Every DPDP programme that stalls between Week 3 and Week 6 has the same autopsy. The DPO was Accountable for everything, so when three things slipped at once, there was nobody above the DPO who was willing to escalate. The RACI, if there was one, had six columns and nobody could read it. Fix the RACI and most of this disappears.
Why four columns, not six
Classic RACI has four roles. Accountable, Responsible, Consulted, Informed. One A per row, one or two Rs, however many Cs and Is make sense. Some consultants extend this to RASCI or RACIO or DACI. Please do not. I have never seen a six-column RACI used past Week 2. The columns start blending ("is the CFO Supportive or Consulted on retention?") and the document stops being a decision tool.
Four columns, strictly. One A per row, strictly.
Rows: one per deliverable, not one per task
The other common mistake is listing tasks instead of deliverables. A task-level RACI has four hundred rows and nobody reads it. A deliverable-level RACI has about twelve rows and sits on one page. We care about who owns the artifact, not who owns each click along the way.
Here are the ten deliverable rows that cover 90 percent of a DPDP engagement.
- Data inventory and RoPA
- Lawful basis matrix and retention schedule
- Rule 3 standalone privacy notice
[L3-C1] - Section 6 consent flow and Consent Manager plan
- DSAR intake form, workflow and response templates
- Vendor risk register and Section 8(2) DPAs
- Rule 15 cross-border transfer decision log
- Rule 7 breach runbook and tabletop exercise
[L3-C2] - DPIA for high-risk processing (where applicable)
- DPO 12-month calendar, KPIs and board deck
You can add two or three if the company has unusual constraints (an existing GDPR programme, an SDF designation, a specific sectoral overlay like RBI DGF), but keep the total under fifteen. Beyond fifteen the RACI becomes a project plan, which it is not supposed to be.
Who is Accountable for what
This is where most RACIs go wrong. The DPO is listed as Accountable for every row because the DPO is the obvious owner. But Accountable has a specific meaning. The Accountable person signs the deliverable off, approves spend, resolves blockers, and takes the hit if it fails. A DPO who is Accountable for ten deliverables cannot escalate anywhere, because the DPO is the top of the stack. That is exactly why programmes stall.
Here is a working split. Memorise it, defend it in kickoff, write it into the RACI.
- CEO or founder — Accountable for the programme itself (not for any single row) and Accountable for the breach runbook. Rationale: breach communication is the one deliverable that touches reputation and press, and the CEO must own it.
- General Counsel or Legal Head — Accountable for the Rule 3 notice, the Section 8(2) DPAs, and the Rule 15 cross-border decision log. Rationale: these are legally binding or publicly binding instruments.
- CTO or Head of Engineering — Accountable for the consent-flow wiring and the DSAR technical workflow. Rationale: these require engineering sign-off on telemetry, schema and integrations.
- CMO or Head of Marketing — Accountable for Rule 3 notice copy and the cookie-consent stance. Rationale: Marketing owns the surface where the notice lives, and Marketing owns the vendors who drop the pixels.
- Head of HR — Accountable for the employee data inventory row and the employee-side DSAR workflow where separate from consumer DSAR. Rationale: employee data is a different consent and lawful-basis story from customer data.
- DPO (you, usually) — Responsible for everything. Accountable for only one row: the DPO 12-month calendar and board deck.
Notice what this does. The DPO is Responsible for every row, which is correct, because the DPO is doing the work. But the DPO is Accountable for exactly one row, which gives the DPO five people above her to escalate to when something slips. Programmes with this RACI structure do not stall at Week 3.
Common RACI traps
Trap 1 — Nobody is Accountable because everybody is. If a row has two As, the row has no A. Pick one. If the client insists on two, the real conversation is which of the two actually makes the final call when the other says no. Make the client surface this. Do not paper over it.
Trap 2 — The CTO is Consulted on the DSAR tech workflow but not Accountable. This is a stall pattern. The CTO treats Consulted as "give an opinion when asked". The row needs the CTO as A. Make it clear in the kickoff that for engineering-heavy deliverables, Engineering owns the sign-off.
Trap 3 — Named person leaves and nobody updates the RACI. This happens roughly 40 percent of the time in a 90-day engagement because Indian tech teams churn fast. Add a two-line "amendments" footer to the RACI. When a named person leaves, you update the footer with the date and the replacement. Keep the history. It defuses arguments later.
Trap 4 — The RACI never gets used. If the RACI is written in Week 1 and then referred to zero times for the rest of the programme, it may as well not exist. Use it in every weekly steering call. When a row is slipping, point at the A column and ask the A directly. The whole value of a RACI is in Week 5 when a vendor DPA is three weeks late and you need to ask the GC, not the DPO, to escalate.
What a RACI call sounds like in Week 5
The whole point of writing the RACI in Week 1 is so that in Week 5, when something slips, you have a script. Here is roughly how the conversation goes in a steering call that is using the RACI properly.
DPO: "Row 6, vendor DPAs. We are three signatures short. The Accountable owner on this row is the GC. GC, where are the three outstanding?"
GC: "AWS and Zendesk are in red-line. The third is MoEngage, and MoEngage has not responded in ten days."
DPO: "On MoEngage, the Consulted role on this row is Procurement. Procurement, has your contract owner escalated the non-response?"
Procurement: "Not yet. I will do that today."
DPO: "Agreed. CEO, you are Informed on this row. We are now at risk on one of three signatures. If MoEngage does not respond this week we will need to decide between a kill-switch (move off MoEngage) and accepting the risk. I will put that decision in front of you next week with options."
Notice what just happened in that exchange. In sixty seconds, the DPO pulled a stuck deliverable, identified by name who was accountable, surfaced the one at-risk sub-item, assigned the escalation to the right role, and gave the CEO advance notice of a decision he would soon have to make. The DPO did not personally take on a single new action item. Every escalation was handed to the role listed in the RACI.
Programmes that run meetings like this hit Day 90. Programmes where every stuck item defaults back to the DPO do not. The difference is not the DPO's talent. It is the RACI.
Sample: ABC Tyres RACI (12 rows)
Below is the live RACI for ABC Tyres, filled with the stakeholders named in the Lesson 2 scope document. Twelve deliverable rows, named individuals in every cell. Rakesh Agarwal (MD), Vivek Khanna (GC), Praveen Kumar (Head of IT), Priya Shah (CMO), Anita Rao (Head of HR), Nandini Pillai (DPO), Deepak Mehta (CFO). Read it the way you would read it in a Week-5 steering call: when Row 6 is slipping, your eye should go straight to the A column.
| # | Deliverable | Accountable (A) | Responsible (R) | Consulted (C) | Informed (I) |
|---|---|---|---|---|---|
| 1 | Data inventory and RoPA | Vivek Khanna (GC) | Nandini Pillai (DPO) | Praveen Kumar, Anita Rao, Priya Shah | Rakesh Agarwal |
| 2 | Lawful basis matrix and retention schedule | Vivek Khanna (GC) | Nandini Pillai (DPO) | Deepak Mehta (CFO, on tax-retention) | Rakesh Agarwal |
| 3 | Rule 3 standalone privacy notice [L3-C1] | Priya Shah (CMO) for copy; Vivek Khanna (GC) for legal sign-off | Nandini Pillai (DPO) | Praveen Kumar (placement) | Rakesh Agarwal |
| 4 | Section 6 consent flow and Consent Manager plan | Praveen Kumar (Head of IT) | Nandini Pillai (DPO) | Priya Shah, Vivek Khanna | Rakesh Agarwal |
| 5 | DSAR intake form, workflow and response templates | Praveen Kumar (Head of IT) | Nandini Pillai (DPO) | Anita Rao (employee DSAR), Vivek Khanna | Rakesh Agarwal |
| 6 | Vendor risk register and Section 8(2) DPAs | Vivek Khanna (GC) | Nandini Pillai (DPO) | Praveen Kumar, Deepak Mehta (contract value) | Rakesh Agarwal |
| 7 | Rule 15 cross-border transfer decision log | Vivek Khanna (GC) | Nandini Pillai (DPO) | Praveen Kumar, Priya Shah (marketing vendors) | Rakesh Agarwal |
| 8 | Rule 7 breach runbook and tabletop [L3-C2] | Rakesh Agarwal (MD) | Nandini Pillai (DPO) | Vivek Khanna, Praveen Kumar, Priya Shah | Deepak Mehta |
| 9 | Employee data inventory and HR-side DSAR | Anita Rao (Head of HR) | Nandini Pillai (DPO) | Praveen Kumar, Vivek Khanna | Rakesh Agarwal |
| 10 | Marketing cookie-consent and tracker stance | Priya Shah (CMO) | Nandini Pillai (DPO) | Praveen Kumar, Vivek Khanna | Rakesh Agarwal |
| 11 | Budget approvals and quarterly spend review | Deepak Mehta (CFO) | Nandini Pillai (DPO) | Rakesh Agarwal | Vivek Khanna |
| 12 | DPO 12-month calendar, KPIs and Board deck | Nandini Pillai (DPO) | Nandini Pillai (DPO) | Vivek Khanna, Rakesh Agarwal | Deepak Mehta, Priya Shah, Anita Rao, Praveen Kumar |
Count the As. Vivek Khanna is A on five rows (legal-binding instruments). Praveen Kumar is A on two rows (engineering-dependent). Priya Shah, Anita Rao, Deepak Mehta and Rakesh Agarwal are each A on one. Nandini Pillai is A on exactly one row — her own calendar. She is R on all twelve. That is the shape of a RACI that lets a DPO sleep.
Amendments footer. 15 Oct 2026 — original. (No amendments yet. When Praveen Kumar's deputy Suresh Iyer takes over Rows 4-5 in Week 7, record it here with date.)
Your artifact from Lesson 3
Fill in the RACI template from the resource panel for ABC Tyres (or adapt the sample above for your own client). Stress-test by picking three rows and asking, out loud, "if this slips in Week 4, who do I call?" If the answer is clean for all three, your RACI works. If the answer is "the DPO, I guess" for all three, your RACI needs to go back to the kickoff.