Live 17 practitioner certifications live · First lesson free on every course Back to main site →

The stakeholder RACI that actually works (and the trap in a six-column RACI)

Four columns, one row per deliverable, six names on the page. The one trap that makes most RACIs useless, and the specific A/R assignments for the ten big DPDP deliverables that stop the DPO from drowning in Week 3.

Free preview 10 min read Verified

Every DPDP programme that stalls between Week 3 and Week 6 has the same autopsy. The DPO was Accountable for everything, so when three things slipped at once, there was nobody above the DPO who was willing to escalate. The RACI, if there was one, had six columns and nobody could read it. Fix the RACI and most of this disappears.

Why four columns, not six

Classic RACI has four roles. Accountable, Responsible, Consulted, Informed. One A per row, one or two Rs, however many Cs and Is make sense. Some consultants extend this to RASCI or RACIO or DACI. Please do not. I have never seen a six-column RACI used past Week 2. The columns start blending ("is the CFO Supportive or Consulted on retention?") and the document stops being a decision tool.

Four columns, strictly. One A per row, strictly.

Rows: one per deliverable, not one per task

The other common mistake is listing tasks instead of deliverables. A task-level RACI has four hundred rows and nobody reads it. A deliverable-level RACI has about twelve rows and sits on one page. We care about who owns the artifact, not who owns each click along the way.

Here are the ten deliverable rows that cover 90 percent of a DPDP engagement.

  1. Data inventory and RoPA
  2. Lawful basis matrix and retention schedule
  3. Rule 3 standalone privacy notice [L3-C1]
  4. Section 6 consent flow and Consent Manager plan
  5. DSAR intake form, workflow and response templates
  6. Vendor risk register and Section 8(2) DPAs
  7. Rule 15 cross-border transfer decision log
  8. Rule 7 breach runbook and tabletop exercise [L3-C2]
  9. DPIA for high-risk processing (where applicable)
  10. DPO 12-month calendar, KPIs and board deck

You can add two or three if the company has unusual constraints (an existing GDPR programme, an SDF designation, a specific sectoral overlay like RBI DGF), but keep the total under fifteen. Beyond fifteen the RACI becomes a project plan, which it is not supposed to be.

Who is Accountable for what

This is where most RACIs go wrong. The DPO is listed as Accountable for every row because the DPO is the obvious owner. But Accountable has a specific meaning. The Accountable person signs the deliverable off, approves spend, resolves blockers, and takes the hit if it fails. A DPO who is Accountable for ten deliverables cannot escalate anywhere, because the DPO is the top of the stack. That is exactly why programmes stall.

Here is a working split. Memorise it, defend it in kickoff, write it into the RACI.

  • CEO or founder — Accountable for the programme itself (not for any single row) and Accountable for the breach runbook. Rationale: breach communication is the one deliverable that touches reputation and press, and the CEO must own it.
  • General Counsel or Legal Head — Accountable for the Rule 3 notice, the Section 8(2) DPAs, and the Rule 15 cross-border decision log. Rationale: these are legally binding or publicly binding instruments.
  • CTO or Head of Engineering — Accountable for the consent-flow wiring and the DSAR technical workflow. Rationale: these require engineering sign-off on telemetry, schema and integrations.
  • CMO or Head of Marketing — Accountable for Rule 3 notice copy and the cookie-consent stance. Rationale: Marketing owns the surface where the notice lives, and Marketing owns the vendors who drop the pixels.
  • Head of HR — Accountable for the employee data inventory row and the employee-side DSAR workflow where separate from consumer DSAR. Rationale: employee data is a different consent and lawful-basis story from customer data.
  • DPO (you, usually) — Responsible for everything. Accountable for only one row: the DPO 12-month calendar and board deck.

Notice what this does. The DPO is Responsible for every row, which is correct, because the DPO is doing the work. But the DPO is Accountable for exactly one row, which gives the DPO five people above her to escalate to when something slips. Programmes with this RACI structure do not stall at Week 3.

Common RACI traps

Trap 1 — Nobody is Accountable because everybody is. If a row has two As, the row has no A. Pick one. If the client insists on two, the real conversation is which of the two actually makes the final call when the other says no. Make the client surface this. Do not paper over it.

Trap 2 — The CTO is Consulted on the DSAR tech workflow but not Accountable. This is a stall pattern. The CTO treats Consulted as "give an opinion when asked". The row needs the CTO as A. Make it clear in the kickoff that for engineering-heavy deliverables, Engineering owns the sign-off.

Trap 3 — Named person leaves and nobody updates the RACI. This happens roughly 40 percent of the time in a 90-day engagement because Indian tech teams churn fast. Add a two-line "amendments" footer to the RACI. When a named person leaves, you update the footer with the date and the replacement. Keep the history. It defuses arguments later.

Trap 4 — The RACI never gets used. If the RACI is written in Week 1 and then referred to zero times for the rest of the programme, it may as well not exist. Use it in every weekly steering call. When a row is slipping, point at the A column and ask the A directly. The whole value of a RACI is in Week 5 when a vendor DPA is three weeks late and you need to ask the GC, not the DPO, to escalate.

What a RACI call sounds like in Week 5

The whole point of writing the RACI in Week 1 is so that in Week 5, when something slips, you have a script. Here is roughly how the conversation goes in a steering call that is using the RACI properly.

DPO: "Row 6, vendor DPAs. We are three signatures short. The Accountable owner on this row is the GC. GC, where are the three outstanding?"

GC: "AWS and Zendesk are in red-line. The third is MoEngage, and MoEngage has not responded in ten days."

DPO: "On MoEngage, the Consulted role on this row is Procurement. Procurement, has your contract owner escalated the non-response?"

Procurement: "Not yet. I will do that today."

DPO: "Agreed. CEO, you are Informed on this row. We are now at risk on one of three signatures. If MoEngage does not respond this week we will need to decide between a kill-switch (move off MoEngage) and accepting the risk. I will put that decision in front of you next week with options."

Notice what just happened in that exchange. In sixty seconds, the DPO pulled a stuck deliverable, identified by name who was accountable, surfaced the one at-risk sub-item, assigned the escalation to the right role, and gave the CEO advance notice of a decision he would soon have to make. The DPO did not personally take on a single new action item. Every escalation was handed to the role listed in the RACI.

Programmes that run meetings like this hit Day 90. Programmes where every stuck item defaults back to the DPO do not. The difference is not the DPO's talent. It is the RACI.

Sample: ABC Tyres RACI (12 rows)

Below is the live RACI for ABC Tyres, filled with the stakeholders named in the Lesson 2 scope document. Twelve deliverable rows, named individuals in every cell. Rakesh Agarwal (MD), Vivek Khanna (GC), Praveen Kumar (Head of IT), Priya Shah (CMO), Anita Rao (Head of HR), Nandini Pillai (DPO), Deepak Mehta (CFO). Read it the way you would read it in a Week-5 steering call: when Row 6 is slipping, your eye should go straight to the A column.

# Deliverable Accountable (A) Responsible (R) Consulted (C) Informed (I)
1Data inventory and RoPAVivek Khanna (GC)Nandini Pillai (DPO)Praveen Kumar, Anita Rao, Priya ShahRakesh Agarwal
2Lawful basis matrix and retention scheduleVivek Khanna (GC)Nandini Pillai (DPO)Deepak Mehta (CFO, on tax-retention)Rakesh Agarwal
3Rule 3 standalone privacy notice [L3-C1]Priya Shah (CMO) for copy; Vivek Khanna (GC) for legal sign-offNandini Pillai (DPO)Praveen Kumar (placement)Rakesh Agarwal
4Section 6 consent flow and Consent Manager planPraveen Kumar (Head of IT)Nandini Pillai (DPO)Priya Shah, Vivek KhannaRakesh Agarwal
5DSAR intake form, workflow and response templatesPraveen Kumar (Head of IT)Nandini Pillai (DPO)Anita Rao (employee DSAR), Vivek KhannaRakesh Agarwal
6Vendor risk register and Section 8(2) DPAsVivek Khanna (GC)Nandini Pillai (DPO)Praveen Kumar, Deepak Mehta (contract value)Rakesh Agarwal
7Rule 15 cross-border transfer decision logVivek Khanna (GC)Nandini Pillai (DPO)Praveen Kumar, Priya Shah (marketing vendors)Rakesh Agarwal
8Rule 7 breach runbook and tabletop [L3-C2]Rakesh Agarwal (MD)Nandini Pillai (DPO)Vivek Khanna, Praveen Kumar, Priya ShahDeepak Mehta
9Employee data inventory and HR-side DSARAnita Rao (Head of HR)Nandini Pillai (DPO)Praveen Kumar, Vivek KhannaRakesh Agarwal
10Marketing cookie-consent and tracker stancePriya Shah (CMO)Nandini Pillai (DPO)Praveen Kumar, Vivek KhannaRakesh Agarwal
11Budget approvals and quarterly spend reviewDeepak Mehta (CFO)Nandini Pillai (DPO)Rakesh AgarwalVivek Khanna
12DPO 12-month calendar, KPIs and Board deckNandini Pillai (DPO)Nandini Pillai (DPO)Vivek Khanna, Rakesh AgarwalDeepak Mehta, Priya Shah, Anita Rao, Praveen Kumar

Count the As. Vivek Khanna is A on five rows (legal-binding instruments). Praveen Kumar is A on two rows (engineering-dependent). Priya Shah, Anita Rao, Deepak Mehta and Rakesh Agarwal are each A on one. Nandini Pillai is A on exactly one row — her own calendar. She is R on all twelve. That is the shape of a RACI that lets a DPO sleep.

Amendments footer. 15 Oct 2026 — original. (No amendments yet. When Praveen Kumar's deputy Suresh Iyer takes over Rows 4-5 in Week 7, record it here with date.)

Your artifact from Lesson 3

Fill in the RACI template from the resource panel for ABC Tyres (or adapt the sample above for your own client). Stress-test by picking three rows and asking, out loud, "if this slips in Week 4, who do I call?" If the answer is clean for all three, your RACI works. If the answer is "the DPO, I guess" for all three, your RACI needs to go back to the kickoff.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 11 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 11 paid modules (58 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Act 2023, Section 5 (Notice to Data Principal) L3-C1
Every consent request must be accompanied or preceded by a notice describing the personal data, purpose of processing, how to exercise rights, and how to complain to the Board. Notice must be available in English or any language listed in the Eighth Schedule.
DPDP Rules 2025, Rule 7 (DPDP breach notification (parallel to CSCRF for personal data)) L3-C2
DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Programme in One Diagram — Scoping, Buy-In and the 90-Day Calendar
Module 2: Discovery Sprint — Finding Where Personal Data Actually Lives
  • Discovery interview questions that get engineering to actually tell you where data lives
  • Reading a database schema the way an auditor reads it
  • The four hiding places engineering always forgets to mention
  • File-share and cloud-storage scanning without buying a six-figure DLP
  • Building the draft data inventory that will survive Day 15
  • Discovery sign-off and the Day-15 stop-or-go decision pack
Module 3: Building the Records of Processing (RoPA) That Will Survive an Audit
  • The eight columns of a DPDP RoPA, and why no ninth belongs
  • Filling the RoPA from the Module 2 inventory, column by column
  • The three red-flag cells an auditor spots in the first sixty seconds
  • The twenty-minute RoPA walkthrough a DPB officer will ask you to run
  • ABC Tyres worked example: four RoPA rows, filled column by column
  • RoPA sign-off, the Day-30 Board update, and setting up Module 4
Module 4: Lawful Basis Mapping and the Retention Schedule
  • The lawful basis decision tree, and why "legitimate interest" is not an answer
  • The retention matrix, layered by sector, that defends every cell
  • The Third Schedule three-year inactivity rule and the 48-hour pre-erasure notice
  • Erasure requests and the "unless required by law" response
  • Getting the retention schedule signed off by Day 30
Module 5: Notice, Consent, Cookies and the Consent Manager Wire-Up
  • Drafting the Rule 3 standalone notice without turning it into a wall of text
  • The Section 6 consent flow and the auditable consent record
  • Cookies and tracking under DPDP, when the Act does not mention cookies
  • Multilingual notice under the Eighth Schedule: 22 languages, Claude AI, not Bhashini
  • The Rule 4 Consent Manager integration plan: live-frontier work
  • Going live: the Day-45 checklist that keeps the notice from embarrassing you
Module 6: DSAR Intake, Workflow and the 90-Day Clock
  • The DSAR intake form that collects what you need and nothing more
  • Identity verification without over-collection — three tiers, one decision tree
  • The 90-day clock, and why you must beat it, not touch it
  • The four response templates — grant, carve-out, refuse, escalate
  • Section 13 grievance and the Section 15 duty that handles bad-faith requests
Module 7: Vendor Risk, DPAs and the Cross-Border Register
  • The vendor risk register — ten columns, one row per vendor, nothing more
  • The ten DPA clauses you do not negotiate away
  • The Rule 15 cross-border decision log — four columns and the empty negative list
  • Three vendor conversations that go sideways — and the exact scripts
  • Section 17 exemptions — when they genuinely apply and when founders only think they do
  • The Day-75 cutoff — accept the risk, or kill-switch the vendor
Module 8: Breach Response — Running Rule 7 and CERT-In in Parallel
  • Classifying an incident as a personal data breach under Section 2(u)
  • Rule 7 Stage 1 — the "without delay" intimation to Data Principals and the Board
  • Rule 7 Stage 2 — the 72-hour detailed report to the Data Protection Board
  • The CERT-In six-hour parallel clock — filing twice without duplicating effort
  • The two-hour tabletop that turns a paper runbook into a tested one
Module 9: DPIA for High-Risk Processing and the SDF Playbook
  • Scoping a DPIA before Legal is the one asking you to run one
  • A risk-rating methodology that survives a Board meeting
  • Algorithmic due diligence for AI systems, worked on a credit-scoring model
  • The Rule 13 independent audit on a 12-month clock
  • The DPO role that survives a change of CEO
Module 10: DPO Operations — Calendar, Metrics and Board Reporting
  • The 12-month DPO calendar that keeps a programme alive after Day 91
  • Five KPIs that indicate programme health — and the gaming behaviour that corrupts each
  • Board reporting cadence and the six-slide deck that gets fifteen minutes well-spent
  • The budget renewal ask — how to argue for a 10 percent increase, not accept a 10 percent cut
  • The DPO handover document — what a departing DPO owes a successor
Module 11: Running the Programme (Not Just the Checklist) — Leadership, Politics and Making Engineering Say Yes
  • Running a steering committee that decides, not one that updates
  • Converting an engineering "no, not this quarter" into a scheduled Yes
  • Handling the marketing pixel removal fight without losing the CMO
  • Briefing a Board on DPDP risk in ten minutes and six slides
  • The three recurring cross-functional disputes and how to mediate each
  • When to escalate to the CEO, when to absorb, and how to escalate once
Module 12: Capstone — Run the Full Programme on ABC Tyres (Fictional) + Final Exam
  • ABC Tyres — the client brief and your Day-0 engagement plan
  • Walking the full ABC Tyres programme file end to end
  • Submitting your capstone and preparing for the final exam