A policy document that says the right things and a business that actually does them are two different achievements. Here’s the gap between them.
Policy (on paper)
- “We obtain consent before processing personal data.”
- “We respond to data subject requests promptly.”
- “We delete data once it's no longer needed.”
Operations (in practice)
- A consent flow that logs what was agreed to, when, and lets someone withdraw it just as easily.
- A named owner, a defined process, and a way to track requests so none get missed.
- A retention schedule that's actually enforced by the systems holding the data, not just written down.
A regulator — or a customer, or a journalist — doesn’t evaluate the policy document. They evaluate what actually happens when a request comes in, a breach occurs, or someone asks to see their data. Operations are where compliance either holds up or doesn’t.
A privacy policy describes what should happen. Privacy operations make sure it actually does.
SOURCES The DPDP Rules, 2025 — official text, MeitY — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf