DPDPA readiness for the mid-market: a pragmatic 90-day plan
The Digital Personal Data Protection Act is here. A practical, control-based readiness path that a mid-sized business can actually execute.
- Published
- 05 March 2026
- Last reviewed
- 25 July 2026
- Law as at
- 01 March 2026
- Reading time
- 8 min
- Author
- ATPM And Co
- Technical reviewer
- Partner, ATPM And Co
Most mid-market DPDPA programmes fail not on policy drafting but on operationalisation - the moment a data-principal request lands, gaps in inventory and retention surface immediately.
Start with a data-map. You cannot protect what you have not inventoried. Sales, HR and support tools are typically where regulated personal data lives.
Contracts with processors - payroll, marketing, cloud - need updated data-processing terms. Silence here is the single largest exposure in the mid-market.
Finally, treat consent and breach-response as engineering problems, not legal ones. Both need runbooks, owners and tested workflows.
Faceless assessments: what to expect in the next scrutiny cycle
A firm-level view of preparing for faceless scrutiny - documentation posture, response drafting, and choosing when to seek a personal hearing.
GST litigation in 2026: the shifts every finance head should track
From ITC time-limits to the operationalised GST Tribunal - the practical implications for corporates and MSMEs.
