• Contact 1 : +16506441375
  • Contact 2 : +443308087384
  • Contact 3 : +4915735986750
  • Contact 3 : +46271809884
CYBERSECURITY

DPDP Act 2023: Is Your Organization Ready for 13 May 2027?

 

The Digital Personal Data Protection (DPDP) Act is moving organisations from simply “protecting data” to establishing a structured framework for how personal data is collected, used, stored, shared and managed.

For organizations operating in India, privacy and data protection can no longer be treated as an isolated IT or legal exercise. It requires coordinated action across technology, business processes, people, governance and third-party relationships.

And while the compliance journey may appear long, starting early is critical.

The Government of India notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025, with different provisions coming into force in phases. The 18-month provisions are scheduled to take effect on 13 May 2027.

So, the real question for organizations is not:

“When does the deadline arrive?”

It is:

“How ready are we today?”

What is the DPDP Act, 2023?

The Digital Personal Data Protection Act, 2023 establishes a legal framework governing the processing of digital personal data in India.

At its core, the Act focuses on responsible processing of personal data while recognizing the rights of individuals, referred to as Data Principals, and establishing obligations for organizations that determine the purpose and means of processing personal data, referred to as Data Fiduciaries.

The Act requires personal data to be processed for a lawful purpose, generally based on consent or certain legitimate uses. It also establishes requirements around notice, consent, security safeguards, breach-related responsibilities, data retention and rights of Data Principals.

This means DPDP compliance is not simply about installing another security tool.

It is about understanding what personal data your organization holds, why it is processing that data, where it resides, who has access to it, how long it is retained and how individuals can exercise their rights.

Is DPDP compliance only an IT responsibility?

No.

Technology plays an important role, but DPDP compliance cuts across the organization.

Consider a typical customer journey:

A customer provides personal information through a website → marketing uses the information → sales accesses it → CRM stores it → a third-party service provider processes it → analytics platforms may receive certain data → the organization eventually needs to determine whether and when that information should be retained or deleted.

Every step raises questions around privacy, governance, security and accountability.

That is why effective DPDP readiness requires collaboration between:

  • Business teams
  • IT and cybersecurity
  • Legal and compliance
  • HR
  • Marketing
  • Procurement
  • Data owners
  • Third-party/vendor management
  • Senior management

What does DPDP readiness mean?

Being “DPDP ready” is more than having a privacy policy on your website.

Organizations should evaluate their readiness across multiple dimensions.

  1. Data discovery and inventory

Do you know what personal data your organization collects and processes?

Can you identify where that data is stored and which systems, applications and vendors have access to it?

  1. Purpose and processing

Do you clearly understand why personal data is being collected and processed?

Is your processing activities aligned with the applicable legal basis and stated purpose?

  1. Notice and consent

Are individuals receiving appropriate information about the processing of their personal data?

Are consent mechanisms, where applicable, designed and managed appropriately?

  1. Data Principal rights

Can your organization effectively handle requests relating to the rights provided to Data Principals?

More importantly, do you have defined processes, ownership and technology support to respond consistently?

  1. Security safeguards

Are appropriate technical and organizational measures in place to protect personal data?

This includes areas such as access controls, security monitoring, incident management and data protection practices.

  1. Data retention and deletion

Do you know how long different categories of personal data are retained?

Do systems and processes support deletion or other required actions when retention is no longer necessary?

  1. Third-party and vendor risk

Your organization may not be the only entity processing personal data.

Cloud providers, SaaS platforms, marketing technology providers, payroll vendors, customer support platforms and other partners may also process personal data.

Their role in your data ecosystem needs to be understood and governed appropriately.

Common DPDP readiness gaps

Many organizations may discover that their biggest challenge is not a lack of policies, but a lack of visibility and operationalization.

Some common areas to examine include:

“We don’t have a complete inventory of personal data.”

“Different departments use different consent and data-handling practices.”

“Our privacy policy exists, but our operational processes haven’t caught up.”

“We don’t have a clearly defined process for Data Principal requests.”

“We don’t have complete visibility into third-party data processing.”

“Retention and deletion requirements are not consistently implemented.”

“Responsibility for privacy compliance isn’t clearly assigned.”

These gaps can become significantly harder to address when organizations wait until the last moment.

Why should organizations start now?

Successful DPDP implementation is rarely quick policy exercise.

It can involve:

Discover → Assess → Prioritize → Remediate → Implement → Validate → Monitor

Depending on the size and complexity of an organization, this can require coordination across multiple departments, systems, applications, vendors and business processes.

Starting early gives organizations the opportunity to:

  • Understand their current maturity
  • Identify compliance gaps
  • Prioritize high-risk areas
  • Assign clear ownership
  • Update policies and processes
  • Strengthen technical controls
  • Improve vendor governance
  • Establish processes for Data Principal requests
  • Test and validate their readiness

Most importantly, it allows organizations to approach compliance strategically rather than reactively.

A practical starting point: DPDP Readiness Assessment

Before investing heavily in implementation, organizations should first understand where they stand.

A structured DPDP Readiness Assessment can help answer questions such as:

Where are we today?

What are our key gaps?

Which areas require immediate attention?

What should we prioritize?

What capabilities, processes and controls need to be implemented?

Who should own each action?

The outcome should not simply be a long list of compliance requirements.

It should provide a practical roadmap, from the organization’s current state to its desired state of readiness.

Don’t wait for the deadline to start the journey

The DPDP journey should not begin when the deadline is approaching.

It should begin with understanding.

  • Know your data.
  • Know your obligations.
  • Know your gaps.
  • Know your priorities.

For organizations that have not yet assessed their DPDP readiness, now is a good time to start.

How Sphinx can help

Sphinx can support organizations across their DPDP journey, from understanding current maturity and identifying gaps to supporting implementation and audit readiness.

Our DPDP services can include:

  • DPDP Readiness Assessment
  • Gap Assessment
  • DPDP Consulting
  • Implementation Support
  • Data Protection Governance
  • Privacy & Security Controls
  • Audit and Compliance Support

The objective is simple:

Help organizations move from uncertainty to a structured, actionable DPDP compliance roadmap.

Is your organization ready for 13 May 2027?

Don’t wait until the deadline is close to discover your compliance gaps.

Start with a DPDP Readiness Assessment and understand where your organization stands today. Connect with Sphinx’s Cyber Security Practice to begin your DPDP readiness journey.

 

Leave a Reply

Your email address will not be published. Required fields are marked *