Twelve items, ordered by dependency, sized for a company with no legal team. Most of the work is the first one, and most teams skip it.
Twelve items get a 20-person company from nothing to defensible under India's DPDP Act. They are ordered by dependency, not by effort — you cannot write a consent notice before you know what you collect, and you cannot answer an erasure request before you know where the data lives. Budget eight to twelve weeks if one person owns it part-time.
The May 2027 enforcement date makes that sound comfortable. It isn't, because item one is slower than everyone expects.
Before you start: name an owner
One person, with the authority to change how other teams work. Not a committee. If nobody owns this, the inventory stalls at 60% and stays there for a year.
Publish their contact as your grievance channel while you are at it. It is a requirement, and it takes ten minutes.
The checklist
| # | Item | Depends on | Rough effort |
|---|---|---|---|
| 1 | Data inventory | — | 2–3 weeks |
| 2 | Purpose register | 1 | 2 days |
| 3 | Lawful basis per purpose | 2 | 2 days |
| 4 | Consent notices rewritten | 2, 3 | 1 week |
| 5 | Consent records | 4 | 1 week |
| 6 | Processor list | 1 | 2 days |
| 7 | Processing agreements signed | 6 | 3–6 weeks (vendor-paced) |
| 8 | Retention schedule | 2 | 3 days |
| 9 | Erasure mechanism | 1, 8 | 1 week |
| 10 | Rights-request process | 1, 9 | 1 week |
| 11 | Security baseline | 1 | 2 weeks |
| 12 | Breach playbook | 6, 11 | 3 days |
1. Data inventory. One spreadsheet. Every place personal data lives: website forms, CRM, Tally, HR files, WhatsApp Business, the ops team's shared drive, that CSV somebody exported in March. For each: what data, why you have it, who can access it, where it is stored, how long you keep it. This is roughly 80% of the total work and nobody enjoys it. Walk desks and ask; do not send a form and wait.
2. Purpose register. For each dataset, the specific purpose. "Business operations" is not a purpose. "Deliver the order and handle returns for 12 months" is.
3. Lawful basis. Consent, or one of the legitimate uses the Act recognises (employment, legal obligation, and so on). Write down which applies to each purpose. If nothing applies, you have found something to stop doing.
4. Consent notices. Rewrite the notice at every collection point as a standalone, plain-language notice — what you collect, the specific purpose, how to withdraw, how to complain to the Board. Not a link to a 20-page policy. Available in English and the Eighth Schedule languages.
5. Consent records. You must be able to show what a person was shown and when they agreed. A timestamp plus a version identifier of the notice text is enough; a checkbox with no record is not.
6. Processor list. Every vendor that touches personal data — cloud, email, payroll, CRM, courier, analytics, that freelance designer with access to the customer folder.
7. Processing agreements. Each processor needs one covering security obligations, breach notification timelines back to you, audit rights, sub-processor disclosure, and deletion on termination. Start early. Large vendors have standard terms and small ones need chasing, and this item paces the whole project.
8. Retention schedule. How long each dataset lives and what triggers deletion. Where another law sets a minimum — tax and company records, for instance — that wins.
9. Erasure mechanism. Can you actually delete a person from every system, including backups and that spreadsheet? Test it once. Discovering the answer during a live request is expensive.
10. Rights-request process. A published route to ask, a named owner, and a tracked 90-day clock. Access, correction, erasure, nomination.
11. Security baseline. Encryption or equivalent protection, access controls with real offboarding, logging and monitoring, backups. Access control is where small companies fail most often: people change roles and keep old permissions.
12. Breach playbook. Who gets called, who decides it is a breach, who drafts the notice, who files with the Board within 72 hours, who talks to affected individuals. One page. Seventy-two hours is not enough time to invent a process at 2am.
What to do first if you only have a week
Do item 1 badly rather than not at all. A rough inventory covering your five biggest data stores is worth more than a perfect one covering none, because everything downstream keys off it.
Then item 12. A breach with a playbook and a breach without one are very different conversations with the Board — and the Board explicitly weighs what you did to remediate.
What "compliant" actually means here
There is no certificate. Nobody hands you a badge. What you build is evidence: an inventory that is current, notices that match what you actually do, agreements with the people who hold your data, and a record showing you spotted problems and fixed them.
The Board weighs the nature and gravity of a breach, how many people were affected, your compliance history, and your remediation. A small firm with a documented programme that caught a breach, reported it on time, and fixed it sits in a very different position from one that had nothing. That gap is the entire return on this work.
Where CapEasy fits
We run the inventory with SMEs, close the gaps it exposes, and put the notices, agreements and playbooks in place — sized for a small team with no in-house counsel.
Pramaan, our DPDP platform, holds the inventory, tracks consent and data-principal requests against the clock, and keeps the audit trail. *(Pramaan is a compliance tool for Data Fiduciaries. It is not a registered Consent Manager under the DPDP Rules.)*
If you would rather start alone, do item 1 this week. It is the one nobody can do for you without talking to your team anyway.
This article is general information, not legal advice. Regulations change and interpretations evolve. Verify against the current Gazette notification or consult a qualified professional before acting.
Frequently asked questions
How long does DPDP readiness take for a 20-person company?
Plan for eight to twelve weeks of part-time work if one person owns it. The inventory usually takes two to three weeks because it means talking to every team, not reading a document. Rewriting notices and getting processing agreements signed is where the calendar slips, since vendors move at their own pace.
Do we need a lawyer for this?
Not for the inventory or the playbook. Get legal review on your consent notice wording and on processing agreements you are asked to sign, particularly indemnity and audit clauses. Those are the parts that bind you contractually.
What is the single most commonly missed data store?
Personal devices and messaging apps. Customer numbers in an employee's WhatsApp, CVs in a founder's personal inbox, an exported CSV on a laptop. They rarely appear on the first pass of an inventory and they are exactly what gets breached when a phone is lost.
Do we need a Data Protection Officer?
Only if the Central Government designates you a Significant Data Fiduciary, which is unlikely at 20 people. Every Data Fiduciary still has to publish a contact point for data-protection queries, and someone has to genuinely own it.
Is consent needed for employee data?
Some employment-related processing falls under legitimate uses rather than requiring fresh consent. Security, retention, erasure and breach duties still apply. Treat HR data with the same rigour as customer data — it is often more sensitive.
We use Google Workspace and AWS. Is that a problem?
No. Cross-border transfer is permitted unless the Central Government restricts a specific country by notification, so this is not a localisation regime. What you need is a processing agreement with each provider and clarity on who can access what. Sector regulators may impose their own rules on top.

