In the most detailed published survey of Indian DPDP readiness, EY's January 2026 report, the most commonly reported challenge was not interpreting the law. It was adopting privacy technology in legacy environments, cited by 77% of respondents, narrowly ahead of a lack of subject-matter expertise (76.4%) and understanding the Act (70.9%). The reason is structural: most of what the DPDP Rules, 2025 require from 13 May 2027 (itemised notices, easy consent withdrawal, access controls, logs kept for a year, breach reports within 72 hours, and timely answers to access, correction and erasure requests) are things a system has to be able to do, not things a policy can promise.
This is general information, not legal advice.
DPDP obligations depend on the facts of your organisation and how it processes personal data. The Rules are phased and some provisions have not yet commenced. Before you act on anything here, take advice from a qualified professional on your own circumstances.
Key takeaways
- EY's January 2026 survey of around 150 professionals across Indian industries, including education, ranked adopting privacy technology in legacy environments as the most common challenge (77%).
- Lack of subject-matter expertise (76.4%) and understanding the Act (70.9%) were close behind. Managing data transfer (58.8%) and financial constraints (45.3%) were further down.
- Execution lagged awareness: more than 83% had not started implementation across processes and systems, and about 80% had not started drafting or updating policies.
- The Rules explain why legacy systems are the bottleneck. Notice, consent withdrawal, security safeguards, logging, breach reporting and rights requests are system capabilities.
- Learning platforms are a sharp case: records are built to be permanent, plugins and integrations accumulate, and learner identifiers travel into content and reporting tools.
- The survey is self-reported, cross-industry and not specific to edtech. It shows where organisations feel the strain, not how hard each task actually is.
What the survey asked, and who answered
The figures in this post come from one source: EY's report India's digital privacy crossroads: Understanding the DPDP Act and Rules impact and enterprise readiness, dated January 2026, with a companion article published on 27 January 2026. EY describes surveying nearly 150 professionals, including senior leaders, mid-level managers and executives, across financial services, technology services, consumer and retail, healthcare, manufacturing, telecom, media and entertainment, education and automotive.
Asked about the key challenges in implementing the DPDP Act and Rules, respondents reported:
| Challenge | Share of respondents |
|---|---|
| Adoption of privacy technology in legacy environments | 77% |
| Lack of subject-matter expertise | 76.4% |
| Understanding the Act | 70.9% |
| Managing data transfer | 58.8% |
| Financial constraints | 45.3% |
Two points about reading this table. Respondents could name more than one challenge, which is why the figures add up to more than 100%. And the top three are close together: legacy technology leads expertise by less than one percentage point. The honest reading is that three problems are reported almost equally often, with the technology problem at the top, rather than that one problem dominates.
The finding is still notable because of what it is not. Much published commentary on DPDP treats interpretation as the main difficulty. In this survey, understanding the Act came third.
Why legacy systems come first: what the Rules ask a system to do
The Digital Personal Data Protection Rules, 2025 were published in the Official Gazette on 13 November 2025 (G.S.R. 846(E)). Under rule 1, rules 3, 5 to 16, 22 and 23 commence eighteen months after publication, which is 13 May 2027. Most of what follows sits inside that window.
Read provision by provision, a large share of these obligations describe things a system must be able to do. A policy document can commit an organisation to them. Only the software can carry them out.
| Provision | What it requires, in summary | What a system has to be able to do |
|---|---|---|
| Rule 3, notice | A notice that stands on its own, with an itemised description of the personal data and the purposes, and a link to withdraw consent "with the ease of doing so being comparable" to giving it | Know which personal data each process collects, and offer withdrawal in the same channel as consent |
| Rule 6, security safeguards | Encryption, obfuscation, masking or virtual tokens; control of access; visibility through logs, monitoring and review; continued processing, for example through backups; logs and personal data retained for one year; security terms in contracts with processors | Encrypt or mask data at rest, enforce role-based access, keep and review access logs, and restore from backups |
| Rule 7, breach intimation | Inform each affected person without delay; inform the Data Protection Board without delay, with a fuller report within 72 hours of becoming aware | Establish quickly what was accessed, whose data it was, and when, which depends on the logging above |
| Section 8(7) of the Act and Rule 8, erasure and retention | Erasure when the purpose is served, with fixed periods for three named classes of platform; a minimum one-year retention of personal data, traffic data and logs for purposes in the Seventh Schedule | Delete or isolate data on a schedule, while still keeping the logs the Rules require |
| Rule 14, rights of Data Principals | Publish how people can make requests; answer grievances within a reasonable period not exceeding ninety days | Find all of one person's data across systems, and correct or erase it |
Seen this way, the survey result is less surprising. An organisation can hire expertise and can commission a legal reading of the Act. If its core systems cannot find one person's records, mask a field, or say who looked at what last Tuesday, neither of those fixes the gap. For context, the Schedule to the Act sets the penalty for failing to take reasonable security safeguards at up to ₹250 crore, and for failing to notify a breach at up to ₹200 crore.
What the Rules assume a system can do
- Say exactly which personal data each process holds
- Withdraw consent as easily as it was given
- Mask or encrypt personal data and restrict who can see it
- Keep logs of access for at least a year and review them
- Reconstruct the scope of a breach within 72 hours
- Find, correct or erase one person's data on request
How long-running systems are often built
- Data spread across modules, plugins, exports and backups
- Consent captured once at sign-up, with no withdrawal path
- Broad admin access granted over years and rarely reviewed
- Logging configured for troubleshooting, not for audit
- No single view of what a given incident exposed
- Records designed to be permanent, with no erasure workflow
How this shows up in a learning platform
EY's report touches education directly. It names updating legacy student information systems to handle real-time access and correction requests, and modernising legacy systems for consent management, including verifiable parental consent, as areas institutions face. A learning management system tends to sharpen each of the general problems above, for reasons that come from how learning platforms are designed:
- The record is the point. Completion history, assessment attempts and certificates are kept because they are the evidence of training. A system built to never forget does not come with an erasure workflow.
- Plugins accumulate. A platform that has run for several years usually carries plugins and integrations added by different people for different reasons. Each may store its own copy of learner data in its own tables.
- Learner identifiers travel. SCORM and xAPI content, video tools, proctoring services and reporting connectors can each receive learner identifiers. Few organisations have a map of where those identifiers end up.
- Reports become copies. Scheduled exports and analytics dashboards create copies of personal data outside the platform, often in spreadsheets and shared drives.
- Backups keep everything. A record erased from the live system may still sit in months of backups, which Rule 6 itself expects an organisation to keep for continuity.
Where the learners are children, the stakes rise. The previous post in this series, on children’s data and the education provisions, sets out what the Fourth Schedule does and does not lift for educational institutions.
The rest of the readiness picture
The same report gives a view of how far organisations had got at the time of the survey. EY reported that:
- more than 83% had not yet initiated implementation across relevant processes and systems;
- about 80% had not initiated drafting or updating their policies and framework, and about 81% had not begun establishing a privacy governance structure;
- 48% had carried out current-state or gap assessments;
- 43.9% had identified their personal data processing activities;
- 37.8% had carried out data discovery and classification, and 37.8% had identified their third-party vendors.
The order of those last figures fits the legacy-systems finding. Assessments are the most common step taken. Identifying processing comes next, and discovery and classification, the step that actually locates personal data inside systems, comes last. The step that depends most on the systems themselves is the one fewest organisations had reached.
EY also reported how many organisations in each sector had started compliance work: 50% in consumer, retail and e-commerce, 38.8% in technology services, 34.7% in financial services, 20% in metals, mining and energy, and 9.9% in healthcare and life sciences. The report does not give a comparable figure for education.
What the Rules imply about sequence
The Rules do not prescribe an order of work. Read together, though, several provisions depend on others, and that dependency is worth setting out because it explains why technology work tends to sit early rather than late.
| This obligation | Depends on first being able to |
|---|---|
| An itemised notice under Rule 3 | List the personal data each process collects |
| Answering an access, correction or erasure request under Rule 14 | Find every place one person's data is held |
| A 72-hour report to the Board under Rule 7 | Tell from logs what was accessed, and whose data it was |
| Erasure under Rule 8, alongside one-year log retention | Separate data that must go from logs that must stay |
| Security terms with processors under Rule 6 | Know which vendors and integrations receive personal data |
Almost every row traces back to the same capability: knowing what personal data exists, where it is, and who touches it. That is the data inventory, and in an older system it is usually the slowest part to establish. Whether a particular organisation needs to do all of this, and on what timeline, depends on its own facts, its classification under the Act, and advice it takes on its own circumstances.
What the survey can and cannot tell you
- It is self-reported. The figures show what respondents said was hard. They do not measure how hard each task actually is.
- It is small and cross-industry. Around 150 professionals across many sectors is a useful signal and a thin basis for any one sector. It is not an edtech survey.
- The timing is not stated. The report does not say exactly when responses were collected, so figures may describe readiness some months before publication.
- Awareness figures differ between documents. The report and its companion article give different numbers for how familiar organisations are with the Act, so this post does not use them.
- Dates. The Rules are dated 13 November 2025 in the Gazette, while the government press release refers to notification on 14 November. This series counts the phased dates from 13 November.
Frequently asked questions
What is the biggest challenge in DPDP readiness?
In EY's January 2026 survey of around 150 Indian professionals, the most commonly reported challenge was adopting privacy technology in legacy environments (77%), narrowly ahead of a lack of subject-matter expertise (76.4%) and understanding the Act (70.9%). The survey is self-reported and cross-industry.
When do the main DPDP Rules obligations apply?
Under rule 1 of the DPDP Rules, 2025, rules 3, 5 to 16, 22 and 23, which include notice, security safeguards, breach intimation, erasure and the rights of Data Principals, commence eighteen months after publication, which is 13 May 2027. Rule 4, on Consent Managers, commences one year after publication.
Which DPDP Rules depend most on IT systems?
Rule 3 (itemised notice and consent withdrawal), Rule 6 (encryption or masking, access control, logging, backups and one-year log retention), Rule 7 (breach reports to the Board within 72 hours), Rule 8 (erasure and minimum retention of logs) and Rule 14 (handling access, correction and erasure requests) each assume capabilities that older systems often lack.
How long must logs be kept under the DPDP Rules?
Rule 6(1)(e) requires logs and personal data to be retained for one year, unless another law requires otherwise. Rule 8(3) also requires personal data, associated traffic data and logs to be retained for at least one year from processing for the purposes listed in the Seventh Schedule.
Are edtech platforms and educational institutions in the Third Schedule on erasure?
No. The Third Schedule names three classes with fixed retention periods: large e-commerce entities, online gaming intermediaries and social media intermediaries. Educational institutions and edtech platforms are not among them.
Why are learning management systems hard to make DPDP-ready?
Learning records are designed to be permanent, platforms accumulate plugins that store their own data, learner identifiers travel into SCORM, xAPI, video and proctoring tools, reports create copies outside the platform, and backups retain erased records.
How many organisations had started DPDP implementation?
EY reported that more than 83% of respondents had not yet initiated implementation across relevant processes and systems. 48% had carried out a gap assessment and 43.9% had identified their personal data processing activities.
Sources
This post relies on the following, and on nothing else.
- EY India, India's digital privacy crossroads: Understanding the DPDP Act and Rules impact and enterprise readiness (January 2026), and the companion article (27 January 2026). All survey figures in this post.
- The Digital Personal Data Protection Rules, 2025, notified in the Official Gazette by G.S.R. 846(E) dated 13 November 2025, as corrected by G.S.R. 892(E) of 10 December 2025. Rules relied on: 1 (commencement), 3 (notice), 6 (reasonable security safeguards), 7 (breach intimation), 8 (erasure and retention) and 14 (rights of Data Principals), with the Third and Seventh Schedules.
- The Digital Personal Data Protection Act, 2023, published by the Ministry of Electronics and Information Technology: section 33 and the Schedule (penalties).
Nothing in this post describes the affairs of any client, institution or individual.
Where this connects to the rest of the series
This is part three of a series reading the DPDP regime from inside a learning platform. The overview of the three commencement phases, who counts as a Data Fiduciary in a learning context, and the penalty structure is in DPDP for LMS and Edtech: what the Rules say, and when they apply. Part two covers children's data and the education provisions, and the training question is covered in DPDP employee awareness training.
The next part in the series walks through a learning platform system by system: where personal data sits, and where the Rules become relevant to each part.
Want to see what your learning platform actually holds about learners, and where?
Book a Free Demo