Authors: Shweta Chaudhury and Vinod Rajasekaran (Inputs from Vijay Rasquinha, Sushil Kambampati, Nitish Gupta
India notified the Digital Personal Data Protection (DPDP) rules in November 2025. The regulations apply to digital data, as well as offline data that is subsequently digitized. At its core, the DPDP Act puts the rights of Data Principals front and centre, requiring organisations that collect, process, or use personal data to take significant steps to protect those rights. The rollout of enforcement is happening in phases, with full statutory compliance for all provisions required by May 2027. With the compliance deadline looming, T4D’s Fractional CxO program saw a growing number of questions from NGOs we work with and are connected to. Many organisations reached out to understand where to begin, what actions they needed to take, and how they could prepare themselves within the given timelines.
This coalesced well with what we have loosely worked on at Project Tech4Dev over the previous years on cyber and data security, and privacy. And it aligns with the perspective of the communities we, as a sector, work with, with them trusting us with their stories long before any law required it. It’s on us now, as a sector, if were not doing it already, to protect that trust.
One thing was clear: the development sector needed practical, reliable guidance and support on DPDP compliance. We had seen a lot of position papers and heavy legal sounding guidance but we wanted to come in from the angle of how do we translate that into action from a tech and data perspective, and break things down into something that would help non profits roadmap their way to legal compliance, and better cyber and data security principles.
As we started engaging with NGOs on this topic, we saw a lot of uncertainty around what the requirements actually meant. There was concern about the cost and complexity of implementation, as well as anxiety around the consequences of non-compliance. Most NGOs felt overwhelmed and weren’t sure where to even start.
Our Approach: Designing for the Development Sector
For many NGOs in India, this challenge is particularly significant. They operate in low-resource environments, work with some of the most marginalized communities, and often have limited time and capacity to dedicate to complex regulatory requirements.
It quickly became clear from working deeply with a couple of NGOs on DPDP compliance that our role needed to happen at multiple tiers. We realised we need to help demystify the DPDP Act, provide snapshots of where we were at a dipstick level to better understand the gaps and also in comparison to our peers in the ecosystem, create accessible resources for the ecosystem, and build a hands-on advisory practice to support organisations in implementing the processes and systems needed for compliance.
- We built a self-serve platform where NGOs can access practical DPDP resources. On this platform, NGOs can also take a dipstick self-assessment, answering 25 questions across five DPDP compliance areas to receive an instant readiness score. Based on their responses, they also receive an AI-generated customised 30/90/365-day action plan to help them prioritise their next steps. This should allow for NGOs to align with their management and board on what’s needed for compliance at a high strategic level.Â


- A free resource hub on the same site, created specifically for NGOs, includes a DPDP primer to help organisations understand the key requirements of the law. As we learn more and also possibly leverage resources from other organisations, we intend to populate this site with self-help resources that organisations can use effectively towards DPDP compliance and more importantly safeguarding the data of their communities.Â
- We designed a tiered advisory engagement model for NGOs, ranging from a structured light-touch review to a deeper implementation partnership.
This multi-pronged approach has ensured that NGOs and CSOs of all sizes can access relevant guidance and begin their journey towards compliance.
Planning for Success
Being DPDP compliant is not just a technology exercise. It is equally about people, processes, and organisational practices. There are two factors that will be critical to the success of DPDP implementation within NGOs:
- The first is organizational will. We highly recommend that the DPDP program is sat inside the CEO/senior leader’s office, ensuring there is a strong mandate and direction from the top. And that there is a dedicated lead who can anchor all the DPDP related activities in one place.
- The second is strong change and culture management. Being compliant to DPDP will require changing the ways of working, it will require field SOPs to be changed – not just on paper but in practice as well. And that will require shepherding teams internally to ensure everyone is able to move to the new ways of working with as little disruption as possible. A lot of behaviour and culture change to work through
The Future: Scale Up and Scale Out
As we hear more from the ecosystem, and engage with individual NGOs, we will keep building open resources which are most relevant and useful for the sector. These may be simple artefacts like examples of good vetted policies, consent messages, or industry standard anonymisation algorithms / techniques. Or they may be on more involved topics like factors to consider when deciding whether to get a consent manager or not, or building a data access matrix and how to audit PII data usage. We will continue to build our open repository of resources for the ecosystem.
We plan to conduct ecosystem engagements such as webinars and in-person convenings with other partners to allow for cross learning. As we iteratively learn and conduct each of our deep DPDP compliance engagements, we will apply those learnings to create more open resources and products that can help set the development sector for DPDP success.