Digital Personal Data Protection Act, 2023 — Compliance Programme
Get ready for India's DPDP Act and the DPDP Rules, 2025: data mapping, consent and notices, security safeguards, breach response and data-principal rights — implemented, not just documented.
The DPDP Rules were notified in November 2025 with an 18-month runway for most obligations. Penalties go up to ₹250 crore per instance for failing to take reasonable security safeguards. Most organisations still do not know where all their personal data lives.
What we cover
Data discovery & mapping
Find personal data across apps, databases, spreadsheets, vendors and backups; build a record of processing.
Notice & consent
Plain-language notices, consent capture and withdrawal flows, and Consent Manager integration readiness.
Security safeguards
Encryption, access control, logging and monitoring mapped to the "reasonable security safeguards" in the Rules.
Breach response
Playbooks to inform affected Data Principals and the Data Protection Board, with the detailed report inside 72 hours.
Rights handling
Processes for access, correction, erasure, grievance redressal and nomination — with response tracking.
Processors & retention
Vendor contracts, retention schedules, deletion and 1-year log retention as required by the Rules.
Five clear steps, no surprises
Discover
Map data, systems, vendors and gaps.
Plan
Risk-based roadmap with owners.
Implement
Policies, controls and evidence.
Verify
Internal audit and readiness check.
Certify
Stand with you through the audit.
What you get
- DPDP gap report with prioritised roadmap
- Data inventory / record of processing
- Privacy notices and consent flows
- Breach response playbook
- Training for staff and leadership
Pick how you'd like to work with us
Gap assessment
Two to four weeks: where you stand and a prioritised roadmap.
End-to-end programme
From gap assessment to audit-ready, with your team trained.
Virtual CISO / DPO support
Ongoing monthly support to keep evidence current.
Every engagement starts with a free scoping call and a fixed, written quote.
Where we've done this

E-commerce Security
Securing high-volume global transactions and customer PII for a premium ethnic-wear brand.
Patient Data Protection
Security architecture and compliance auditing to protect electronic medical records and patient portals.
Common questions
When do we need to comply?
Does DPDP apply to B2B companies?
Is your free DPDP check really free?
See where you stand in 5 minutes.
15 questions, instant score, prioritised actions. Runs in your browser.
Find out how an attacker sees you — before they do.
Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.