Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Compliance13 services in this practice area

Meet the DPDP Act

DPDP Act Readiness and India Data Protection Compliance

The DPDP Act is India's personal data protection law. We help you understand your obligations, build the right controls, and get ready for enforcement with confidence.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The DPDP Act governs how organisations collect, use, and protect the personal data of people in India. It introduces duties around consent, notice, data principal rights, and breach reporting, backed by real penalties. It matters because it applies to almost anyone handling Indian personal data, and the Rules give it teeth. We help you find where personal data lives, fix the gaps, and stand up a privacy programme that meets the DPDP Act without drowning your teams in paperwork.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the DPDP Act engagement, 6 phases in order, each one selectable. Phase 1, Data Discovery and Mapping. We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found. Activities: Scan systems and databases for personal data; Interview teams on collection and sharing points; Map data flows across vendors and borders; Build the personal data inventory. Hands over Data Flow and Inventory Map. Phase 2, Gap Assessment Against the DPDP Act. We measure your current practices against the DPDP Act and its Rules, covering consent, notice, and data principal rights. Activities: Assess consent and notice practices against the Act; Review readiness for data principal rights; Check breach reporting and security safeguards; Rank gaps by penalty exposure and effort. Hands over DPDP Act Gap Assessment Report. Phase 3, Consent and Notice Design. We help you build clear notices and a consent mechanism that meets the law, including consent manager considerations. Activities: Draft notices in plain language per purpose; Design the consent capture and withdrawal flow; Assess consent manager integration options; Plan notice delivery in the required languages. Hands over Consent and Notice Framework. Phase 4, Rights and Breach Processes. We set up processes for data principal requests and for reporting breaches within the required timelines. Activities: Build the data principal request workflow; Define grievance redressal roles and timelines; Write the breach notification procedure; Run a breach response tabletop exercise. Hands over Data Principal Rights Playbook and Breach Procedure. Phase 5, Control Implementation. We help you put in place the security safeguards and retention rules the DPDP Act expects. Activities: Implement encryption and access safeguards; Set retention and erasure schedules; Update processor contracts with DPDP Act clauses; Roll out privacy training to data-handling teams. Hands over Implemented Safeguards and Retention Schedule. Phase 6, Readiness Review. We run a final review so you can show a regulator, or a customer, that your programme holds together. Activities: Test the consent and rights workflows end to end; Verify remediation of earlier gaps; Compile the accountability evidence pack; Brief leadership on residual risk. Hands over DPDP Act Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Data Discovery and Mapping

We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.

What Happens In This Phase

  • Scan systems and databases for personal data
  • Interview teams on collection and sharing points
  • Map data flows across vendors and borders
  • Build the personal data inventory

The Handover

Data Flow and Inventory Map

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Data Discovery and Mapping

    We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.

    OutputData Flow and Inventory Map

    Activities

    • Scan systems and databases for personal data
    • Interview teams on collection and sharing points
    • Map data flows across vendors and borders
    • Build the personal data inventory
  2. 02

    Gap Assessment Against the DPDP Act

    We measure your current practices against the DPDP Act and its Rules, covering consent, notice, and data principal rights.

    OutputDPDP Act Gap Assessment Report

    Activities

    • Assess consent and notice practices against the Act
    • Review readiness for data principal rights
    • Check breach reporting and security safeguards
    • Rank gaps by penalty exposure and effort
  3. 03

    Consent and Notice Design

    We help you build clear notices and a consent mechanism that meets the law, including consent manager considerations.

    OutputConsent and Notice Framework

    Activities

    • Draft notices in plain language per purpose
    • Design the consent capture and withdrawal flow
    • Assess consent manager integration options
    • Plan notice delivery in the required languages
  4. 04

    Rights and Breach Processes

    We set up processes for data principal requests and for reporting breaches within the required timelines.

    OutputData Principal Rights Playbook and Breach Procedure

    Activities

    • Build the data principal request workflow
    • Define grievance redressal roles and timelines
    • Write the breach notification procedure
    • Run a breach response tabletop exercise
  5. 05

    Control Implementation

    We help you put in place the security safeguards and retention rules the DPDP Act expects.

    OutputImplemented Safeguards and Retention Schedule

    Activities

    • Implement encryption and access safeguards
    • Set retention and erasure schedules
    • Update processor contracts with DPDP Act clauses
    • Roll out privacy training to data-handling teams
  6. 06

    Readiness Review

    We run a final review so you can show a regulator, or a customer, that your programme holds together.

    OutputDPDP Act Readiness Report

    Activities

    • Test the consent and rights workflows end to end
    • Verify remediation of earlier gaps
    • Compile the accountability evidence pack
    • Brief leadership on residual risk

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the DPDP Act scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Microsoft Purview, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: Digital Personal Data Protection Act 2023, DPDP Rules, ISO/IEC 27701:2019, ISO/IEC 27001:2022, NIST Privacy Framework.

What We Run

7 tools

  • OneTrust
  • Securiti
  • TrustArc
  • Microsoft Purview
  • BigID
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • Digital Personal Data Protection Act 2023
  • DPDP Rules
  • ISO/IEC 27701:2019
  • ISO/IEC 27001:2022
  • NIST Privacy Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Data flow and inventory map
  • DPDP Act gap assessment report
  • Consent and notice framework
  • Data principal rights playbook
  • Breach response procedure

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Who does the DPDP Act apply to?

Almost any organisation that processes the personal data of people in India, whether based in India or abroad. If you handle Indian personal data, it likely applies to you.

What is a data principal under the DPDP Act?

A data principal is the individual the personal data is about. The law gives them rights such as access, correction, and erasure, which you must be ready to honour.

What penalties does the DPDP Act carry?

The Act allows significant financial penalties for failures such as poor security safeguards or missed breach reporting. Getting ready early is far cheaper than a penalty.

Keep Moving Through Compliance

Service 5 of 13 in this practice area