Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

DPDP Act12 min read

DPDP Act Consultant in Noida: What They Do and What Compliance Costs

What a DPDP Act consultant in Noida actually does, week by week, and what compliance costs by company size before the May 2027 enforcement date.

12 min readBy , Director

Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX

DPDP Act: DPDP Act consultant in Noida. Illustrated cover by SecureRoot Risk Advisory.

The Digital Personal Data Protection Rules were notified on 13 November 2025. Consent Manager registration opens in November 2026. Penalties become enforceable on 13 May 2027. That is the real clock, and it is shorter than it looks once you count backwards through a data mapping exercise, a consent rebuild and a vendor contract review.

Most Noida businesses we speak to have read the summaries. Very few can answer the first question an auditor asks: where does personal data actually sit in your organisation, and who put it there. This post explains what a DPDP Act consultant does about that, in what order, and what the work costs at different company sizes.

What a DPDP Act consultant actually does

The job is not writing a privacy policy. A privacy policy is an output, and usually the last one. The work that matters happens before it.

A consultant takes your organisation from “we think we are mostly fine” to a documented, defensible position: you know what personal data you hold, why you hold it, who you share it with, how a data principal exercises their rights, and what happens in the first hour after a breach. Everything else follows from that inventory.

In practice the engagement splits into five workstreams that overlap rather than run in sequence.

1. Data discovery and mapping

Every system that touches personal data gets catalogued: CRM, HR platform, support desk, marketing automation, payment processor, analytics, backups, and the spreadsheets nobody admits to. For each one the consultant records what categories of data sit there, the lawful basis, retention period, and which third parties receive it.

This is the least glamorous phase and the one that determines whether the rest of the programme is real. Organisations that skip it end up with policies describing a company they do not have.

2. Gap assessment against the Act and Rules

With the inventory in hand, the consultant tests your current state against the obligations: notice and consent, purpose limitation, retention limits, security safeguards, breach notification, data principal rights, and children’s data where relevant. Each gap gets a severity and an owner.

Our DPDP compliance audit work follows this pattern, and the finding that recurs most often is retention. Companies collect lawfully and then keep the data forever, which turns a compliant collection into a non-compliant holding.

The Rules set expectations for how a notice reads and how consent is captured, withdrawn and recorded. Most existing implementations fail on withdrawal: consent is easy to give and quietly impossible to take back.

If your organisation plans to work through a registered Consent Manager, registration opens in November 2026, which means the design decision needs making well before that.

4. Governance, roles and the DPO question

Someone has to own this. Significant Data Fiduciaries carry additional obligations including appointing a Data Protection Officer based in India. Companies below that threshold still need a named accountable person, a documented grievance mechanism and a response clock that somebody actually watches.

5. Vendor and contract remediation

Your processors are your exposure. Contracts need data processing terms, security obligations, breach notification timelines that are shorter than your own regulatory clock, and deletion commitments at termination. This workstream runs longest because it depends on other companies’ legal teams.

Why the Noida and Delhi NCR context matters

Noida and the wider NCR region carry an unusual density of the exact business types the Act pressures hardest: IT services firms processing client data under contract, SaaS companies holding customer records, healthtech handling medical information, and a large BPO and support sector where personal data is the raw material of the work.

Two local realities shape how these programmes run. First, many NCR companies are processors rather than fiduciaries for their largest data flows, which changes the obligations and puts the commercial risk in the client contract rather than the statute. Second, the same firms are usually mid-way through an ISO 27001 or SOC 2 programme, and the control overlap is significant. A consultant who treats DPDP Act work as a separate silo will make you pay twice for the same evidence.

There is also a practical point about proximity. Data mapping interviews go faster in a room than on a call, and the first serious breach exercise is worth running in person.

What DPDP Act compliance costs

Published figures vary widely because the scope varies widely. The honest answer depends on your data volume, system count and how much of the work your team absorbs. Indicative bands for the Indian market look like this.

Organisation profile Indicative programme cost Typical duration
Startup, under 10,000 users, few systems Under ₹50,000 per year 4 to 6 weeks
SME, up to 500,000 users ₹3 lakh to ₹8 lakh 10 to 16 weeks
Mid-size, multi-system, some processors ₹1.5 lakh to ₹4 lakh end-to-end consulting 12 to 16 weeks
Large enterprise, subsidiaries and complex flows ₹15 lakh to ₹60 lakh 6 to 12 months

Three things move these numbers more than anything else.

System count, not headcount. A 40 person company running 25 SaaS tools costs more to map than a 300 person company running six.

Whether you handle children’s data. The additional obligations around verifiable parental consent add real engineering work, not just paperwork.

Contract volume. Vendor remediation is priced per contract in practice. Fifty processor agreements is a different project from five.

Set against this, the penalty schedule under the Act reaches ₹250 crore for failure to implement reasonable security safeguards and ₹200 crore for failure to notify a breach. The comparison is not meant as a scare tactic. It is the reason boards approve the budget.

A realistic 16 week plan

This is the shape of a mid-size engagement. Compress it if your estate is simple, extend it if your vendor list is long.

Weeks 1 to 3. Kick off, stakeholder interviews, system inventory, data flow mapping across business units. Deliverable: personal data inventory and flow diagrams.

Weeks 4 to 6. Gap assessment against the Act and Rules. Deliverable: prioritised gap register with owners and severity.

Weeks 7 to 10. Notice and consent redesign, retention schedule, grievance and rights fulfilment process. Deliverable: revised notices, consent architecture, rights workflow with response clocks.

Weeks 11 to 13. Vendor classification and contract remediation pack. Deliverable: processor register and clause set issued to vendors.

Weeks 14 to 15. Security safeguards review and breach response drill. Deliverable: tested incident playbook aligned to reporting obligations, which is where continuous monitoring earns its place, including CERT-In directions where the incident is also a reportable cyber incident.

Week 16. Board reporting pack, residual risk register, and the operating rhythm that keeps the programme alive after the consultant leaves.

How to choose a DPDP Act consultant

The market has three kinds of provider and they are not interchangeable.

Law firms give you the statutory interpretation and strong contract work. They are usually less strong on system-level discovery and security controls.

Platform vendors sell software that automates consent capture or data mapping. Useful, but a tool does not know where your shadow IT lives, and buying one before the mapping exercise means you automate a picture you have not verified.

Security and GRC consultancies work from the data and control side, which suits organisations already running ISO 27001, SOC 2 or PCI DSS programmes because the evidence is shared.

Questions worth asking any of them: who exactly does the mapping interviews, will you produce a data inventory we own and can maintain, how do you handle the overlap with our existing certifications, and what does the handover look like on the last day.

Be wary of anyone quoting a fixed price before seeing your system list. The scope genuinely is not knowable in advance, and a fixed price set blind gets recovered later through change requests.

Where SecureRoot fits

SecureRoot runs DPDP Act compliance programmes for organisations across Noida and Delhi NCR, from data discovery through to board reporting. Because the same team runs our ISO 27001, SOC 2 and penetration testing engagements, the security safeguards evidence your DPDP programme needs is usually work you are already doing, documented once and used in both places. You can see the full range on our services page.

We will also tell you when a full programme is not yet the right spend. For a small estate with a short vendor list, a focused gap assessment and a retention clean-up gets you most of the way, and we would rather scope that honestly than sell you sixteen weeks you do not need.

Frequently asked questions

When does the DPDP Act actually become enforceable?

13 May 2027 is the date that matters, but it is not the date to plan to. The Rules were notified on 13 November 2025, Consent Manager registration opens in November 2026, and the core obligations carry enforceable penalties from 13 May 2027. Read that sequence backwards and the picture changes. A mid-size programme runs twelve to sixteen weeks of actual work, and that assumes stakeholders answer interview requests, vendors return signed clause sets and your board approves budget without a second cycle. None of those are safe assumptions in a quarter that also contains an audit. The Consent Manager date is the one most organisations miss, because a decision to route consent through a registered Consent Manager changes the architecture you build, not just the vendor you sign. Decide that before November 2026 or you will build twice. Organisations starting in early 2027 are not planning a programme; they are planning a policy document.

Do we need a Data Protection Officer?

Probably not a formal DPO, but certainly a named owner. Only Significant Data Fiduciaries are required to appoint a Data Protection Officer based in India, and that classification is made by the Central Government rather than self-declared. Everyone else still needs an accountable person, a published grievance mechanism and a response clock somebody actually watches, because a data principal's request does not pause while you decide who owns it. In practice this lands with whoever already runs information security or legal, and it fails when it lands with both. Write the role into a document: who receives rights requests, who decides on them, who signs the breach notification, and who covers each of those when they are on leave. Our post on Data Protection Officer services in India works through the outsourced option for companies that cannot justify the headcount. The obligation is smaller than a DPO appointment, but it is not optional.

We are a processor, not a fiduciary. Does the Act apply to us?

Yes, but mostly through your contracts rather than directly through the statute. As a Data Processor your obligations flow from the agreement with the fiduciary who engaged you, and that is where the commercial risk sits: security safeguards, breach notification to your client on their clock rather than yours, deletion on termination, and demonstrable control over the sub-processors you pass data to. NCR IT services and BPO firms sit in this position constantly, often as processor for a large client and fiduciary for their own employee and prospect data at the same time. That dual position is worth mapping explicitly, because the two roles carry different duties over the same infrastructure. Separately, CERT-In's April 2022 Directions apply to you as a body corporate regardless of which role you hold, with their own six-hour reporting window for notified cyber incidents. Reconcile the two clocks before an incident, not during one.

Does our ISO 27001 certification cover DPDP Act compliance?

No, and no certification does, because the DPDP Act has no certification scheme. What ISO 27001 does is carry a large share of the load. Your access control, cryptography, logging, supplier management and incident response evidence maps directly onto the reasonable security safeguards the Act expects, and a consultant who makes you rebuild that evidence is billing you twice for one control set. What certification does not give you is the privacy layer: lawful basis analysis, notice and consent architecture, retention schedules with actual deletion behind them, and a data principal rights workflow with response times. Those are purpose and accountability questions, not security ones, and Annex A does not answer them. SecureRoot holds ISO/IEC 27001:2022 certificate IN60432E and ISO 9001:2015, and we run compliance and DPDP Act programmes from the same team, which is why the overlap gets used rather than re-evidenced.

How long does a gap assessment take on its own?

Three to five weeks for a mid-size organisation, from kick off to a prioritised gap register with owners and severities against each finding. The analysis is rarely the constraint. Interview scheduling is: you need forty-five minutes each with the people who actually operate the CRM, the HR platform, the support desk and the marketing stack, and those people are busy in exactly the weeks you want them. Book the full interview set before week one starts and the assessment lands on time. A gap assessment alone is often the right first spend, particularly for a small estate with a short vendor list, because it tells you whether you are looking at a retention clean-up or a sixteen-week programme before you commit to either. We would rather scope that honestly than sell a full programme you do not need, which is what the scoping call is for.

What happens if we do nothing until 2027?

You end up buying a tool and publishing a policy, which is the failure pattern worth naming. Late programmes compress the wrong phase: teams skip discovery, buy consent software, publish a notice and declare the work finished. The mapping exercise does not compress, because it depends on other people's calendars, and vendor remediation compresses least of all, because it depends on other companies' legal teams returning your clause set. So the two gaps that survive are retention and processors, and those are precisely where the Act's penalty schedule bites hardest: up to two hundred and fifty crore rupees for failing to implement reasonable security safeguards and up to two hundred crore for failing to notify a breach. A policy describing a company you do not have is not a defence. If you are starting late, start with the inventory anyway and sequence the rest from what it tells you.

Next step

If you are working out whether you need a full programme or a focused gap assessment, we can tell you in a single call. Bring your system list and an idea of your data volumes.

Book a 30 minute scoping call with our GRC team, or call +91 73071 48874.

Have a Question About This?

If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.

We reply within one business day.

All Articles
  • DPDP Act17 min read

    DPDP Act Breach Notification: What Applies Now and What Starts in 2027

    There are two breach clocks in Indian law and only one of them is running. CERT-In's six-hour incident report has been live since 2022. The DPDP Act's duty to intimate the Data Protection Board and every affected Data Principal, with the contents Rule 7 prescribes, commences in May 2027. This guide sets out what a breach obliges you to do today, what lands in 2027, and what to build in between so the new duty costs you nothing when it arrives.

    Read Article
  • DPDP Act: Do you need a DPO? Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    Data Protection Officer Services in India: Do You Need a DPO?

    The DPDP Act, 2023 expects many businesses to appoint a Data Protection Officer, but hiring a full-time expert is costly and slow. Data protection officer services in india give you that expertise on demand, without the headcount.

    Read Article
  • DPDP Act: The DPDP compliance audit. Illustrated cover by SecureRoot Risk Advisory.
    DPDP Act10 min read

    DPDP Compliance Audit in India: Process, Checklist & Cost

    A policy on paper means nothing until someone tests it. A dpdp compliance audit in india independently verifies that your controls actually meet the Digital Personal Data Protection Act, 2023 – not just that they exist on a slide.

    Read Article