable progress.

Instead of measuring success by the number of policies completed, organisations can measure whether controls actually exist and operate effectively.

  • What percentage of critical processes have completed personal-data discovery?
  • How many systems have clearly assigned owners?
  • Are access reviews performed?
  • Have important third parties been assessed?
  • Are retention requirements implemented?
  • Can requests and incidents follow an established workflow?
Change the conversation

“Our privacy policy is complete” is very different from “We understand where critical personal data exists, who owns it, where it is shared and which risks still need to be addressed.”

This approach also gives management a better foundation for deciding where technology investment will provide genuine value.

06

Start with a practical readiness roadmap.

DPDPA readiness does not need to become one enormous transformation programme.

A phased approach makes the work easier to prioritise, execute and measure.

01

Discover

Identify important processes, systems, personal-data flows, third parties and existing controls.

02

Assess

Compare the current environment with applicable requirements and identify operational gaps.

03

Prioritise

Focus first on higher-volume, higher-exposure and business-critical processing activities.

04

Implement

Embed practical controls into forms, access, vendors, retention, requests and incident handling.

05

Validate

Test whether controls work in practice rather than assuming they operate as intended.

06

Monitor

Periodically review the environment as systems, employees, vendors and processes change.

Compliance is the outcome. Better data governance is the opportunity.

DPDPA will understandably encourage organisations to review privacy notices, consent practices, contracts and regulatory obligations.

But organisations that stop there may miss the larger opportunity.

A good readiness exercise can expose unnecessary data collection, excessive access, duplicate information, unmanaged spreadsheets, forgotten integrations and information being retained without a clear purpose.

Addressing these issues can reduce security exposure, simplify operations, improve data quality and create stronger foundations for analytics, automation and AI.

Know the data. Understand the flow. Fix the risk. Then automate the control.

A practical place to begin is with one important business process.

Follow personal information from the moment it enters the organisation until the point at which it should no longer be required.

Identify every system, person, transfer and third party involved.

The gaps you discover will often tell you more about your true DPDPA readiness than a compliance checklist alone.

DPDPA Readiness

Turn compliance requirements into practical operational controls.

Epicarp helps organisations understand personal-data flows, identify control gaps and build a practical roadmap for DPDPA readiness.

This article is intended for general informational purposes and does not constitute legal advice. Organisations should assess applicable legal and regulatory obligations based on their individual circumstances.