Live 17 practitioner certifications live · First lesson free on every course Back to main site →

The shape of a DPDP engagement, before anyone opens a Section

The whole 90-day programme fits on one slide. Four phases, four verbs, four checkpoints. Learn this shape before you learn a single Rule, because every operational decision in the next 89 days is really a decision about which phase you are currently in.

Free preview 11 min read Verified

A client once told me he had read every lesson of our Rules course twice, scored 91 on the final exam, and still watched his company's DPDP programme stall at Day 60. Discovery was done, RoPA was half-built, notice was drafted and sitting with the CMO, and the whole thing had the energy of a WhatsApp group where people have stopped replying. He asked me what he had missed.

He had not missed anything in the law. He had missed the shape of the engagement.

Why shape beats knowledge in the first week

DPDP is not a hard law. The DPDP Act 2023 is 44 Sections. The DPDP Rules 2025 are 23 Rules and 7 Schedules. A competent reader finishes both in an afternoon. The reason implementations stall is almost never that someone misread Section 8 [L1-C1]. It is that nobody drew the shape of the 90-day engagement on day one, so the programme developed a different shape every week depending on who last asked a question.

Think of the shape like this. Every DPDP engagement, no matter how big the company, has four phases. Each phase has one verb. Each phase ends in a checkpoint. If you cannot answer the question "which phase are we in and what verb is this week," you are drifting.

The four phases, with the four verbs

Phase A, Weeks 1 to 2 — Scope and Discover. The verb is find. You find the stakeholders, you find the budget, you find the data. By Day 15 you have a one-page scope document, a stakeholder RACI, and a draft data inventory. Nothing is correct yet. The point is that something exists.

Phase B, Weeks 3 to 6 — Build. The verb is produce. You produce the RoPA, the retention schedule, the Rule 3 standalone notice, the Section 6 consent flow, and the DSAR intake and workflow [L1-C2]. These are the five artifacts that an auditor will ask to see first, in that order. By Day 30 the RoPA and retention schedule should be signed off. By Day 45 the notice should be live. By Day 60 the DSAR workflow should be in staging.

Phase C, Weeks 7 to 10 — Harden. The verb is pressure-test. You run the vendor outreach, you sign the Section 8(2) DPAs, you draft the Rule 7 breach runbook, you execute a tabletop breach exercise, and if the company is a Significant Data Fiduciary or has high-risk processing, you run the DPIA [L1-C3]. This is the ugliest phase because real-world friction shows up. Vendors do not sign. Engineering pushes back on telemetry. Marketing wants to keep the pixel. Your job is to document friction, not pretend it does not exist.

Phase D, Weeks 11 to 13 — Handover. The verb is install. You install the 12-month DPO calendar, the board-reporting cadence, the KPI dashboard, and the audit evidence file. By Day 90 the client should be able to run the programme without you. If they still need you on Day 91, you built a dependency, not a programme.

Why 90 days is the right number

Clients ask three versions of the same question. Can you do it in 30 days. Can you do it in 60. Why not 180.

Thirty days does not clear a single engineering sprint cycle. Most Indian tech teams run two-week sprints. Any ask that requires a schema change, a telemetry audit, or a consent-flow rebuild needs at least two sprints, which is one month, and that is before you have found the right engineer to assign it to. Sixty days finishes the build phase but leaves no time to pressure-test and install. The programme technically ships and then collapses in Month 4 when the first vendor renewal lands and nobody owns the DPA review.

One hundred and eighty days is worse than you think. The problem is not calendar time. The problem is political attention. In an Indian SME or mid-market firm, a non-revenue project holds leadership attention for about one quarter. By Month 4 someone has launched a new product line, a key engineer has given notice, and a board meeting has pushed DPDP down from Item 3 to Item 11. Programmes that run past 90 days do not finish strong. They finish tired.

Ninety days is exactly one financial quarter. The CFO can slot a budget decision into one Board meeting. The CEO can report at the next. The programme fits inside one quarterly cycle of attention, and that is a feature, not a coincidence.

The one slide you will carry into every kickoff

Here is the slide. Four boxes left to right. Each box has a date range, a verb in bold, and three to five bullet points of what is produced. Phase A, Weeks 1-2, Find. Phase B, Weeks 3-6, Produce. Phase C, Weeks 7-10, Pressure-test. Phase D, Weeks 11-13, Install.

Below the four boxes, a timeline with four checkpoint markers. Day 15, Day 30, Day 60, Day 90. We will fill the checkpoints in Lesson 4 of this module.

When a client asks what we are doing this week, you point at a box. When the Board asks for a status update, you point at the checkpoint you most recently cleared. When Engineering asks why they are being asked for schema access on Day 8, you point at Phase A and say "find". The slide is boring on purpose. Boring slides do not get argued with.

Three ways this shape goes wrong in practice

I have seen each of these three times in the last eighteen months. Watch for them.

Shape mistake 1: Running phases in parallel from Day 1. A new consultant will try to start RoPA building in Week 1 because "we might as well". Do not do this. The RoPA built before Discovery is complete gets rebuilt in Week 4 when three new systems turn up that nobody mentioned. You do not save time. You just produce a RoPA twice.

Shape mistake 2: Skipping Phase C because the build "feels done". By Week 7 the artifacts look good and energy is high. The pressure-test phase feels like admin. It is not. It is where the vendor who told you he would sign the DPA says he actually cannot sign anything that uses the word "indemnity". It is where the breach runbook that read well on paper turns out to assume Engineering is on call at 2am when they are not. Pressure-testing is where DPDP programmes get real.

Shape mistake 3: Treating Phase D as "wrapping up". Handover is the entire reason the client paid. If the DPO calendar does not install, the client calls you back in Month 4 asking what to do about the first Rule 7 drill. That is not a renewal opportunity. That is a failure to transfer ownership.

Your artifact from Lesson 1

Nothing to produce yet. The artifact of this lesson is the picture in your head. Before you touch a Section, before you open a template, before you schedule the first stakeholder call, you should be able to close your eyes and see the four phases in order, with the four verbs attached, and know which phase you are entering. If you can do that, you are already ahead of the client who scored 91 on the Rules exam and still watched the programme stall at Day 60.

In the next lesson we build the one-page scope document that locks Phase A in place.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (58 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Act 2023, Section 8 (General obligations of Data Fiduciary) L1-C1
The Data Fiduciary is responsible for compliance regardless of any agreement to the contrary or Data Principal duty failure. Must engage Processors only under a valid contract. Must ensure data quality where the data will affect the Data Principal. Must implement reasonable security safeguards. Must intimate personal data breaches to the Board and affected Data Principals. Must erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. Must publish contact details of the Data Protection Officer or a designated person to answer queries.
DPDP Act 2023, Section 6 (Consent) L1-C2
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent. Consent may be given, managed, reviewed or withdrawn through a Consent Manager registered with the Board.
DPDP Rules 2025, Rule 13 (Additional obligations of Significant Data Fiduciary) L1-C3
A Significant Data Fiduciary must (a) undertake a Data Protection Impact Assessment and independent audit at least once every 12 months from the date of notification as SDF, and shall submit the results of the DPIA and audit and observations to the Board; (b) exercise due diligence to verify that algorithmic software deployed for hosting, display, uploading, modification, publishing, transmission, storage or sharing of personal data is not likely to pose a risk to the rights of the Data Principal; (c) undertake such measures as the Central Government may specify, including in relation to certain classes of personal data or traffic data that shall not be transferred outside India.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Programme in One Diagram — Scoping, Buy-In and the 90-Day Calendar
Module 2: Discovery Sprint — Finding Where Personal Data Actually Lives
  • Discovery interview questions that get engineering to actually tell you where data lives
  • Reading a database schema the way an auditor reads it
  • The four hiding places engineering always forgets to mention
  • File-share and cloud-storage scanning without buying a six-figure DLP
  • Building the draft data inventory that will survive Day 15
  • Discovery sign-off and the Day-15 stop-or-go decision pack
Module 3: Building the Records of Processing (RoPA) That Will Survive an Audit
  • The eight columns of a DPDP RoPA, and why no ninth belongs
  • Filling the RoPA from the Module 2 inventory, column by column
  • The three red-flag cells an auditor spots in the first sixty seconds
  • The twenty-minute RoPA walkthrough a DPB officer will ask you to run
  • ABC Tyres worked example: four RoPA rows, filled column by column
  • RoPA sign-off, the Day-30 Board update, and setting up Module 4
Module 4: Lawful Basis Mapping and the Retention Schedule
  • The lawful basis decision tree, and why "legitimate interest" is not an answer
  • The retention matrix, layered by sector, that defends every cell
  • The Third Schedule three-year inactivity rule and the 48-hour pre-erasure notice
  • Erasure requests and the "unless required by law" response
  • Getting the retention schedule signed off by Day 30
Module 5: Notice, Consent, Cookies and the Consent Manager Wire-Up
  • Drafting the Rule 3 standalone notice without turning it into a wall of text
  • The Section 6 consent flow and the auditable consent record
  • Cookies and tracking under DPDP, when the Act does not mention cookies
  • Multilingual notice under the Eighth Schedule: 22 languages, Claude AI, not Bhashini
  • The Rule 4 Consent Manager integration plan: live-frontier work
  • Going live: the Day-45 checklist that keeps the notice from embarrassing you
Module 6: DSAR Intake, Workflow and the 90-Day Clock
  • The DSAR intake form that collects what you need and nothing more
  • Identity verification without over-collection — three tiers, one decision tree
  • The 90-day clock, and why you must beat it, not touch it
  • The four response templates — grant, carve-out, refuse, escalate
  • Section 13 grievance and the Section 15 duty that handles bad-faith requests
Module 7: Vendor Risk, DPAs and the Cross-Border Register
  • The vendor risk register — ten columns, one row per vendor, nothing more
  • The ten DPA clauses you do not negotiate away
  • The Rule 15 cross-border decision log — four columns and the empty negative list
  • Three vendor conversations that go sideways — and the exact scripts
  • Section 17 exemptions — when they genuinely apply and when founders only think they do
  • The Day-75 cutoff — accept the risk, or kill-switch the vendor
Module 8: Breach Response — Running Rule 7 and CERT-In in Parallel
  • Classifying an incident as a personal data breach under Section 2(u)
  • Rule 7 Stage 1 — the "without delay" intimation to Data Principals and the Board
  • Rule 7 Stage 2 — the 72-hour detailed report to the Data Protection Board
  • The CERT-In six-hour parallel clock — filing twice without duplicating effort
  • The two-hour tabletop that turns a paper runbook into a tested one
Module 9: DPIA for High-Risk Processing and the SDF Playbook
  • Scoping a DPIA before Legal is the one asking you to run one
  • A risk-rating methodology that survives a Board meeting
  • Algorithmic due diligence for AI systems, worked on a credit-scoring model
  • The Rule 13 independent audit on a 12-month clock
  • The DPO role that survives a change of CEO
Module 10: DPO Operations — Calendar, Metrics and Board Reporting
  • The 12-month DPO calendar that keeps a programme alive after Day 91
  • Five KPIs that indicate programme health — and the gaming behaviour that corrupts each
  • Board reporting cadence and the six-slide deck that gets fifteen minutes well-spent
  • The budget renewal ask — how to argue for a 10 percent increase, not accept a 10 percent cut
  • The DPO handover document — what a departing DPO owes a successor
Module 11: Running the Programme (Not Just the Checklist) — Leadership, Politics and Making Engineering Say Yes
  • Running a steering committee that decides, not one that updates
  • Converting an engineering "no, not this quarter" into a scheduled Yes
  • Handling the marketing pixel removal fight without losing the CMO
  • Briefing a Board on DPDP risk in ten minutes and six slides
  • The three recurring cross-functional disputes and how to mediate each
  • When to escalate to the CEO, when to absorb, and how to escalate once
Module 12: Capstone — Run the Full Programme on ABC Tyres (Fictional) + Final Exam
  • ABC Tyres — the client brief and your Day-0 engagement plan
  • Walking the full ABC Tyres programme file end to end
  • Submitting your capstone and preparing for the final exam