Skip to content

ISO 27001, SOC 2, the DPDP Act and manual VAPT. Book a Free Scoping Call

Part of Compliance13 services in this practice area

Meet the DPDP Act

DPDP Act Compliance and Readiness Services in India

The DPDP Act is India's personal data protection law. We help you understand your obligations, build the right controls, and get ready for enforcement with confidence.

See the engagement path, 6 phasesSee the full Compliance service index

Overview

The DPDP Act governs how organisations collect, use, and protect the personal data of people in India. It introduces duties around consent, notice, data principal rights, and breach reporting, backed by real penalties. It matters because it applies to almost anyone handling Indian personal data, and the Rules give it teeth. We help you find where personal data lives, fix the gaps, and stand up a privacy programme that meets the DPDP Act without drowning your teams in paperwork.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

6 Phases, 6 Named Handovers

Flow

Flow chart of the DPDP Act engagement, 6 phases in order, each one selectable. Phase 1, Data Discovery and Mapping. We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found. Activities: Scan systems and databases for personal data; Interview teams on collection and sharing points; Map data flows across vendors and borders; Build the personal data inventory. Hands over Data Flow and Inventory Map. Phase 2, Gap Assessment Against the DPDP Act. We measure your current practices against the DPDP Act and its Rules, covering consent, notice, and data principal rights. Activities: Assess consent and notice practices against the Act; Review readiness for data principal rights; Check breach reporting and security safeguards; Rank gaps by penalty exposure and effort. Hands over DPDP Act Gap Assessment Report. Phase 3, Consent and Notice Design. We help you build clear notices and a consent mechanism that meets the law, including consent manager considerations. Activities: Draft notices in plain language per purpose; Design the consent capture and withdrawal flow; Assess consent manager integration options; Plan notice delivery in the required languages. Hands over Consent and Notice Framework. Phase 4, Rights and Breach Processes. We set up processes for data principal requests and for reporting breaches within the required timelines. Activities: Build the data principal request workflow; Define grievance redressal roles and timelines; Write the breach notification procedure; Run a breach response tabletop exercise. Hands over Data Principal Rights Playbook and Breach Procedure. Phase 5, Control Implementation. We help you put in place the security safeguards and retention rules the DPDP Act expects. Activities: Implement encryption and access safeguards; Set retention and erasure schedules; Update processor contracts with DPDP Act clauses; Roll out privacy training to data-handling teams. Hands over Implemented Safeguards and Retention Schedule. Phase 6, Readiness Review. We run a final review so you can show a regulator, or a customer, that your programme holds together. Activities: Test the consent and rights workflows end to end; Verify remediation of earlier gaps; Compile the accountability evidence pack; Brief leadership on residual risk. Hands over DPDP Act Readiness Report. Each phase begins from the artefact the phase before it produced.

Phase 01 Data Discovery and Mapping

We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.

What Happens In This Phase

  • Scan systems and databases for personal data
  • Interview teams on collection and sharing points
  • Map data flows across vendors and borders
  • Build the personal data inventory

The Handover

Data Flow and Inventory Map

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Data Discovery and Mapping

    We map where personal data enters, flows, and rests across your systems. You cannot protect what you have not found.

    OutputData Flow and Inventory Map

    Activities

    • Scan systems and databases for personal data
    • Interview teams on collection and sharing points
    • Map data flows across vendors and borders
    • Build the personal data inventory
  2. 02

    Gap Assessment Against the DPDP Act

    We measure your current practices against the DPDP Act and its Rules, covering consent, notice, and data principal rights.

    OutputDPDP Act Gap Assessment Report

    Activities

    • Assess consent and notice practices against the Act
    • Review readiness for data principal rights
    • Check breach reporting and security safeguards
    • Rank gaps by penalty exposure and effort
  3. 03

    Consent and Notice Design

    We help you build clear notices and a consent mechanism that meets the law, including consent manager considerations.

    OutputConsent and Notice Framework

    Activities

    • Draft notices in plain language per purpose
    • Design the consent capture and withdrawal flow
    • Assess consent manager integration options
    • Plan notice delivery in the required languages
  4. 04

    Rights and Breach Processes

    We set up processes for data principal requests and for reporting breaches within the required timelines.

    OutputData Principal Rights Playbook and Breach Procedure

    Activities

    • Build the data principal request workflow
    • Define grievance redressal roles and timelines
    • Write the breach notification procedure
    • Run a breach response tabletop exercise
  5. 05

    Control Implementation

    We help you put in place the security safeguards and retention rules the DPDP Act expects.

    OutputImplemented Safeguards and Retention Schedule

    Activities

    • Implement encryption and access safeguards
    • Set retention and erasure schedules
    • Update processor contracts with DPDP Act clauses
    • Roll out privacy training to data-handling teams
  6. 06

    Readiness Review

    We run a final review so you can show a regulator, or a customer, that your programme holds together.

    OutputDPDP Act Readiness Report

    Activities

    • Test the consent and rights workflows end to end
    • Verify remediation of earlier gaps
    • Compile the accountability evidence pack
    • Brief leadership on residual risk

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the DPDP Act scope, running left to right in three stages. Stage one, what we run, 7 tools and techniques: OneTrust, Securiti, TrustArc, Microsoft Purview, BigID, Jira, Confluence. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: Digital Personal Data Protection Act 2023, DPDP Rules, ISO/IEC 27701:2019, ISO/IEC 27001:2022, NIST Privacy Framework.

What We Run

7 tools

  • OneTrust
  • Securiti
  • TrustArc
  • Microsoft Purview
  • BigID
  • Jira
  • Confluence

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • Digital Personal Data Protection Act 2023
  • DPDP Rules
  • ISO/IEC 27701:2019
  • ISO/IEC 27001:2022
  • NIST Privacy Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Data flow and inventory map
  • DPDP Act gap assessment report
  • Consent and notice framework
  • Data principal rights playbook
  • Breach response procedure

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Who does the DPDP Act apply to?

The Act applies to any organisation that processes the digital personal data of people in India, whether it operates from India or from abroad. If you sit outside India and offer goods or services to people in India, you are still in scope. In the Act's language you are a data fiduciary, the entity that decides why and how personal data is processed. Processors who handle data on your behalf are covered through the contract you hold with them, which means your vendor agreements become part of your compliance position. There is no revenue or headcount threshold to fall below, so a twenty person SaaS company and a listed bank are both in scope, and what differs is the depth of programme each needs. Purely personal or domestic processing sits outside the Act, as does data the data principal has themselves made publicly available.

What is a data principal under the DPDP Act?

A data principal is the individual the personal data belongs to, the term the Act uses where GDPR says data subject. The Act gives them the right to ask what data you hold and who you have shared it with, the right to correction and completion, the right to erasure, the right to nominate someone to exercise their rights if they die or become incapacitated, and the right to a grievance redressal route that actually answers them. Each of those is an operational commitment rather than a policy statement. You need a channel for the request to arrive on, a way to find that person's data across every system that holds it, and a defined turnaround you can evidence. Where a child's data is involved you also need verifiable parental consent. We build the request workflow and the audit trail that shows you honoured it.

What penalties does the DPDP Act carry?

The Schedule to the Act sets the penalties the Data Protection Board of India can impose, and they are assessed per contravention rather than as a single annual cap. Failure to take reasonable security safeguards to prevent a personal data breach carries up to 250 crore rupees. Failure to notify the Board and the affected data principals of a breach carries up to 200 crore rupees, as does a breach of the additional obligations that apply to children's data. Failure to meet the extra duties placed on a Significant Data Fiduciary carries up to 150 crore rupees, and any other contravention carries up to 50 crore rupees. The Board weighs the nature and gravity of the breach, whether it was repeated, and what you did to mitigate it, so a documented programme and a working breach process reduce your exposure even when something does go wrong.

How long does DPDP Act readiness take?

Our engagement runs six phases and most organisations complete them in thirteen to twenty three weeks. Data discovery and mapping takes two to three weeks, the gap assessment against the Act and its Rules another two to three, consent and notice design two to four, rights and breach processes two to three, control implementation four to eight, and the readiness review one to two. The range is wide because the two variables that move it are how many systems hold personal data and how much of your security control set already exists. A company with three products, a data warehouse and an offshore support desk spends far longer in discovery than one with a single application. We give you a firm timeline after the gap assessment rather than before it, and phases can overlap where your teams have capacity to run them in parallel.

Do we need to appoint a Data Protection Officer?

Only if you are notified as a Significant Data Fiduciary. The government can designate you on the volume and sensitivity of the data you process, the risk to data principals, and the potential impact on the sovereignty and integrity of India and on electoral democracy. If you are designated, you must appoint a Data Protection Officer based in India who reports to your board or governing body, appoint an independent data auditor, and run periodic Data Protection Impact Assessments. Every other data fiduciary still has to publish contact details for someone who can answer data principal questions, which in practice means a named person and a channel somebody monitors. Many organisations appoint the role voluntarily because enterprise customers ask for it during due diligence. We run it as a service through our vDPO offering when you would rather not hire for it.

Keep Moving Through Compliance

Service 5 of 13 in this practice area