For many organisations, data protection begins with documents: a privacy policy, a consent statement, a retention policy, perhaps a processor agreement.
Those things matter. But they are not the same as operational readiness.
The difficult questions live underneath the policy.
Suppose a customer asks for their personal data to be corrected or erased. Can the organisation identify every relevant system in which that data resides?
Suppose consent is withdrawn. Does that decision propagate through the applications, databases, marketing platforms and external processors that rely on it?
Suppose a personal-data breach occurs tomorrow morning. Can the organisation determine what happened, what information was affected, who had access and what evidence exists?
DPDP readiness ultimately has to work in systems — not merely on paper.
India's Digital Personal Data Protection framework brings data governance, individual rights, security safeguards and accountability into sharper focus. The Digital Personal Data Protection Rules, 2025 were notified in November 2025 with a phased commencement framework.
That transition creates something valuable for organisations: time to move from interpretation to implementation.
Start with the data itself.
Before an organisation can protect personal data effectively, it needs to understand what it has.
That means being able to identify personal data across customer platforms, employee systems, applications, databases, cloud environments, analytics platforms and external parties — and understand why that data is being processed.
A spreadsheet may be a useful starting point. It is not the end state.
Then examine whether the controls actually operate.
A mature readiness exercise asks for evidence.
Are privileged accounts appropriately controlled? Is MFA implemented where expected? Are vulnerabilities identified and remediated? Are backups protected? Are logs available? Are access reviews actually performed? Can retention and deletion be demonstrated?
Third parties belong inside the picture.
Modern businesses rarely process information alone. SaaS providers, cloud platforms, payment partners, communications providers and technology vendors can all become part of the processing environment.
Understanding who receives personal data, what they can access and what obligations govern that relationship is therefore part of understanding your own readiness.
Readiness is a technology question.
The strongest DPDP programmes will bring legal interpretation, governance, technology and operations together.
Policies establish intent. Systems determine whether that intent can actually be executed.
And evidence tells you whether it really is.
Tricona examines systems, cloud environments, controls, data flows and third parties to help organisations understand the technology behind their DPDP programme.