Guides
DPDP for your role
Your organisation's obligations are the same whoever is reading. Your role changes which work you own, which work you contribute to, and what you see first. Finishing your part never makes the company compliant by itself.
Role guide
CTO and engineering leaders
Your organisation's DPDP obligations do not change because you are the CTO. What changes is which work your function usually leads, which work you feed into, and what you should see first.
Read
Role guide
Legal and privacy counsel
Legal usually interprets the framework for the organisation and drafts what users see. The obligations still bind the organisation as a whole, and much of the delivery sits with other functions.
Read
Role guide
Compliance and data protection officers
Compliance usually runs the company plan: tracking what applies, who owns what, and whether the evidence would satisfy a reviewer. Ownership of individual controls stays with the delivering functions.
Read
Role guide
Security teams
Security carries the safeguards and the breach clock. The duties bind the organisation, but the first hours of a breach usually live entirely inside your function.
Read
Role guide
HR and people teams
Employee data is personal data. HR usually owns the employment lifecycle processing and feeds the company plan rather than running it.
Read
Role guide
Founders and small teams
In a small company every function above is you. Nothing in the rules on file gives small companies an automatic carve out, and the work is very tractable when approached as one plan instead of rule by rule firefighting.
Read