Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Managed Services7 services in this practice area

Privacy Done Properly

vDPO Services

Privacy law now expects a named, competent person accountable for how you handle personal data. Our vDPO fills that role for you, running your privacy operations day to day and keeping you ready for the regulator.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

A vDPO is an experienced data protection officer who acts for your organisation on a flexible basis. We map the personal data you hold, run the rights and consent processes your customers expect, and stand ready to handle a breach or a regulator's questions. This suits organisations that need real accountability under the DPDP Act, GDPR or similar laws but do not have the volume to justify a full-time DPO. You get a competent point of contact and a privacy programme that holds up under scrutiny.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the vDPO engagement, 5 phases in order, each one selectable. Phase 1, Appointment and Scope. We formally take on the DPO role, agree our remit and reporting lines, and register the point of contact your customers and the regulator can reach. Activities: Formalise the DPO appointment and board reporting line; Publish the point of contact on your notices and website; Confirm your role as data fiduciary or processor per system; Agree the privacy operating model with legal and product. Hands over DPO Appointment Record. Phase 2, RoPA and Data Mapping. We map what personal data you hold, where it flows and why, and build your record of processing activities so nothing is hidden or unaccounted for. Activities: Draft the RoPA with each business unit; Trace personal data flows across systems and vendors; Record the lawful basis and retention period for each purpose; Flag cross-border transfers and processor contracts. Hands over Record of Processing Activities and Data Map. Phase 3, Rights and Consent Operations. We run the day-to-day work of handling data principal requests, managing consent and keeping your notices accurate and honest. Activities: Run data principal requests from intake to response; Verify identity before any data is disclosed; Maintain consent records and withdrawal handling; Keep privacy notices aligned with actual processing. Hands over Data Principal Request Register. Phase 4, Breach Handling. When a personal data breach happens, we assess it, guide containment and manage notification to the regulator and affected people within the required timelines. Activities: Assess the breach against the DPDP Act notification duties; Determine the categories and volume of data affected; Draft notifications to the Data Protection Board and individuals; Record remediation actions and lessons learned. Hands over Breach Assessment and Notification File. Phase 5, Regulator Liaison. We act as your contact with the Data Protection Board and other authorities, responding to queries and demonstrating your compliance calmly and clearly. Activities: Answer regulator queries with evidence from the RoPA; Keep the accountability file ready for inspection; Report privacy programme status to your board; Track changes to the DPDP Act rules and advise on impact. Hands over Regulator Correspondence File. Each phase begins from the artefact the phase before it produced.

Phase 01 Appointment and Scope

We formally take on the DPO role, agree our remit and reporting lines, and register the point of contact your customers and the regulator can reach.

What Happens In This Phase

  • Formalise the DPO appointment and board reporting line
  • Publish the point of contact on your notices and website
  • Confirm your role as data fiduciary or processor per system
  • Agree the privacy operating model with legal and product

The Handover

DPO Appointment Record

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Appointment and Scope

    We formally take on the DPO role, agree our remit and reporting lines, and register the point of contact your customers and the regulator can reach.

    OutputDPO Appointment Record

    Activities

    • Formalise the DPO appointment and board reporting line
    • Publish the point of contact on your notices and website
    • Confirm your role as data fiduciary or processor per system
    • Agree the privacy operating model with legal and product
  2. 02

    RoPA and Data Mapping

    We map what personal data you hold, where it flows and why, and build your record of processing activities so nothing is hidden or unaccounted for.

    OutputRecord of Processing Activities and Data Map

    Activities

    • Draft the RoPA with each business unit
    • Trace personal data flows across systems and vendors
    • Record the lawful basis and retention period for each purpose
    • Flag cross-border transfers and processor contracts
  3. 03

    Rights and Consent Operations

    We run the day-to-day work of handling data principal requests, managing consent and keeping your notices accurate and honest.

    OutputData Principal Request Register

    Activities

    • Run data principal requests from intake to response
    • Verify identity before any data is disclosed
    • Maintain consent records and withdrawal handling
    • Keep privacy notices aligned with actual processing
  4. 04

    Breach Handling

    When a personal data breach happens, we assess it, guide containment and manage notification to the regulator and affected people within the required timelines.

    OutputBreach Assessment and Notification File

    Activities

    • Assess the breach against the DPDP Act notification duties
    • Determine the categories and volume of data affected
    • Draft notifications to the Data Protection Board and individuals
    • Record remediation actions and lessons learned
  5. 05

    Regulator Liaison

    We act as your contact with the Data Protection Board and other authorities, responding to queries and demonstrating your compliance calmly and clearly.

    OutputRegulator Correspondence File

    Activities

    • Answer regulator queries with evidence from the RoPA
    • Keep the accountability file ready for inspection
    • Report privacy programme status to your board
    • Track changes to the DPDP Act rules and advise on impact

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Built by SecureRoot

DPDPA Compass

Our own privacy platform. Consent, notices, data principal requests and records of processing under the DPDP Act.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the vDPO scope, running left to right in three stages. Stage one, what we run, 6 tools and techniques: Privacy management platforms, Data-mapping tools, Consent management platforms, Data discovery tools, DSAR workflow tooling, Records of processing registers. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 5 published standards: the DPDP Act, GDPR, ISO/IEC 27701:2019, ISO/IEC 27001:2022, NIST Privacy Framework.

What We Run

6 tools

  • Privacy management platforms
  • Data-mapping tools
  • Consent management platforms
  • Data discovery tools
  • DSAR workflow tooling
  • Records of processing registers

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

5 standards

  • DPDPIndiaAct
  • GDPR
  • ISO/IEC 27701:2019
  • ISO/IEC 27001:2022
  • NIST Privacy Framework
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Formal DPO appointment and registered point of contact
  • Record of processing activities and data map
  • Rights and consent handling process
  • Breach response plan and notification support
  • Privacy programme report on an agreed cadence

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Does the DPDP Act require us to appoint a DPO?

Significant data fiduciaries must appoint a data protection officer based in India and accountable to their board. A vDPO lets you meet that duty without a full-time hire, and helps other organisations that simply want strong accountability.

What happens if we have a data breach?

We assess the breach, guide your containment and manage notification to the Data Protection Board and affected people within the required timelines, so you respond correctly under pressure.

Can a vDPO handle data principal requests for us?

Yes. We run the process end to end, from verifying identity to responding within the legal deadline, and keep a defensible record of every request.

Keep Moving Through Managed Services

Service 4 of 7 in this practice area