Start with a responsibility map
A privacy owner can coordinate the programme; operational teams carry out changes; security specialists assess and manage technical safeguards; qualified legal advisers address legal interpretation within their scope. A DPO role has its own mandate and applicable requirements.
Ask four questions for each activity
For a new data use, a rights request or a supplier change, make the handover explicit.
- Who gathers the facts and recommends a response?
- Who has authority to approve the decision?
- Who carries out the change and confirms completion?
- Who checks the result and receives unresolved concerns?
Example: a new support provider
The business owner explains the purpose. Procurement and security collect supplier information. Privacy and legal reviewers identify relevant questions. The authorised owner approves the arrangement and operations implement it.
Record the appointment boundary
Advice, a public contact role and a formal appointment must be described accurately. The DPDP SDF appointment question requires the actual notification and mandate to be reviewed; an enquiry or assessment report does not establish either.
Common questions
Can one person cover several roles?
Possibly, if they have the capacity, authority and appropriate expertise, and any applicable independence or conflict requirements are addressed.
What should a written scope include?
Activities, responsibilities, deliverables, access, reporting, escalation, availability, exclusions and how additional work is agreed.
Discuss the work you need
Agree the service, deliverables, responsibilities and fees before committing to an engagement.
Related reading
References
- MeitY: Digital Personal Data Protection Act, 2023
- ICO: Data protection officers — guidance marked under review
This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.
← Practical guides