Skip to content

Executive overview

OpenDPDP should be funded as a privacy operations and evidence plane, not as a badge generator. Its job is to give each obligation a source, effective date, owner, operational workflow, system task and evidence trail while keeping raw personal data in customer systems wherever feasible.

DPDP — not yet effective

Most main DPDP obligations start on 13 May 2027. Readiness is nevertheless a multi-quarter data, contract, identity and integration programme.

Approve a 90-day engineering MVP that can:

  • establish the customer’s entities, roles, licences and applicability profile;
  • approve versioned purposes and standalone notices;
  • issue and withdraw consent receipts through an API;
  • intake and route rights requests and grievances;
  • operate retention rules, legal holds and manual deletion tasks;
  • manage a breach case with separate DPDP, CERT-In and sector clocks;
  • maintain processor/vendor obligations and an append-only evidence log;
  • ship two connectors: one generic webhook/API adapter and one metadata-only database scanner;
  • deploy securely through Docker Compose for evaluation and Kubernetes for controlled pilots; and
  • apply one deep sector pack, initially banking/fintech/payments.

This is the smallest coherent control loop. A consent banner alone cannot handle downstream withdrawal, rights, retention, incidents or evidence; an inventory alone cannot operate a request.

Accountable groupOwnsOpenDPDP providesDoes not replace
Board / executive riskappetite, funding, designation responsereadiness and risk dashboardsboard judgement
Privacy / DPOlegal interpretation, notice, rights, grievancesource-linked workflow and evidencecounsel
CISO / incident commandsafeguards and responsecontrols, clocks, packs, immutable timelinesecurity programme
Data and system ownerspurpose, inventory, fulfilment, deletionassignments, APIs, reconciliationsource systems
Procurement / vendor riskcontracts and outsourcing decisionsprocessor register and evidence roomsnegotiations
Internal auditassurance plan and conclusionscontrol/evidence index and exportindependent audit

Build a modular monolith first. Separate a shared control plane from customer-side connector agents. Persist subject references and workflow evidence, not a shadow copy of customer PII. Support multi-tenant SaaS, a dedicated tenant, customer VPC and on-premises Kubernetes from the same versioned product, with air-gapped update bundles later.

By the end of a pilot, a customer should answer five questions using current evidence:

  1. Why is this data processed, under which DPDP route, and where does it flow?
  2. Which notice and consent proof applied at a specific time?
  3. Can withdrawal, correction, erasure or grievance reach every relevant system?
  4. When an incident occurs, which clocks apply and who approved each notification?
  5. Which records were retained, held or deleted, under which source-linked rule?

The success metric is not “number of consents collected.” It is the percentage of high-risk processing with approved purpose, current notice, tested fulfilment path and verifiable evidence.