Why DPDP compliance is now a CIO problem, not just a legal one

By Chintan Shah, Founder, DPDPGuard.ai

Here’s the point worth leading with: DPDP compliance is not, at its core, a legal deliverable it’s an engineering one. Legal counsel can interpret the law, but only technology systems can actually deliver on it the databases that store personal data, the pipelines that move it, and the access controls that decide who can touch it. That’s what makes this a CIO problem first, and a legal one second.

India’s Digital Personal Data Protection Act, 2023 laid down the country’s first comprehensive framework for how personal data is collected, processed, and protected. The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 through a gazette notification dated November 13, 2025, while the Data Protection Board of India (DPBI) has been formally established as the regulatory body responsible for implementing and enforcing the framework.

Why This Is an Engineering Conversation
Nearly every obligation the Rules create is, underneath the legal language, a systems challenge:
Breach notification within 72 hours — Data Fiduciaries must give immediate notice to affected Data Principals and detailed particulars to the DPBI within 72 hours of becoming aware of a breach.

Consent and notice management at scale — Every consent request must be itemised, revocable, and traceable. Organisations must be able to prove, technically and not just contractually, that consent was properly obtained and can be withdrawn as easily as it was given. Delivering that across web, mobile, and backend systems is a product and engineering build.

Data Principal rights fulfilment — Retaining, correcting, erasing, and securing personal data on request needs real workflows and audit trails behind it.

Significant Data Fiduciary obligations — Larger organisations designated as Significant Data Fiduciaries take on periodic audits and impact assessments that depend on well-instrumented, well-documented technology environments.

Where AI Adds a New Layer of Risk
AI has moved from an afterthought in this conversation to one of its central concerns. Two examples CIOs are grappling with right now: when customer support transcripts, KYC documents, or health records are fed into a large language model for summarisation or a copilot, that personal data is now being processed through a new system that needs to be accounted for within the organisation’s DPDP framework, including applicable consent, retention and access controls — the same DPDP obligations that apply to a database apply to a prompt.

Separately, retrieval-augmented generation (RAG) pipelines drawing on internal knowledge bases can surface personal data to users, or send it to third-party model providers, in ways the original notice to the data principal never contemplated. Building privacy controls into AI pipelines — data minimisation before ingestion, redaction, and clear model-provider agreements — is now as much a DPDP task as securing a database.

IBM’s 2026 Cost of a Data Breach Report found the average breach in India now costs ₹25.5 crore, with the volume of records compromised per incident climbing to roughly 39,500. It also found that 26% of malicious breaches in India involved AI-generated attacks, while organisations without AI-driven security and automation paid an average of ₹31.6 crore per breach — around ₹10 crore more than organisations with mature AI defences — and took roughly 236 days to detect a breach, against 175 days for more automated peers. The takeaway for CIOs: the same AI investment that helps meet DPDP’s 72-hour breach clock is also the investment that lowers the cost of getting breached.

A Practical Roadmap, and the Real Deadlines
The DPDP timeline is genuinely phased, and it’s worth being precise about it rather than treating notification as the finish line. The Rules took effect in November 2025, activating the DPBI and its complaint mechanism — that’s a starting point, not full applicability. November 2026 is the next real milestone, when the Consent Manager provisions come into force, bringing organisations closer to the framework’s substantive compliance requirements. Full substantive compliance — consent architecture, breach protocols, data principal rights, security safeguards — is due by May 13, 2027, the 18-month mark, after which the DPBI can impose penalties of up to ₹250 crore for specified contraventions

Reading November 2025 as “compliance done” rather than “the clock has started” is the most common, and most costly, misread of the law.

This isn’t only an enterprise-scale concern, either. A fifty-person D2C brand collecting customer data through a website, a payment gateway, and a WhatsApp support line faces the same 72-hour breach clock and the same consent-traceability bar as a large bank — just without a dedicated privacy team to build it.

That’s exactly where a growing category of privacy-tech and compliance-automation platforms is finding traction: we have tools today that are built to help a CIO — or, at a smaller company, whoever is wearing that hat — operationalise consent capture, data-principal request handling, retention schedules, breach workflows, and ongoing compliance monitoring, without a large in-house build.

With roughly 18 months of runway between notification and hard enforcement, there’s real time to do this properly:

Map your data flows — Build a Record of Processing Activities (RoPA) covering what personal data is collected, where it lives, and who touches it.

Modernise consent infrastructure — Make granting and withdrawing consent equally simple, and plan around the Consent Manager window opening in November 2026.

Automate breach detection and response — Make sure the 72-hour clock is realistically achievable through real-time monitoring and clear escalation playbooks.

Strengthen access and retention controls — Align logging, storage, and deletion practices with audit-trail and erasure requirements.

Design privacy into AI systems — Apply consent basis, minimisation, and access logging to any pipeline feeding personal data into a model or copilot, not just to traditional databases.

Partner closely with legal and compliance — Translate statutory language into system requirements together, so technology and legal move forward in step.

Organisations that use this runway well will come out the other side with more than a compliance certificate: better data quality, stronger customer trust, and an architecture built for a future where privacy is a design requirement, not an afterthought.

DPDP
Comments (0)
Add Comment