01

DPDPA Gap Assessment

A 4-to-6 week structured diagnostic that maps your current data practices against every applicable clause of the DPDPA. You receive a prioritised remediation roadmap with effort, cost and risk estimates for each gap — usable by your board and your auditors.

4–6 weeks Fixed-fee
  • Personal data inventory
  • Data flow mapping across systems
  • Clause-by-clause compliance scoring
  • Prioritised roadmap with cost estimates
  • Board-ready executive summary
02

Implementation & Remediation

We translate the gap assessment into working artefacts: privacy notices that hold up legally and read well, consent flows that work in your apps, retention schedules engineers can enforce, and a breach response playbook tested through tabletop exercises.

8–12 weeks T&M, capped
  • Privacy notices & consent text
  • Data retention schedules
  • Breach response playbooks
  • Data Principal rights workflows
  • Third-party processor agreements
03

DPO-as-a-Service

For organisations classified as Significant Data Fiduciaries, the DPDPA requires the appointment of a Data Protection Officer based in India and accountable to the board. Our retainer model gives you a qualified, dedicated DPO without the cost and complexity of an in-house hire.

Annual retainer Named officer
  • Named DPO accountable to your board
  • Monthly compliance reporting
  • Data Principal grievance handling
  • Regulator liaison & response
  • Quarterly board briefings
04

Training & Awareness

Compliance is a people problem before it's a paperwork problem. We deliver role-based training tailored to boards, frontline staff, engineering teams, and HR — with completion certificates that form part of your audit evidence.

2–4 weeks Hindi · English · Marathi
  • Board-level governance workshops
  • Frontline staff modules
  • Engineering & product deep-dives
  • HR & recruiting privacy training
  • LMS-ready content packs
05

Independent Data Audits

Annual independent audits performed against the DPDPA and its supporting rules. We produce a documented evidence pack that can withstand regulator scrutiny, customer due diligence, and board review — and we tell you what to fix before anyone else asks.

6–8 weeks Annual cadence
  • Full-scope DPDPA audit
  • Sample-based control testing
  • Evidence pack for regulators
  • Management action report
  • Year-on-year maturity tracking
06

Technology Implementation

Our engineering team implements the technical layer of DPDPA — consent management platforms, data-subject request portals, encryption-at-rest controls, and breach-monitoring dashboards — integrated with the systems you already run.

4–10 weeks Stack-agnostic
  • Consent Management Platform rollout
  • Data Subject Request portals
  • Data discovery & classification
  • Breach detection & logging
  • Cross-border transfer controls
Tangible outputs

What you walk away with.

Compliance work has a reputation for producing slide decks no one reads. Our deliverables are designed to be used — by operators, by auditors, and by the regulator if it ever comes to that.

/ DELIVERABLE 01

Compliance Maturity Score

A single-number, multi-axis assessment your board can track quarter over quarter.

/ DELIVERABLE 02

RoPA Register

A complete Record of Processing Activities — the foundational document under DPDPA.

/ DELIVERABLE 03

Policy Library

Privacy policy, internal SOP, retention schedule, breach playbook, vendor due diligence pack.

/ DELIVERABLE 04

Training Evidence Pack

Attendance logs, completion certificates and assessment scores — ready for any audit.

/ DELIVERABLE 05

Regulator Response Kit

Templated, fact-based responses to common Data Protection Board enquiries — ready to deploy.

/ DELIVERABLE 06

Quarterly Health Check

A standing review that flags drift, new regulatory updates, and emerging risks.

Not sure where to start?

Most clients begin with a
2-week scoping call.

Schedule a call