How are Indian companies actually preparing for DPDPA?
I’m trying to get my head around what DPDPA implementation actually looks like inside a company. Everything I read makes sense at the legal level, but once you start thinking about actual systems — customer databases, CRM, analytics, vendors, employee data, deletion requests, access controls etc. — it seems like a much bigger project.
For companies that are already doing ISO 27001 or SOC 2, are you just extending the existing controls for DPDPA or treating it as a completely separate project? And for smaller companies without a dedicated privacy team, what are people actually doing?