The DPDP Cost Equation: What Every CFO and Founder Must Know Before May 2027
Author
aishwarya
Date Published

There are roughly 9 months left before DPDP enforcement begins on 13 May 2027. Most boardroom conversations about the DPDPA still focus on the law itself. Very few are about what compliance actually costs to get wrong, or to get right.
That is the gap Privy by IDfy set out to close in a recent webinar, "The DPDP Cost Equation: What Every Founder and CFO Must Know Before May 2027." The conversation brought together two practitioners who see the same regulation from opposite ends of an organisation: Krishnanand Bhat, DPO and Chief of Data Governance, Privacy Governance, and AI at IDBI Bank, and Kunal Sanghavi, Former CFO at HDFC Securities. This blog distills the most substantive arguments from that discussion.
The numbers that frame the conversation come from IBM's 2026 Cost of a Data Breach Report. The average data breach in India has hit an all-time high of ₹25.5 crore, up 15.9 percent year on year. Financial services alone averages ₹40.9 crore per breach, the highest of any sector. One in four malicious breaches is now AI-generated. These are the benchmarks against which a CFO has to price the cost of inaction.

The DPDP Cost Equation: What Every Founder and CFO Must Know Before May 2027
Why DPDP Is Not Like Any Other Compliance Programme
The instinct in most large enterprises, particularly in BFSI, is to treat DPDP as another compliance programme: scope it, staff it, complete it, move on. Krishnanand Bhat's first point was that this framing gets the problem wrong from the start.
"If you take this only as a compliance program," he said, "it may not be a complete picture of what is expected to be done. If you take it only as an automation project, again, it is not complete."
What DPDP actually requires is an infrastructure of privacy: a standing capability that runs continuously across every department, every process, every system. Consent needs to be managed in real time. Data principal rights need to be honoured within defined timelines. Breaches need to be reported to the Data Protection Board within 72 hours. None of these are one-time activities. They happen continuously, driven by the behaviour of customers, vendors, and internal teams.
"A personal data breach can happen at any point in time," Krishnanand Bhat observed. "And it's not necessarily a technology breach. It could be a process breach. It could be a human error, knowing and unknowing."
The right question for a CFO to ask isn't what a compliance programme costs to implement once. It's what it costs to run every year, and what a failure costs on top of that.
The Visible Cost and the Real Cost
Kunal Sanghavi framed the CFO's version of this problem with a question that cuts through most compliance discussions: "The question is not what DPDP costs. It is what an ungoverned data foundation costs, everything built on it."
He walked through a live example from his own experience. A business unit was sharing leads with a partner entity as standard practice, generating significant revenue. When DPDP era scrutiny arrived, the data sharing stopped, because the original consent structure did not cover it. "The whole business came to a standstill," he said. "This is a few hundred crores of line item for an organisation."
This is the first category of cost most finance teams undercount: revenue disruption from governance gaps that were never treated as gaps until a regulation made them visible. The disruption is immediate, organisation-wide, and accompanied by accountability questions that go to the top of the house. It's one of the hidden costs Indian companies routinely leave out of the budget conversation.
The second category is what both speakers called the silent debt of distrust. Krishnanand Bhat described the pattern precisely. An organisation collects personal data, uses it for a primary purpose, then lets it drift into secondary uses, cross-selling, lead sharing, analytics, without additional consent. The customer who shared their information with organisation A starts receiving calls from organisations B, C, and D. "Somewhere along the way, he feels cheated," Krishnanand Bhat said. "This silent debt that keeps accumulating of distrust carries a cost. And that cost hits an organisation in the long run."
This debt does not show up in a P&L until it becomes a breach, a complaint, a penalty, or a news headline. By then, the cost is no longer a line item. It is a crisis.

How a Small Miss Compounds
One of the most useful frameworks from the webinar was Krishnanand Bhat's account of how a seemingly contained privacy failure cascades. He described the current state of most enterprise data ecosystems: "Data sharing, consuming multiple uses of data, secondary uses, and maybe N level of purposes for which that personal data was used. It's a practice which is very much prevalent right now."
The DPDP Act changes the consequences of this practice, not the practice itself. A single missing consent for a secondary use of personal data means that data is being processed without a lawful basis. In a digital-first financial services organisation, that data may have already moved through dozens of upstream and downstream applications before the gap is identified.
"A small miss at my end," Krishnanand Bhat said, "maybe it can be contained. But if that small miss happens regularly, that impact is going to be something which will have a larger repercussion for the organisation in the long run."
This is where DPDP Act penalty exposure gets real for a finance leader. Penalties stack by contravention, not by incident. A single mishandled breach can simultaneously trigger the ₹250 crore security safeguard penalty and the ₹200 crore breach notification penalty. Combined exposure from one event can run well above the headline figure; a DPDP Act fine that starts at one number and compounds fast.
The CFO's Sequencing Framework
Kunal Sanghavi's advice on where to start was specific enough to be directly actionable. He recommended a gap analysis first, "to identify areas impacted by these regulations, and areas that are not impacted but may have a consequential impact." This creates visibility before any spending.
Gap analysis then leads directly to data discovery. "Where what data is residing in the organisation," as he put it. Most organisations, he noted, do not have a complete, holistic view of where their data lives. PII data may be on laptops, in endpoints, in systems the privacy team has never audited. Without that inventory, everything that follows is built on an incomplete foundation.
From discovery comes classification: what is PII data, what is sensitive PII data, what is non-PII. "PII data in different organisations are different," Sanghavi observed. While Aadhaar numbers and mobile numbers appear on almost every organisation's list, the boundaries shift by sector and business model.
From classification, the architecture: which systems handle which privacy impact assessments and consent obligations, what access controls are needed, which data must be anonymised, masked, or tokenised. And then vendor risk: "When a vendor is essentially managing certain aspects of the organisation, be it outsourcing or supporting certain applications, again, the whole data processor angle comes into picture."
His closing point on sequencing was direct: "If DPDP cost is not factored in, it will come as a surprise later. And at the same time, it will come as an urgent surprise, which means the vendors and the support teams will give a much accelerated cost, because they have to arrange everything at the last minute."
The last-minute premium is a real, measurable part of this equation. Emergency privacy impact assessments, rushed implementations, and unplanned vendor engagements all cost materially more than planned ones. The savings from starting early aren't speculative. They're the gap between implementation at market rates and implementation at crisis rates.
The DPO's Investment Priorities
Krishnanand Bhat's priority sequence for a regulated B2C or B2B2C entity was clear. Start with data discovery: "To put in place an order to discover where it is that personal data is sitting in my entire ecosystem." For a bank with complex technology architecture and personal data ingested across the entire customer lifecycle, this is not a small exercise.
Follow discovery with external-facing compliance: consent management and data principal rights. These are the obligations most likely to generate a complaint, a rights request, or a regulator inquiry first. Getting them right early lays the foundation on which internal compliance, records of processing activities, DPIAs, and audit preparation can be built.
His rapid fire answer when pressed on the single thing he would not compromise on, even if the budget gets squeezed: "Investment in technology as an enabler."
Kunal Sanghavi's rapid fire answer was equally direct: "A consent system, and a consent system should be linked to a centralised access control system, which does a real-time change in consents anywhere happening, vis-a-vis applications and data, so that there is no inadvertent compromise."

What the Two Worlds Look Like Post-May 2027
Krishnanand Bhat's contrast between the organisation that started early and the one that waited was the clearest statement in the webinar. "Say today it is 14th May 2027. For me, it will be a normal day because many of the ticks in the boxes have already been addressed. What remains could be some unforeseen zero-day scenarios, which were not anticipated, but we are already geared up to handle these scenarios."
The other organisation: "Absolute chaos. In fact, I will end up spending more in terms of getting myself into compliance. Under constant pressure, because I'm already way behind. And I'm trying to do a patchwork. And I think, end of the day, the outcome may not be desirable, and it's a sure-short journey towards disaster."
The premium paid for late implementation shows up across every cost category. Implementation runs faster, which means it runs at higher rates and misses more. Training is compressed. Vendors are engaged urgently. Incident management cannot be retrofitted to an unplanned system. The organisation ends up spending more and getting less.
The organisations that built early, Krishnanand Bhat argued, reach the other side with a genuine competitive asset: privacy compliance as a business enabler. "Privacy compliance becomes a business enabler rather than a disruptor." That is the position Kunal Sanghavi's research reference supports too: among organisations that navigate a new privacy regulation, a small number significantly outperform competitors because they built the foundation right, while others lag or fail.
What Privacy Infrastructure Actually Builds
Kunal Sanghavi's framing of privacy as infrastructure rather than compliance is the most useful lens for a CFO allocating a budget. "Think of this more as an infrastructure line item, which is building you, which is helping you to grow and magnify." The same infrastructure that satisfies DPDP also makes the organisation safe enough to deploy AI tools internally, share data with partners confidently, and build customer relationships on a foundation of demonstrated trust.
Krishnanand Bhat's formulation was equally precise: "Privacy compliance is not a cost for complying. It's a journey of rebuilding trust. Providing that comfort to individuals that the information that they have shared with us is something which we consider as sacrosanct."
This matters for BFSI organisations specifically, which Krishnanand Bhat placed in the most demanding category: regulated entities with complex tech stacks, B2C and B2B2C customer relationships, and the highest average breach cost of any sector in the IBM report. These organisations also face the most structured sequencing requirement: external-facing compliance first, internal compliance second, and all of it built on a data discovery foundation.
How Privy by IDfy Helps Build This Foundation
Privy by IDfy is built around the sequencing Krishnanand Bhat and Kunal Sanghavi described. Data Compass handles the data discovery and classification foundation.
The consent governance platform manages the external-facing consent and data principal rights layer, including real-time consent propagation to access control systems of the kind Sanghavi specified as non-negotiable. Privacy impact assessments, incident management, and vendor risk management connect on the same audit trail, so the evidence base builds continuously rather than being assembled under pressure when a regulator asks for it. For a full breakdown of what each layer costs to build versus buy, see our CFO's guide to DPDPA compliance cost.
The penalty structure makes this equation straightforward. A single breach that triggers both the security safeguard and notification penalties can reach ₹450 crore in combined exposure. IBM's 2026 Cost of a Data Breach Report puts the average financial services breach in India at ₹40.9 crore. Getting the foundation right before May 2027 costs a fraction of either number.
.png&w=3840&q=75)
Conclusion
"It is definitely not enough time to do it twice," Rahul Lakhani said in opening the session. "One has to get it right the first time."
That is the DPDP cost equation in a single sentence. The visible cost of compliance is real but knowable. The hidden cost- revenue disruption, silent trust debt, emergency implementation premiums, reputational damage from a breach, and the compounding penalty exposure from stacked contraventions- runs higher than most P&L conversations have yet accounted for.
Nine months is enough time to build this right. It is not enough time to build it twice. If you want to discuss where your organisation stands in its DPDP programme, or see how Privy by IDfy structures the cost equation across your specific obligations, write to shivani@idfy.com.
FAQ's
What is the DPDP cost equation?
The DPDP cost equation refers to the full financial picture of DPDPA compliance: not just the direct cost of implementation, but the cost of non-compliance (penalties up to ₹250 crore per contravention), revenue disruption from ungoverned data flows, reputational damage from a breach, and the last-minute premium organisations pay when they start too late.
How much does a data breach cost Indian enterprises under DPDPA?
According to IBM's 2026 Cost of a Data Breach Report, the average data breach in India has reached ₹25.5 crore, up 15.9 percent year on year. Financial services averages ₹40.9 crore per breach, the highest of any sector.
How do DPDP Act penalties stack after a single breach?
Penalties stack by contravention rather than by incident. A single breach can trigger both the ₹250 crore security safeguard penalty and the ₹200 crore breach notification penalty at once, meaning one DPDP Act fine can compound into a combined exposure of ₹450 crore from a single event.
Where should a data fiduciary start its DPDP investment?
Both panelists recommended the same sequence: gap analysis first, then data discovery to build a complete inventory of where personal data sits, then classification, then architecture and consent system design, then vendor and third-party risk management. External-facing compliance (consent, data principal rights) should be addressed before internal compliance (DPIAs, record of processing activities).
What is the cost of starting late on DPDP compliance?
Late implementation means working at emergency rates: accelerated vendor costs, compressed training, rushed PIAs, and systems built without the design time required to get them right. Krishnanand Bhat's description of the late-starting organisation was direct: "absolute chaos," with material additional spend and outcomes that may not withstand regulatory scrutiny.
How does strong privacy governance create competitive advantage?
Kunal Sanghavi cited research showing that organisations that invest correctly in privacy governance ahead of a new regulation significantly outperform competitors that do not. The same infrastructure that satisfies DPDPA makes an organisation safe enough to deploy AI tools, share data with partners confidently, and build customer trust as a differentiated business asset.

Analyze the implications of the allocation of ₹10 crore in the FY 2026-2027 budget for the Data Protection Board. Understand the shift from setup to activation, the digital-first operating model, and what enterprises must do to prepare for the DPDP Act enforcement

DPDP readiness is no longer a legal exercise it’s board's responsibility. Governance, maturity, roadmap, full-stack privacy execution. Privy by IDfy