A transition window is a delivery plan, not a waiting period
India’s Digital Personal Data Protection framework turns privacy principles into operating responsibilities for organisations handling digital personal data. In a November 2025 interview, MeitY Secretary S. Krishnan described a deliberately phased compliance window and a digital-first process. The practical message for organisations is not to wait for the final month. Consent, rights handling, deletion, vendor oversight and incident response all require changes across systems and teams.
Krishnan also emphasised that data ownership lies with the individual. For a privacy programme, that principle should be visible in the user journey: notices people can understand, choices they can exercise and requests the organisation can actually fulfil.
Start with personal-data flows
A privacy policy is not a map of processing. Before selecting controls, document where personal data enters, why it is used, where it is stored, who receives it and when it should be deleted.
For each processing activity, record:
- The data principal and data categories
- The specific purpose and lawful basis
- The product, department and accountable owner
- Processors, sub-processors and cross-border transfers
- Retention trigger and deletion method
- Security safeguards and incident route
- Rights-request search and fulfilment steps
This inventory becomes the common source for consent notices, contracts, retention schedules, assessments and incident response.
Make consent an operating control
Official government guidance stresses clear, standalone notices in plain language. That means consent should not be hidden in a general terms document or captured without a record of what the person saw.
| Consent control | Minimum evidence |
|---|---|
| Notice | Version, purpose, data categories and effective date |
| Choice | Affirmative action, timestamp and channel |
| Withdrawal | Accessible method and completion record |
| Change | Re-consent rule when purpose materially changes |
| Processor action | Proof that downstream handling follows withdrawal |
The difficult part is not displaying an accept button. It is ensuring that withdrawal propagates to marketing tools, analytics, data warehouses and processors without breaking legitimate obligations.
Design a digital rights workflow
A digital regime needs more than an email inbox. Requests should move through identity verification, system search, decision, fulfilment and closure with deadlines and evidence.
Test these scenarios before launch
- A customer asks what personal data is held across the CRM, support platform and billing system.
- A former employee requests correction of an inaccurate record.
- A user withdraws consent while a processor still holds a copy.
- A deletion request conflicts with a legal retention obligation.
- A grievance is escalated after the first response is disputed.
Each test should reveal the owner, systems touched, decision rule, response template and audit trail.
Treat vendors as part of the privacy system
Contracts establish obligations, but assurance requires operating evidence. Build a processor register that links each vendor to its purpose, data, security assessment, contract, sub-processors, incident duties, deletion requirements and review date.
High-risk vendors should be tested rather than accepted on declaration alone. Useful evidence includes independent assurance reports, penetration-test summaries, incident metrics, access-control reviews and deletion confirmations.
Use ISO 27701 as the management layer
ISO/IEC 27701 can help turn DPDP tasks into a repeatable Privacy Information Management System. It provides structure for roles, risk assessment, documented controls, internal audit, management review and continual improvement.
The mapping must remain honest: ISO 27701 does not replace legal interpretation or prove DPDP compliance by itself. Use it to operate and audit the programme, then map each applicable legal obligation to the responsible process and evidence.
A phased implementation roadmap
Phase 1: discover and govern
- Confirm scope, leadership accountability and privacy roles.
- Build the processing inventory and processor register.
- Approve purpose, retention and risk-assessment methods.
Phase 2: change journeys and systems
- Rewrite notices and consent interactions.
- Implement withdrawal, rights and grievance workflows.
- Add deletion, logging and processor instructions.
Phase 3: prove operation
- Run request, withdrawal and breach exercises.
- Sample vendor and consent records.
- Complete internal audit and management review.
- Track corrective actions to closure.
ICyberWave perspective
Krishnan’s digital-first framing makes privacy evidence especially important: every choice, request, decision and correction should be traceable. ICyberWave supports data mapping, DPDP gap assessment, privacy controls, ISO 27701 alignment and internal audit. Continue with our data fiduciary obligations guide and DPDP Rules analysis, or talk to us about a practical roadmap.

