DPO under the DPDP Act: Appointment, Role and Responsibilities in India
Understand who must appoint a DPO under India’s DPDP Act, the May 2027 commencement position, reporting lines, responsibilities, checklist and KPIs.
Privacy governance under India’s DPDP framework is the system by which leaders make, fund, evidence and revisit decisions about personal data. It is broader than appointing a privacy contact and narrower than a generic ESG programme. Current status, verified 29 August 2026: most substantive DPDP duties are notified but scheduled to commence around May 2027. Organisations can use the lead time to assign decision rights and test controls without presenting future obligations as already enforceable.
Start with accountability. The board or governing body sets risk appetite and receives material privacy, security and remediation information. An executive sponsor resolves cross-functional conflicts and owns resources. Legal interprets obligations; product and data teams own purpose and design decisions; security operates safeguards and incident response; procurement governs processors; and the privacy lead coordinates evidence, rights and change control. Only a notified Significant Data Fiduciary must appoint the statutory India-based DPO under Section 10 when that provision applies. Other organisations may appoint a DPO or privacy lead voluntarily, but should describe the role accurately.
Use a decision-rights map for high-impact moments: launching a new purpose, using children’s data, onboarding a processor, transferring data across borders, changing a notice, retaining data beyond the stated purpose, responding to a breach and rejecting a rights request. Each decision should have a named owner, required reviewers, evidence fields, escalation threshold and expiry or review date. A RACI is useful only if it maps to the real product and incident workflow.
Operate governance on a cadence. Product teams can review new or materially changed processing at release gates; procurement can perform risk-tiered processor reviews at onboarding and renewal; security and privacy can reconcile data maps, consent evidence, rights queues and retention exceptions monthly; and leadership can review high-risk gaps and incident readiness quarterly. A notified SDF will have additional statutory DPIA, independent-audit and reporting requirements once the relevant provisions commence; other organisations can adopt similar assurance proportionately as good practice.
Evidence matters more than organisational charts. Retain approved purposes, processing records, notices and versions, consent or permitted-use decisions, processor contracts, risk acceptances, deletion and restriction decisions, training records, incidents, exercises and remediation closure. Board reporting should connect metrics to decisions: overdue high-risk gaps, untested critical data flows, rights-request ageing, withdrawal propagation failures, processor exceptions, security-control evidence and repeat incidents.
Use the linked specialist pages to go deeper: the DPO guide owns appointment and operating responsibilities; the SDF guide owns notification criteria and enhanced duties; the audit checklist owns control evidence; the board-KPI guide owns measures and thresholds; and the breach playbook owns incident decisions. This hub is the leadership route map joining those subjects without duplicating them.
6 articles
Back to home
Understand who must appoint a DPO under India’s DPDP Act, the May 2027 commencement position, reporting lines, responsibilities, checklist and KPIs.
Build board privacy KPIs with reproducible formulas, owners, data sources, cadence, risk-appetite thresholds, RAG rules and escalation triggers.
A strategic guide for Indian retail and D2C leaders on managing 3PL data sharing under the DPDP Act 2023 and DPDP Rules 2025, clarifying brand, 3PL, and processor responsibilities so first-party data programs can grow without creating regulatory risk.
DPDP-aware pre-launch checklist and validation strategy for releasing privacy and consent features in Indian digital products, aimed at engineering and technical leaders.
A business-style piece for decision-makers that explains cross-functional privacy governance— legal, product, security, marketing and turns policy requirements
A business-style piece for decision-makers that explains how to create a privacy steering committee that actually works and turns policy requirements into an
Here to help
Share your details and the team can take it forward from here.