The nine operational capabilities companies need to build for DPDP compliance

https://cdn1.expresscomputer.in/wp-content/uploads/2024/01/09113031/privacy-security-data-protection-shield-graphic-concept.jpg

By Sachin Salian, SVP & Global Business Head – Cloud and Data Services, Writer Information

For the past two years, DPDP readiness in India was largely treated as a documentation exercise.

Enterprises published privacy notices, rewrote consent language, appointed data protection Officers and assured their boards that compliance programmes were progressing well. Those were necessary first steps. Yet they leave unanswered the question that regulators, auditors and customers will ultimately ask: when an individual withdraws consent, requests access to their data or seeks its deletion, can the organisation prove that every system handling that information acted accordingly within the required timeframe?

That question marks the transition from policy to operations. With the Digital Personal Data Protection (DPDP) Rules, 2025 now notified, the Data Protection Board operational and a phased compliance window closing in May 2027, that transition is no longer theoretical. Organisations are discovering that compliance will not be judged...

Copyright of this story solely belongs to expresscomputer.in. To see the full text click HERE

Read more