A client once told me he had read every lesson of our Rules course twice, scored 91 on the final exam, and still watched his company's DPDP programme stall at Day 60. Discovery was done, RoPA was half-built, notice was drafted and sitting with the CMO, and the whole thing had the energy of a WhatsApp group where people have stopped replying. He asked me what he had missed.
He had not missed anything in the law. He had missed the shape of the engagement.
Why shape beats knowledge in the first week
DPDP is not a hard law. The DPDP Act 2023 is 44 Sections. The DPDP Rules 2025 are 23 Rules and 7 Schedules. A competent reader finishes both in an afternoon. The reason implementations stall is almost never that someone misread Section 8 [L1-C1]. It is that nobody drew the shape of the 90-day engagement on day one, so the programme developed a different shape every week depending on who last asked a question.
Think of the shape like this. Every DPDP engagement, no matter how big the company, has four phases. Each phase has one verb. Each phase ends in a checkpoint. If you cannot answer the question "which phase are we in and what verb is this week," you are drifting.
The four phases, with the four verbs
Phase A, Weeks 1 to 2 — Scope and Discover. The verb is find. You find the stakeholders, you find the budget, you find the data. By Day 15 you have a one-page scope document, a stakeholder RACI, and a draft data inventory. Nothing is correct yet. The point is that something exists.
Phase B, Weeks 3 to 6 — Build. The verb is produce. You produce the RoPA, the retention schedule, the Rule 3 standalone notice, the Section 6 consent flow, and the DSAR intake and workflow [L1-C2]. These are the five artifacts that an auditor will ask to see first, in that order. By Day 30 the RoPA and retention schedule should be signed off. By Day 45 the notice should be live. By Day 60 the DSAR workflow should be in staging.
Phase C, Weeks 7 to 10 — Harden. The verb is pressure-test. You run the vendor outreach, you sign the Section 8(2) DPAs, you draft the Rule 7 breach runbook, you execute a tabletop breach exercise, and if the company is a Significant Data Fiduciary or has high-risk processing, you run the DPIA [L1-C3]. This is the ugliest phase because real-world friction shows up. Vendors do not sign. Engineering pushes back on telemetry. Marketing wants to keep the pixel. Your job is to document friction, not pretend it does not exist.
Phase D, Weeks 11 to 13 — Handover. The verb is install. You install the 12-month DPO calendar, the board-reporting cadence, the KPI dashboard, and the audit evidence file. By Day 90 the client should be able to run the programme without you. If they still need you on Day 91, you built a dependency, not a programme.
Why 90 days is the right number
Clients ask three versions of the same question. Can you do it in 30 days. Can you do it in 60. Why not 180.
Thirty days does not clear a single engineering sprint cycle. Most Indian tech teams run two-week sprints. Any ask that requires a schema change, a telemetry audit, or a consent-flow rebuild needs at least two sprints, which is one month, and that is before you have found the right engineer to assign it to. Sixty days finishes the build phase but leaves no time to pressure-test and install. The programme technically ships and then collapses in Month 4 when the first vendor renewal lands and nobody owns the DPA review.
One hundred and eighty days is worse than you think. The problem is not calendar time. The problem is political attention. In an Indian SME or mid-market firm, a non-revenue project holds leadership attention for about one quarter. By Month 4 someone has launched a new product line, a key engineer has given notice, and a board meeting has pushed DPDP down from Item 3 to Item 11. Programmes that run past 90 days do not finish strong. They finish tired.
Ninety days is exactly one financial quarter. The CFO can slot a budget decision into one Board meeting. The CEO can report at the next. The programme fits inside one quarterly cycle of attention, and that is a feature, not a coincidence.
The one slide you will carry into every kickoff
Here is the slide. Four boxes left to right. Each box has a date range, a verb in bold, and three to five bullet points of what is produced. Phase A, Weeks 1-2, Find. Phase B, Weeks 3-6, Produce. Phase C, Weeks 7-10, Pressure-test. Phase D, Weeks 11-13, Install.
Below the four boxes, a timeline with four checkpoint markers. Day 15, Day 30, Day 60, Day 90. We will fill the checkpoints in Lesson 4 of this module.
When a client asks what we are doing this week, you point at a box. When the Board asks for a status update, you point at the checkpoint you most recently cleared. When Engineering asks why they are being asked for schema access on Day 8, you point at Phase A and say "find". The slide is boring on purpose. Boring slides do not get argued with.
Three ways this shape goes wrong in practice
I have seen each of these three times in the last eighteen months. Watch for them.
Shape mistake 1: Running phases in parallel from Day 1. A new consultant will try to start RoPA building in Week 1 because "we might as well". Do not do this. The RoPA built before Discovery is complete gets rebuilt in Week 4 when three new systems turn up that nobody mentioned. You do not save time. You just produce a RoPA twice.
Shape mistake 2: Skipping Phase C because the build "feels done". By Week 7 the artifacts look good and energy is high. The pressure-test phase feels like admin. It is not. It is where the vendor who told you he would sign the DPA says he actually cannot sign anything that uses the word "indemnity". It is where the breach runbook that read well on paper turns out to assume Engineering is on call at 2am when they are not. Pressure-testing is where DPDP programmes get real.
Shape mistake 3: Treating Phase D as "wrapping up". Handover is the entire reason the client paid. If the DPO calendar does not install, the client calls you back in Month 4 asking what to do about the first Rule 7 drill. That is not a renewal opportunity. That is a failure to transfer ownership.
Your artifact from Lesson 1
Nothing to produce yet. The artifact of this lesson is the picture in your head. Before you touch a Section, before you open a template, before you schedule the first stakeholder call, you should be able to close your eyes and see the four phases in order, with the four verbs attached, and know which phase you are entering. If you can do that, you are already ahead of the client who scored 91 on the Rules exam and still watched the programme stall at Day 60.
In the next lesson we build the one-page scope document that locks Phase A in place.