Meet the DPDP Act
DPDP Act Readiness and India Data Protection Compliance
The DPDP Act is India's personal data protection law. We help you understand your obligations, build the right controls, and get ready for enforcement with confidence.
See the engagement path, 6 phasesSee the full Compliance service index
Overview
The DPDP Act governs how organisations collect, use, and protect the personal data of people in India. It introduces duties around consent, notice, data principal rights, and breach reporting, backed by real penalties. It matters because it applies to almost anyone handling Indian personal data, and the Rules give it teeth. We help you find where personal data lives, fix the gaps, and stand up a privacy programme that meets the DPDP Act without drowning your teams in paperwork.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
6 Phases, 6 Named Handovers
Flow
Flow chart of the DPDP Act engagement, 6 phases in order, each one selectable. Phase 1, Data Discovery and Mapping. We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found. Activities: Scan systems and databases for personal data; Interview teams on collection and sharing points; Map data flows across vendors and borders; Build the personal data inventory. Hands over Data Flow and Inventory Map. Phase 2, Gap Assessment Against the DPDP Act. We measure your current practices against the DPDP Act and its Rules, covering consent, notice, and data principal rights. Activities: Assess consent and notice practices against the Act; Review readiness for data principal rights; Check breach reporting and security safeguards; Rank gaps by penalty exposure and effort. Hands over DPDP Act Gap Assessment Report. Phase 3, Consent and Notice Design. We help you build clear notices and a consent mechanism that meets the law, including consent manager considerations. Activities: Draft notices in plain language per purpose; Design the consent capture and withdrawal flow; Assess consent manager integration options; Plan notice delivery in the required languages. Hands over Consent and Notice Framework. Phase 4, Rights and Breach Processes. We set up processes for data principal requests and for reporting breaches within the required timelines. Activities: Build the data principal request workflow; Define grievance redressal roles and timelines; Write the breach notification procedure; Run a breach response tabletop exercise. Hands over Data Principal Rights Playbook and Breach Procedure. Phase 5, Control Implementation. We help you put in place the security safeguards and retention rules the DPDP Act expects. Activities: Implement encryption and access safeguards; Set retention and erasure schedules; Update processor contracts with DPDP Act clauses; Roll out privacy training to data-handling teams. Hands over Implemented Safeguards and Retention Schedule. Phase 6, Readiness Review. We run a final review so you can show a regulator, or a customer, that your programme holds together. Activities: Test the consent and rights workflows end to end; Verify remediation of earlier gaps; Compile the accountability evidence pack; Brief leadership on residual risk. Hands over DPDP Act Readiness Report. Each phase begins from the artefact the phase before it produced.
Phase 01 Data Discovery and Mapping
We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.
What Happens In This Phase
- Scan systems and databases for personal data
- Interview teams on collection and sharing points
- Map data flows across vendors and borders
- Build the personal data inventory
The Handover
Data Flow and Inventory Map
The next phase starts from this.
Phase 01 Data Discovery and Mapping
We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.
What Happens In This Phase
- Scan systems and databases for personal data
- Interview teams on collection and sharing points
- Map data flows across vendors and borders
- Build the personal data inventory
The Handover
Data Flow and Inventory Map
The next phase starts from this.
- 01
Data Discovery and Mapping
We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.
OutputData Flow and Inventory MapActivities
- Scan systems and databases for personal data
- Interview teams on collection and sharing points
- Map data flows across vendors and borders
- Build the personal data inventory
- 02
Gap Assessment Against the DPDP Act
We measure your current practices against the DPDP Act and its Rules, covering consent, notice, and data principal rights.
OutputDPDP Act Gap Assessment ReportActivities
- Assess consent and notice practices against the Act
- Review readiness for data principal rights
- Check breach reporting and security safeguards
- Rank gaps by penalty exposure and effort
- 03
Consent and Notice Design
We help you build clear notices and a consent mechanism that meets the law, including consent manager considerations.
OutputConsent and Notice FrameworkActivities
- Draft notices in plain language per purpose
- Design the consent capture and withdrawal flow
- Assess consent manager integration options
- Plan notice delivery in the required languages
- 04
Rights and Breach Processes
We set up processes for data principal requests and for reporting breaches within the required timelines.
OutputData Principal Rights Playbook and Breach ProcedureActivities
- Build the data principal request workflow
- Define grievance redressal roles and timelines
- Write the breach notification procedure
- Run a breach response tabletop exercise
- 05
Control Implementation
We help you put in place the security safeguards and retention rules the DPDP Act expects.
OutputImplemented Safeguards and Retention ScheduleActivities
- Implement encryption and access safeguards
- Set retention and erasure schedules
- Update processor contracts with DPDP Act clauses
- Roll out privacy training to data-handling teams
- 06
Readiness Review
We run a final review so you can show a regulator, or a customer, that your programme holds together.
OutputDPDP Act Readiness ReportActivities
- Test the consent and rights workflows end to end
- Verify remediation of earlier gaps
- Compile the accountability evidence pack
- Brief leadership on residual risk
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
Built by SecureRoot
DPDPA Compass
Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.
What Is Examined, and What it Is Measured Against
Map
Map of the DPDP Act scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Microsoft Purview, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: Digital Personal Data Protection Act 2023, DPDP Rules, ISO/IEC 27701:2019, ISO/IEC 27001:2022, NIST Privacy Framework.
What We Run
7 tools
- Securiti
- Microsoft Purview
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
5 standards
Deliverables
What You Receive
- Data flow and inventory map
- DPDP Act gap assessment report
- Consent and notice framework
- Data principal rights playbook
- Breach response procedure
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
Who does the DPDP Act apply to?
Almost any organisation that processes the personal data of people in India, whether based in India or abroad. If you handle Indian personal data, it likely applies to you.
What is a data principal under the DPDP Act?
A data principal is the individual the personal data is about. The law gives them rights such as access, correction, and erasure, which you must be ready to honour.
What penalties does the DPDP Act carry?
The Act allows significant financial penalties for failures such as poor security safeguards or missed breach reporting. Getting ready early is far cheaper than a penalty.
Keep Moving Through Compliance
Service 5 of 13 in this practice area
Practice Area
More in Compliance
- ISO 27001Build and certify your information security management system.
- ISO 27701Extend your ISMS into a privacy information management system.
- ISO 22301Certify how your business keeps running through disruption.
- ISO 42001Govern your AI systems with the first AI management standard.
- PCI DSSProtect cardholder data and pass your PCI assessment.
- HIPAAProtect health information and meet HIPAA requirements.
- SOC 2Earn a SOC 2 report your customers can trust.
- CCPAMeet California's consumer privacy requirements.
- GDPRMeet Europe's data protection standard with confidence.
- NEN 7510Certify information security for Dutch healthcare.
- EU AI ActPrepare for Europe's risk-based AI regulation.
- Third Party Risk Assessment (TPRM)Understand and manage the risk your vendors bring.