Data-processing inventory
Every processing activity across product, HR, marketing, support, finance and third-party tools: what is collected, why, on what basis, where it is stored, who it is shared with and how long it is kept.
Data Protection · India
A fixed-scope, fixed-price diagnostic that answers four questions: what personal data you hold, what role you play under the Act, where you fall short of the Act and the 2025 Rules, and what has to happen in what order before 13 May 2027. Two to four weeks, one report, no retainer attached to it.
Most DPDP conversations stall in the same place. Someone senior asks how exposed the organisation is, and the honest answer is that nobody knows, because nobody has written down what personal data the company holds, why it holds it, who it goes to and how long it stays. Until that document exists, every other decision — what to build, what to budget, whether to worry — is guesswork with a deadline attached.
This engagement produces that document and the gap register that follows from it. It is deliberately narrow. We are not implementing anything, not selling a retainer inside it, and not producing a legal opinion — we are not a law firm, and where a genuinely contested question of interpretation appears we say so and recommend you take it to counsel rather than quietly guessing on your behalf.
What you get instead is an operational picture: your processing, your role, your gaps ranked by risk and by date, and a plan that works backwards from 13 May 2027. Some clients then hand it to their own team and run the remediation internally. That is a legitimate outcome and we scope the assessment as though it will be the one.
Coverage
Eight workstreams, assessed against the Act and the DPDP Rules, 2025. Every one of them produces findings in the same register, so the output is one prioritised list rather than eight separate opinions.
Every processing activity across product, HR, marketing, support, finance and third-party tools: what is collected, why, on what basis, where it is stored, who it is shared with and how long it is kept.
Whether you are a Data Fiduciary, a Data Processor, or both for different activities — reasoned per activity, because most organisations are genuinely both and treating themselves as one is a common and expensive simplification.
An honest read on whether the volume and sensitivity of what you process puts Significant Data Fiduciary designation within reach, and what the additional duties would cost you if it does.
Your existing notices and consent capture assessed against the plain-language requirement, the purpose limitation, and the rule that withdrawing consent must be as easy as giving it.
Whether you could actually service an access, correction, erasure, grievance or nomination request today — tested against your real systems, not against your policy document.
Whether your logging, alerting and escalation would surface a personal data breach in time to notify without delay and file the detailed report inside 72 hours.
Retention schedules and erasure on withdrawal or purpose completion, plus any exposure to under-18 data and the verifiable parental consent that comes with it.
Your processor contracts assessed for the binding terms the Act requires, and your security controls assessed against the reasonable security safeguards standard — the ₹250 crore limb.
Approach
Two to four weeks elapsed for a typical mid-sized organisation, driven by how quickly we can get time with the people who own the systems rather than by our side of the work.
A half-day to agree entities, systems and business units in scope, identify the owners we need to speak to, and fix the price. Nothing after this point changes the number.
Structured interviews with the people who actually operate the systems, plus review of your notices, contracts, retention practice and security documentation. Typically six to twelve sessions.
Clause-by-clause assessment against the Act and the 2025 Rules, RAG-rated, with each gap tied to the processing activity it affects so the finding is specific enough to act on.
Remediation sequenced backwards from 13 May 2027, with effort estimates, dependencies and a suggested owner for each item — including the items you should do first because they reduce risk before the deadline, not because of it.
A working session with your team on the findings, then a separate short session for leadership on exposure, cost and sequence. The report is written so both audiences can read the same document.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
A structured record of every processing activity, its purpose, basis, storage, recipients and retention. The RoPA-equivalent that everything else depends on, delivered in a form you can maintain rather than a PDF you cannot.
Fiduciary, Processor or both, reasoned per activity, with the Significant Data Fiduciary trigger assessment alongside it.
Every gap against the Act and the 2025 Rules, red, amber or green, with the affected processing named, the effort sized and an owner suggested.
Sequenced backwards from the deadline with dependencies made visible, so the programme can be funded by quarter instead of discovered in the last one.
Two pages in business language: where you stand, what the realistic exposure is, what it takes to close, and what happens if you do not. Written to be read by a board, not forwarded to one.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
Two to four weeks elapsed for a typical mid-sized organisation. From you we need about six to twelve interview sessions with the people who own the systems — product, engineering, HR, marketing, support and whoever handles vendors — plus your current notices, processor contracts and any retention or security documentation that exists. The bottleneck is almost always calendar access to those people, so we agree the interview list at kick-off and hold the dates.
No. We are a security and compliance firm, not a law firm, and we are explicit about that. The assessment tells you what personal data you process, what your obligations look like operationally, and where you are short of them. Where a question turns on genuinely contested interpretation, we flag it as such and recommend you take that specific question to counsel — rather than quietly picking an answer and presenting it as settled.
A fixed price, quoted after a 30-minute scoping call and confirmed in the kick-off. The variables are the number of entities and business units in scope and how many distinct systems process personal data, not headcount. We quote the whole engagement rather than a day rate, so the number you agree is the number you pay.
We can, and many clients ask us to, but it is a separate engagement scoped after this one and it is not bundled in. Keeping them separate is deliberate: an assessment whose author is paid more the more work it finds is an assessment nobody should trust. A meaningful number of clients take the register and remediate internally, which is a perfectly good outcome.
Usually not, but it will be a smaller engagement. The Act does not have a headcount exemption, and a forty-person SaaS company with Indian users has the same core obligations as a large one — notice, consent, rights, breach reporting — just across fewer systems. What changes is scope and therefore price. If we think you genuinely do not need this yet, we will say so on the scoping call, because a bad-fit engagement costs us more than it earns.
The assessment flags whether the triggers are within reach and what the additional duties would mean for you — a Data Protection Officer based in India, an annual Data Protection Impact Assessment, an independent data audit and algorithmic due diligence. Designation is a government decision, not a self-assessment, so nobody can tell you for certain in advance. What we can do is make sure it would not arrive as a surprise with a build programme attached.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.