The Path · From the Field

7 Steps From Zero to DPDP Compliant

A founder can reach DPDP compliance through seven steps in a fixed order: audit, law, technology, officer, paperwork, recapture, breach readiness.

In one line

A founder can reach DPDP compliance through seven steps in a fixed order: audit, law, technology, officer, paperwork, recapture, breach readiness.

Step 1: Audit your data

List every piece of personal data you hold: customer and employee, every form field, every database table, every spreadsheet. Record where it lives, how it is secured, and every third party that touches it. Our DPDP checklist walks the full audit. Every later step depends on this one.

Step 2: Understand how the law applies to you

Work out your role: Data Fiduciary for the data you decide about, Data Processor where you handle it for others, and whether the Significant Data Fiduciary thresholds catch you. The obligations flow from the role.

Step 3: Make the technology and operations changes

Consent capture per purpose, secure storage, access controls, and working withdrawal sync. Buy tools only after the audit names the problem each tool solves. Start with what a consent manager is and the setup tax before any purchase. Companies that buy tools first usually buy twice.

Step 4: Appoint your accountable person

Decide who owns compliance: a full-time DPO, a fractional one, or the founder. The CA test settles it in five questions.

Step 5: Get the paperwork right

A privacy policy that describes what your business actually does, and a Data Processing Agreement with every vendor that touches personal data. Templates copied from the internet fail the moment a regulator compares the policy to your practice.

Step 6: Recapture consent from existing customers

Your legacy base needs a notice or fresh consent depending on how it was collected. This is the slowest step in the whole programme, so it starts early. The full method: consent recapture.

Step 7: Prepare for the breach before it happens

A personal data breach triggers notification duties on a short clock. Write the incident plan, assign the roles, pre-draft the notification emails, and test the backups while things are calm.

The order matters

The audit in step 1 feeds every decision after it: which tools you need, who should own the role, what the policy must say, and how big the recapture campaign is. Sector detail lives in the guides for fintech, D2C brands, restaurants, and SMEs.

Start this week

1

Open a sheet and start the step 1 data inventory today.

2

Name the single owner of the compliance programme.

3

Put the enforcement deadline and your start date on one calendar.

Next step

Step 1 in ten minutes: see what your stack holds and where the gaps are.

Run the free DPDP audit →

Related reading

Sushant Pasumarty

Written by Sushant Pasumarty

DPDP consultant. Founder, Meridian Bridge Strategy. This page began as field notes from live client work.