DPDPA Compliance & Data Privacy
Prepare for India's DPDPA before Data Fiduciary obligations become enforceable in May 2027, with data mapping, consent design, and tested security safeguards.
Overview
DPDPA Compliance and Data Privacy advisory prepares organizations to meet India's Digital Personal Data Protection Act ahead of enforcement, translating a broad statutory framework into a concrete technical and organizational programme. The Act was gazette-notified in August 2023, and the Digital Personal Data Protection Rules, 2025 were notified in November 2025 and took effect that month on a phased timeline: the first phase established and operationalised the Data Protection Board of India, the second phase — from November 2026 — brings Consent Manager registration and related obligations into force, and the third phase — from May 2027 — brings the core Data Fiduciary obligations into force, comprising 26 sections of the Act and 15 of the Rules. That final date is the one that carries real commercial weight: it is when the penalty exposure, running as high as ₹250 crore for a single provision and cumulatively higher across multiple failures, actually becomes enforceable against a Data Fiduciary.
The obligations apply to any organization processing digital personal data of individuals in India — a Data Fiduciary determining the purpose and means of processing, or a Data Processor acting on its instructions — and extend extraterritorially to entities outside India that offer goods or services to Data Principals located within it. We work with clients to build the practical artefacts a compliance programme actually runs on: a personal data inventory and Records of Processing Activities (RoPA), data flow diagrams, itemized notices and consent mechanisms that meet the Act's free, specific, informed and unambiguous standard, a rights-request workflow for access, correction and erasure, a retention and deletion schedule, and a breach response runbook built around the 72-hour reporting obligation to the Data Protection Board of India. Where a client qualifies as a Significant Data Fiduciary, we help it prepare for the additional Data Protection Impact Assessments and audits that status requires.
Personal Data Lifecycle
How personal data moves through a compliant organization
Collect
Personal data is gathered under a notice and a lawful basis — consent or a legitimate use.
Process
Data is used strictly for the purpose stated in the notice, under documented security controls.
Store
Data is held under access controls and encryption appropriate to its sensitivity.
Transfer / Disclose
Data moves to processors or across borders under contract and, where restricted, regulatory limits.
Retain / Dispose
Data is kept only per the retention schedule, then deleted or anonymized.
- 101
Collect
Personal data is gathered under a notice and a lawful basis — consent or a legitimate use.
- 202
Process
Data is used strictly for the purpose stated in the notice, under documented security controls.
- 303
Store
Data is held under access controls and encryption appropriate to its sensitivity.
- 404
Transfer / Disclose
Data moves to processors or across borders under contract and, where restricted, regulatory limits.
- 505
Retain / Dispose
Data is kept only per the retention schedule, then deleted or anonymized.
Service Taxonomy
What does a DPDPA compliance engagement cover?
DPDPA Readiness & Gap Assessment
A structured assessment of current data processing activities, notices, and consent mechanisms against the Act's requirements, producing a prioritized gap list and remediation roadmap ahead of the May 2027 enforcement date.
Compliance Programme Implementation
Hands-on build-out of the artefacts a DPDPA programme runs on — the RoPA, consent flows, DPIAs, retention schedules, and breach response runbook — implemented alongside the client's product and engineering teams.
Ongoing Data Protection Advisory
Continuing advisory support for new processing activities, vendor and processor contract review, and preparation for the audits and assessments a Significant Data Fiduciary must undergo as the programme matures.
Why Us
Privacy Engineering From a Security Firm — Practiced on Our Own Site
Most DPDPA advisory is delivered by legal and policy consultancies producing documentation with no technical verification behind it. We are a security firm first, so the Act's 'reasonable security safeguards' obligation gets an actual technical test — configuration review, access control validation, and encryption checks — rather than a policy binder asserting that safeguards exist. We are not an Independent Data Auditor and we do not register as a Consent Manager; those are specific statutory roles under the Act, and where a client needs either we help it prepare for and work with the body that holds it. What we can offer is proof we apply this discipline to ourselves: our own /privacy and /terms name a Grievance Officer, state a defined enquiry retention period, and document an escalation path to the Data Protection Board — the same artefacts we build for clients, running on our own site, verifiable by anyone.
FAQ
Frequently Asked Questions
Ready to secure
your future?
Don't wait for a breach to happen. Get in touch with our cybersecurity experts and fortify your digital infrastructure today.