How much effort and time will it take to be ready by 13 May 2027?
Short answer: Six to nine months of steady work for most
For most organisations it is a programme of six to nine months, not a single project. The heavy parts are the data inventory, vendor contracts, access control and the request process. Notices, the contact person and training are lighter. Starting now leaves time to fix what you find.
What the law says
Most duties under the DPDP Rules start on 13 May 2027.
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 8(1)–(2): The organisation that decides why and how data is used (the Data Fiduciary) stays responsible, even when a vendor (Data Processor) does the work. A processor may be engaged only under a valid contract.
Sections 11–14 · Rule 14: People can ask for a summary of their data and who it was shared with, ask for correction, completion, updating or erasure, complain, and nominate someone to act for them. You must publish how to do this.
Steps
Month 1: name the owner, set a budget line, start the inventory.
CEO / MD: Treat it as a nine-month programme with one owner. The cost is mostly people's time and some system changes, not a single tool.
Director: Ask for evidence against the plan, such as signed contracts, rehearsal reports and request logs, not just status colours.
Chief risk officer: Track the programme against dated milestones and report slippage early.
What a good answer from management sounds like
“We have a dated plan with named owners. Each month we see evidence, not just colours, and we expect to finish before March 2027.” Effort and time: Programme · six to nine months.