The Digital Personal Data Protection Rules were notified on 13 November 2025. Consent Manager registration opens in November 2026. Penalties become enforceable on 13 May 2027. That is the real clock, and it is shorter than it looks once you count backwards through a data mapping exercise, a consent rebuild and a vendor contract review.
Most Noida businesses we speak to have read the summaries. Very few can answer the first question an auditor asks: where does personal data actually sit in your organisation, and who put it there. This post explains what a DPDP Act consultant does about that, in what order, and what the work costs at different company sizes.
The job is not writing a privacy policy. A privacy policy is an output, and usually the last one. The work that matters happens before it.
A DPDP Act consultant maps your personal data, tests it against the Act and Rules, rebuilds consent and notices, sorts governance and remediates vendor contracts. Indicative cost runs from under 50,000 rupees for a startup to 15 to 60 lakh for a large enterprise, with penalties enforceable from 13 May 2027.
A consultant takes your organisation from “we think we are mostly fine” to a documented, defensible position: you know what personal data you hold, why you hold it, who you share it with, how a data principal exercises their rights, and what happens in the first hour after a breach. Everything else follows from that inventory.
In practice the engagement splits into five workstreams that overlap rather than run in sequence.
Every system that touches personal data gets catalogued: CRM, HR platform, support desk, marketing automation, payment processor, analytics, backups, and the spreadsheets nobody admits to. For each one the consultant records what categories of data sit there, the lawful basis, retention period, and which third parties receive it.
This is the least glamorous phase and the one that determines whether the rest of the programme is real. Organisations that skip it end up with policies describing a company they do not have.
With the inventory in hand, the consultant tests your current state against the obligations: notice and consent, purpose limitation, retention limits, security safeguards, breach notification, data principal rights, and children’s data where relevant. Each gap gets a severity and an owner.
Our DPDP compliance audit work follows this pattern, and the finding that recurs most often is retention. Companies collect lawfully and then keep the data forever, which turns a compliant collection into a non-compliant holding.
The Rules set expectations for how a notice reads and how consent is captured, withdrawn and recorded. Most existing implementations fail on withdrawal: consent is easy to give and quietly impossible to take back.
If your organisation plans to work through a registered Consent Manager, registration opens in November 2026, which means the design decision needs making well before that.
Someone has to own this. Significant Data Fiduciaries carry additional obligations including appointing a Data Protection Officer based in India. Companies below that threshold still need a named accountable person, a documented grievance mechanism and a response clock that somebody actually watches.
Your processors are your exposure. Contracts need data processing terms, security obligations, breach notification timelines that are shorter than your own regulatory clock, and deletion commitments at termination. This workstream runs longest because it depends on other companies’ legal teams.
Noida and the wider NCR region carry an unusual density of the exact business types the Act pressures hardest: IT services firms processing client data under contract, SaaS companies holding customer records, healthtech handling medical information, and a large BPO and support sector where personal data is the raw material of the work.
Two local realities shape how these programmes run. First, many NCR companies are processors rather than fiduciaries for their largest data flows, which changes the obligations and puts the commercial risk in the client contract rather than the statute. Second, the same firms are usually mid-way through an ISO 27001 or SOC 2 programme, and the control overlap is significant. A consultant who treats DPDP Act work as a separate silo will make you pay twice for the same evidence.
There is also a practical point about proximity. Data mapping interviews go faster in a room than on a call, and the first serious breach exercise is worth running in person.
Published figures vary widely because the scope varies widely. The honest answer depends on your data volume, system count and how much of the work your team absorbs. Indicative bands for the Indian market look like this.
| Organisation profile | Indicative programme cost | Typical duration |
|---|---|---|
| Startup, under 10,000 users, few systems | Under ₹50,000 per year | 4 to 6 weeks |
| SME, up to 500,000 users | ₹3 lakh to ₹8 lakh | 10 to 16 weeks |
| Mid-size, multi-system, some processors | ₹1.5 lakh to ₹4 lakh end-to-end consulting | 12 to 16 weeks |
| Large enterprise, subsidiaries and complex flows | ₹15 lakh to ₹60 lakh | 6 to 12 months |
Three things move these numbers more than anything else.
System count, not headcount. A 40 person company running 25 SaaS tools costs more to map than a 300 person company running six.
Whether you handle children’s data. The additional obligations around verifiable parental consent add real engineering work, not just paperwork.
Contract volume. Vendor remediation is priced per contract in practice. Fifty processor agreements is a different project from five.
Set against this, the penalty schedule under the Act reaches ₹250 crore for failure to implement reasonable security safeguards and ₹200 crore for failure to notify a breach. The comparison is not meant as a scare tactic. It is the reason boards approve the budget.
This is the shape of a mid-size engagement. Compress it if your estate is simple, extend it if your vendor list is long.
Weeks 1 to 3. Kick off, stakeholder interviews, system inventory, data flow mapping across business units. Deliverable: personal data inventory and flow diagrams.
Weeks 4 to 6. Gap assessment against the Act and Rules. Deliverable: prioritised gap register with owners and severity.
Weeks 7 to 10. Notice and consent redesign, retention schedule, grievance and rights fulfilment process. Deliverable: revised notices, consent architecture, rights workflow with response clocks.
Weeks 11 to 13. Vendor classification and contract remediation pack. Deliverable: processor register and clause set issued to vendors.
Weeks 14 to 15. Security safeguards review and breach response drill. Deliverable: tested incident playbook aligned to reporting obligations, which is where continuous monitoring earns its place, including CERT-In directions where the incident is also a reportable cyber incident.
Week 16. Board reporting pack, residual risk register, and the operating rhythm that keeps the programme alive after the consultant leaves.
The market has three kinds of provider and they are not interchangeable.
Law firms give you the statutory interpretation and strong contract work. They are usually less strong on system-level discovery and security controls.
Platform vendors sell software that automates consent capture or data mapping. Useful, but a tool does not know where your shadow IT lives, and buying one before the mapping exercise means you automate a picture you have not verified.
Security and GRC consultancies work from the data and control side, which suits organisations already running ISO 27001, SOC 2 or PCI DSS programmes because the evidence is shared.
Questions worth asking any of them: who exactly does the mapping interviews, will you produce a data inventory we own and can maintain, how do you handle the overlap with our existing certifications, and what does the handover look like on the last day.
Be wary of anyone quoting a fixed price before seeing your system list. The scope genuinely is not knowable in advance, and a fixed price set blind gets recovered later through change requests.
SecureRoot runs DPDP Act compliance programmes for organisations across Noida and Delhi NCR, from data discovery through to board reporting. Because the same team runs our ISO 27001, SOC 2 and penetration testing engagements, the security safeguards evidence your DPDP programme needs is usually work you are already doing, documented once and used in both places. You can see the full range on our services page.
We will also tell you when a full programme is not yet the right spend. For a small estate with a short vendor list, a focused gap assessment and a retention clean-up gets you most of the way, and we would rather scope that honestly than sell you sixteen weeks you do not need.
The Rules were notified on 13 November 2025. Consent Manager registration opens in November 2026, and the core obligations with their associated penalties become enforceable on 13 May 2027. Working backwards from a 12 to 16 week programme, mid-size organisations need to start well before the final months.
Only Significant Data Fiduciaries are required to appoint a DPO based in India. Every other organisation still needs a named accountable person and a working grievance mechanism, which is a smaller commitment but not an optional one.
Your obligations flow largely through your contract with the fiduciary rather than directly from the statute, but the practical requirements land in the same place: security safeguards, breach notification to your client, deletion on termination and demonstrable control over sub-processors. NCR IT services firms sit in this position frequently.
No, but it does a lot of the heavy lifting. ISO 27001 gives you the security safeguards and much of the evidence. What it does not give you is the lawful basis analysis, consent architecture, retention schedule and data principal rights workflow, which are privacy obligations rather than security ones.
For a mid-size organisation, three to five weeks from kick off to a prioritised gap register, assuming stakeholders are available for interviews. The bottleneck is almost always interview scheduling rather than analysis.
The mapping work does not compress. Organisations that start late tend to buy a consent tool, publish a policy and call it done, which leaves the retention and vendor gaps untouched. Those are the two areas where penalties for security failures and breach notification failures actually bite.
If you are working out whether you need a full programme or a focused gap assessment, we can tell you in a single call. Bring your system list and an idea of your data volumes.
Book a 30 minute scoping call with our GRC team, or call +91 73071 48874.