Insights · Regulatory

DPDPA readiness for the mid-market: a pragmatic 90-day plan

The Digital Personal Data Protection Act is here. A practical, control-based readiness path that a mid-sized business can actually execute.

Published
05 March 2026
Last reviewed
25 July 2026
Law as at
01 March 2026
Reading time
8 min
Author
ATPM And Co
Technical reviewer
Partner, ATPM And Co

Most mid-market DPDPA programmes fail not on policy drafting but on operationalisation - the moment a data-principal request lands, gaps in inventory and retention surface immediately.

Start with a data-map. You cannot protect what you have not inventoried. Sales, HR and support tools are typically where regulated personal data lives.

Contracts with processors - payroll, marketing, cloud - need updated data-processing terms. Silence here is the single largest exposure in the mid-market.

Finally, treat consent and breach-response as engineering problems, not legal ones. Both need runbooks, owners and tested workflows.

Disclaimer
This note is a general summary written for professional colleagues and clients of ATPM And Co. It reflects the position of law as at the date shown and is not a substitute for professional advice on the specific facts of any matter. Readers should consult the firm before acting on any point covered here.