Days 1–30: find the processing
List the customer, employee, prospect and vendor data the company actually uses. Connect each dataset to a purpose, system, processor, lawful ground, retention point and accountable owner.
Start with high-volume and high-impact journeys such as onboarding, payments, support, analytics, recruiting and marketing. The goal is a useful decision map, not an exhaustive spreadsheet that nobody maintains.
Days 31–60: repair the public journeys
Rewrite notices around real purposes, separate consent where required and design withdrawal. Publish a rights and grievance channel that can locate records using identifiers the startup already controls.
Review processors and sub-processors at the same time. Product changes cannot be made reliably without knowing which vendors receive the data and how deletion or incidents are communicated.
Days 61–90: prove the workflows
Test one withdrawal, one access or erasure request and one breach scenario end to end. Record where ownership, tooling or evidence fails and convert those gaps into a dated remediation backlog.
Leadership should receive a short readiness report: material processing, top gaps, risk owners, target dates and decisions that require funding. This creates governance without pretending the programme is finished.
- Do not wait for a perfect privacy policy before fixing the product.
- Do not assume a vendor's compliance replaces your accountability.
- Do not collect more data merely because storage is inexpensive.
Sources and editorial review
Prepared by DPDP Academy Editorial (Legal education and implementation guidance). Reviewed by DPDP Academy Source Review using the sources below on 2 August 2026. Statutory text, notified Rules and practical interpretation are kept distinct. Educational content, not legal advice.