Latest alerts
  1. Home
  2. Services
  3. Get compliant
  4. DPDP
// get compliant · compliance & grc

Digital Personal Data Protection Act, 2023 — Compliance Programme

Get ready for India's DPDP Act and the DPDP Rules, 2025: data mapping, consent and notices, security safeguards, breach response and data-principal rights — implemented, not just documented.

DPDP Act, 2023DPDP Rules, 2025ISO/IEC 27701CERT-In Directions 2022
// the problem

The DPDP Rules were notified in November 2025 with an 18-month runway for most obligations. Penalties go up to ₹250 crore per instance for failing to take reasonable security safeguards. Most organisations still do not know where all their personal data lives.

Helps you meet: DPDP Act, 2023
// scope

What we cover

Data discovery & mapping

Find personal data across apps, databases, spreadsheets, vendors and backups; build a record of processing.

Notice & consent

Plain-language notices, consent capture and withdrawal flows, and Consent Manager integration readiness.

Security safeguards

Encryption, access control, logging and monitoring mapped to the "reasonable security safeguards" in the Rules.

Breach response

Playbooks to inform affected Data Principals and the Data Protection Board, with the detailed report inside 72 hours.

Rights handling

Processes for access, correction, erasure, grievance redressal and nomination — with response tracking.

Processors & retention

Vendor contracts, retention schedules, deletion and 1-year log retention as required by the Rules.

// how it works

Five clear steps, no surprises

01

Discover

Map data, systems, vendors and gaps.

02

Plan

Risk-based roadmap with owners.

03

Implement

Policies, controls and evidence.

04

Verify

Internal audit and readiness check.

05

Certify

Stand with you through the audit.

// deliverables

What you get

  • DPDP gap report with prioritised roadmap
  • Data inventory / record of processing
  • Privacy notices and consent flows
  • Breach response playbook
  • Training for staff and leadership
// standards & frameworks
DPDP Act, 2023DPDP Rules, 2025ISO/IEC 27701CERT-In Directions 2022
// engagement models

Pick how you'd like to work with us

Gap assessment

Two to four weeks: where you stand and a prioritised roadmap.

Most popular

End-to-end programme

From gap assessment to audit-ready, with your team trained.

Virtual CISO / DPO support

Ongoing monthly support to keep evidence current.

Every engagement starts with a free scoping call and a fixed, written quote.

// faq

Common questions

When do we need to comply?
The Rules were notified in November 2025. Consent Manager provisions apply after 12 months, and most substantive obligations — notices, safeguards, breach reporting, rights — after 18 months. Starting now leaves comfortable time; starting late does not.
Does DPDP apply to B2B companies?
Yes. Any personal data of individuals — employees, customer contacts, vendors' staff — is covered when processed in digital form.
Is your free DPDP check really free?
Yes. The self-assessment runs in your browser and shows your score instantly. We only receive your details if you choose to request the detailed report.
// free tool

See where you stand in 5 minutes.

15 questions, instant score, prioritised actions. Runs in your browser.

Get a quoteCall
// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check