Skip to main content

Sources last verified on 17 August 2026. Methodology

Role guide

CTO and engineering leaders

Your organisation's DPDP obligations do not change because you are the CTO. What changes is which work your function usually leads, which work you feed into, and what you should see first.

How to read this page. The obligations belong to your organisation, not to a role or a sector. Everything here is practical emphasis: which official duties this audience usually leads or feeds into, with links to the official text. Finishing one function's work never makes the company compliant by itself.

Work your function usually leads

  • Security safeguardsRule 6, official text →

    Encryption, access control, logging, backups and log retention are engineering owned controls in most organisations.

  • Retention and erasure mechanicsRule 8, official text →

    Erasure timers, the forty eight hour notice before erasure and the one year log retention are built and operated by engineering.

  • Breach detection and containmentRule 7, official text →

    The clocks start on awareness, and awareness usually starts in engineering monitoring.

Work your function usually feeds into

  • Notice and consent flowsRule 3, official text →

    Legal usually drafts the notice; engineering ships the itemised description, withdrawal path and complaint link.

  • Rights request handlingRule 14, official text →

    Publishing the request channel and meeting the grievance response system expectations needs product and engineering work.

Tools for this role