Back to blog
Compliance

DPDP Compliance Timeline (2026) | Step-by-Step Roadmap

Learn a practical DPDP compliance timeline for startups and businesses. Follow this 90-day roadmap to prepare your organization for India's data protection law.

Bilal Shaikh
July 23, 2026
11 min read

DPDP Compliance Timeline (2026)

One of the biggest questions founders ask is:

"How long does DPDP compliance take?"

The honest answer: it depends on your business.

A startup with one product and ten employees can usually establish a basic privacy program much faster than an enterprise with multiple departments, legacy systems, and thousands of customers.

The good news: you don't need to finish everything in one week. DPDP compliance works best as a structured project with clear milestones — and you have until 13 May 2027 for full compliance under the Act and DPDP Rules notified 13 November 2025.

This guide provides a practical 90-day implementation roadmap you can adapt. It mirrors the week-by-week plan in DPDPKit's compliance workbook.

Related guides: Compliance checklist · Ultimate guide (2026) · DPDP Rules explained · Free readiness check · DPDPKit


Table of contents


Why You Need a Compliance Timeline

Many companies fail because they try to "be compliant" without a plan. Instead, break the work into manageable phases:

  • Understand your data
  • Identify gaps
  • Create documentation
  • Improve processes
  • Train employees
  • Review regularly through May 2027

A roadmap makes the project measurable and easier to manage — and gives you a defensible answer when investors or enterprise buyers ask about your privacy posture.

Start here: Take the free 50-question readiness check to baseline your gaps before Week 1.


Before You Begin

Before creating your timeline, collect information about:

  • Website URLs and mobile apps
  • Customer database and CRM
  • HR and payroll software
  • Cloud providers and hosting
  • Analytics and marketing tools
  • Payment gateways
  • Email and support platforms
  • Third-party vendors and subprocessors

You'll use this throughout the project. DPDPKit's Data Inventory tab is built to capture exactly this.


Phase 1 — Assessment (Week 1–2)

The first step is understanding your current situation — not writing policies.

Objectives

  • Identify all personal data (customers, employees, leads, vendors)
  • Map systems and data flows
  • Identify gaps against the DPDP compliance checklist
  • Review existing documentation

Activities

  • Identify customer and user data
  • Identify employee and HR data
  • Identify vendor and partner contacts
  • List every software platform that holds personal data
  • Review website forms and signup flows
  • Review mobile app permissions and collection
  • Identify third-party services (analytics, ads, support)
  • Run gap assessment — score each of 50 requirements

Deliverables

  • Data Inventory (v1)
  • System and vendor list
  • Gap Assessment scored in workbook — target knowing your top 3 gaps

DPDPKit template: Data Inventory tab + Gap Assessment tab


Phase 2 — Documentation (Week 3–4)

Once you know what data you process, document your privacy program.

Public documents

  • Privacy Policy (DPDP-aligned, not copied GDPR)
  • Itemised Consent Notice
  • Cookie / tracking notice (where applicable)

Internal documents

  • Employee Privacy Notice
  • Data Retention Schedule
  • Data Breach Response SOP (72-hour Board reporting)
  • Grievance Officer Appointment and Charter
  • Vendor Register
  • Rights Request Register
  • Security policy aligned to your stack

Deliverables

  • Privacy Policy drafted from template
  • Grievance Officer appointed and contact published
  • Vendor Register populated
  • Data Inventory complete with purposes column
  • Internal policies reviewed by counsel or CA

DPDPKit templates: All 11 Word documents + workbook registers


Phase 3 — Implementation (Week 5–8)

Put policies into practice across product, website, and operations.

Website and product

Review and update:

  • Contact and newsletter forms
  • Signup and login flows
  • Checkout and payment pages
  • Consent withdrawal mechanism
  • Account deletion or erasure flow

Mobile apps

Review registration, permissions, consent flows, profile management, and account deletion.

Internal systems

Review CRM, HR software, payroll, customer support, and marketing automation for data handling alignment.

Vendor management

For each processor (AWS, GCP, Azure, Razorpay, Stripe, HubSpot, Freshdesk, etc.):

  • Document what data they process and why
  • Send DPA for signature
  • Log in Vendor Register
  • Note cross-border storage locations

Deliverables

  • Live consent flows with versioned logging
  • DPAs out for signature (target 80%+ signed by Week 8)
  • Rights request intake channel live
  • Grievance Officer contact visible on site and in policy

Phase 4 — Testing (Week 9–10)

Test your processes before you consider implementation complete.

Rights requests

Verify someone can:

  • Request access to their data
  • Request correction
  • Request erasure (where applicable)
  • Withdraw consent
  • Reach the Grievance Officer

Log each test in the Rights Request Register.

Security

Review MFA, backups, encryption in transit, password policies, role-based access, and log retention.

Incident response

Run a 1-hour tabletop exercise. Example scenario:

"A vulnerable dependency exposes customer emails. No evidence of exploitation yet."

Ask: Who detects it? Who investigates? When do you notify users? When do you intimate the Board? Where is the 72-hour report template?

Log the drill in your Breach Register — including near-misses.

Deliverables

  • Successful test export and erasure runbook
  • Tabletop drill notes and fixes assigned
  • Gap Assessment re-run — target 80%+ Done

Phase 5 — Continuous Improvement (Weeks 11–12)

Privacy is ongoing — not a one-time project before May 2027.

Monthly

  • Review new vendors
  • Review access permissions
  • Review breach register and incidents
  • Update documentation for product changes

Quarterly (through May 2027)

  • Re-run Gap Assessment
  • Review policies and retention schedules
  • Audit consent mechanisms
  • Refresh vendor DPAs where needed

Annually

  • Comprehensive privacy review
  • Security assessment
  • Employee awareness training refresh
  • Documentation update

Deliverables

  • Quarterly review calendar booked through May 2027
  • Employee training completed
  • SDF self-assessment recorded (if applicable)
  • Final gap assessment ≥ 80% — dashboard green

90-Day Compliance Roadmap

Summary view. For week-by-week tasks with owners and status columns, use the 90-Day Roadmap tab in DPDPKit.

Days 1–15 — Discover

  • Build data inventory across all systems
  • List vendors and subprocessors
  • Review website and mobile app collection
  • Run initial gap assessment

Days 16–30 — Document

  • Draft Privacy Policy, consent notices, employee notice
  • Appoint Grievance Officer
  • Populate Vendor Register and retention schedule
  • Draft breach SOP with 72-hour Board reporting

Days 31–60 — Implement

  • Ship consent UI changes and consent logging
  • Send DPAs; chase signatures
  • Publish rights channels and start DSR Tracker
  • Close top security gaps (MFA, logs, masking)

Days 61–90 — Validate

  • Test access, erasure, and consent withdrawal
  • Run breach tabletop drill
  • Train team; document decisions on under-18 users if applicable
  • Re-run gap assessment; schedule quarterly reviews

Suggested project timeline

Week Goal Key deliverable
1 Data discovery Data Inventory v1
2 Gap assessment Scored gap list + priorities
3 Core documentation Draft Privacy Policy + notices
4 Governance Grievance Officer live
5 Consent implementation Live consent flow + logging
6 Rights handling Export + erase runbook tested
7 Security Top gap items → Done
8 Vendors DPAs ≥ 80% signed
9 Breach readiness Tabletop drill completed
10 HR and children Employee notice + under-18 decision
11 Training and SDF Team trained; assessment recorded
12 Review Gap ≥ 80%; quarterly calendar set

Who Should Be Involved?

DPDP compliance is cross-functional.

Role Responsibility
Founder / CEO Owns strategy, resources, Grievance Officer appointment
Product Customer journeys, consent flows, account deletion
Engineering Consent logging, deletion APIs, access controls, security
HR Employee data, privacy notice, offboarding deletion
Operations Workbook tracking, vendor chase, register maintenance
Legal / CA Policy review and sign-off (recommended before publishing)

You do not need a dedicated compliance team at startup stage — you need a named owner and a workbook.


Milestones

By the end of 90 days you should have:

  • Data Inventory complete
  • Privacy Policy published (counsel-reviewed)
  • Itemised Consent Notice live
  • Grievance Officer appointed and published
  • Vendor Register with DPAs ≥ 80% signed
  • Employee Privacy Notice adopted
  • Data Retention Schedule in force
  • Rights Request Register active
  • Breach Register and SOP tested
  • Gap Assessment ≥ 80% Done on dashboard
  • Quarterly review calendar through May 2027

Get the workbook and templates →


Common Mistakes

Many businesses:

  • Start writing policies before understanding their data
  • Ignore third-party vendors and DPAs
  • Forget employee records and HR systems
  • Keep data indefinitely without retention schedules
  • Skip Grievance Officer appointment
  • Never test erasure or breach procedures
  • Treat compliance as a one-time task instead of ongoing through May 2027
  • Use the January 2025 draft Rules instead of the November 2025 notified Rules

A phased roadmap reduces these issues. See also: Common mistakes in our pillar guide.


Frequently Asked Questions

Can I complete DPDP compliance in one week?

You may draft initial documents quickly, but implementing governance, reviewing systems, and embedding processes usually takes several weeks.

Is 90 days enough?

For many startups, a focused 90-day project provides a practical foundation. Larger or more complex organisations may need 8–12 weeks or longer — but should still finish before 13 May 2027.

Should I hire a consultant?

Many startups self-implement using templates and a workbook, with counsel or CA review at the end. Consulting firms often quote ₹3–5 lakh for full implementation; DPDPKit starts at ₹4,999 for the document and workbook layer.

Should privacy reviews continue after implementation?

Yes. Products, vendors, and processing activities change. Schedule quarterly reviews through May 2027 and at least annually after that.

Can I use spreadsheets?

Yes. Many startups begin with structured spreadsheets and registers. DPDPKit's 8-tab workbook is designed for this stage and tracks % complete on the dashboard.


Get DPDPKit

Building all of this manually takes time. DPDPKit includes the templates and workbook this timeline references:

  • 11 Word templates (Privacy Policy, consent notices, SOPs, DPA, etc.)
  • 8-tab Excel workbook: Dashboard · Gap Assessment · Data Inventory · Consent Register · DSR Tracker · Breach Register · Vendor Register · 90-Day Roadmap
  • Drafted against DPDP Rules notified 13 November 2025

₹4,999 — instant download after payment.

Get DPDPKit →


Take the Free DPDP Readiness Check

Not sure where to start on the timeline?

Our free DPDP readiness check — 50 questions, about 2 minutes — tells you which phase to prioritise and names your top three gaps.

Start your free assessment →


Final thoughts

A successful DPDP compliance program isn't built in a day. It develops through well-planned steps: understand your data, document your practices, implement controls, test them, and review regularly until 13 May 2027 and beyond.

For startups, aim for progress over perfection — but aim for 80%+ on your gap assessment before the deadline. A structured 90-day timeline reduces risk, improves operational discipline, and builds customer trust without overwhelming your team.

Next steps:

  1. Take the readiness check — know your starting point
  2. Get DPDPKit — workbook with the 90-day tab pre-built
  3. Read the full compliance checklist alongside this timeline

This guide is for informational purposes only and does not constitute legal advice. Have your counsel or CA review your customised documents before you rely on them.

Written by

Bilal Shaikh

Founder, UXLaunch Lab

11+ years across fintech, Web3, and SaaS. Shipped RoleGrowth — an AI-powered career platform — end-to-end in 8 weeks.

Frequently asked questions

Quick answers.

How long does DPDP compliance take?
For many startups, a focused implementation takes 4–12 weeks depending on complexity. DPDPKit includes a 90-day roadmap; full compliance under the Act and notified Rules is mandatory by 13 May 2027.
Can I complete DPDP compliance in one week?
You may draft initial documents quickly, but effective governance — data inventory, consent flows, vendor DPAs, Grievance Officer, and breach readiness — usually takes several weeks.
Is 90 days enough for DPDP compliance?
For many early-stage startups, a focused 90-day project provides a strong foundation. Larger organisations or complex data stacks may need additional time before the 13 May 2027 deadline.
What is the DPDP compliance deadline?
Full compliance under the DPDP Act, 2023 and DPDP Rules, 2025 is mandatory by 13 May 2027. The Data Protection Board has been operational since 13 November 2025.
What is the first step in a DPDP timeline?
Start with assessment — build a data inventory, list vendors, and run a gap assessment before writing policies.
Should privacy reviews continue after implementation?
Yes. Schedule quarterly reviews through May 2027 and at least annually thereafter, or whenever products, vendors, or processing activities change.

Related articles