DPDP NavigatorAct 2023 · Rules 2025
All guides
Role-Based Playbooks

DPDP for Data Protection Officers: Structuring Your First 90 Days

29 Jul 202612 min read

Walking into a newly created DPO role with a broad mandate and no starting map. A practical 30-60-90 structure to build real traction fast.

Start by understanding what the role actually requires here

Section 8(9) requires a published business contact for privacy questions; Section 10 requires a resident DPO reporting to the board for organisations designated as a Significant Data Fiduviary, alongside an independent data auditor and periodic DPIAs. Before building a plan, confirm which of these applies to your organisation today, because the scope of the mandate differs meaningfully between a general privacy contact person and a full SDF-grade DPO function.

Whatever the formal designation, the practical job in the first 90 days is the same: find out what's actually true about how the organisation handles personal data, distinguish that from what policy documents claim is true, and build the minimum durable infrastructure to close the gap.

Days 1-30: map reality, not policy

Run a Personal Data Inventory exercise across every function that plausibly touches personal data — not just the obvious ones like product and support, but HR, finance, marketing, and facilities. The goal in month one is breadth over depth: know that a data flow exists before trying to perfect its governance.

Review existing vendor contracts for Section 8(2) coverage, existing consent flows for Section 6 sufficiency, and whatever breach-response process (if any) currently exists. Treat every gap you find as data, not as a personal failing of whoever came before you — the point of the first month is an honest baseline, not blame.

Meet the people who will be your actual working partners: engineering leadership (for technical controls), legal (for contracts and regulatory exposure), and whoever currently fields customer complaints (for rights-request reality on the ground).

Days 31-60: fix the highest-risk gaps first

Prioritise by exposure, not by ease. A missing erasure mechanism for a core customer database is a bigger problem than an imperfect vendor contract for a low-risk internal tool, even if the vendor fix is quicker to execute.

Stand up (or fix) the breach response process first among the operational items — Section 8(6)'s intimation obligations to the Board and Data Principals mean this is the one gap where 'we'll get to it next quarter' carries the most acute risk if an incident happens in the meantime.

Put a working, trackable rights-request process in place, even a manual one, covering access, correction and erasure under Sections 11 and 12, with the internal grievance step required by Section 13 clearly defined before requests need to escalate.

Days 61-90: build durability, not just fixes

Turn one-off inventory and vendor review work into a repeatable cadence — a quarterly refresh of the Personal Data Inventory and vendor register, rather than a single point-in-time exercise that goes stale within months.

Establish the review gate that should catch new risk going forward: a lightweight privacy check embedded into product design reviews and vendor procurement intake, so the DPO isn't perpetually cleaning up after decisions made elsewhere without input.

Report a concise status to leadership or the board: what's fixed, what's in progress, what's known but not yet resourced. A DPO's credibility in month four depends heavily on how honestly this first report is framed in month three.

Where to go next

Use the Readiness Assessment to establish the baseline in week one, and the Evidence Tracker from day one so that everything fixed in the first 90 days has a documented trail rather than living only in memory.