By Himanshu Gautam, Founder & CEO of GoTrust.
Most enterprises start their DPDP journey with a checklist. Appoint a grievance officer. Update the privacy policy. Add a consent banner. Run a data audit. Tick, tick, tick, done.
Then they actually try to do it, and the checklist falls apart.
The Digital Personal Data Protection Act, 2023 became operational law on November 13, 2025, when the DPDP Rules were notified and the Data Protection Board of India came into being. Full substantive enforcement lands on May 13, 2027, and the Consent Manager framework activates this November. That sounds like a generous runway. In practice, enterprises with sprawling legacy systems, multi-vendor data chains, and years of accumulated digital sprawl are discovering that 18 months is a compressed timeline, not a comfortable one, and that compliance is less a checklist and more an excavation.
The gap between “policy exists” and “policy works”
A privacy policy is a document. DPDP compliance is an operating system. That distinction is where most enterprise compliance programs quietly stall.
Consider what a survey of Indian firms recently surfaced: for roughly a third of respondents, DPDP compliance costs could exceed 10 percent of turnover, a number substantial enough to make leadership pause the whole initiative. And as of early 2026, DPDP omits “legitimate interest” as a lawful basis for processing, a provision that exists under GDPR and that a majority of surveyed firms did not realise was missing until they tried to map their existing consent flows against it. Assumptions borrowed from a GDPR program do not transfer cleanly. Neither do assumptions borrowed from a checklist.
Here is what actually has to happen underneath the checklist item that just says “map your data”:
Personal data does not live where you think it does. It is scattered across CRMs, HR systems, marketing tools, cloud storage, SharePoint sites, endpoint folders, email threads, forgotten databases, and archived backups nobody has opened in years. Enterprises typically discover that a large share of this, some estimates put unstructured data at over 80 percent of what a company holds, sits in formats standard discovery tools were never built to scan. You cannot protect, retain-limit, or delete data you cannot see. Most enterprises do not know how much of their data estate is actually invisible to them until they try to build a real inventory.
Data maps go stale almost as fast as you build them. In a modern tech stack built on microservices and constantly shipping product changes, a data flow map drawn in January can be obsolete by March. A one-time audit produces a snapshot of a moving target. Enterprises that treat data mapping as a project with an end date find themselves reauditing every few months, which is exactly the kind of manual, repetitive burden that burns out compliance teams and never quite catches up.
Consent is rarely centralized, even when it looks like it is. Consent gets collected through the website, the mobile app, the CRM, third-party marketing tools, call centre scripts, and offline forms, often with no single system tracking what was actually agreed to, when, for what purpose, and whether it was later withdrawn. Under DPDP, every one of those consent events needs a lawful basis, a version history, and a way for someone to revoke it just as easily as they gave it. Stitching that together after the fact, across five or six disconnected tools, is where compliance timelines quietly slip by months.
Legacy systems were not built for this law. Older core systems, especially in BFSI, healthcare, and manufacturing, frequently lack the modular architecture needed to support purpose-bound access or automated retention and deletion. Enterprises end up needing external privacy layers, tokenization, encryption gateways, key management, wrapped around systems that cannot be rearchitected on a DPDP timeline. That is not a policy fix. It is an infrastructure investment most checklists never mention.
Vendor chains multiply the exposure. A breach at a third-party processor is still the enterprise’s liability. Yet most organisations have limited visibility into their subprocessors, let alone their sub-processors’ sub-processors. Weak vendor oversight is now one of the most cited reasons enterprises fail to contain a breach’s blast radius, both financially and in terms of the mandatory notification clock.
Breach response is a coordination problem, not just a technical one. DPDP requires notifying both the Board and affected individuals, with penalties up to 200 crore for delayed or missing notification. But breach detection depends on real-time monitoring that many enterprises still lack, and once a breach is detected, the response usually has to move across IT, security, legal, and communications teams simultaneously. Without a rehearsed workflow linking identity systems, security tooling, and legal sign-off, that coordination happens for the first time during an actual crisis, which is the worst possible time to build a process from scratch.
AI adds a layer nobody budgeted for. As enterprises push data into AI pipelines, model training sets, and analytics platforms, personal data increasingly moves through systems with no DPDP controls attached at all. Anonymisation before processing, access controls for data science teams who typically want broad permissions by default, and retention discipline inside continuously learning models are all new problems that a 2023-era compliance checklist never anticipated.
Why the checklist mindset fails
None of the items above are exotic edge cases. They are the default condition of any enterprise old enough to have accumulated real scale. And they share a common thread: each one requires continuous operational capability, not a one-time fix. A checklist gets ticked once. Data flows change every sprint. Vendors rotate. New tools get adopted. Consent gets collected in a hundred small moments a day, not once at signup.
This is precisely why manual, spreadsheet-driven compliance efforts consistently fall behind, no matter how diligent the team running them is. When data discovery, consent tracking, vendor risk scoring, retention automation, and breach workflows all live in separate systems maintained by separate people, the seams between them are where compliance actually breaks. Enterprises that have made real progress are the ones that stopped trying to hold this together manually and instead built, or adopted, unified infrastructure: automated discovery that keeps scanning as the data estate changes, a consent layer that syncs across every channel in real time, policy and retention rules enforced programmatically instead of by memory, and vendor risk continuously monitored rather than reviewed once a year during audit season.
The real takeaway
DPDP was written as a technology-neutral law, but achieving it in practice is fundamentally a technology and operations problem. The enterprises struggling most are not the ones that misunderstand the law. They are the ones who treated it as a documentation exercise when it actually demands a rebuilt data operating model. The ones pulling ahead are treating discovery, consent, and governance as living infrastructure that runs continuously in the background, not a folder of policies updated once a year before an audit.
The checklist was never the finish line. It was the table of contents for a much longer, much harder book, and most enterprises are only now realising how many chapters are left.
