Live 17 practitioner certifications live · First lesson free on every course Back to main site →

Three programme killers that sink DPDP in week 2 — and the two-minute CFO pitch

Three specific failure modes I have watched sink DPDP programmes before Week 3, with the counter-move for each. Then the exact two-minute pitch that gets a sceptical CFO to sign the budget without a second meeting.

Free preview 12 min read Verified

Half of all DPDP programmes that fail did not reach Week 4. The usual story is that something broke in Week 2 and nobody fixed it, and by Week 3 the energy was gone. I have watched this three times in the last eighteen months. The same three killers each time. Learn to spot them and the programme survives its first month almost by default.

Killer 1 — Discovery produces nothing in Week 2

The pattern looks like this. You run three discovery interviews with Engineering in Week 1. Engineering shows up, nods, answers your questions. You leave feeling the meeting went well. In Week 2 you ask for the data inventory draft and the engineer sends you a spreadsheet with twelve rows. All twelve rows are the obvious systems. Nothing in the twelve rows is personal data you did not already know about from the website.

This is the single most common Week-2 failure. Engineering has not lied to you. Engineering has answered the specific questions you asked. If you asked "what databases hold customer data" you got the three obvious databases. You did not get the Zendesk attachments full of PAN card scans. You did not get the Google Sheet Sales uses for lead lists. You did not get the four-year-old S3 bucket nobody has permissions to delete.

The counter-move. Replace your Week-2 interview question set. Stop asking "where is personal data." Start asking three specific operational questions. First: "walk me through the last three support tickets you escalated to engineering. Where did the customer's identifying information live during that escalation?" Second: "when a sales rep emails a lead list to marketing, where does that list end up in your systems?" Third: "if we had a Data Principal erasure request for someone who last did business with us in 2021, which system of record would we check and which three would we probably forget to check?" These three questions produce the four hiding places that never make the first list.

I learned this from a client who nearly fired me in Week 2 because my inventory had fourteen rows and his Head of Support took one look and added seven. The Head of Support was right. The questions were wrong.

Killer 2 — Marketing has already shipped the thing you need undone

Week 2, Day 10 or so. You walk through the company's website and find a Meta Pixel, a GA4 tag, a Hotjar session recorder, a LinkedIn Insight Tag, and a Clearbit enrichment script. Each is dropping cookies before any consent interaction, and each is sending personal data to a vendor in the US [L5-C1]. Marketing shipped all of these over the last two years because performance dashboards needed them. The CMO is proud of the stack.

If you walk into the Day-15 steering call and announce that four of these have to come off before the Rule 3 notice goes live, you will lose. The CMO will say the stack is non-negotiable. The CEO will side with revenue. The programme stalls.

The counter-move. Do not frame it as removal. Frame it as sequencing. In the Day-15 call, show the CMO three options. Option A, hard-stop every tracker that drops data before consent. Option B, defer every tracker until after consent is captured (Consent Mode v2 pattern for GA4, OneTrust-style blocking tag for others). Option C, replace the tracker with a server-side equivalent that uses first-party data only. For each option, show the revenue-attribution impact (usually small, 2-5 percent) and the compliance posture.

Nine out of ten CMOs choose Option B. The one who chooses Option A does so because her CEO already told her to. Either way you have moved from "you have to kill marketing's stack" to "marketing picks the sequencing posture it is comfortable with." That reframe keeps the CMO on your side for the next eleven weeks.

Killer 3 — Legal is reviewing vendor DPAs "properly"

Week 2, you ask the GC when the first batch of vendor DPAs will be out. The GC says she is reviewing the Section 8(2) DPA template carefully to make sure clauses are tight [L5-C2]. In Week 4 you ask again. Still reviewing. In Week 6 the review is complete but outreach has not started. By Week 8 you are chasing vendor signatures with four weeks left in the engagement, and vendors take six weeks to sign.

Legal is not being obstructive. Legal is being Legal. The default pace of legal review is slower than the pace of a 90-day engagement, and that is a feature of good legal practice, not a bug. The programme has to work around it.

The counter-move. On Day 2 of the engagement, bring the GC a pre-drafted Section 8(2) DPA template. Tell her the ten clauses you consider non-negotiable (we cover each in Module 7) and tell her the rest is negotiable. Ask her for one week to red-line, not three. Agree in writing that outreach to the top ten vendors begins on Day 10 regardless of whether the red-line is complete, using a provisional template, and that the final template will drop in by Day 15.

The GC may push back on starting outreach before her review is final. The honest response is that vendor red-lines take six weeks of calendar time to resolve, and vendors do not refuse to sign a template because its wording was provisional at the moment of first contact. Vendors negotiate every DPA regardless. The template evolves through the negotiation. Starting late does not improve the template. It just starts the clock later.

The two-minute CFO pitch

CFOs do not want to hear about Sections and Rules. They want three numbers and a decision. Here is the pitch, verbatim, in the order I use it.

[Stage direction: Walk into the CFO's room with one printed page — the scope document from Lesson 2 — and nothing else. Sit, do not stand. Do not open a laptop.]

"We have one financial quarter to get our DPDP programme to audit-ready. The hard date is 13 May 2027, when the Rule 7 breach-reporting obligation and the retention regime become fully enforceable [L5-C3]. The Data Protection Board is operational. Section 33 and the Schedule cap monetary penalty at ₹250 crore for serious contraventions [L5-C4]."

[Pause for CFO reaction. If he nods, continue. If he frowns at the ₹250 crore, add one sentence: "That is the ceiling, not the base case. Star Health is the base-case reference." Then continue.]

"The two numbers you care about. First number, the cost of this programme: ₹18 lakh plus GST, phased 40/30/30 across 90 days. Second number, the cost of a late-reported breach, using Star Health as the public reference: regulatory scrutiny, listed-company disclosure consequences, class-action risk, and reputational cost that we can only estimate but that runs into eight digits in the India mid-market."

[Point at Row 7 of the scope document — the Timeline row — on the printed page. Keep the finger there for the next sentence.]

"The three asks. One, approve the ₹18 lakh budget on the schedule in Row 6. Two, name a Board sponsor who takes 30 minutes of my time once a month for three months — I am proposing Rakesh as sponsor. Three, let me present at the next Board meeting, which will be Day 30, so the Board stays informed. If you approve all three, we are audit-ready by Day 90 and ongoing operational cost after that is ₹6 lakh per year on retainer. If any of the three is a no, tell me which one and I will come back with options."

[Stop talking. Do not fill the silence. CFOs sign in the silence, not in the pitch.]

Two minutes. Three numbers (programme cost, breach exposure, ongoing run cost). Three asks (budget, sponsor, Board slot). CFOs sign this pitch more than 80 percent of the time on first hearing because it is honest, specific, and ends with asks instead of ambiguity. The silence at the end is doing more work than any of the words. Let it work.

Your artifact from Lesson 5

Write out your version of the CFO pitch for ABC Tyres, filling in the ₹X and ₹Y with plausible numbers for a 350-employee tyre manufacturer. Read it out loud, timed. If it runs longer than 150 seconds, cut. The pitch earns its name only when it fits in two minutes.

Module 1 is done. You now have the shape of the engagement, the scope document, the RACI, the Gantt, the three killer patterns and the CFO pitch. In Module 2 we leave planning behind and start finding where personal data actually lives.

The 2-click version

If you are a dcomply-app Privacy Suite tenant, your tenant workspace ships with the scope document, the RACI template, the Gantt and the breach-runbook starter in the Programme Setup section. Fill four fields in the New Engagement wizard and all four artifacts generate pre-populated with your tenant's context. If you would rather we run the whole 90-day engagement for you, Decipher does this as a done-for-you service: fixed-fee, 30 days to Day-30 checkpoint, your team keeps the audit evidence file on handover. See dcomply.in/decipher for pricing.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview complete You've read every free lesson in Module 1

Ready for the rest of DPDP Implementation Practitioner — 90 Days to Audit-Ready?

  • All 11 paid modules (58 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Lifetime access plus every future update
Inclusive of 18% GST. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Act 2023, Section 16 (Processing of personal data outside India) L5-C1
The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to countries or territories outside India. Nothing in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection or restriction on transfer.
DPDP Act 2023, Section 8 (General obligations of Data Fiduciary) L5-C2
The Data Fiduciary is responsible for compliance regardless of any agreement to the contrary or Data Principal duty failure. Must engage Processors only under a valid contract. Must ensure data quality where the data will affect the Data Principal. Must implement reasonable security safeguards. Must intimate personal data breaches to the Board and affected Data Principals. Must erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. Must publish contact details of the Data Protection Officer or a designated person to answer queries.
DPDP Rules 2025, Rule 7 (DPDP breach notification (parallel to CSCRF for personal data)) L5-C3
DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
DPDP Act 2023, Section 33 (Penalties for breach) L5-C4
The Board may impose penalty as specified in the Schedule. Factors to consider include nature/gravity/duration of breach, type of data affected, repetitive nature, gain avoided or loss suffered, mitigation, proportionality and impact. Penalty is credited to the Consolidated Fund of India.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: The Programme in One Diagram — Scoping, Buy-In and the 90-Day Calendar
Module 2: Discovery Sprint — Finding Where Personal Data Actually Lives
  • Discovery interview questions that get engineering to actually tell you where data lives
  • Reading a database schema the way an auditor reads it
  • The four hiding places engineering always forgets to mention
  • File-share and cloud-storage scanning without buying a six-figure DLP
  • Building the draft data inventory that will survive Day 15
  • Discovery sign-off and the Day-15 stop-or-go decision pack
Module 3: Building the Records of Processing (RoPA) That Will Survive an Audit
  • The eight columns of a DPDP RoPA, and why no ninth belongs
  • Filling the RoPA from the Module 2 inventory, column by column
  • The three red-flag cells an auditor spots in the first sixty seconds
  • The twenty-minute RoPA walkthrough a DPB officer will ask you to run
  • ABC Tyres worked example: four RoPA rows, filled column by column
  • RoPA sign-off, the Day-30 Board update, and setting up Module 4
Module 4: Lawful Basis Mapping and the Retention Schedule
  • The lawful basis decision tree, and why "legitimate interest" is not an answer
  • The retention matrix, layered by sector, that defends every cell
  • The Third Schedule three-year inactivity rule and the 48-hour pre-erasure notice
  • Erasure requests and the "unless required by law" response
  • Getting the retention schedule signed off by Day 30
Module 5: Notice, Consent, Cookies and the Consent Manager Wire-Up
  • Drafting the Rule 3 standalone notice without turning it into a wall of text
  • The Section 6 consent flow and the auditable consent record
  • Cookies and tracking under DPDP, when the Act does not mention cookies
  • Multilingual notice under the Eighth Schedule: 22 languages, Claude AI, not Bhashini
  • The Rule 4 Consent Manager integration plan: live-frontier work
  • Going live: the Day-45 checklist that keeps the notice from embarrassing you
Module 6: DSAR Intake, Workflow and the 90-Day Clock
  • The DSAR intake form that collects what you need and nothing more
  • Identity verification without over-collection — three tiers, one decision tree
  • The 90-day clock, and why you must beat it, not touch it
  • The four response templates — grant, carve-out, refuse, escalate
  • Section 13 grievance and the Section 15 duty that handles bad-faith requests
Module 7: Vendor Risk, DPAs and the Cross-Border Register
  • The vendor risk register — ten columns, one row per vendor, nothing more
  • The ten DPA clauses you do not negotiate away
  • The Rule 15 cross-border decision log — four columns and the empty negative list
  • Three vendor conversations that go sideways — and the exact scripts
  • Section 17 exemptions — when they genuinely apply and when founders only think they do
  • The Day-75 cutoff — accept the risk, or kill-switch the vendor
Module 8: Breach Response — Running Rule 7 and CERT-In in Parallel
  • Classifying an incident as a personal data breach under Section 2(u)
  • Rule 7 Stage 1 — the "without delay" intimation to Data Principals and the Board
  • Rule 7 Stage 2 — the 72-hour detailed report to the Data Protection Board
  • The CERT-In six-hour parallel clock — filing twice without duplicating effort
  • The two-hour tabletop that turns a paper runbook into a tested one
Module 9: DPIA for High-Risk Processing and the SDF Playbook
  • Scoping a DPIA before Legal is the one asking you to run one
  • A risk-rating methodology that survives a Board meeting
  • Algorithmic due diligence for AI systems, worked on a credit-scoring model
  • The Rule 13 independent audit on a 12-month clock
  • The DPO role that survives a change of CEO
Module 10: DPO Operations — Calendar, Metrics and Board Reporting
  • The 12-month DPO calendar that keeps a programme alive after Day 91
  • Five KPIs that indicate programme health — and the gaming behaviour that corrupts each
  • Board reporting cadence and the six-slide deck that gets fifteen minutes well-spent
  • The budget renewal ask — how to argue for a 10 percent increase, not accept a 10 percent cut
  • The DPO handover document — what a departing DPO owes a successor
Module 11: Running the Programme (Not Just the Checklist) — Leadership, Politics and Making Engineering Say Yes
  • Running a steering committee that decides, not one that updates
  • Converting an engineering "no, not this quarter" into a scheduled Yes
  • Handling the marketing pixel removal fight without losing the CMO
  • Briefing a Board on DPDP risk in ten minutes and six slides
  • The three recurring cross-functional disputes and how to mediate each
  • When to escalate to the CEO, when to absorb, and how to escalate once
Module 12: Capstone — Run the Full Programme on ABC Tyres (Fictional) + Final Exam
  • ABC Tyres — the client brief and your Day-0 engagement plan
  • Walking the full ABC Tyres programme file end to end
  • Submitting your capstone and preparing for the final exam