Data Protection · India

You cannot plan for DPDP until you know what you hold.

A fixed-scope, fixed-price diagnostic that answers four questions: what personal data you hold, what role you play under the Act, where you fall short of the Act and the 2025 Rules, and what has to happen in what order before 13 May 2027. Two to four weeks, one report, no retainer attached to it.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
FixedScope and price
2–4 weeksTypical elapsed time
RAGRated gap register
13 May 2027What the roadmap works back from

The cheapest useful thing you can do first

Most DPDP conversations stall in the same place. Someone senior asks how exposed the organisation is, and the honest answer is that nobody knows, because nobody has written down what personal data the company holds, why it holds it, who it goes to and how long it stays. Until that document exists, every other decision — what to build, what to budget, whether to worry — is guesswork with a deadline attached.

This engagement produces that document and the gap register that follows from it. It is deliberately narrow. We are not implementing anything, not selling a retainer inside it, and not producing a legal opinion — we are not a law firm, and where a genuinely contested question of interpretation appears we say so and recommend you take it to counsel rather than quietly guessing on your behalf.

What you get instead is an operational picture: your processing, your role, your gaps ranked by risk and by date, and a plan that works backwards from 13 May 2027. Some clients then hand it to their own team and run the remediation internally. That is a legitimate outcome and we scope the assessment as though it will be the one.

Coverage

What the assessment covers

Eight workstreams, assessed against the Act and the DPDP Rules, 2025. Every one of them produces findings in the same register, so the output is one prioritised list rather than eight separate opinions.

Data-processing inventory

Every processing activity across product, HR, marketing, support, finance and third-party tools: what is collected, why, on what basis, where it is stored, who it is shared with and how long it is kept.

Role determination

Whether you are a Data Fiduciary, a Data Processor, or both for different activities — reasoned per activity, because most organisations are genuinely both and treating themselves as one is a common and expensive simplification.

SDF trigger review

An honest read on whether the volume and sensitivity of what you process puts Significant Data Fiduciary designation within reach, and what the additional duties would cost you if it does.

Notice and consent review

Your existing notices and consent capture assessed against the plain-language requirement, the purpose limitation, and the rule that withdrawing consent must be as easy as giving it.

Data-principal rights readiness

Whether you could actually service an access, correction, erasure, grievance or nomination request today — tested against your real systems, not against your policy document.

Breach detection and reporting

Whether your logging, alerting and escalation would surface a personal data breach in time to notify without delay and file the detailed report inside 72 hours.

Retention, erasure and children’s data

Retention schedules and erasure on withdrawal or purpose completion, plus any exposure to under-18 data and the verifiable parental consent that comes with it.

Processors, contracts and safeguards

Your processor contracts assessed for the binding terms the Act requires, and your security controls assessed against the reasonable security safeguards standard — the ₹250 crore limb.

Approach

How the assessment runs

Two to four weeks elapsed for a typical mid-sized organisation, driven by how quickly we can get time with the people who own the systems rather than by our side of the work.

  1. 01 · Kick-off and scope

    A half-day to agree entities, systems and business units in scope, identify the owners we need to speak to, and fix the price. Nothing after this point changes the number.

  2. 02 · Discovery

    Structured interviews with the people who actually operate the systems, plus review of your notices, contracts, retention practice and security documentation. Typically six to twelve sessions.

  3. 03 · Gap analysis

    Clause-by-clause assessment against the Act and the 2025 Rules, RAG-rated, with each gap tied to the processing activity it affects so the finding is specific enough to act on.

  4. 04 · Roadmap

    Remediation sequenced backwards from 13 May 2027, with effort estimates, dependencies and a suggested owner for each item — including the items you should do first because they reduce risk before the deadline, not because of it.

  5. 05 · Readout

    A working session with your team on the findings, then a separate short session for leadership on exposure, cost and sequence. The report is written so both audiences can read the same document.

Run against recognised standards

  • DPDP Act, 2023Enacted 11 August 2023
  • DPDP Rules, 2025Notified 13 November 2025
  • Notice and consentAssessed clause by clause
  • Data-principal rightsTested against live systems
  • Reasonable security safeguardsAssessed, and testable separately
  • Breach notificationWithout delay, detailed report in 72 hours

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Data-processing inventory

A structured record of every processing activity, its purpose, basis, storage, recipients and retention. The RoPA-equivalent that everything else depends on, delivered in a form you can maintain rather than a PDF you cannot.

Written role determination

Fiduciary, Processor or both, reasoned per activity, with the Significant Data Fiduciary trigger assessment alongside it.

RAG-rated gap register

Every gap against the Act and the 2025 Rules, red, amber or green, with the affected processing named, the effort sized and an owner suggested.

Remediation roadmap to May 2027

Sequenced backwards from the deadline with dependencies made visible, so the programme can be funded by quarter instead of discovered in the last one.

Leadership summary

Two pages in business language: where you stand, what the realistic exposure is, what it takes to close, and what happens if you do not. Written to be read by a board, not forwarded to one.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • Somebody senior has asked how exposed you are to DPDP and nobody can answer.
  • You need a budget number for DPDP work and have nothing to base one on.
  • You have never written down what personal data the organisation actually holds.
  • A customer or investor questionnaire has asked about DPDP readiness and you improvised.
  • You want an independent view before committing to a multi-quarter compliance programme.
  • You are not sure whether you are a Data Fiduciary, a Data Processor, or both.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

DPDP Readiness Assessment — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

How long does it take and what do you need from us?

Two to four weeks elapsed for a typical mid-sized organisation. From you we need about six to twelve interview sessions with the people who own the systems — product, engineering, HR, marketing, support and whoever handles vendors — plus your current notices, processor contracts and any retention or security documentation that exists. The bottleneck is almost always calendar access to those people, so we agree the interview list at kick-off and hold the dates.

Is this a legal opinion?

No. We are a security and compliance firm, not a law firm, and we are explicit about that. The assessment tells you what personal data you process, what your obligations look like operationally, and where you are short of them. Where a question turns on genuinely contested interpretation, we flag it as such and recommend you take that specific question to counsel — rather than quietly picking an answer and presenting it as settled.

What does it cost?

A fixed price, quoted after a 30-minute scoping call and confirmed in the kick-off. The variables are the number of entities and business units in scope and how many distinct systems process personal data, not headcount. We quote the whole engagement rather than a day rate, so the number you agree is the number you pay.

Do you fix the gaps as well?

We can, and many clients ask us to, but it is a separate engagement scoped after this one and it is not bundled in. Keeping them separate is deliberate: an assessment whose author is paid more the more work it finds is an assessment nobody should trust. A meaningful number of clients take the register and remediate internally, which is a perfectly good outcome.

We are a startup with forty people. Is this overkill?

Usually not, but it will be a smaller engagement. The Act does not have a headcount exemption, and a forty-person SaaS company with Indian users has the same core obligations as a large one — notice, consent, rights, breach reporting — just across fewer systems. What changes is scope and therefore price. If we think you genuinely do not need this yet, we will say so on the scoping call, because a bad-fit engagement costs us more than it earns.

What happens if we are notified as a Significant Data Fiduciary later?

The assessment flags whether the triggers are within reach and what the additional duties would mean for you — a Data Protection Officer based in India, an annual Data Protection Impact Assessment, an independent data audit and algorithmic due diligence. Designation is a government decision, not a self-assessment, so nobody can tell you for certain in advance. What we can do is make sure it would not arrive as a surprise with a build programme attached.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.