Skip to content
FaceOff Technologies

DPDP by industry

DPDP for large enterprises and conglomerates

Group structures multiply every obligation: multiple legal entities, shared services, a common CRM and cross-entity data flows that were never modelled as transfers between separate Fiduciaries.

Deadline
13 May 2027
Pressure points
3 identified
Controls
5 products
Max penalty
₹250 Cr, per instance

Already regulated by

  • MeitY
  • CERT-In
  • sector regulators per entity

DPDP sits alongside these rather than replacing them. Where a sectoral rule requires retention and the Act requires erasure, both are satisfiable — but only where the basis is recorded per attribute.

Where the pressure lands

What DPDP actually changes for large institutions

The Act applies uniformly. The obligations that bite first do not — these are the ones this sector fails on.

Sec. 2(i), 4

Which entity is the Fiduciary?

Shared platforms across group companies make the determining party ambiguous. The Act attaches duties to whoever determines purpose and means, so the answer has to be recorded per processing activity rather than assumed from the org chart.

Sec. 8(3), 11

Cross-entity sharing is sharing

Moving personal data between group companies is disclosure to another Fiduciary, with the notice and lawful-basis consequences that follow.

Sec. 10

SDF notification by class

Volume and sensitivity make large groups the most likely candidates for Significant Data Fiduciary notification, which switches on DPO, auditor, DPIA and algorithmic duties on a government timetable rather than yours.

What closes them

The controls, in the order they land

Discovery first, because every other obligation is undeliverable without a catalogue. Everything after that consumes what it built.

  1. 01

    Privacy Program Governance

    Run the whole privacy programme from one control plane, so the next regulation lands as configuration.

    Sec. 4, 7, 10, 16

  2. 02

    Intelligent Data Mapper

    Replace stale inventories with a live, identity-resolved map of every place personal data actually lives.

    Sec. 8(3), 8(7)

  3. 03

    PIA / DPIA Assessment

    Find and price privacy risk at design time, and keep a defensible assessment record the auditor can read.

    Sec. 10(2)

  4. 04

    Audit & Evidence Management

    Prove compliance from evidence rather than assert it from policy, at any depth, on demand.

    Sec. 10(2)(b)

  5. 05

    DSAR Management

    Receive, verify, fulfil and audit every access, correction, erasure and grievance request inside the statutory clock.

    Sec. 11–14

Sequence

A readiness plan that buys down the biggest exposure first

The same four phases apply in every sector; what changes is which systems go first.

  1. Phase 1

    Weeks 1–6

    See the estate

    • Deploy Discovery across priority systems
    • Build the identity-resolved catalogue
    • Reconcile collected data against notice
  2. Phase 2

    Weeks 4–12

    Stop the bleeding

    • Mask non-production and analytics estates
    • Deploy breach detection and playbooks
    • Wire intimation to the catalogue
  3. Phase 3

    Weeks 8–18

    Fix the basis

    • Roll out purpose-level consent and notice
    • Enforce withdrawal parity and cessation
    • Turn on children's age-band gating
  4. Phase 4

    Weeks 14–26

    Prove it

    • Automate DSAR intake and fulfilment
    • Run DPIA cadence for SDF duties
    • Open the auditor workspace

Also defending large institutions?

Enterprise-scale deployment with federated architecture, so trust analytics run without centralising sensitive biometric data.

See the Large Institutions solution

Find the gaps in your large institutions programme.

A readiness walkthrough maps what you already run onto the eighteen obligations, and names what is missing with the exposure attached.