DATA PROTECTION · INDIA DPDP

Your policy says the right things. Do your systems do them?

DPDP is not a document exercise. Consent has to be recorded and revocable, retention has to expire on its own, erasure has to reach every copy, and a breach has to be reportable within 72 hours. That is engineering work, and it is what we do.

13 Nov 2026

Consent Manager registration framework

13 May 2027

Core obligations enforceable

₹250 crore

Maximum penalty per violation

Get your free readiness score5 minutes · no call required
WHERE COMPANIES ACTUALLY ARE

The legal work is done. The engineering has not started.

Most organisations we assess have a reviewed privacy policy, an updated notice and a legal opinion on file. Almost none can delete a customer across every system, prove when consent was captured, or file a Board report inside three days. The gap is not understanding. It is that nobody has built the machinery.

Consent is collected but not recorded

No timestamp, no purpose, no notice version. When a regulator asks what a person agreed to and when, there is no answer.

Retention periods exist on paper only

Nothing expires automatically. Data accumulates until someone remembers to clean it up, which is never.

Erasure stops at the primary database

Backups, analytics warehouses, logs and third-party tools keep their copies indefinitely.

Breach response has no clock

There is an incident process for outages. There is nothing that produces a regulator-ready report within 72 hours of discovery.

WHAT WE BUILD

Five workstreams, shipped into your stack

Workstream 01

Data inventory and mapping

A live record of what personal data you hold, where it came from, where it flows and who else touches it.

  • Automated discovery across systems
  • Flow mapping including sub-processors
  • Purpose recorded per collection point
Workstream 02

Notice and consent

Notices at the point of collection and consent that is recorded, versioned and as easy to withdraw as it was to give.

  • Plain-language notices, multilingual
  • Auditable consent ledger
  • Self-serve withdrawal path
Workstream 03

Retention and erasure

Retention clocks that run without human intervention, and deletion that reaches every copy including backups.

  • Retention policy enforced in code
  • Pre-erasure notification
  • Deletion audit trail
Workstream 04

Breach detection and reporting

A path from detection to a filed Board report inside 72 hours, with affected principals identified and notified.

  • Scoping tooling for affected records
  • Report templates and named owners
  • Tested playbook, not a document
Workstream 05

Vendors, rights and governance

Processor contracts updated, data principal requests handled to an SLA, and a grievance path that works.

  • Vendor DPA remediation
  • Rights request queue and SLA
  • Grievance officer setup
Ongoing

Compliance operations

Obligations do not end at launch. Evidence has to stay current, impact assessments run annually, and breach readiness has to be exercised.

  • Quarterly evidence pack
  • Annual DPIA cycle
  • Breach drills and rules-change updates
HOW WE ENGAGE

Three ways in, depending on how far along you are

Start small if you need to prove the value internally first. Most clients begin with a sprint and move up.

Start here

Deadline sprint

Two weeks

One business unit or product

A focused gap score and remediation plan for a single unit. Designed to be small enough to approve without a committee, and credited in full against a full assessment booked within 30 days.

Start Scorecard First
Most chosen

Full assessment

Four weeks

Organisation-wide

Data mapping, control testing, gap scoring against every obligation, and a board-ready remediation plan with sequencing, effort and owners.

Start Scorecard First
The full programme

Build and operate

Eight to sixteen weeks

Then ongoing operations

Implementation of every control above, then continuous compliance operations so your evidence, impact assessments and breach readiness stay current.

Start Scorecard First
WHAT YOU RECEIVE

Comprehensive Tangible Deliverables

Readiness report

Scored by workstream, every finding mapped to the provision it touches.

Data inventory

A maintained record, not a one-off spreadsheet.

Remediation roadmap

Sequenced by dependency and deadline, with effort and owners.

Breach playbook

Named owners, decision tree and pre-drafted filings.

Evidence pack

What you show a regulator, an auditor or an enterprise buyer.

Board summary

Two pages your directors will actually read.

WHO THIS IS FOR

Companies that will be asked to prove it

Indian enterprises above 200 people in BFSI, healthcare, edtech, e-commerce and IT services. Foreign companies serving Indian users, who are in scope whether or not they have an Indian entity. And global capability centres, where the parent is overseas but the processing is here.

80+ engineers
20+ years in enterprise systems
Hosted in India
7+ patents filed
Nasscom AGI Roadmap contributor
CASE STUDY

From policy on paper to compliance in production

How we rebuilt consent capture, automated retention across systems and stood up a tested 72-hour breach path for a manufacturing client.

Read the case study
QUESTIONS WE GET ASKED

Before you book a call

Find out where you actually stand

Fifteen questions across inventory, consent, retention, breach response and vendors. You get a score, a sector benchmark and a two-page report. No call required.

Free · 5 minutes · results on screen