How are Indian companies actually preparing for DPDPA?

I’m trying to get my head around what DPDPA implementation actually looks like inside a company. Everything I read makes sense at the legal level, but once you start thinking about actual systems — customer databases, CRM, analytics, vendors, employee data, deletion requests, access controls etc. — it seems like a much bigger project.

For companies that are already doing ISO 27001 or SOC 2, are you just extending the existing controls for DPDPA or treating it as a completely separate project? And for smaller companies without a dedicated privacy team, what are people actually doing?

reddit.com
u/Little_Face_639 — 20 hours ago

Is anyone else finding that compliance is becoming a second security job?

I’m on the technical side of a growing company and one thing that’s starting to annoy me is how much time gets pulled into compliance requests. Someone needs evidence for a control, someone wants a screenshot, someone asks where a particular type of data lives, another person wants an access-control report, etc.

I understand why it’s necessary, but it feels like we’re spending a lot of engineering time proving that things exist rather than actually improving them. How are other teams handling this? Are you automating evidence collection/GRC stuff or do you just accept that this is part of the job?

reddit.com
u/Little_Face_639 — 20 hours ago

How can 1 person manage so much compliance work?

I’m working with a growing business and I’m starting to realize how messy compliance becomes once the company gets beyond a certain size. There are policies, audits, vendor documents, privacy requirements, evidence requests, internal controls etc., and half the time the information seems to be sitting with different people in different places.

The frustrating part is that none of these things individually seem that difficult, but together they become a full-time coordination exercise. For CAs who work with growing companies, how do you normally handle this? Is there a point where you recommend bringing in a proper GRC/compliance platform rather than continuing with Excel + Drive + consultants?

reddit.com
u/Little_Face_639 — 20 hours ago
▲ 4 r/grc

Here AI Could Change GRC

I think one of the more interesting opportunities in enterprise AI is happening in areas that aren’t traditionally considered “AI-first” markets.

Compliance and GRC are good examples. There is an enormous amount of structured but repetitive work involved in mapping regulations, identifying gaps, maintaining controls, collecting evidence and monitoring changes. At the same time, the consequences of getting something wrong mean you can’t simply remove humans from the process. The companies that figure out the right balance between AI automation and expert oversight could fundamentally change how compliance teams operate.

reddit.com
u/Little_Face_639 — 1 day ago

Discussion around the operational burden of compliance

I’m trying to understand how smaller companies are realistically handling privacy compliance as regulations keep expanding. It feels like the hard part isn’t necessarily understanding GDPR/DPDPA/etc., but actually turning all of those requirements into policies, controls, evidence and processes that the company can maintain.

For companies that don’t have a huge compliance team, what does the practical setup look like? Do you use consultants, dedicated compliance software, internal teams, or some combination of the three? I’m particularly interested in what happens after the initial compliance project is finished.

reddit.com
u/Little_Face_639 — 11 days ago