DPDP Act Compliance Timeline: What a Foreign Company Needs to Do First
The Digital Personal Data Protection Act applies to any company processing personal data of individuals in India, a compliance program typically takes 8 to 12 weeks to stand up from scratch.
India's DPDP Act applies extraterritorially, any company processing the personal data of individuals in India is in scope, regardless of where the company is incorporated, if it's offering goods or services to people in India. For a foreign company with an Indian subsidiary or customer base, the first compliance steps are: mapping what personal data is collected and processed, establishing a valid consent mechanism, and updating privacy notices to meet DPDP's specific disclosure requirements.
Building this out from a standing start, data mapping, consent flow updates, notice revisions, internal policy documentation, typically takes 8 to 12 weeks for a mid-sized operation, longer if the company's existing data flows are poorly documented internally, which is common for companies that haven't previously needed to do this kind of mapping for GDPR or another regime.
Companies already GDPR-compliant have a real head start, the underlying data mapping work overlaps significantly, but DPDP's consent and notice requirements aren't identical to GDPR's, and a straight copy-paste of GDPR documentation won't satisfy DPDP's specific requirements.