Ninety days is enough to go from a messy spreadsheet to an evidence pack the Board can inspect — if you do the work in order.
TL;DR
- A DPDPA readiness roadmap is not a policy PDF. It is six fortnightly windows that end with an evidence pack you can hand to the Data Protection Board without a scramble.
- Everything downstream depends on the inventory. Do not skip Days 1–15 to get to the “interesting” consent work.
- The Digital Personal Data Protection Act, 2023 has no “legitimate interests” ground. Every purpose lands on Section 6 consent or a named Section 7 legitimate use — including Section 7(i) for employment-necessary processing.
- Withdrawal must be as easy as giving consent (Section 6(4)). If your opt-out is an email to support@ and your opt-in is one tap, you are already non-compliant.
- Breach clocks are cumulative, not alternatives: CERT-In 6 hours and the Rule 7 detailed report to the Board within 72 hours.
- Substantive obligations bite on 13 May 2027. Ninety days of honest work now beats nine months of panic later.
What is a DPDPA readiness roadmap for an Indian SMB — and why 90 days?
A DPDPA readiness roadmap is a sequenced plan that takes a company from “we think we’re mostly fine” to “here is the record.” It has a fixed order because the dependencies are real: you cannot assign a lawful ground to a purpose you have not written down, you cannot draft an itemised notice for data you cannot name, and you cannot honour an erasure request across systems you never mapped.
Ninety days is the right container for an Indian SMB because it is long enough to survive one quarter-end and one audit season, and short enough that the same two people who start it will still own it at the end. Below 60 days, the inventory gets faked. Beyond 120, the roadmap becomes a standing agenda item that nobody closes.
Two things make this urgent rather than theoretical. First, the Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and the substantive rules — notice, security safeguards, breach intimation, erasure, rights — commence eighteen months later, on 13 May 2027. Second, the penalty structure is not scaled to your revenue. Failure to take reasonable security safeguards under Section 8(5) carries a penalty of up to ₹250 crore. Failure to intimate a breach under Section 8(6) carries up to ₹200 crore. These are separate entries and should never be added together, but neither is a rounding error for a ₹40-crore company.
Here is the whole plan on one screen.
| Window | Work | DPDPA hook | Privigo screen |
|---|---|---|---|
| Days 1–15 (Wk 1–2) | Personal-data inventory: systems, vendors, purposes, retention | Sec 8(1) accountability; Rule 8 retention | Data map / vault intake |
| Days 16–30 (Wk 3–4) | Assign a lawful ground to every processing activity | Sec 6 consent or Sec 7 legitimate use, incl. 7(i) | Purpose register |
| Days 31–45 (Wk 5–6) | Itemised notices, consent capture, withdrawal path | Sec 5 notice; Sec 6(1)–(4); Rule 3 | Consent capture + immutable records |
| Days 46–60 (Wk 7–8) | Access, correction, erasure, grievance contact | Sec 8(7), 8(9), 8(10); Sec 11–13; Rule 14 | Rights fulfilment |
| Days 61–75 (Wk 9–11) | Dual-clock breach runbook with named owners | Sec 8(6); Rule 7; CERT-In Direction 2022 | Incident / audit trail |
| Days 76–90 (Wk 11–13) | Evidence pack + one live rehearsal | Sec 8(5); Board’s evidentiary expectations | Sealed vault + audit export |
Two named owners for the whole thing: one business owner (usually the founder or ops lead) who can force a decision, and one technical owner who can actually read a database schema. Committees do not finish roadmaps.
How do you inventory personal data in the first 15 days?
Start from the money and the people, not from the IT asset register. Every SMB has four reliable reservoirs of personal data: the CRM, the HR and payroll stack, the billing or invoicing system, and the shared drive where somebody has been keeping a spreadsheet for six years.
Run it as three passes.
Pass one, Days 1–5 — systems and shadow systems. List every place personal data lands, including WhatsApp Business, Google Forms, the Tally instance, the vendor portal your sales team logs into, and the laptop folder marked old_leads_final_v2.xlsx. If someone can name a person from it, it is in scope.
Pass two, Days 6–10 — purposes and fields. For each system, write the purposes in plain business language: “verify a customer’s identity before disbursal”, “run monthly payroll”, “send fortnightly product updates”. Do not write “business operations”. A purpose that cannot be itemised in a notice is not a purpose, it is a habit.
Pass three, Days 11–15 — vendors and retention. Who else touches this data? Your payroll processor, your cloud provider, your email tool, your collections agency. Under Section 8(2), a Data Processor may only be engaged under a valid contract, and under Section 8(1) you remain responsible for their compliance. Then, for each dataset, write the retention period and the trigger that ends it.
One correction worth making early, because it derails a lot of SMB projects: the DPDPA has no “sensitive personal data” tier. There is no special category carve-out to sort your fields into. What the Act does treat distinctly is the personal data of children — Section 9 applies to everyone under 18, which catches school admission forms, coaching-class enquiries, dependant records in employee insurance, and the 17-year-old who applied for your internship.
| Category | Typical source | Lawful ground | What “done” looks like |
|---|---|---|---|
| Customer contact and KYC | Website form, sales call, onboarding portal | Sec 6 consent, or Sec 7(a) voluntary provision | Named purpose, retention trigger, notice text drafted |
| Employee HR and payroll | Offer letter, HRMS, payroll vendor | Sec 7(i) employment purposes | No consent flow; processor contract on file |
| Job applicant data | Careers page, referral, hiring platform | Sec 6 consent; Sec 9 if applicant is under 18 | Rejection-cohort deletion date set |
| Marketing and newsletter list | Lead magnet, event scan, imported list | Sec 6 consent only | Provenance recorded; unconsented rows quarantined |
| Vendor and contractor contacts | Procurement, empanelment | Sec 6 consent, or Sec 7(a) if voluntarily provided for a specified purpose | Ground recorded per purpose, not per vendor |
| Support tickets and call recordings | Helpdesk, cloud telephony | Sec 6 consent, with notice at capture | Retention cap set; recordings not kept indefinitely |
| Children’s data (under 18) | School, coaching, dependant records | Sec 9 verifiable parental consent | Age-check step exists before collection |
The deliverable at Day 15 is one sheet, not a document. Every row: system, dataset, purpose, fields, who else sees it, how long you keep it, who owns it. If a row has an empty owner cell, that row is a future incident.
How should an SMB map every purpose to Section 6 or Section 7?
This is the fortnight where most European-style templates fail Indian companies. The DPDPA does not have a “legitimate interests” balancing test. If your policy was adapted from a GDPR document, there is almost certainly a purpose sitting on legitimate interests with nowhere to go. Find it in Days 16–30, not in a Board proceeding.
Take the purpose sheet from Day 15 and force each row into one of two columns.
Section 6 — consent. Marketing, newsletters, optional analytics, cross-selling to an existing customer beyond the original purpose, most cookie-based tracking. Consent under Section 6(1) must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action. Bundling — “by using this site you agree to everything” — fails on both specific and unconditional.
Section 7 — certain legitimate uses. These are enumerated, not open-ended. The two that matter most to SMBs:
- Section 7(a) — the Data Principal voluntarily provided the data for a specified purpose and has not indicated objection. The walk-in customer who hands over a phone number to get a delivery update is here, not in a consent form.
- Section 7(i) — processing necessary for employment purposes, for safeguarding the employer from loss or liability, or for providing a service or benefit to the employee. Payroll, attendance, PF and ESI, background checks, insurance enrolment and access control all sit here. Do not route employee data through consent. Consent can be withdrawn under Section 6(4), and you cannot stop running payroll because someone clicked withdraw.
Three rules to enforce as you go. One purpose, one ground — if a dataset serves two purposes, it gets two rows. Necessity is the test for Section 7, so “useful for us” does not qualify. And when in doubt between a stretched Section 7 reading and clean Section 6 consent, take the consent — but only where withdrawal is survivable.
The Day 30 deliverable is a purpose register where every row has a section citation, and the count of rows without one is zero.
What do notices, consent and withdrawal look like in weeks 5–6?
Section 5 requires a notice that itemises the personal data being collected and the purpose of processing, and tells the Data Principal how to exercise their rights and how to complain to the Board. Rule 3 of the DPDP Rules, 2025 sharpens this: the notice must stand on its own, in clear and plain language, independent of anything else you have shown the user.
For an SMB, that means the era of the 3,000-word privacy policy as your only notice is over. You need short, contextual notices at the point of collection — at the enquiry form, at the onboarding screen, at the admission desk — plus the full policy behind them.
Build three artefacts in Days 31–45.
The itemised notice. For each collection point: what you collect (fields, not categories), why (the purpose from your register), how long, who else sees it, and how to withdraw or complain. If you cannot fit it in a paragraph, your purpose is too broad.
The consent record. Under Section 6, consent is only as good as your ability to prove it later. A record needs the version of the notice shown, the timestamp, the mechanism, the specific purposes consented to, and the identifier of the person. A consent = TRUE boolean in a user table is not a record, it is an assertion. This is where a cryptographically immutable log stops being a nice-to-have: what the Board will want is proof that the record was not edited after the complaint arrived.
The withdrawal path. Section 6(4) requires that withdrawing consent be as easy as giving it. Practically: one-tap opt-in means one-tap opt-out. A preferences screen the customer can reach without logging a ticket. And under Section 8(7), withdrawal triggers erasure — so the withdrawal button must actually reach your CRM, your email tool and your backups, not just flip a flag on your website.
Test at Day 45: pick one customer record, withdraw consent through the front door, and see how many systems still hold that data an hour later. The number should be zero, and it usually is not.
How do you stand up Data Principal rights and a dual-clock breach SOP before day 75?
Days 46–60 — rights. The Data Principal has the right to access information about their processing (Section 11), to correction, completion, updating and erasure (Section 12), and to grievance redressal (Section 13). Under Section 8(9) you must publish the business contact information of a Data Protection Officer or of the person who can answer questions on your behalf, and under Section 8(10) you must run an effective grievance mechanism. Rule 14 requires you to publish the means for making a rights request and the identifiers you will use to verify the requester.
One point that gets misread constantly: Rule 14(3)‘s ninety days is a ceiling on grievance response, not a licence to take ninety days on every rights request. Publish a period, then meet it. For an SMB, a 15-day access and correction turnaround is realistic and looks materially better in front of the Board.
Build the intake before the process: a single email alias or form that routes to a named person, an identity-verification step that does not collect more data than needed, a log with received-date, action-date and outcome, and a decline path with a reason. Then run three test requests through it — one access, one correction, one erasure — using real staff acting as strangers.
Days 61–75 — breach SOP. The single most common error in SMB breach plans is treating the clocks as alternatives. They run together — the same dual-clock pattern we walk for NBFCs.
| Clock | Trigger | Deadline | Goes to |
|---|---|---|---|
| CERT-In Direction (2022) | Noticing a reportable cyber incident | 6 hours | CERT-In |
| Rule 7, DPDP Rules 2025 — affected individuals | Becoming aware of a personal data breach | Without delay | Each affected Data Principal |
| Rule 7 — initial intimation to the Board | Becoming aware of the breach | Without delay | Data Protection Board |
| Rule 7 — detailed report to the Board | Becoming aware of the breach | 72 hours (extendable on request) | Data Protection Board |
Six hours is not enough time to decide who decides. Your runbook needs a named incident owner and a named deputy with phone numbers, a one-line trigger definition, pre-written templates for the CERT-In report, the Board intimation and the customer notification, and a rule that says the first report goes out on partial facts. Under Section 8(6) the duty is to intimate — not to intimate once you have completed root-cause analysis.
The Day 75 deliverable is a two-page runbook that a person on leave could execute, plus one tabletop drill with the timestamps recorded. The drill log is itself evidence.
What evidence will the Data Protection Board actually ask for?
Days 76–90 answer one question: if a complaint lands on 14 May 2027, what can you produce by Friday?
The Board does not inspect intentions. It inspects records. For an ordinary SMB Data Fiduciary — and note that the annual DPIA and independent audit under Rule 13 apply only to Significant Data Fiduciaries notified under Section 10, so this is almost certainly not you — the evidence pack has six parts:
- Notice evidence. The versioned text of every notice, with the date each version went live. Screenshots, not descriptions.
- Consent evidence. For a named individual: what they saw, when, what they agreed to, and proof the record has not been altered since.
- Withdrawal and erasure evidence. The request, the downstream deletions, and the timestamps.
- Rights evidence. The rights log with turnaround times against your published period, including declines and their reasons.
- Security evidence. What safeguards you implemented under Section 8(5) and when — access controls, encryption, logging. Rule 6 expects logs and monitoring retained for one year.
- Breach evidence. The runbook, the drill log, and any live incidents with the full dual-clock timeline.
This is where the architecture of your systems starts to matter more than the wording of your policies — see how Privigo works. A sealed PII vault means you can answer “where is this person’s data” with one query instead of a week of grep. Cryptographically immutable consent records mean the timestamp is defensible rather than assertable. An evidentiary-grade audit trail means the export you hand over is the record, not a summary someone assembled after the fact. That is the difference between a compliance programme and a compliance claim.
Then rehearse it once, before Day 90. Pick one real customer and one real employee. Produce their full file — notice version, ground, consent or Section 7 citation, rights history, retention clock — in under two hours. Whatever breaks in that rehearsal is your actual gap list, and it will not be the gap list you predicted on Day 1.
Closing
Start this quarter and Day 90 lands in mid-November 2026 — roughly six months before 13 May 2027, which is enough runway to fix what the rehearsal exposes without doing it in an enforcement window. The eighteen-month clock already started when the Rules were notified on 13 November 2025. Most SMBs we work with discover the same three things: the marketing list has rows nobody can source, employee data was routed through a consent form it never belonged in, and withdrawal stops at the website. All three are cheap to fix in 2026 and expensive to explain in 2027.
If you want the roadmap mapped against your actual systems rather than a generic checklist, we can walk it screen by screen — inventory, grounds, notices, rights, breach, evidence — in half an hour.
Book a 30-minute DPDPA discovery call →
Related reading: DPDPA compliance for Indian SMBs: the 2027 readiness picture · DPDPA vs GDPR for Indian SMBs · Employee data for Indian employers · Verifiable parental consent in schools · Dual-clock breach SOP
Frequently asked questions
Is 90 days actually enough for an SMB to get DPDPA-ready?
Yes, for most SMBs under 200 people with a handful of systems. Ninety days is enough to complete an inventory, assign a Section 6 consent or Section 7 legitimate use to every purpose, publish Section 5 notices, stand up rights and grievance handling under Sections 8(9) and 8(10), and rehearse a breach SOP once. It is not enough if you start in April 2027.
Do we need employee consent for HR and payroll data under the DPDPA?
No. Processing that is necessary for employment purposes — including safeguarding the employer from loss or liability and providing services or benefits to employees — sits under Section 7(i) as a legitimate use, not Section 6 consent. Consent collected here creates a withdrawal problem you do not need. Notice and security obligations still apply.
Is 13 May 2027 the real DPDPA compliance deadline for Indian SMBs?
Yes. The substantive obligations under the Digital Personal Data Protection Rules, 2025 — notice, consent, security safeguards, breach intimation, erasure and rights — commence on 13 May 2027, eighteen months after the Rules were notified on 13 November 2025. Consent Manager registration under Rule 4 commences earlier, on 13 November 2026.
Does an SMB have to run an annual DPDPA audit?
No. The annual Data Protection Impact Assessment and independent audit under Rule 13 of the DPDP Rules, 2025 apply only to Significant Data Fiduciaries notified under Section 10 of the Act. An ordinary SMB Data Fiduciary needs demonstrable records — notices, consent, withdrawal, rights requests, breach logs — not a certified annual audit.
Sources
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) — MeitY; Sections 5, 6, 7, 8, 9, 10, 11, 12, 13 and the Schedule of penalties.
- Digital Personal Data Protection Rules, 2025 — MeitY, G.S.R. 846(E), notified 13 November 2025. Rule 3 (notice), Rule 6 (reasonable security safeguards), Rule 7 (intimation of personal data breach), Rule 8 (erasure), Rule 13 (Significant Data Fiduciaries), Rule 14 (rights of Data Principals).
- Digital Personal Data Protection (DPDP) Rules, 2025 — Press Release — Press Information Bureau. Commencement: Rules 1, 2 and 17–21 on publication; Rule 4 one year after publication; Rules 3, 5–16, 22 and 23 eighteen months after publication (13 May 2027).
- Directions under Section 70B(6) of the Information Technology Act, 2000, dated 28 April 2022 — CERT-In / MeitY; six-hour incident reporting.
This guide is general information for Indian businesses, not legal advice. Confirm your specific obligations with counsel before relying on any position taken here.


