The Foundation Standard · 2026

Build once for the law you have — and the five years of law you don’t yet.

India has written its privacy regime in ink. The question for every enterprise operating there is no longer whether to comply, but whether to buy fourteen answers or build one foundation from which all fourteen — and the ones still to come — are computed.

DPDP RULES NOTIFIED 14 NOV 2025 · ONE CORPUS · FOURTEEN OBLIGATIONS · ONE EVIDENCE PACK

01 · The regulatory arc

The rules are notified. The timetable is fixed. The penalties are specific.

On 14 November 2025 the Government of India notified the Digital Personal Data Protection Rules, 2025, giving full effect to the Act of 2023. The Rules set an eighteen-month phased path to compliance, with consent-manager provisions arriving after twelve months and the balance of substantive obligations thereafter. That is the window. It closes in the first half of 2027.

What arrives with it is unusually concrete. Every request from an individual to access, correct or erase personal data must be answered within ninety days. Specified large platforms must erase data after three years of inactivity and warn the individual at least 48 hours before doing so. A breach must be reported to the Data Protection Board without delay and in detail within 72 hours, and to affected individuals in plain language. Logs and personal data are to be retained for one year unless law requires longer. Significant Data Fiduciaries must commission an impact assessment and an independent audit every twelve months and furnish the results to the Board.

Sources: Press Information Bureau, Government of India, 14 November 2025; KPMG India, DPDP Rules 2025: Guidance to DPDP Act implementation. Rule-level detail per the notified text as summarised by KPMG; confirm applicability with counsel.

02 · The strategic error

Most enterprises will buy fourteen answers. The board will receive fourteen spreadsheets.

Faced with a list of obligations, large organisations do what they have always done: assign each one to a workstream. Consent to marketing. Requests to customer service. Retention to IT. Breach to security. Each workstream buys or builds a tool, each tool sees one system, and a compliance team reconciles the result in a spreadsheet before every audit.

The error is structural, not managerial. Every DPDP obligation is a question about the same underlying fact: where is personal data, whose is it, why is it held, and what has been done to it. Answer that once, accurately, across every system that holds Indian personal data, and the fourteen obligations become fourteen computations. Compliance is not fourteen problems. It is one problem, asked fourteen ways.

03 · The thesis

One corpus on a Secure Agent Server. Every obligation computed from it.

Kestryl Cockpit for DPDP rests on a single design decision: bring a read-only copy of every in-scope system — tables and their attachments — onto one server you control, and compute everything downstream from that corpus. Which fields hold personal data. Which policies govern them. Which requests are open and what their clocks say. What was erased, what was held, and what remained afterward.

The consequence is the one line in this paper worth remembering: adding a system is a row on a screen, not a programme. Onboard SAP after Salesforce, or Workday after both, and the inventory, the policy scope, the request handling and the DPDP board update on the next scan.

DECIDED ONCE

Which systems, which tables, where the attachments are.

Three decisions on one screen, inherited by every screen after it.

COMPUTED, NOT COMPILED

Seven obligations are proven at record level.

The board updates when the corpus does — not when someone remembers to update a spreadsheet.

PROVEN, NOT DECLARED

Enforcement stays in the system of record.

A residual scan under the same fingerprint verifies the result. “Done” is a number, and the number is zero.

04 · Why this foundation

The Informatica Secure Agent is already the right place. The Kestryl agent makes it the only place you need.

Ten systems that hold Indian personal data have a CDI connector that exists today and is documented by Informatica: Salesforce, SAP S/4HANA and ECC, SAP SuccessFactors, SAP Ariba, Oracle E-Business Suite, Oracle NetSuite, Microsoft Dynamics 365, ServiceNow, Workday and SharePoint Online.

Why the Secure Agent Server, and not another platform
RequirementPoint solutions per obligationSecure Agent + Kestryl agent
Data residencyEach tool decides where data goesRead-only corpus on your host, your region; no egress during a scan
Coverage of attachmentsUsually out of scopeTable-and-column bindings reach each system’s document store via the vendor’s documented interface
Adding a systemA new integration per toolA row on the Corpus screen; the board updates on the next scan
EvidenceReports assembled by hand before an auditOne signed pack per run and per request, with counts and decisions and no original values
EnforcementEach tool writes to productionEnforcement stays in the system of record; the cockpit verifies with a residual scan
GovernanceSeparate from your data platformOptionally recorded into Informatica CDGC for classification, lineage and policy

You are not buying a new platform. You are finishing the one you have.

05 · What the cockpit delivers

Nine screens that turn an engine into an operating rhythm.

The Kestryl engine has always been able to find and remediate personal data. What the cockpit adds is the journey a privacy officer actually runs — and the discipline of making the law visible on the screen rather than resident in someone’s memory.

Corpus and Import decide, once, which systems, which tables and where the attachments are. Scan declares its mode and fingerprint before the first row is read. Review gives a reviewer one decision control per row and a counter of original values shown — always zero. Attest has data owners sign a dated statement on a cadence. Retention puts a period, trigger, review date and owner on every policy. Requests draws the ninety-day clock. Erasure schedules the 48-hour notice and the run as two separate intents. Evidence assembles the pack. DPDP is the board.

Seven obligations are proven at record level from the corpus. Consent and withdrawal are carried by Salesforce Privacy Center’s Preference Manager. Notice, accuracy, breach notice, grievance and processors are contributed to by the cockpit. Children’s data and cross-border transfer remain your programme, informed by the corpus. The board says which is which.

06 · The five-year view

Regulation will move. A corpus-based foundation moves with it.

Nobody can promise what the Government of India will notify next. What can be said with confidence is where it will move: the Act reserves to the Central Government the designation of Significant Data Fiduciaries, the specification of restricted categories of data and their localisation, the thresholds in the Third Schedule, and the conditions of transfer outside India. Sectoral regulators will layer their own expectations on top.

Each of those moves is a question the corpus already answers. A Significant Data Fiduciary designation demands an annual impact assessment and independent audit — the evidence pack is already assembled per run, and the attestation cadence already produces dated, signed statements. A localisation order demands proof of where that data sits — the corpus is on your host, in your region, and the inventory names every field and count. A new identifier rule is a new line in the rule set, with a new fingerprint to prove when it took effect.

That is the definition of a foundational investment: not that it anticipates every rule, but that every rule becomes a computation over something you already have.

07 · Sequencing

Six steps to a defensible position before the 2027 deadline.

  1. 1 · CorpusStand up the Secure Agent Server in your region. Add Salesforce and your primary ERP through their CDI connectors. Bind the attachment stores.
  2. 2 · Scan and reviewRun discovery under a pinned rule set. Reviewers confirm findings by pattern and hotspot — on record IDs, never on values.
  3. 3 · AttestData owners sign classifications. The overdue list becomes the operating agenda.
  4. 4 · RetentionEvery asset under exactly one policy with a period, trigger, review date and owner. Close the gap list.
  5. 5 · Requests and erasureRoute access, correction and erasure through the ninety-day clock; run retention in Privacy Center with the notice in front and the residual scan behind.
  6. 6 · Evidence and expansionAssemble the pack per run. Then add the next system — a row on screen one — and watch the board update.

08 · Where we are precise on purpose

What is delivered, what is designed, what remains yours.

The Kestryl engine (PIIScan 0.6.0), the Informatica IDMC Secure Agent and the ten CDI connectors are shipping products. The cockpit described here is the design standard now being built; the click-through demonstrated to leadership runs on synthetic data. The attachment extractor is built as a separate module against each vendor’s documented interface, scoped per engagement. Converting a confirmed field into a Privacy Center policy is a guided manual step today, because Salesforce publishes no API to create a policy definition. Per-individual scans and the full India identifier pack (PAN, mobile, IFSC — Aadhaar is already in the rule library) are on the enhancement path.

No product makes an organisation DPDP-compliant. The cockpit produces technical evidence that supports your controls. Legal applicability, consent design, notices, grievance handling and the decision to remediate remain with you and your counsel.

09 · Why Pacific Data Integrators

Fifteen years inside the systems your data actually lives in.

Kestryl Cockpit for DPDP comes from a firm that has spent more than fifteen years and a hundred-plus implementations inside the enterprise data stack — Informatica, Salesforce, Snowflake, Databricks — for banks, insurers, healthcare, government and retail. A privacy foundation is only as good as its fit to the systems it protects.