P.S: This is a voluntarily presented guest post from Advocate M G Kodandaram, IRS. The article has not been edited by Naavi.org
Abstract
The Digital Personal Data Protection Act, 2023 (“DPDPA” or “the Act”) marks a significant transformation in India’s statutory approach to digital personal-data governance. Its regulatory architecture extends well beyond privacy policies, consent mechanisms and cybersecurity controls. It establishes a broader framework of accountability founded upon lawful processing, responsible conduct by Data Fiduciaries, rights of Data Principals, enhanced obligations for Significant Data Fiduciaries (SDFs), independent assurance mechanisms, regulatory oversight by the Data Protection Board of India (DPBI) and substantial monetary penalties for non-compliance.
With the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) notified on 13 November 2025, the framework has moved substantially towards operational implementation. The commencement notification adopts a phased approach, bringing specified provisions into force immediately, while providing for the commencement of other provisions after one year and the principal substantive obligations under Sections 3 to 17 and related provisions after eighteen months, extending into May 2027[1]. This phased implementation provides organisations with an important opportunity to move beyond a narrow compliance-oriented approach and establish a sustainable data-governance architecture.
The critical question is no longer whether an organisation has a privacy policy or has initiated compliance activities. The more fundamental question in the DPDP regime is whether it can demonstrate accountability through reliable governance processes, effective controls, independent assurance and auditable evidence. Such accountability requires an organisation to know what personal data it holds, understand why and on what lawful basis it processes that data, identify associated risks, govern Data Processors, protect information throughout its lifecycle, administer Data Principal rights, manage legacy data, respond effectively to breaches and continuously improve its controls.
Against this background, this article presents NAAVI’s Personal Data Governance Framework for fiduciary organisations and enterprises to assess and strengthen their readiness under the DPDPA. The framework translates the statutory architecture into a practical legal evaluation covering organisational responsibility, data inventory and governance, AI and automated processing, Data Processor management, competence and independence of the Data Protection Officer (DPO), appointment and functioning of an Independent Data Auditor (IDA), legacy-data governance, consent and lawful processing, Data Principal rights, and security and personal-data-breach management.
The framework is intended not merely to measure whether statutory requirements have been addressed, but to examine whether an organisation possesses the institutional capacity to demonstrate compliance, produce evidence of accountability, obtain independent assurance and continuously improve its data-governance practices. In this approach, privacy compliance becomes the foundation rather than the destination. The ultimate objective is to transform regulatory compliance into organisational capability and, ultimately, into Data Trust.
The author claims that the success of the DPDPA regime will depend not merely on avoiding statutory penalties, but on the ability of organisations and their governing boards to nurture a culture in which personal data is treated as a responsibility, requiring lawful processing, purposeful use, appropriate protection, documented evidence, and continuous oversight, as envisioned by NAAVI’s framework.
Key Words: Data Trust, Organisational Readiness, Demonstrable Accountability, Significant Data Fiduciary, Data Protection Board of India, Data Protection Officer, Independent Data Auditor, Data Audit, Data Governance, DGPSI, DGPSI-AI.
- End of the “Wait for the Breach” Approach
For several years, privacy and data protection in India were largely viewed through the lens of cybersecurity incidents. In many organisations, meaningful attention to personal-data protection was triggered only after a data breach, cyberattack, customer complaint or regulatory intervention. The DPDPA fundamentally changes this approach by moving the focus from post-incident response to continuous governance and accountability.
The significance of this change becomes clearer when the statutory framework is examined as a whole. The Act regulates the processing of digital personal data[2] and imposes obligations on persons and organisations undertaking such processing. Section 3 gives the legislation territorial reach to digital personal data processed in India, including data collected digitally or subsequently digitised, and extends in specified circumstances to processing outside India connected with offering goods or services to Data Principals in India. Section 4 establishes the foundational principle that personal data may be processed only in accordance with the Act, for a lawful purpose, and on the basis of consent or specified legitimate uses. The notified DPDP Rules further operationalise this framework. Rule 3 emphasises clear and understandable notices containing an itemised description of personal data and the purposes of processing. Rule 6 addresses reasonable security safeguards, while Rule 7 provides the operational framework for personal-data-breach notifications.
The regulatory philosophy is therefore no longer “wait for the breach.” Organisations and enterprises must know what data they hold, understand why it is processed, establish the lawful basis, implement appropriate controls, protect the data, preserve evidence, audit compliance and continuously improve their governance framework. The journey is consequently from privacy compliance to demonstrable accountability, where an organisation must be capable of proving, but not merely asserting, the responsible data governance. This change in regulatory philosophy also requires a broader understanding of privacy itself. The statutory framework does not operate in isolation; it forms part of a constitutional and legal evolution concerning informational autonomy.
- Privacy and Informational Autonomy
The statutory framework must be understood against the constitutional recognition of privacy. In Justice K.S. Puttaswamy (Retd.) v. Union of India, [(2017) 10 SCC 1] the Supreme Court recognised privacy as a constitutionally protected right under Article 21 and the broader fundamental-rights framework. The judgment recognised informational privacy as an important dimension of privacy in the digital age.
The DPDP Act does not attempt to codify every dimension of constitutional privacy. Instead, it establishes a statutory framework for the processing[3] of digital personal data. Privacy is the broader constitutional value; data protection is a statutory governance mechanism through which an important part of informational privacy is protected. The Act consequently introduces a structured legal vocabulary that gives operational meaning to the regulation of personal data. It identifies the individual to whom the personal data relates as the Data Principal[4], while placing primary responsibility for determining the purpose and means of processing on the Data Fiduciary[5]. The Data Processor[6] represents another important participant in the data-processing ecosystem, acting on behalf of the Data Fiduciary.
Alongside these institutional roles, the act defines the concepts of personal data, processing, consent, and legitimate uses, thereby establishing the legal foundations on which data processing is permitted and regulated. For organisations having greater data-related responsibilities or heightened risk, the framework introduces the concept of a SDF, together with enhanced compliance obligations, including the role of a DPO and the requirement for an independent data auditor. At the regulatory level, the DPBI provides the institutional mechanism for enforcement and adjudication.
This fundamentally changes the nature of the legal conversation. The question is no longer confined to the abstract proposition of “What is privacy?” Instead, the regulatory inquiry becomes substantially more concrete and operational: What personal data is being processed, who is processing it, for what purpose, on what legal basis, through which systems and processes, and subject to what safeguards and controls? The Act thus transforms privacy from a broad principle into an accountability framework capable of being translated into identifiable responsibilities, processes, controls, evidence and regulatory oversight. It is against this background that the first question for an organisation must be its own position within the statutory architecture.
III. Role of the Organisation
The role of the organisation is the starting point of any meaningful assessment of DPDPA readiness. Before an organisation can determine what controls, policies, audits or accountability mechanisms it must establish, it must first understand what role it occupies within the data-processing ecosystem and what level of statutory responsibility attaches to that role.
The DPDPA defines a Data Fiduciary as a person who determines the purpose and means of processing personal data, while a Data Processor is a person who processes personal data on behalf of a Data Fiduciary. The Act also recognises an SDF, which is a Data Fiduciary or class of Data Fiduciaries notified by the Central Government. Section 10 identifies several factors relevant to such notification, including the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, the security of the State, and public order. Section 10(2) requires an SDF to appoint a DPO, appoint an IDA, undertake periodic Data Protection Impact Assessments (DPIAs), conduct periodic audits, and comply with such other prescribed measures. Thus, the classification of the organisation is not merely a matter of terminology; it directly influences the governance architecture, accountability structure, resource allocation and compliance framework that the organisation must establish.
- NAAVI’s Personal Data Governance Framework
It is against this background that NAAVI’s Personal Data Governance Framework approaches organisational readiness by beginning with the most fundamental question: what is the organisation’s role in relation to the personal data it processes? The framework proceeds on the premise that an organisation cannot meaningfully claim to be DPDPA-ready unless it has first established a clear understanding of what data it processes, why it processes it, in what capacity it processes such data, what risks arise from such processing, and what level of accountability the law places upon it. These questions are intended to enable the organisation to assess the preparedness of its entire operational network and its ability to undertake a smooth and structured transformation towards the DPDP regime.
The ten questions comprising NAAVI’s Framework are therefore designed not merely as a compliance checklist, but as a practical test of organisational readiness. They seek to examine whether the statutory principles of the DPDPA have actually been translated into an identifiable governance structure, defined responsibilities, operational controls, documented evidence and continuing oversight. The emphasis is consequently not on whether policies exist on paper, but on whether those policies are understood, implemented and capable of being demonstrated through evidence.
Taken together, these ten questions provide an organisational pathway for determining where the organisation presently stands, what gaps exist, what risks require attention, and what corrective measures are necessary. The objective is to move the organisation progressively from formal compliance to demonstrable accountability, responsible data governance and, ultimately, data trust.
- Question 1: Have We Formally Assessed Our Organisational Role?
Every organisation should place before its board or equivalent governing body a documented assessment answering:
- What categories of personal data do we process?
- Whose data do we process?
- For what purposes?
- At what volume?
- Through which systems?
- Through which processors?
- What risks arise from the processing?
- Do we undertake large-scale or high-impact processing?
- Are children or persons with disabilities involved?
- Is there any reason to anticipate classification as an SDF?
The organisation should not wait passively for government notification before thinking about its own risk profile. The statutory notification power remains with the Central Government, but internal assessment is an essential governance exercise. A board resolution recording the assessment, methodology and conclusions would provide an important governance trail. Once the organisation understands its statutory role, the next question is more fundamental: does it actually know what personal data it possesses?
- Question 2: Have We Created a Comprehensive Personal-Data Inventory?
The second question is: Do we actually know what personal data we possess? Section 3 makes the Act applicable not only to information originally collected in digital form but also to personal data collected in non-digital form and subsequently digitised. This makes legacy information particularly important. A data inventory should identify:
| Parameter |
Governance Question |
| Data subject |
Whose data is it? |
| Data category |
What information is processed? |
| Purpose |
Why is it processed? |
| Source |
Where did it originate? |
| System |
Where is it stored? |
| Processor |
Who else receives it? |
| Access |
Who can access it? |
| Retention |
How long is it retained? |
| Security |
How is it protected? |
| Disposal |
When and how is it deleted? |
The source material advocates a centralised data inventory and a “Single Source of Truth” approach. This is particularly important for rights management.
Section 12 gives the Data Principal rights[7] relating to correction, completion, updating and erasure, subject to the statutory conditions. If the same individual’s data exists in ten contradictory databases, correction and erasure become operationally difficult. Therefore, data inventory is not merely a preliminary exercise. It is the foundation of rights compliance.
Once the organisation knows what data it possesses, it must also understand how that data is being used, particularly where emerging technologies are involved.
- Question 3: Do We Know What Our AI Systems Are Doing?
Artificial intelligence (AI) introduces an additional layer of risk. Organisations should not limit the assessment to systems marketed as “AI”. Automated decision-making can be embedded in ordinary software, analytics platforms, credit models, HR systems, fraud-detection systems and customer-management applications. AI-related risks may be difficult to identify in advance and therefore require specific governance attention. The organisation should therefore maintain an AI and automated-processing register containing: system name; vendor; purpose; data used; personal-data categories; decision influenced; degree of automation; human oversight; model validation; explainability; security controls; processor/sub-processor arrangements; and risk assessment.
For SDFs, the statutory DPIA requirement under Section 10(2)(c)(i) becomes especially relevant because the DPIA must include assessment and management of risks to Data Principals’ rights. The governance principle should therefore be: AI cannot be outside the data-governance framework merely because the AI system was purchased from a third party. That principle naturally leads to another critical question. If third parties process the organisation’s personal data, how effectively does the organisation control those relationships?
- Question 4: Do We Control Our Data Processors?
Section 8(1) contains one of the most important accountability principles in the Act. A Data Fiduciary remains responsible for compliance in respect of processing undertaken by it or on its behalf by a Data Processor. This is crucial as the company cannot simply say: “The cloud provider caused the problem.” The Data Fiduciary remains responsible within the statutory framework. Organisations should therefore maintain a Data Processor Register containing details like – processor name; processing purpose; categories of data supplied; geographical location; sub-processors; security measures; retention obligations; breach obligations; audit rights; deletion requirements; and contractual accountability mechanisms. Rule 6 of the DPDP Rules reinforces this contractual and technical dimension by requiring appropriate security safeguards, including measures relating to encryption, access controls, logging and monitoring, backups, contractual safeguards and organisational measures.
The contractual review should therefore move beyond the question: “Do we have a data-processing agreement?” The more appropriate question is: “Does the contract accurately reflect the actual processing relationship and provide enforceable governance controls?” Processor governance, however, cannot substitute for internal accountability. The organisation must have competent persons capable of overseeing the framework and challenging deficiencies.
- Question 5: Is the DPO Competent and Organisationally Independent?
The appointment of a DPO by an SDF cannot be treated as a mere statutory formality or ceremonial designation. Section 10(2)(a) of the Act requires an SDF to appoint a DPO who represents the organisation, is based in India, is responsible to the Board of Directors or an equivalent governing body, and serves as the point of contact for the grievance redressal mechanism.
These statutory responsibilities necessarily require the DPO to possess a combination of legal, technological and governance capabilities. The organisation should therefore establish a clear competency framework covering the Act and Rules, privacy law, data governance, information security, processor management, incident response, Data Principal rights, audit and assurance, DPIA methodology, AI governance and regulatory engagement. The absence of a prescribed conventional academic qualification for the DPO does not reduce the importance of competence. Rather, it places a greater responsibility upon the governing body to assess whether the person appointed possesses the knowledge, experience and professional judgment necessary to discharge the role effectively.
Independence is equally important. A DPO who merely endorses existing practices without questioning them may satisfy the organisational chart but fail the underlying purpose of the statutory framework. The Board should therefore examine whether the DPO has sufficient authority and organisational standing to identify deficiencies, challenge inappropriate processing practices, demand corrective measures and escalate material risks directly to the governing body. The decisive question, therefore, is not merely “Who has been designated as the DPO?” It is whether the appointed DPO is sufficiently competent and organisationally independent to challenge the organisation’s data-processing practices and report material deficiencies without fear or favour.
The next layer of accountability is independent assurance.
- Question 6: Have We Identified an Independent Data Auditor?
The requirement to appoint an independent data auditor marks an important development in India’s data-protection framework. Section 10(2)(b) of the Act expressly requires every SDF to appoint an independent data auditor to undertake a data audit and evaluate compliance with the Act. The provision therefore introduces an assurance layer that is distinct from the organisation’s ordinary internal compliance mechanisms.
The role of the independent data auditor should not be confused with that of the internal auditor, cybersecurity auditor, statutory financial auditor, DPO or IT consultant. Each performs a different function. The data auditor’s responsibility is to provide an independent and objective assessment of whether the organisation’s personal-data governance framework is not only appropriately designed but also effectively implemented.
Such an audit may extend across the organisation’s data inventory, processing purposes, consent and lawful-use records, processor governance, Data Principal rights management, security safeguards, retention and deletion practices, DPIA, governance documentation, and the use of artificial intelligence and algorithmic systems. Equally important is the examination of evidence demonstrating that prescribed controls actually operate in practice rather than merely existing as policies on paper.
The statutory emphasis on independence is therefore critical. The appointment should be structured in a manner that enables the auditor to examine business practices objectively, identify material deficiencies and communicate significant findings without being subordinated to the very function or management team whose activities are being audited.
The independent data auditor should consequently be viewed not merely as another compliance professional, but as an assurance mechanism within the accountability architecture, capable of providing credible evidence of compliance and escalating significant departures from the organisation’s data-protection obligations. The assurance process, however, must also address information that predates the current data-protection framework.
- Question 7: What About Legacy Data?
For many organisations, the most difficult data-protection challenge may not concern the personal data being collected today, but the vast repositories of information accumulated over the past many years. Legacy data often exists across multiple databases, applications, physical records and archival systems, and may have been collected under entirely different regulatory, technological and business environments. The fact that such data is old does not, by itself, remove the organisation’s continuing responsibilities in relation to it.
Section 5(2) of the Act specifically addresses personal data for which consent was obtained before the commencement of the Act. It requires the Data Fiduciary, as soon as reasonably practicable, to provide the prescribed notice relating to the personal data and the purpose for which it is being processed, the rights of the Data Principal and the manner in which a complaint may be made. The provision therefore makes it clear that historical data cannot simply be excluded from the organisation’s privacy-governance framework merely because it was collected before the contemporary data-protection regime came into operation.
Organisations should consequently undertake a structured legacy-data discovery and remediation exercise. Each significant data set should be examined to establish when and how it was collected, the original purpose of collection, whether that purpose remains relevant, the legal basis for continued processing, whether the Data Principal can still be contacted, whether the information remains necessary, whether it is being shared with processors, and what retention requirements apply. The organisation must ultimately determine whether particular data should be retained, securely deleted, anonymised or subjected to additional governance controls.
Legacy data presents a particularly difficult operational challenge because historical records may have been collected without contemporary mechanisms for transparency, consent management or contacting Data Principals. It should therefore not be treated as an ordinary housekeeping exercise. Legacy-data remediation should be constituted as a distinct, board-approved governance project, supported by a documented inventory, risk assessment, remediation plan, accountability structure and evidence of completion. Where consent is relied upon as the lawful basis for processing, another question becomes critical: can the organisation prove it?
- Question 8: Can We Prove Consent?
Consent under the Act should not be understood merely as an event that occurs when an individual clicks a button on a website or application. It is a legal and evidentiary requirement, and organisations must be capable of demonstrating how that consent was obtained and maintained throughout the relevant processing lifecycle. Section 6(10) places a significant evidentiary burden on the Data Fiduciary where consent is relied upon as the basis for processing. If the question of consent arises in a proceeding, the Data Fiduciary must be able to prove that the prescribed notice was given and that consent was obtained in accordance with the Act and the Rules.
This makes consent records an important component of the organisation’s evidence architecture. The organisation should be able to establish the identity of the Data Principal, the version and contents of the notice presented, the personal data identified in that notice, the purpose communicated, the date and time of consent, the mechanism through which consent was obtained, the actual consent record, any subsequent withdrawal, and relevant changes or audit trails. It should be possible to reconstruct the consent journey even after the original transaction has taken place.
The notified DPDP Rules further strengthen this architecture. Rule 3 requires a standalone and understandable notice containing an itemised description of the personal data and the specified purposes of processing, together with information enabling the Data Principal to withdraw consent, exercise rights and make a complaint to the Data Protection Board. Rule 4 provides the framework governing Consent Managers, including their registration and operational obligations.
The compliance philosophy is therefore straightforward but significant: consent must be demonstrable, not merely asserted. An organisation should not merely state that it obtained consent; it should possess reliable, retrievable and auditable evidence capable of proving when, how and on what terms that consent was obtained. Consent, however, is only one part of the relationship between the organisation and the Data Principal. The next question is whether the rights created by the Act can actually be exercised in practice.
- Question 9: Can We Operationalise Data Principal Rights?
The chapter dealing with the rights of Data Principals under the Digital Personal Data Protection Act, 2023 converts individual privacy rights into concrete operational obligations for organisations. Section 11 provides the Data Principal with the right to obtain information concerning personal data and its processing, including, subject to the statutory qualifications, information regarding the Data Fiduciaries and Data Processors with whom the personal data has been shared. Section 12 further provides rights relating to the correction, completion and updating of personal data, as well as its erasure where applicable. Section 13 provides a mechanism for grievance redressal, while Section 14 enables a Data Principal, in specified circumstances, to nominate another individual to exercise the Data Principal’s rights.
These provisions cannot remain confined to a privacy policy or legal document. They require the organisation to establish a functioning Data Principal Rights Management System capable of receiving, authenticating, processing and responding to requests in a timely and accountable manner. The operational journey should ordinarily proceed from receipt of the request through authentication of the requester, identification and search of relevant data, verification of the request, coordination with Data Processors and other relevant functions, taking an appropriate decision, communicating the response and preserving evidence of the entire process.
The notified DPDP Rules reinforce this operational requirement. Rule 9 requires the publication of appropriate contact information for responding to questions relating to the processing of personal data and, where applicable, the business contact information of the Data Protection Officer. The real test of compliance is therefore not whether an organisation has drafted an impressive privacy policy, but whether it can actually operationalise the rights of a Data Principal. A policy promising access, correction or erasure is of little practical value if the organisation cannot identify where the individual’s personal data resides, determine how it has been processed or coordinate with processors holding that data.
Data Principal rights must therefore be supported by systems, workflows, accountability and evidence—not merely by words on paper. The final operational question concerns the protection of the data itself and the organisation’s ability to respond when preventive safeguards fail.
- Question 10: Are Security and Breach-Response Mechanisms Operational?
Security safeguards and personal-data-breach[8] response represent one of the most important operational dimensions of the Act. The statutory framework does not treat data security merely as a matter of technical protection entrusted to the information-technology department. Section 8(5) places a direct responsibility upon the Data Fiduciary[9] to protect personal data in its possession or control, including processing undertaken by or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent a personal-data breach. The responsibility therefore extends beyond the organisation’s own systems and encompasses the wider processing ecosystem over which it exercises governance. Rule 6 of DPDP Rules identifies reasonable security safeguards that include measures such as encryption or appropriate protection of personal data, access controls, visibility through logs and monitoring, periodic review, backups and business-continuity measures, retention of relevant logs and personal data for the prescribed periods, and appropriate contractual provisions requiring Data Processors to maintain necessary security measures.
The objective is not simply to install security technologies, but to create a demonstrable system of preventive, detective and corrective controls. Rule 7 establishes the framework for personal-data-breach notification, requiring communication to affected Data Principals without delay and notification to the DPBI in the prescribed manner, including an initial intimation followed by more detailed information within the prescribed period. This makes incident response a statutory governance responsibility rather than an informal IT exercise.
Every organisation should therefore maintain a documented and periodically tested personal-data-breach response protocol. The protocol should clearly identify what constitutes an incident, who is responsible for detecting and escalating it, who determines whether the event constitutes a personal-data breach, and when the DPO, senior management and governing body must be informed. It should also establish responsibility for communication with affected Data Principals and the DPBI. Equally critical is the preservation of evidence, including logs, system records, communications, forensic findings, decisions taken and remedial measures implemented.
The organisation must first detect the incident and take immediate steps to contain its impact. It must then assess the nature, scope and potential consequences of the event and classify whether it constitutes a personal-data breach requiring statutory action. Once classified, the incident should be promptly escalated to the appropriate internal authorities, including the DPO and senior management, followed by the required notifications to the Data Protection Board and affected Data Principals, wherever applicable.
Throughout the process, relevant logs, records, communications and other material evidence must be preserved to establish what happened and how the organisation responded. The organisation must then remediate the underlying vulnerability, restore appropriate controls and address the consequences of the incident. Finally, the matter should undergo a structured post-incident review to identify lessons, determine root causes and strengthen the organisation’s security and data-governance framework. Thus, incident response becomes a continuous cycle of detection, containment, assessment, classification, escalation, notification, evidence preservation, remediation and organisational learning.
The larger governance principle is clear: security compliance cannot be treated as merely an IT function. A personal-data breach can simultaneously become a legal, regulatory, operational, reputational and governance event. The organisation must consequently be capable not only of preventing breaches through reasonable security safeguards, but also of demonstrating that, when an incident occurs, it can identify, investigate, escalate, notify, document and remediate the event in accordance with the statutory framework. Data security, in this sense, becomes a legal-response function supported by technology, rather than technology operating independently of legal accountability.
- The Penalty Architecture: Why Governance Cannot Be Deferred
The Act establishes a significant monetary-penalty regime. Section 33 empowers the Board, after inquiry and opportunity of hearing, to impose monetary penalties specified in the Schedule where the breach is significant. The Schedule provides, among others:
| Breach |
Maximum Penalty |
| Failure to take reasonable security safeguards |
₹250 crore |
| Failure concerning breach notification |
₹200 crore |
| Child-data obligations |
₹200 crore |
| Significant Data Fiduciary obligations |
₹150 crore |
| Breach of Data Principal duties |
₹10,000 |
| Other breaches |
₹50 crore |
The statutory ceiling of ₹250 crore for specified breaches should not, however, be misunderstood as an automatic penalty. Section 33(2) requires the Board to consider factors including the nature, gravity and duration of the breach; the type and nature of personal data affected; the repetitive nature of the breach; gains realised or losses avoided; mitigation measures and their timeliness and effectiveness; proportionality and deterrence; and the likely impact of the penalty. Thus, the penalty architecture combines high statutory ceilings with an assessment of the circumstances of the breach.
The governance lesson is straightforward: a compliance programme that reduces the likelihood and impact of a breach is not merely preventive expenditure; it may become relevant to the regulatory assessment of the organisation’s conduct. This also explains why documentation and evidence assume such importance. If the organisation’s governance practices are ever examined by the regulator, its ability to demonstrate what it did, when it did it and how effectively it operated becomes critical.
- The Data Protection Board and the Evidentiary Dimension
The DPBI is not merely a complaint-receiving body. Section 27 gives it powers to inquire into breaches, including breaches arising from personal-data-breach notifications and complaints by Data Principals. Section 28 provides for an independent Board functioning, as far as practicable, as a digital office. It also provides for inquiry following principles of natural justice and gives the Board powers concerning summoning, evidence and inspection of documents and data. This has a direct implication for corporate governance: compliance records may become regulatory evidence.
A company should therefore preserve data inventories, DPIAs, audit reports, processor registers, consent records, privacy notices, rights-request records, incident registers, security assessments, board decisions, remediation plans and evidence of implementation. This is the emergence of evidence-based privacy compliance. The organisation should be able to demonstrate not only that a policy exists, but also that the policy was implemented, monitored, tested and improved. The ten-point framework can therefore be used as a structured board-level readiness assessment.
VII. The Ten-Point Readiness Matrix
The following matrix may be adopted as a preliminary board-level self-assessment.
| No. |
Compliance Area |
Principal Legal Anchor |
Score /10 |
| 1 |
Organisational role assessment |
Sections 2, 8 & 10 |
/10 |
| 2 |
Personal-data inventory |
Sections 3–5 |
/10 |
| 3 |
AI / automated-processing risk |
Section 10; DPIA framework |
/10 |
| 4 |
Data Processor governance |
Section 8 |
/10 |
| 5 |
DPO competence and reporting line |
Section 10(2)(a) |
/10 |
| 6 |
Independent data auditor |
Section 10(2)(b) |
/10 |
| 7 |
Legacy-data governance |
Section 5(2) |
/10 |
| 8 |
Consent and evidence |
Sections 4–6; Rule 3 |
/10 |
| 9 |
Data Principal rights |
Sections 11–14; Rule 9 |
/10 |
| 10 |
Security and breach response |
Section 8; Rules 6–7 |
/10 |
| Total |
|
|
/100 |
This score is not a statutory compliance certificate. It is a governance diagnostic. An organisation scoring 80 is not automatically compliant; an organisation scoring 40 is not necessarily in breach of every statutory provision. The purpose is to identify weaknesses requiring deeper legal and operational assessment. The matrix should therefore be viewed as the starting point for board discussion rather than the conclusion of the compliance exercise.
VIII. The Board’s Responsibility
The greatest danger in implementing the Act is to treat data protection as an IT compliance function and delegate the entire responsibility to the Information Technology department. Although technology plays an important role in implementing security and privacy controls, DPDPA compliance is fundamentally a matter of organisational governance, accountability and risk management. The responsibility, therefore, cannot end with the department that operates the systems; it must ultimately form part of the oversight responsibility of the organisation’s governing body.
The Act itself points towards such higher-level governance, particularly in the case of an SDF. The DPO is required to be responsible to the Board of Directors or a similar governing body. This statutory architecture recognises that protection of personal data is not merely an operational or technical issue but a matter requiring oversight at the highest level of the organisation.
Accordingly, the Board should periodically receive a Data Protection Governance Report that enables it to understand not merely whether policies exist, but whether the organisation is actually implementing them. Such a report should provide a consolidated view of the organisation’s data inventory, significant processing activities and risk classification, together with the DPO’s report, risks arising from data processors, the status of DPIAs and findings arising from data audits. It should also bring before the Board the nature and status of Data Principal requests and grievances, security incidents and breach notifications, remediation measures, the status of legacy data and emerging risks associated with the use of artificial intelligence.
The purpose of such reporting is not to burden the Board with operational details, but to provide it with sufficient visibility to discharge its governance responsibility. The Board should be able to identify whether the organisation knows what personal data it holds, why it is processing that data, what risks have been identified, whether appropriate safeguards are operating, whether third-party processors are adequately controlled, and whether deficiencies identified through audits or incidents are being effectively remediated.
The Board should therefore move beyond the conventional question, “Are we compliant?” and ask the more meaningful question: “Show us the evidence.” This simple shift in questioning can fundamentally change the quality of data-protection governance. A statement of compliance is essentially a management representation; evidence demonstrates whether that representation is supported by actual records, controls, assessments, audit findings and corrective action.
The transition from delegation to oversight, therefore, represents an important element of NAAVI’s Framework. DPDPA readiness should not be regarded as a one-time certification or a responsibility that can be passed down to a particular department. It should become a continuing governance process in which the Board receives appropriate information, challenges management where necessary, monitors identified risks and ensures that corrective measures are completed. In this manner, data protection moves from being an isolated compliance activity to becoming an integral part of the organisation’s broader risk, accountability and governance framework.
- DPDPA Compliance Is Not a Software Purchase
A predictable market response to the DPDPA is the proliferation of privacy-management software. Technology is useful. But technology cannot decide whether a purpose is legitimate; whether data should be collected; whether legacy data should be retained; whether a processor relationship is appropriately structured; whether an algorithm creates unacceptable risk; whether the DPO is independent; or whether the organisation’s governance model is adequate.
The correct approach to DPDPA readiness should therefore begin with the law and proceed through a logical governance sequence. The organisation must first understand its legal obligations, followed by comprehensive data mapping to identify what personal data is collected, processed, stored and shared. This must then be linked to the purpose for which the data is processed, followed by an assessment of the associated risks. Based on this understanding, appropriate governance structures and policies should be established, leading to the implementation of effective controls. Only thereafter should technology be deployed to support and enforce those controls, with adequate evidence generated and preserved to demonstrate compliance. Finally, the entire framework should be subjected to periodic audit and continuous improvement.
This distinction is particularly important for boards because procurement of software may create the appearance of compliance without creating substantive accountability. Technology should support the governance framework, not become a substitute for it. The real objective is to ensure that the organisation can demonstrate that the controls represented on a dashboard actually operate in practice.
- From Privacy Compliance to Data Trust
The ultimate objective of the DPDP Act should not be to create an organisation that merely operates under the fear of a ₹250-crore penalty. Penalties may provide a powerful incentive for compliance, but they cannot by themselves create a culture of responsible data governance. The deeper objective of the DPDPA is to establish a system in which personal data is treated as an important responsibility requiring lawful, transparent, secure and accountable stewardship.
The organisational journey should therefore begin with the DPDP Act and progressively develop into a broader architecture of data governance. This requires the organisation to first understand and document the personal data that it holds through a comprehensive data inventory. It must then determine the purpose and lawful basis for processing that data, followed by appropriate risk assessment to identify vulnerabilities, regulatory exposure and potential harm to Data Principals. Based on this assessment, the organisation must implement suitable technical and organisational controls covering privacy, security, access, retention, processor management, rights management and incident response.
However, implementation of controls is only one part of the accountability journey. The organisation must also generate and preserve evidence demonstrating that those controls exist and operate effectively. This evidence should be capable of examination through independent assurance, including appropriate audit and review mechanisms. The findings from such assurance should then feed into continuous improvement, ensuring that the organisation’s data-governance framework evolves with changes in technology, business processes, risks and regulatory expectations.
The ultimate outcome should be the creation of Data Trust, i.e., confidence among Data Principals, customers, employees, regulators, business partners and other stakeholders that personal data is being responsibly governed. This is also where sector-specific governance frameworks, such as the DGPSI frameworks, become particularly relevant. Frameworks developed for sectors such as healthcare, banking, education and human resources should not be regarded as substitutes for the DPDPA or as alternative sources of statutory authority. Their value lies in translating broad statutory principles into measurable, operational and auditable organisational controls that can be adapted to the specific risks and processes of a sector.
The statute establishes the legal obligation and tells the organisation what it must do. A governance framework takes the next step by asking who will do it, how it will be done, what evidence will be generated, who will independently verify it, and what corrective action will follow when a control fails. In this sense, governance frameworks bridge the gap between legal prescription and organisational execution. The journey towards data trust in dpdp regime can therefore be expressed as:
The significance of this journey lies in its final destination. Compliance is not the end of data protection; it is the foundation for accountability. Assurance makes that accountability demonstrable, and continuous improvement makes it sustainable. Data Trust emerges when an organisation can consistently demonstrate that personal data is known, lawfully processed, adequately protected, responsibly governed and independently assured.
The future of DPDPA compliance must therefore move beyond the question, “Are we compliant?” The more meaningful question is: “Can we demonstrate, with evidence and independent assurance, that we are trustworthy stewards of personal data?” That is the real transition from privacy compliance to data trust.
And that, ultimately, is the purpose of NAAVI’s Personal Data Governance Framework for Organisational Readiness under the DPDPA: not merely to measure compliance, but to help organisations build the governance capability through which compliance becomes accountability, accountability becomes assurance, and assurance becomes trust.
[1] Ministry of Electronics and Information Technology, Notification G.S.R. 843(E), dated 13 November 2025, issued under s. 1(2), Digital Personal Data Protection Act, 2023. The notification provides for immediate commencement of specified provisions, commencement after one year of s. 6(9) and s. 27(1)(d), and commencement after eighteen months of ss. 3–5, s. 6(1)–(8) and (10), ss. 7–10, 11–17, 27 except clause (d), ss. 28–34, 36–37 and s. 44(2).
[2] s.2 DPDP Act. (n) “digital personal data” means personal data in digital form; (t) “personal data” means any data about an individual who is identifiable by or in relation to such data; (h) “data” means a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means.
[3] s.2 DPDP Act. (x) “processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.
[4] s.2 DPDP Act. (j) “Data Principal” means the individual to whom the personal data relates and where such individual is— (i) a child, includes the parents or lawful guardian of such a child; (ii) a person with disability, includes her lawful guardian, acting on her behalf.
[5] s.2 DPDP Act. (i) “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data.
[6] s.2 DPDP Act. (k) “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary.
[7] DPDP Act. Chap. III, Rights and Duties of Data Principal.
[8]s.2 DPDP Act. (u) “personal data breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data;
[9] s.8 DPDP Act. (5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.
M.G.Kodandaram, IRS