Microsoft Purview for DPDP Act — what to enable on day 1

Pawan Sharma Published 02 Jun 2026  ·  By Pawan Sharma  ·  Compliance  ·  14 min read

The DPDP Act 2023 + its Rules turn data protection from an "internal policy" obligation into a Data Protection Board-supervised compliance regime with up to ₹250 crore Schedule penalty per failure of reasonable safeguards. Microsoft Purview is the operational layer that enforces and evidences those safeguards across M365 + Azure + SaaS. This post is the 30-day Purview activation playbook anchored on DPDP Section 8 — what to enable, in what order, with the audit evidence each step produces.

₹250 cr

DPDP max penalty

Per instance of failing reasonable safeguards. Schedule, DPDP Act 2023.

30 days

Activation plan

Sensitivity labels → DLP → Insider Risk → Retention. Sequential.

E5 bundled

Purview licensing

Information Protection P2 + DLP + Insider Risk + eDiscovery Premium in M365 E5.

Native

M365 integration

No connectors, no engineering — Purview enforces inside the M365 boundary.

DPDP Section 8 — mapped to Purview features

DPDP obligationPurview feature
Sec 8(4) — Maintain accuracy + completeness of personal dataRecords Management + retention policies + audit log
Sec 8(5) — Reasonable security safeguardsInformation Protection (sensitivity labels) + DLP (endpoint + email + cloud) + Defender XDR
Sec 8(6) — Notify breach to Board + affected Data PrincipalsPurview incident timeline + forensic export + Communication Compliance
Sec 8(7) — Erase on consent withdrawal / retention expiryRetention policies + auto-deletion + audit trail
Sec 8(8) — DPO accountability + grievance redressalCompliance Manager + Communication Compliance audit logs
Sec 9 — Reasonable purpose + processing restrictionsSensitivity label policies + DLP rules with allow/block actions
Cross-border transfer (Sec 16 + Rules)Data residency labels + Defender for Cloud Apps + Conditional Access

The 30-day Purview activation plan

1

Days 1-7 — Sensitivity label taxonomy + auto-labelling

Define labels: Public / Internal / Confidential / Restricted-PII / Restricted-PII-Financial. Auto-labelling rules driven by sensitive-info types (PAN, Aadhaar, account numbers) + ML-based classifiers. Roll out to Word / Excel / PowerPoint / Outlook + SharePoint / OneDrive.

2

Days 8-14 — DLP for the high-risk PII categories

Endpoint DLP, Email DLP (Exchange + Defender for O365), Cloud Apps DLP for sanctioned SaaS. Policy: block external sharing of Restricted-PII; warn-on-internal-sharing; block download to USB. Microsoft's pre-built India PII detector covers PAN, Aadhaar, Voter ID, Passport.

3

Days 15-21 — Insider Risk Management baseline

Detect: data downloads at scale before resignation, anomalous SharePoint access, sensitivity-label downgrades. Privacy-preserving by default (anonymised investigation mode until escalation). Aligns with DPDP Sec 8(5) reasonable safeguards.

4

Days 22-30 — Retention + eDiscovery + audit evidence

Retention policies aligned to DPDP Sec 8(7) — auto-delete on consent withdrawal trigger, retain on legal hold. eDiscovery Premium for Data Principal access requests (DSARs). Compliance Manager dashboard tracks DPDP-control attainment monthly.

What you can show your DPO + auditor on day 30

Data classification report

How many documents carry each sensitivity label, by department + workspace. Auditable evidence of "reasonable safeguards" execution.

DLP policy-violation log

Every attempt to send Restricted-PII externally — blocked, logged, available for Compliance Manager scoring.

Insider Risk indicators

Trend of anomalous data access events; investigation-ready cases; remediated incidents.

Retention compliance dashboard

Data eligible for deletion (consent withdrawn / retention expired) — execution status.

Cross-border transfer log

Restricted-PII movement events surfaced via Defender for Cloud Apps + sensitivity labels.

DSAR readiness

eDiscovery Premium runs Data Principal access / erasure requests in hours not days.

Common pitfalls + mitigations

PitfallMitigation
Sensitivity-label sprawl (15+ labels confuses users)5-label taxonomy max; consistent across business units
DLP false-positive fatigue (employees overrride every block)Tune in monitor-mode for 2 weeks before enforce; per-policy false-positive review
Insider Risk privacy concernsConfigure anonymised investigation mode by default; DPO oversight on de-anonymisation
Retention policies conflict with backup toolingCoordinate with backup team (Veeam / Druva) — Purview retention is source-of-truth for legal hold
"We installed Purview but no one uses it"Phase rollout team-by-team with training; track adoption via Compliance Manager

FAQ

Does Microsoft Purview by itself satisfy DPDP compliance?
Purview gives you the data discovery, classification, DLP, retention, and audit-trail tooling that DPDP Section 8 'reasonable safeguards' expects. It doesn't make policy decisions — your DPO + legal team still own the data-fiduciary determinations. Purview is the operational layer that lets you enforce + evidence those decisions across M365 + Azure + SaaS.
What's the minimum Purview SKU to start DPDP compliance work?
Microsoft 365 E5 includes Purview Information Protection P2, Insider Risk Management, DLP for endpoint, eDiscovery Premium. For organisations on E3, Compliance E5 add-on lights up the full Purview stack at additional per-user cost. Standalone Purview SKUs exist for pure-Azure / non-M365 deployments.
How does Purview handle the 'reasonable purpose' and 'consent' requirements?
Purview's Records Management + Retention policies enforce data-lifecycle rules at scale. Communication Compliance + Insider Risk surface policy violations. Customer consent records typically live in a CRM / DPDP-specific consent management platform; Purview integrates via Compliance Manager for audit-trail.
What about cross-border data transfer restrictions under DPDP?
DPDP allows cross-border transfer to countries notified by the Central Government as 'reasonable' destinations (negative-list approach in Rules). Purview's data residency mapping + sensitivity labels can be configured to flag or block cross-region movement based on classification. Combine with Azure Information Protection + Defender for Cloud Apps for SaaS-side enforcement.
Does Purview surface breach notifications automatically?
Purview detects + alerts on policy violations + data exfiltration patterns. The DPDP notification to the Data Protection Board is a human-in-the-loop decision — your DPO assesses materiality. Purview's incident timeline + forensic data export provide the evidence pack that supports that decision.
Insider Risk Management — what does it cost?
Bundled with M365 E5 / Compliance E5. Standalone licence available. Cost is in the noise compared to the breach-cost it prevents — average Indian enterprise breach costs run into tens of crores per DPDP penalty schedule + reputation impact.
How does Purview compare to Symantec / Forcepoint / Proofpoint DLP?
For Microsoft-anchored estates, Purview's native E5 integration + zero-deploy endpoint DLP + Defender XDR correlation are decisive. Third-party DLP wins on cross-platform depth (Linux, legacy Unix) and on specific regulated-industry policy templates. For 80%+ M365-anchored Indian enterprises, Purview is the right answer in 2026.
What's the 30-day Purview activation plan?
Week 1: sensitivity label taxonomy + auto-labelling rules. Week 2: DLP policy for the high-risk PII categories. Week 3: Insider Risk Management baseline + Communication Compliance. Week 4: Records Management + retention policies for DPDP audit evidence. Ogma's Purview DPDP service runs this end-to-end.

Free Purview DPDP readiness assessment

Map your current data-protection posture to DPDP Section 8 in 7 working days

Ogma audits your M365 / Azure / SaaS estate, identifies DPDP gaps, and returns a 30-day Purview activation plan sized to your tenant. INR + GST quote for licences + implementation. No commitment to roll forward.

Request the readiness assessment or explore the Microsoft Purview landing

Related: Purview DSPM for AI · Sentinel for India compliance · Microsoft Purview landing

Stay ahead of cyber threats

One short email a week — curated Indian cybersecurity news, Fortinet releases, DPDPA updates. No fluff.


Cato Firewall as a Service
Cato ZTNA — Zero Trust Network Access
Cato SASE Solution