Which systems, which tables, where the attachments are.
Three decisions on one screen, inherited by every screen after it.
The Foundation Standard · 2026
India has written its privacy regime in ink. The question for every enterprise operating there is no longer whether to comply, but whether to buy fourteen answers or build one foundation from which all fourteen — and the ones still to come — are computed.
DPDP RULES NOTIFIED 14 NOV 2025 · ONE CORPUS · FOURTEEN OBLIGATIONS · ONE EVIDENCE PACK
01 · The regulatory arc
On 14 November 2025 the Government of India notified the Digital Personal Data Protection Rules, 2025, giving full effect to the Act of 2023. The Rules set an eighteen-month phased path to compliance, with consent-manager provisions arriving after twelve months and the balance of substantive obligations thereafter. That is the window. It closes in the first half of 2027.
What arrives with it is unusually concrete. Every request from an individual to access, correct or erase personal data must be answered within ninety days. Specified large platforms must erase data after three years of inactivity and warn the individual at least 48 hours before doing so. A breach must be reported to the Data Protection Board without delay and in detail within 72 hours, and to affected individuals in plain language. Logs and personal data are to be retained for one year unless law requires longer. Significant Data Fiduciaries must commission an impact assessment and an independent audit every twelve months and furnish the results to the Board.
Sources: Press Information Bureau, Government of India, 14 November 2025; KPMG India, DPDP Rules 2025: Guidance to DPDP Act implementation. Rule-level detail per the notified text as summarised by KPMG; confirm applicability with counsel.
02 · The strategic error
Faced with a list of obligations, large organisations do what they have always done: assign each one to a workstream. Consent to marketing. Requests to customer service. Retention to IT. Breach to security. Each workstream buys or builds a tool, each tool sees one system, and a compliance team reconciles the result in a spreadsheet before every audit.
The error is structural, not managerial. Every DPDP obligation is a question about the same underlying fact: where is personal data, whose is it, why is it held, and what has been done to it. Answer that once, accurately, across every system that holds Indian personal data, and the fourteen obligations become fourteen computations. Compliance is not fourteen problems. It is one problem, asked fourteen ways.
03 · The thesis
Kestryl Cockpit for DPDP rests on a single design decision: bring a read-only copy of every in-scope system — tables and their attachments — onto one server you control, and compute everything downstream from that corpus. Which fields hold personal data. Which policies govern them. Which requests are open and what their clocks say. What was erased, what was held, and what remained afterward.
The consequence is the one line in this paper worth remembering: adding a system is a row on a screen, not a programme. Onboard SAP after Salesforce, or Workday after both, and the inventory, the policy scope, the request handling and the DPDP board update on the next scan.
Three decisions on one screen, inherited by every screen after it.
The board updates when the corpus does — not when someone remembers to update a spreadsheet.
A residual scan under the same fingerprint verifies the result. “Done” is a number, and the number is zero.
04 · Why this foundation
Ten systems that hold Indian personal data have a CDI connector that exists today and is documented by Informatica: Salesforce, SAP S/4HANA and ECC, SAP SuccessFactors, SAP Ariba, Oracle E-Business Suite, Oracle NetSuite, Microsoft Dynamics 365, ServiceNow, Workday and SharePoint Online.
| Requirement | Point solutions per obligation | Secure Agent + Kestryl agent |
|---|---|---|
| Data residency | Each tool decides where data goes | Read-only corpus on your host, your region; no egress during a scan |
| Coverage of attachments | Usually out of scope | Table-and-column bindings reach each system’s document store via the vendor’s documented interface |
| Adding a system | A new integration per tool | A row on the Corpus screen; the board updates on the next scan |
| Evidence | Reports assembled by hand before an audit | One signed pack per run and per request, with counts and decisions and no original values |
| Enforcement | Each tool writes to production | Enforcement stays in the system of record; the cockpit verifies with a residual scan |
| Governance | Separate from your data platform | Optionally recorded into Informatica CDGC for classification, lineage and policy |
You are not buying a new platform. You are finishing the one you have.
05 · What the cockpit delivers
The Kestryl engine has always been able to find and remediate personal data. What the cockpit adds is the journey a privacy officer actually runs — and the discipline of making the law visible on the screen rather than resident in someone’s memory.
Corpus and Import decide, once, which systems, which tables and where the attachments are. Scan declares its mode and fingerprint before the first row is read. Review gives a reviewer one decision control per row and a counter of original values shown — always zero. Attest has data owners sign a dated statement on a cadence. Retention puts a period, trigger, review date and owner on every policy. Requests draws the ninety-day clock. Erasure schedules the 48-hour notice and the run as two separate intents. Evidence assembles the pack. DPDP is the board.
Seven obligations are proven at record level from the corpus. Consent and withdrawal are carried by Salesforce Privacy Center’s Preference Manager. Notice, accuracy, breach notice, grievance and processors are contributed to by the cockpit. Children’s data and cross-border transfer remain your programme, informed by the corpus. The board says which is which.
06 · The five-year view
Nobody can promise what the Government of India will notify next. What can be said with confidence is where it will move: the Act reserves to the Central Government the designation of Significant Data Fiduciaries, the specification of restricted categories of data and their localisation, the thresholds in the Third Schedule, and the conditions of transfer outside India. Sectoral regulators will layer their own expectations on top.
Each of those moves is a question the corpus already answers. A Significant Data Fiduciary designation demands an annual impact assessment and independent audit — the evidence pack is already assembled per run, and the attestation cadence already produces dated, signed statements. A localisation order demands proof of where that data sits — the corpus is on your host, in your region, and the inventory names every field and count. A new identifier rule is a new line in the rule set, with a new fingerprint to prove when it took effect.
That is the definition of a foundational investment: not that it anticipates every rule, but that every rule becomes a computation over something you already have.
07 · Sequencing
08 · Where we are precise on purpose
The Kestryl engine (PIIScan 0.6.0), the Informatica IDMC Secure Agent and the ten CDI connectors are shipping products. The cockpit described here is the design standard now being built; the click-through demonstrated to leadership runs on synthetic data. The attachment extractor is built as a separate module against each vendor’s documented interface, scoped per engagement. Converting a confirmed field into a Privacy Center policy is a guided manual step today, because Salesforce publishes no API to create a policy definition. Per-individual scans and the full India identifier pack (PAN, mobile, IFSC — Aadhaar is already in the rule library) are on the enhancement path.
No product makes an organisation DPDP-compliant. The cockpit produces technical evidence that supports your controls. Legal applicability, consent design, notices, grievance handling and the decision to remediate remain with you and your counsel.
09 · Why Pacific Data Integrators
Kestryl Cockpit for DPDP comes from a firm that has spent more than fifteen years and a hundred-plus implementations inside the enterprise data stack — Informatica, Salesforce, Snowflake, Databricks — for banks, insurers, healthcare, government and retail. A privacy foundation is only as good as its fit to the systems it protects.