Level 1: Initial Awareness
At the initial level, organisations recognise that DPDPA creates legal obligations but have not yet translated that recognition into systematic action. Privacy activities, if any, occur reactively in response to specific incidents or requests rather than as part of organised programmes.
Characteristics of Level 1 organisations include: absence of documented privacy policies, no designated privacy responsibility, ad hoc responses to data subject requests, and no systematic data inventory. Many organisations occupied this level when DPDPA was enacted and some remain here, particularly smaller enterprises without dedicated compliance resources.
Advancing from Level 1 requires establishing basic foundations: assigning privacy responsibility to specific individuals, creating initial policy documentation, and beginning the data inventory process. These steps need not be elaborate, but they must be deliberate.
Key Points
- Recognition of obligations without systematic implementation
- Reactive rather than proactive privacy activities
- No designated privacy responsibility or documented policies
Practical Note
If your organisation is at Level 1, begin by designating a privacy coordinator and conducting a high-level assessment of personal data processing activities. Even a spreadsheet-based inventory provides essential visibility.