Live 17 practitioner certifications live · First lesson free on every course Back to main site →

The 90-day Gantt with four checkpoint reviews baked in

Day 15, Day 30, Day 60 and Day 90. What each checkpoint is for, what gets signed off at each, and the three activities that look sequential but can run in parallel to save you two weeks of calendar time.

Free preview 11 min read Verified

A Gantt is only as useful as its checkpoints. A Gantt without checkpoints is a mural. The 90-day DPDP engagement has exactly four checkpoints, and if you run them well, the programme navigates itself. Miss a checkpoint and the next three slip by a week each.

Checkpoint 1 — Day 15, "Stop or Go"

This is the most important of the four checkpoints and the one most consultants skip. By Day 15 the Phase A verb (find) should be complete. You have the scope document signed. The RACI is live. The data inventory is a draft, not final, but it exists. Discovery interviews are done with the primary stakeholder set.

At Day 15 you ask one question in the steering call: are the facts on the ground consistent with the scope document we signed on Day 0? If they are, you proceed to Phase B. If they are not, you reopen the scope.

Four examples of what I have seen trigger a scope reopen at Day 15. The company said it had one customer-facing product but discovery found three. The company said employee data was in-scope but HR will not share Workday access. The company said no sensitive data was processed but marketing has been uploading phone numbers to a WhatsApp Business API vendor. The company said the Singapore entity was out of scope but every cross-border transfer flows through the Singapore DNS. Any of these means the scope needs an amendment, not that the project is failing. The failure is pretending the scope is still accurate when it is not.

If you skip the Day 15 checkpoint, you spend Week 4 building a RoPA against an outdated inventory and Week 7 rebuilding it. Do not skip it.

Checkpoint 2 — Day 30, "RoPA and Retention Sign-Off" plus Board Update 1

By Day 30 the two foundational artifacts are complete. The RoPA, built off the Day-15 inventory. The lawful-basis matrix and retention schedule, built off the RoPA. Both are presented in the steering call. The A column of the RACI signs off each row by name.

Sign-off is not "yes it looks fine". Sign-off is "yes, I accept that this is the record my organisation will present to a Data Protection Board officer if asked under Section 8" [L4-C1]. The language matters. You want the GC to say that sentence out loud. Record the meeting. Email the recording summary.

Day 30 is also the first Board update. Six slides, ten minutes. We write the Board deck template in Module 10. For now, remember: at Day 30 the Board sees the RoPA structure, the retention philosophy, and the risk register (preview). You are not asking the Board for a decision. You are keeping them in the loop so that at Day 60 and Day 90 they can approve what has already been socialised. Boards hate surprises. Pace the surprise.

Checkpoint 3 — Day 60, "Build Review" plus Board Update 2

At Day 60 the Phase B verb (produce) is complete. The Rule 3 standalone notice is live or staged [L4-C2]. The Section 6 consent flow is wired in staging. The DSAR intake and workflow are drafted and in staging. The vendor risk register is populated. Phase C has started with vendor DPA outreach in flight.

The Day 60 checkpoint is the first full audit dry run. You bring in either an internal audit lead or an external reviewer and walk through the artifacts as if the DPB had asked for them. The dry run surfaces the gaps you did not know you had. Expect to find three to five. That is normal. If you find none, your audit lead was being polite. Push harder.

Second Board update at Day 60. Same six slides, updated. Now the Board can see the notice (because it is live or imminently going live) and the Board can approve the retention philosophy formally. The ask is now narrower and specific: approve the retention schedule, approve the vendor DPA template, acknowledge the breach runbook. Three asks, three resolutions in the Board minutes. Programmes that get these three Board resolutions on paper by Day 60 almost never fail audit.

Checkpoint 4 — Day 90, "Handover and Audit File"

Day 90 is handover. The DPO 12-month calendar is live. The audit evidence file is assembled and indexed. The board deck template is handed to the DPO so she can run Board updates herself. The programme is officially the client's, not yours.

The handover meeting has one deliverable: the DPO can walk a hypothetical DPB officer through the whole programme in sixty minutes using only the audit evidence file. If she can, you are done. If she cannot, the file is incomplete and you have one more week of work, which is why you build in a one-week buffer between Day 90 and the final payment.

Day 90 is also the handshake moment where you offer the ongoing DPO-as-a-Service retainer or the Phase 2 engagement for the items you listed as out-of-scope in Field 2 of the scope document (Lesson 2). This offer is not pushy. It is a natural continuation. About 60 percent of clients take one or the other. The ones who do not are the ones you want to call in six months to ask how the first breach drill went.

Three activities that look sequential but can parallel-run

The naive Gantt runs every phase strictly serial: discover, then build, then harden, then install. In practice three activities can start earlier than they look, and the savings compound.

Vendor DPA outreach can start on Day 10, not Day 45. Vendors take four to six weeks to sign anything, so if you wait until Phase C to begin outreach, you are chasing signatures in Week 11. Start on Day 10 with a vendor-list dump from Procurement, send the Section 8(2) DPA template to the top ten vendors, and spend the next six weeks negotiating in the background. By Day 60 you have most signatures.

Breach runbook drafting can start on Day 20, not Day 60. The runbook does not need a complete RoPA. It needs a stakeholder list and an understanding of your incident-response team structure. Both exist by Day 20. Draft the runbook, run the Day-30 tabletop against it, iterate once, and by Day 60 you have a tested runbook instead of a first draft.

DPO 12-month calendar can be drafted on Day 60, not Day 85. The calendar is a repeatable rhythm. It does not depend on the specifics of this engagement. Draft it at Day 60, review with the DPO at Day 75, finalise at Day 85, operate from Day 90. This gives the DPO fifteen days of consultation time instead of five.

These three parallel-runs save about two weeks of calendar time across the engagement. In a programme where the hard constraint is one financial quarter, two weeks matters.

Sample: ABC Tyres 90-day Gantt (text view)

Below is the Gantt we would run for ABC Tyres, start date 15 October 2026, end date 12 January 2027. A real Gantt is a chart; the text view below is what a steering-call attendee reads to find out what week they are in and which deliverables are live. Study the overlaps. Discovery ends in Week 2, but vendor DPA outreach (Row 6) starts in Week 2 as a parallel-run. Breach runbook drafting (Row 8) starts in Week 3, not Week 9. Those two early starts are what makes 90 days feasible.

WeekDatesPhase / verbActive deliverablesCheckpoint
115-21 OctA — FindStakeholder interviews (all six). Scope doc signed Day 1. RACI drafted Day 3.—
222-28 OctA — FindData inventory draft (Row 1). Parallel-run: Vendor DPA outreach starts Day 10 (Row 6, top-10 vendor list from Procurement). Discovery questions reset per Lesson 5 Killer 1 counter-move.Day 15 — Stop/Go (29 Oct). Scope reconfirmed or amended.
329 Oct-4 NovB — ProduceRoPA build (Row 1). Lawful-basis matrix (Row 2). Parallel-run: Breach runbook drafting starts Day 20 (Row 8). Vendor DPA red-lines in flight.—
45-11 NovB — ProduceRetention schedule (Row 2). Rule 3 notice copy drafting (Row 3) begins. HR employee inventory (Row 9) begins.—
512-18 NovB — ProduceRoPA and retention schedule freeze. Rule 3 notice legal review (Row 3). Vendor DPA count: aim for 5 of 10 signed.Day 30 — RoPA sign-off + Board Update 1 (13 Nov).
619-25 NovB — ProduceConsent flow wiring (Row 4) in staging. DSAR intake form (Row 5) build. Breach runbook v1 complete; tabletop scheduled.—
726 Nov-2 DecC — Pressure-testRule 3 notice goes live. DSAR workflow (Row 5) staging. Marketing tracker reseq (Row 10) decision locked. Vendor DPA count: aim for 8 of 10.—
83-9 DecC — Pressure-testTabletop breach exercise run and recorded (Row 8). Cross-border register (Row 7) populated. DPIA scoping if SDF-triggered.—
910-16 DecC — Pressure-testAudit dry run preparation. Consent flow production cutover plan. Gaps from tabletop closed.Day 60 — Audit dry run + Board Update 2 (13 Dec). Three Board resolutions sought.
1017-23 DecC — Pressure-testDry-run findings remediated. Parallel-run: DPO 12-month calendar drafting starts Day 60 (Row 12). Vendor DPAs: all 10 signed or kill-switched.—
1124-30 DecD — InstallAudit evidence file assembly. DPO calendar review with Nandini. Board deck template handover. Low-traffic week — plan accordingly.—
1231 Dec-6 JanD — InstallKPI dashboard wiring. DPO walk-through rehearsal (dry run of the handover). DPO calendar finalised Day 85.—
137-12 JanD — InstallHandover meeting. Audit evidence file index approved. Final payment milestone. Phase-2 offer presented.Day 90 — Handover (12 Jan). Nandini runs the sixty-minute walk-through solo.

The three parallel-run activities (Row 6 vendor DPAs from Day 10, Row 8 breach runbook from Day 20, Row 12 DPO calendar from Day 60) are marked bold above. Together they save about two calendar weeks across the engagement.

Your artifact from Lesson 4

Open the Gantt template in the resource panel. Mark the four checkpoint dates for a hypothetical start date of 15 October (or adapt the sample above). Lay in the three parallel-run activities. Share with a peer and ask one question: at any point in the 90 days, can you point at the current week and name the active phase, the next checkpoint, and the two deliverables due inside the current week? If yes, your Gantt is ready. If no, you have gaps to close.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (58 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Act 2023, Section 8 (General obligations of Data Fiduciary) L4-C1
The Data Fiduciary is responsible for compliance regardless of any agreement to the contrary or Data Principal duty failure. Must engage Processors only under a valid contract. Must ensure data quality where the data will affect the Data Principal. Must implement reasonable security safeguards. Must intimate personal data breaches to the Board and affected Data Principals. Must erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. Must publish contact details of the Data Protection Officer or a designated person to answer queries.
DPDP Act 2023, Section 5 (Notice to Data Principal) L4-C2
Every consent request must be accompanied or preceded by a notice describing the personal data, purpose of processing, how to exercise rights, and how to complain to the Board. Notice must be available in English or any language listed in the Eighth Schedule.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Programme in One Diagram — Scoping, Buy-In and the 90-Day Calendar
Module 2: Discovery Sprint — Finding Where Personal Data Actually Lives
  • Discovery interview questions that get engineering to actually tell you where data lives
  • Reading a database schema the way an auditor reads it
  • The four hiding places engineering always forgets to mention
  • File-share and cloud-storage scanning without buying a six-figure DLP
  • Building the draft data inventory that will survive Day 15
  • Discovery sign-off and the Day-15 stop-or-go decision pack
Module 3: Building the Records of Processing (RoPA) That Will Survive an Audit
  • The eight columns of a DPDP RoPA, and why no ninth belongs
  • Filling the RoPA from the Module 2 inventory, column by column
  • The three red-flag cells an auditor spots in the first sixty seconds
  • The twenty-minute RoPA walkthrough a DPB officer will ask you to run
  • ABC Tyres worked example: four RoPA rows, filled column by column
  • RoPA sign-off, the Day-30 Board update, and setting up Module 4
Module 4: Lawful Basis Mapping and the Retention Schedule
  • The lawful basis decision tree, and why "legitimate interest" is not an answer
  • The retention matrix, layered by sector, that defends every cell
  • The Third Schedule three-year inactivity rule and the 48-hour pre-erasure notice
  • Erasure requests and the "unless required by law" response
  • Getting the retention schedule signed off by Day 30
Module 5: Notice, Consent, Cookies and the Consent Manager Wire-Up
  • Drafting the Rule 3 standalone notice without turning it into a wall of text
  • The Section 6 consent flow and the auditable consent record
  • Cookies and tracking under DPDP, when the Act does not mention cookies
  • Multilingual notice under the Eighth Schedule: 22 languages, Claude AI, not Bhashini
  • The Rule 4 Consent Manager integration plan: live-frontier work
  • Going live: the Day-45 checklist that keeps the notice from embarrassing you
Module 6: DSAR Intake, Workflow and the 90-Day Clock
  • The DSAR intake form that collects what you need and nothing more
  • Identity verification without over-collection — three tiers, one decision tree
  • The 90-day clock, and why you must beat it, not touch it
  • The four response templates — grant, carve-out, refuse, escalate
  • Section 13 grievance and the Section 15 duty that handles bad-faith requests
Module 7: Vendor Risk, DPAs and the Cross-Border Register
  • The vendor risk register — ten columns, one row per vendor, nothing more
  • The ten DPA clauses you do not negotiate away
  • The Rule 15 cross-border decision log — four columns and the empty negative list
  • Three vendor conversations that go sideways — and the exact scripts
  • Section 17 exemptions — when they genuinely apply and when founders only think they do
  • The Day-75 cutoff — accept the risk, or kill-switch the vendor
Module 8: Breach Response — Running Rule 7 and CERT-In in Parallel
  • Classifying an incident as a personal data breach under Section 2(u)
  • Rule 7 Stage 1 — the "without delay" intimation to Data Principals and the Board
  • Rule 7 Stage 2 — the 72-hour detailed report to the Data Protection Board
  • The CERT-In six-hour parallel clock — filing twice without duplicating effort
  • The two-hour tabletop that turns a paper runbook into a tested one
Module 9: DPIA for High-Risk Processing and the SDF Playbook
  • Scoping a DPIA before Legal is the one asking you to run one
  • A risk-rating methodology that survives a Board meeting
  • Algorithmic due diligence for AI systems, worked on a credit-scoring model
  • The Rule 13 independent audit on a 12-month clock
  • The DPO role that survives a change of CEO
Module 10: DPO Operations — Calendar, Metrics and Board Reporting
  • The 12-month DPO calendar that keeps a programme alive after Day 91
  • Five KPIs that indicate programme health — and the gaming behaviour that corrupts each
  • Board reporting cadence and the six-slide deck that gets fifteen minutes well-spent
  • The budget renewal ask — how to argue for a 10 percent increase, not accept a 10 percent cut
  • The DPO handover document — what a departing DPO owes a successor
Module 11: Running the Programme (Not Just the Checklist) — Leadership, Politics and Making Engineering Say Yes
  • Running a steering committee that decides, not one that updates
  • Converting an engineering "no, not this quarter" into a scheduled Yes
  • Handling the marketing pixel removal fight without losing the CMO
  • Briefing a Board on DPDP risk in ten minutes and six slides
  • The three recurring cross-functional disputes and how to mediate each
  • When to escalate to the CEO, when to absorb, and how to escalate once
Module 12: Capstone — Run the Full Programme on ABC Tyres (Fictional) + Final Exam
  • ABC Tyres — the client brief and your Day-0 engagement plan
  • Walking the full ABC Tyres programme file end to end
  • Submitting your capstone and preparing for the final exam