Building a DPDP Compliance Operating Model: Who Owns Privacy Across HR, IT, Legal, Security and Marketing?
Compliance fails quietly when no one owns it. A RACI-style model for spreading DPDP accountability across departments.
Compliance without an owner is a policy, not a practice
Most organizations can produce a privacy policy PDF. Far fewer can answer, on the spot, who is responsible when a rights request arrives on a Friday afternoon, or who signs off before marketing launches a new tracking pixel.
Section 8 of the DPDP Act places the compliance burden squarely on the Data Fiduciary as a legal entity — but internally, that responsibility has to be distributed across real people and teams, or it collapses into nobody's job.
A simple ownership split
Legal / Privacy Lead: owns interpretation of the Act and Rules, approves new processing purposes, and is the final escalation point for ambiguous cases.
IT / Security: owns technical safeguards under Section 8(5), breach detection, and the first 24 hours of any incident response.
HR: owns employee and candidate data processing, including background checks and any special exceptions for employment-related processing.
Marketing: owns consent capture for campaigns, cookie banners, and any behavioural advertising — with a hard rule that new tracking mechanisms are reviewed before launch, not after.
Customer Support / Operations: owns first-line handling of rights requests and grievances, escalating to Legal when a request is disputed or ambiguous.
The single artefact that keeps this honest
A one-page RACI (Responsible, Accountable, Consulted, Informed) chart mapped against the eight-step implementation framework — Understand, Check Applicability, Map Data, Manage Consent, Secure Data, Manage Retention, Respond to Breaches, Review & Improve — keeps ownership visible and prevents the 'I thought someone else was doing that' failure mode.
Revisit this chart whenever a new product line, vendor, or data category is introduced — ownership models decay quietly as organizations grow if nobody is assigned to update them.
Where to go next
Run the Readiness Assessment with representatives from each function in the room, and use the weakest-scoring pillar to decide who needs clearer ownership first.