Data inventory and mapping
A live record of what personal data you hold, where it came from, where it flows and who else touches it.
- Automated discovery across systems
- Flow mapping including sub-processors
- Purpose recorded per collection point
DPDP is not a document exercise. Consent has to be recorded and revocable, retention has to expire on its own, erasure has to reach every copy, and a breach has to be reportable within 72 hours. That is engineering work, and it is what we do.
13 Nov 2026
Consent Manager registration framework
13 May 2027
Core obligations enforceable
₹250 crore
Maximum penalty per violation
Most organisations we assess have a reviewed privacy policy, an updated notice and a legal opinion on file. Almost none can delete a customer across every system, prove when consent was captured, or file a Board report inside three days. The gap is not understanding. It is that nobody has built the machinery.
No timestamp, no purpose, no notice version. When a regulator asks what a person agreed to and when, there is no answer.
Nothing expires automatically. Data accumulates until someone remembers to clean it up, which is never.
Backups, analytics warehouses, logs and third-party tools keep their copies indefinitely.
There is an incident process for outages. There is nothing that produces a regulator-ready report within 72 hours of discovery.
A live record of what personal data you hold, where it came from, where it flows and who else touches it.
Notices at the point of collection and consent that is recorded, versioned and as easy to withdraw as it was to give.
Retention clocks that run without human intervention, and deletion that reaches every copy including backups.
A path from detection to a filed Board report inside 72 hours, with affected principals identified and notified.
Processor contracts updated, data principal requests handled to an SLA, and a grievance path that works.
Obligations do not end at launch. Evidence has to stay current, impact assessments run annually, and breach readiness has to be exercised.
Start small if you need to prove the value internally first. Most clients begin with a sprint and move up.
Two weeks
One business unit or product
A focused gap score and remediation plan for a single unit. Designed to be small enough to approve without a committee, and credited in full against a full assessment booked within 30 days.
Four weeks
Organisation-wide
Data mapping, control testing, gap scoring against every obligation, and a board-ready remediation plan with sequencing, effort and owners.
Eight to sixteen weeks
Then ongoing operations
Implementation of every control above, then continuous compliance operations so your evidence, impact assessments and breach readiness stay current.
Scored by workstream, every finding mapped to the provision it touches.
A maintained record, not a one-off spreadsheet.
Sequenced by dependency and deadline, with effort and owners.
Named owners, decision tree and pre-drafted filings.
What you show a regulator, an auditor or an enterprise buyer.
Two pages your directors will actually read.
Indian enterprises above 200 people in BFSI, healthcare, edtech, e-commerce and IT services. Foreign companies serving Indian users, who are in scope whether or not they have an Indian entity. And global capability centres, where the parent is overseas but the processing is here.
How we rebuilt consent capture, automated retention across systems and stood up a tested 72-hour breach path for a manufacturing client.
Read the case studyFifteen questions across inventory, consent, retention, breach response and vendors. You get a score, a sector benchmark and a two-page report. No call required.
Free · 5 minutes · results on screen