Ask any business owner where their company stands on DPDP and you will usually get one of two answers.
“Our legal team is handling it.” Or, “We already paid a consulting firm for an assessment.”
Both answers sound like progress. Neither one usually is.
Here is a quick story that makes the point. A founder running a two hundred person software company told me DPDP was “with legal” and considered the matter closed. Around the same time, another business owner showed me a thick report his company had just paid a large consulting firm for. It had charts, diagrams, and on the very first page, in bold letters, the ₹250 crore penalty figure.
I asked him what had actually changed inside his company since that report landed on his desk. He thought about it and said, “We know more.”
Nothing else had moved. The same employees could still access customer data. Former staff whose logins were never switched off could still log in. The only new thing in the building was a very expensive document describing all of this in detail.
Two companies, two different approaches, and neither one is any closer to being compliant.
What DPDP actually is
The Digital Personal Data Protection Act is India’s first real data protection law. It covers every business holding personal data, regardless of size or industry. The exemptions are mostly for government bodies, not private companies.
And that ₹250 crore number every vendor loves to open with? It is not your fine. It is the maximum penalty, reserved for a company with zero safeguards that also lied to the regulator afterward. When a sales pitch leads with that figure, it is not informing you. It is scaring you into signing.
Strip away the fear and DPDP is really the government handing itself the power to enforce something businesses already owed their customers: basic data security. Until now, that obligation was optional unless a sector regulator like RBI or SEBI already required it.
Your lawyer can’t compliance you out of this
Lawyers are essential here, but only for a slice of the work. They can write your consent notices, build data protection clauses into vendor contracts, sort out where erasure rules clash with other laws like tax retention requirements, and represent you if the Data Protection Board ever comes calling.
That is real, necessary work. It is also roughly ten percent of the total job.
Look at what the law punishes hardest, and it is not paperwork. The steepest penalties are for failing to protect data and failing to report a breach. Both are operational failures, not legal ones.
Where the money actually goes
Based on a year of doing this work with clients, the real breakdown looks something like this. Half of the effort is security work: controlling who can touch personal data, protecting the devices it sits on, and noticing when it leaves through email, uploads, or AI tools. This is expensive, but it is also work you already owed your customers before DPDP existed.
Roughly a third is IT work: figuring out where personal data actually lives across your databases, spreadsheets, and SaaS tools, and building the plumbing so a correction or deletion request reaches every copy of that data, including at your vendors.
The remaining fifth splits between legal drafting and consent tooling, the banners and withdrawal flows on your website and apps.
If you sell to consumers, that consent slice grows, since every signup form and app screen becomes a collection point. If you sell mostly to businesses, your personal data is largely your own staff and a handful of client contacts, so consent work shrinks and security takes up the rest of the budget.
And the biggest piece of this puzzle has no price tag at all. It is a decision: collect only what you need, say why you are collecting it, use it only for that reason, and delete it once the purpose is served. That decision costs nothing, and it is the hardest one on the list, because it means telling your own sales and marketing team no.
The order that matters: discover, prune, defend, prove
Handily, the law’s own initials spell out the right sequence. Discover what personal data you hold and where it lives. Prune it down to only what you need. Defend it with real security controls. Prove all of this through documents your lawyer drafts, backed by evidence your IT and security teams generate.
Most vendors sell the “prove” step first, as a glossy report, before any of the actual defending has happened. That is backwards, and it shows on the day something actually goes wrong. The Data Protection Board will read your privacy policy, then check it against what your systems actually do. A policy written before the controls exist is just a list of promises you already broke, on your own letterhead.
Even if the deadline moves, you lose nothing
Maybe the deadline gets extended. That is possible, and worth welcoming if it happens. But test each piece of the work against one question: does it pay off even without the law?
Finding out where your data lives helps the moment you have any kind of incident. Collecting less data means less to protect and less to leak. Strong security stops breaches and answers the audit questionnaires your biggest customers are already sending you. Only the documents and consent banners are truly deadline shaped, and they are the smallest, last part of the job.
The deadline was never the start line. It is just the date you have to show your homework.
Where AI actually earns its place in this
The hardest part of the “discover” step is that personal data rarely lives in one tidy place. It is scattered across databases, spreadsheets, CRMs, and half a dozen SaaS tools that different teams signed up for over the years. Mapping all of that by hand is slow, and it goes stale the moment someone adds a new field or a new vendor.
This is exactly the kind of messy, ongoing tracking that agentic AI is suited for, and it is where Evvo Technology comes in. Evvo builds agentic AI systems that can continuously scan and map where personal data actually sits across a company’s systems, flag copies that were never accounted for, and keep that map current as the business changes, instead of leaving you with a one time PDF that is outdated in six months.
If your DPDP work is stuck at the discovery stage, or you need the plumbing that keeps corrections and deletions flowing to every copy of a record, that is a conversation worth having with Evvo Technology.
Protecting data while it sits in storage or moves across networks is only part of the picture. If you want to see how encryption gaps get closed even while data is being processed, read our piece on Confidential Computing: Securing Data in Use.

