Data Protection & Compliance

Moving Beyond the Legal Checkbox: An 8-Domain Operational Framework for DPDP Compliance

DPDP compliance is not a policy document that sits with legal. This practical framework helps Indian businesses find operational gaps across HR, sales, IT, vendors and incident response.

By Atul Singh11 min readSeptember 4, 2026
Moving Beyond the Legal Checkbox: An 8-Domain Operational Framework for DPDP Compliance

A business can have a privacy policy, a consent notice and a signed vendor agreement — and still be unable to answer basic questions about its personal data.

Where did a prospect’s phone number come from? Which employee records are stored in a third-party HR platform? Who must respond when a customer asks about their data? What happens if a spreadsheet containing personal information is emailed to the wrong person?

These are operational questions, not merely legal ones. The Digital Personal Data Protection (DPDP) Act, 2023 creates a privacy framework for organisations handling digital personal data in India. Meeting that responsibility requires more than publishing documents. It requires repeatable workflows across HR, sales, marketing, IT, finance, procurement and leadership.

The practical way to begin is an eight-domain maturity assessment: Governance, Data Discovery, Consent, Rights Management, Security, Vendor Governance, Incident Response and Audit Readiness. Used properly, the framework shows where the business is exposed and which improvements should come first.

Legal teams can interpret obligations and approve policies, but they do not control every system and process that handles personal data. Sales teams collect prospect details. HR manages employee records. Operations shares information with vendors. IT configures access controls and backups. Finance may retain customer and supplier information for business and regulatory reasons.

If these workflows are not connected to the organisation’s privacy controls, a policy can be technically correct while daily practice remains inconsistent.

Consider a typical sales process:

  1. A salesperson exports contacts from an event platform.
  2. The spreadsheet is uploaded to a CRM.
  3. A marketing colleague adds the contacts to an email sequence.
  4. A contractor receives a copy for campaign preparation.
  5. The original file remains in email, a shared drive and a personal laptop.

A privacy policy does not explain whether each step is authorised, necessary, documented or secure. An operational framework does.

The consequences of weak processes can be significant. The source article identifies maximum financial penalties of up to ₹250 crore for failures relating to security safeguards and up to ₹200 crore for failure to notify a data breach. These are maximum figures, not automatic penalties for every incident; the Data Protection Board of India considers factors including the nature, gravity and duration of a violation. The business lesson is straightforward: security and incident response cannot be left until after a problem occurs.

Employee and HR data also belong in the assessment. A company that reviews only customer data may overlook recruitment forms, identity documents, payroll records, performance information and exit documentation stored across HR systems and email.

The eight-domain maturity framework

The framework works best as a diagnostic, not as a certificate. Score each domain according to the evidence the organisation can produce — not according to what a policy says should happen.

A simple internal scale is:

  • 0 — Unknown: No clear owner, inventory or documented process.
  • 1 — Informal: Some activity exists, but it depends on individual judgement.
  • 2 — Defined: A documented process and owner exist, but coverage is inconsistent.
  • 3 — Operating: The process is used, monitored and supported by evidence.
  • 4 — Improving: The organisation tests, measures and periodically improves the process.

The score is not a legal determination. It is a way to prioritise work.

1. Governance

Governance establishes who makes decisions about personal data and who is accountable when controls fail. It should cover policy ownership, escalation routes, departmental responsibilities, staff training and review cycles.

For a small business, this does not necessarily mean creating a large privacy department. It may mean naming an operations lead as the coordinator, assigning system owners in HR and IT, and requiring leadership approval for high-risk processing or new vendors.

A useful test is whether the business can answer three questions quickly:

  • Who owns DPDP compliance overall?
  • Who owns each system that stores personal data?
  • Who has authority to stop or change a risky process?

2. Data discovery and inventory

You cannot protect data that you cannot locate. Create an inventory of systems, spreadsheets, shared folders, paper-to-digital processes and vendors that handle personal data.

For each data store, record:

  • What information is collected.
  • Whose information it is — customers, prospects, employees, applicants or suppliers.
  • Why it is processed.
  • Where it is stored.
  • Who can access it.
  • Which vendors receive it.
  • How long it is retained.
  • How it is deleted or corrected.

Start with high-volume workflows rather than attempting a perfect enterprise-wide inventory on day one. HR, CRM, customer support, finance and marketing are usually practical starting points for an SMB assessment.

3. Consent management

Consent should be connected to the actual collection and communication workflow. A checkbox without a reliable record is weak evidence.

For a marketing form, the organisation should be able to link the person, date, purpose, notice presented, channel, consent status and withdrawal or change history. If a person withdraws consent, the instruction should reach the systems that send messages — not remain in a support inbox.

A practical workflow might look like this:

  1. The website form captures the stated purpose and consent status.
  2. The CRM stores the timestamp and source of the record.
  3. Marketing automation checks consent before sending a campaign.
  4. An unsubscribe or withdrawal request updates the central record.
  5. Any downstream agency receives the updated suppression list.
  6. A monthly review identifies records with missing or conflicting consent evidence.

Do not assume that buying a consent-management tool solves the problem. If teams continue to import old spreadsheets or create unapproved contact lists, the underlying workflow remains broken.

4. Data principal rights management

Rights requests need an operating procedure, not only an email address. Define how the business receives, verifies, assigns, investigates and closes a request.

For example, a request from a former employee may require coordination between HR, IT, payroll and an external HR platform. The organisation must identify relevant records, verify the requester, determine what can be provided or changed, record the decision and retain evidence of the response.

Create a rights-request register with fields such as:

  • Request date and channel.
  • Requester identity and verification status.
  • Type of request.
  • Systems and departments involved.
  • Assigned owner.
  • Due date.
  • Action taken.
  • Closure evidence.

The register should not become a second uncontrolled repository of sensitive information. Limit access and retain only what is necessary to manage the request.

5. Security safeguards

Security controls should reflect the real ways the organisation handles data. Begin with access management, authentication, device security, backups, encryption where appropriate, patching, logging and secure disposal.

A common SMB failure is broad shared access. For instance, a sales spreadsheet containing personal data may be accessible to every employee because it lives in a general shared folder. A better workflow assigns access by role, removes access when people change roles or leave, and reviews permissions periodically.

Security also includes human behaviour. Staff need clear instructions for handling attachments, using personal devices, sharing files with vendors and reporting suspicious activity. Training should be tied to actual workflows rather than generic annual slides.

6. Vendor governance

Third-party processing creates a chain of responsibility that procurement cannot manage through contract signatures alone. Build a vendor register for every provider that receives or can access personal data.

For each vendor, capture:

  • Services provided.
  • Categories of data shared.
  • Business purpose.
  • Access method.
  • Security and privacy commitments.
  • Subcontractor or sub-processor information where relevant.
  • Retention and deletion arrangements.
  • Incident notification process.
  • Review date and accountable owner.

Consider a recruitment agency that receives applicant CVs. The business should know what information is shared, why it is needed, how the agency protects it, when it deletes it and how an incident would be escalated. A signed agreement is useful, but it does not replace operational oversight.

7. Incident response

The first hours after a suspected breach are often chaotic. A documented response process reduces uncertainty about who must act.

Define:

  1. How employees report a suspected incident.
  2. Who performs initial triage.
  3. Who preserves logs, emails and affected files.
  4. Who determines the scope and severity.
  5. When leadership, legal advisers, vendors or authorities must be involved.
  6. How affected systems are contained and restored.
  7. How the organisation records decisions and lessons learned.

Run a tabletop exercise using a realistic scenario, such as an employee sending an HR spreadsheet to the wrong external recipient or a compromised CRM account exporting customer records. The exercise should test contact lists, decision rights, evidence preservation and notification procedures — not just whether a policy exists.

8. Audit readiness

Audit readiness means being able to demonstrate what the organisation does, who owns it and whether the process operates in practice. Relevant evidence may include data inventories, access reviews, training records, consent logs, rights-request registers, vendor reviews, incident exercises and policy approvals.

Store evidence in a controlled location with clear naming, ownership and review dates. Avoid creating a last-minute compliance folder filled with undated documents. Evidence should be generated as part of normal work.

Turning the framework into a business workflow

An eight-domain assessment becomes useful when it leads to prioritised decisions. A practical implementation sequence is as follows.

Step 1: Form a cross-functional working group

Include at least one representative from leadership, operations, HR, sales or marketing, IT and procurement. Assign one coordinator, but do not place every responsibility on that person.

The coordinator manages the assessment. System and process owners remain accountable for the controls in their areas.

Step 2: Map the highest-risk workflows first

Choose three to five workflows that combine large volumes, sensitive information, external sharing or weak visibility. Examples include:

  • Employee recruitment and onboarding.
  • Lead capture and outbound marketing.
  • Customer support and complaint handling.
  • Payroll and finance processing.
  • Vendor onboarding.

For each workflow, follow the data from collection to deletion. Note every system, manual handoff, export, external recipient and access point.

Step 3: Score each domain using evidence

Ask the owner to provide proof. If a team says consent is recorded, inspect a sample of records. If IT says access is reviewed, check the most recent review and its outcomes. If procurement says vendors are assessed, inspect the register and a sample of completed assessments.

This prevents optimistic scoring based on intentions.

Step 4: Prioritise by risk and effort

Do not attempt to fix every gap simultaneously. Prioritise issues that could expose large volumes of data, affect many people, create uncontrolled third-party access or delay incident response.

A simple action register can include:

Gap Risk Owner Next action Evidence of completion Review date
CRM exports stored in personal drives High Sales operations Restrict export access and move approved files to controlled storage Access review and storage audit 30 days
No central rights-request register High Operations Create intake, assignment and closure workflow Completed request record 30 days
Vendor data-sharing terms inconsistent Medium Procurement Add privacy review to vendor onboarding Approved assessment and contract record 60 days

The exact timeframes should reflect the organisation’s risk, resources and legal advice. The important point is to assign an owner and a verifiable outcome.

Step 5: Establish a review rhythm

Compliance should become part of operating cadence. A monthly review might cover open rights requests, new vendors, access changes and security incidents. A quarterly review might revisit the data inventory, retention practices, staff training and domain scores.

Repeat the assessment after major changes such as a new CRM, acquisition, outsourcing arrangement, marketing programme or HR platform. A process that was appropriate last year may not be appropriate after the business changes how it collects or shares data.

What this framework cannot do

An operational checklist is useful, but it has limits.

It does not replace advice from qualified legal counsel, especially where processing is high risk, obligations are unclear or the organisation may meet the criteria for a Significant Data Fiduciary. SDF classification and related obligations require verification against the current statutory and regulatory position.

The DPDP Rules, 2025 and the exact legal obligations should also be checked against official sources before the organisation relies on a compliance decision. The framework here is for readiness assessment and workflow design, not a legal opinion.

Technology is not a shortcut around poor ownership. Automated discovery, consent and ticketing tools may improve consistency, but they cannot decide why data is needed, whether a process is proportionate or who should approve an exception. They can also create new risk if configured poorly or connected to uncontrolled data sources.

Finally, a high score does not prove that no violation can occur. It indicates that the organisation has stronger processes for preventing, detecting, responding to and evidencing its handling of personal data.

Make DPDP compliance part of how work gets done

The most useful question is not, “Have we completed our DPDP policy?” It is, “What happens to personal data at every step of this workflow, and can we prove that the process is controlled?”

The eight-domain framework gives Indian businesses a practical starting point. Map the data, assign ownership, test the workflows, close the highest-risk gaps and preserve evidence as part of normal operations. That shift moves DPDP compliance from a legal checkbox to an ongoing capability — one that supports better governance, faster incident response and more trustworthy handling of customer and employee data.

FAQs

Does DPDP compliance apply to employee and HR data?

Yes. Employee, applicant and HR records are digital personal data when processed digitally, so they should be included in the organisation’s DPDP data inventory and workflow assessment.

How should a small business begin a DPDP compliance assessment?

Start by assigning an accountable coordinator, mapping three to five high-risk workflows, and scoring the eight domains using evidence. Prioritise gaps involving uncontrolled access, third-party sharing, missing consent records and weak incident response.

Does using a privacy or consent-management tool make a business DPDP compliant?

No. Tools can support discovery, consent records and workflow tracking, but they do not replace clear ownership, sound data decisions, secure processes, vendor oversight or legal review.

A

Atul Singh

15 years across teaching, sales, and building. Trained 2,500+ students. Six years in corporate sales and social media. Six years building web and AI products for SMBs at Qriyas. Based in Noida, working with sales and marketing professionals across the US, UK, Australia, and English-speaking markets globally.