Half of all DPDP programmes that fail did not reach Week 4. The usual story is that something broke in Week 2 and nobody fixed it, and by Week 3 the energy was gone. I have watched this three times in the last eighteen months. The same three killers each time. Learn to spot them and the programme survives its first month almost by default.
Killer 1 — Discovery produces nothing in Week 2
The pattern looks like this. You run three discovery interviews with Engineering in Week 1. Engineering shows up, nods, answers your questions. You leave feeling the meeting went well. In Week 2 you ask for the data inventory draft and the engineer sends you a spreadsheet with twelve rows. All twelve rows are the obvious systems. Nothing in the twelve rows is personal data you did not already know about from the website.
This is the single most common Week-2 failure. Engineering has not lied to you. Engineering has answered the specific questions you asked. If you asked "what databases hold customer data" you got the three obvious databases. You did not get the Zendesk attachments full of PAN card scans. You did not get the Google Sheet Sales uses for lead lists. You did not get the four-year-old S3 bucket nobody has permissions to delete.
The counter-move. Replace your Week-2 interview question set. Stop asking "where is personal data." Start asking three specific operational questions. First: "walk me through the last three support tickets you escalated to engineering. Where did the customer's identifying information live during that escalation?" Second: "when a sales rep emails a lead list to marketing, where does that list end up in your systems?" Third: "if we had a Data Principal erasure request for someone who last did business with us in 2021, which system of record would we check and which three would we probably forget to check?" These three questions produce the four hiding places that never make the first list.
I learned this from a client who nearly fired me in Week 2 because my inventory had fourteen rows and his Head of Support took one look and added seven. The Head of Support was right. The questions were wrong.
Killer 2 — Marketing has already shipped the thing you need undone
Week 2, Day 10 or so. You walk through the company's website and find a Meta Pixel, a GA4 tag, a Hotjar session recorder, a LinkedIn Insight Tag, and a Clearbit enrichment script. Each is dropping cookies before any consent interaction, and each is sending personal data to a vendor in the US [L5-C1]. Marketing shipped all of these over the last two years because performance dashboards needed them. The CMO is proud of the stack.
If you walk into the Day-15 steering call and announce that four of these have to come off before the Rule 3 notice goes live, you will lose. The CMO will say the stack is non-negotiable. The CEO will side with revenue. The programme stalls.
The counter-move. Do not frame it as removal. Frame it as sequencing. In the Day-15 call, show the CMO three options. Option A, hard-stop every tracker that drops data before consent. Option B, defer every tracker until after consent is captured (Consent Mode v2 pattern for GA4, OneTrust-style blocking tag for others). Option C, replace the tracker with a server-side equivalent that uses first-party data only. For each option, show the revenue-attribution impact (usually small, 2-5 percent) and the compliance posture.
Nine out of ten CMOs choose Option B. The one who chooses Option A does so because her CEO already told her to. Either way you have moved from "you have to kill marketing's stack" to "marketing picks the sequencing posture it is comfortable with." That reframe keeps the CMO on your side for the next eleven weeks.
Killer 3 — Legal is reviewing vendor DPAs "properly"
Week 2, you ask the GC when the first batch of vendor DPAs will be out. The GC says she is reviewing the Section 8(2) DPA template carefully to make sure clauses are tight [L5-C2]. In Week 4 you ask again. Still reviewing. In Week 6 the review is complete but outreach has not started. By Week 8 you are chasing vendor signatures with four weeks left in the engagement, and vendors take six weeks to sign.
Legal is not being obstructive. Legal is being Legal. The default pace of legal review is slower than the pace of a 90-day engagement, and that is a feature of good legal practice, not a bug. The programme has to work around it.
The counter-move. On Day 2 of the engagement, bring the GC a pre-drafted Section 8(2) DPA template. Tell her the ten clauses you consider non-negotiable (we cover each in Module 7) and tell her the rest is negotiable. Ask her for one week to red-line, not three. Agree in writing that outreach to the top ten vendors begins on Day 10 regardless of whether the red-line is complete, using a provisional template, and that the final template will drop in by Day 15.
The GC may push back on starting outreach before her review is final. The honest response is that vendor red-lines take six weeks of calendar time to resolve, and vendors do not refuse to sign a template because its wording was provisional at the moment of first contact. Vendors negotiate every DPA regardless. The template evolves through the negotiation. Starting late does not improve the template. It just starts the clock later.
The two-minute CFO pitch
CFOs do not want to hear about Sections and Rules. They want three numbers and a decision. Here is the pitch, verbatim, in the order I use it.
[Stage direction: Walk into the CFO's room with one printed page — the scope document from Lesson 2 — and nothing else. Sit, do not stand. Do not open a laptop.]
"We have one financial quarter to get our DPDP programme to audit-ready. The hard date is 13 May 2027, when the Rule 7 breach-reporting obligation and the retention regime become fully enforceable
[L5-C3]. The Data Protection Board is operational. Section 33 and the Schedule cap monetary penalty at ₹250 crore for serious contraventions[L5-C4]."[Pause for CFO reaction. If he nods, continue. If he frowns at the ₹250 crore, add one sentence: "That is the ceiling, not the base case. Star Health is the base-case reference." Then continue.]
"The two numbers you care about. First number, the cost of this programme: ₹18 lakh plus GST, phased 40/30/30 across 90 days. Second number, the cost of a late-reported breach, using Star Health as the public reference: regulatory scrutiny, listed-company disclosure consequences, class-action risk, and reputational cost that we can only estimate but that runs into eight digits in the India mid-market."
[Point at Row 7 of the scope document — the Timeline row — on the printed page. Keep the finger there for the next sentence.]
"The three asks. One, approve the ₹18 lakh budget on the schedule in Row 6. Two, name a Board sponsor who takes 30 minutes of my time once a month for three months — I am proposing Rakesh as sponsor. Three, let me present at the next Board meeting, which will be Day 30, so the Board stays informed. If you approve all three, we are audit-ready by Day 90 and ongoing operational cost after that is ₹6 lakh per year on retainer. If any of the three is a no, tell me which one and I will come back with options."
[Stop talking. Do not fill the silence. CFOs sign in the silence, not in the pitch.]
Two minutes. Three numbers (programme cost, breach exposure, ongoing run cost). Three asks (budget, sponsor, Board slot). CFOs sign this pitch more than 80 percent of the time on first hearing because it is honest, specific, and ends with asks instead of ambiguity. The silence at the end is doing more work than any of the words. Let it work.
Your artifact from Lesson 5
Write out your version of the CFO pitch for ABC Tyres, filling in the ₹X and ₹Y with plausible numbers for a 350-employee tyre manufacturer. Read it out loud, timed. If it runs longer than 150 seconds, cut. The pitch earns its name only when it fits in two minutes.
Module 1 is done. You now have the shape of the engagement, the scope document, the RACI, the Gantt, the three killer patterns and the CFO pitch. In Module 2 we leave planning behind and start finding where personal data actually lives.
The 2-click version
If you are a dcomply-app Privacy Suite tenant, your tenant workspace ships with the scope document, the RACI template, the Gantt and the breach-runbook starter in the Programme Setup section. Fill four fields in the New Engagement wizard and all four artifacts generate pre-populated with your tenant's context. If you would rather we run the whole 90-day engagement for you, Decipher does this as a done-for-you service: fixed-fee, 30 days to Day-30 checkpoint, your team keeps the audit evidence file on handover. See dcomply.in/decipher for pricing.