India’s DPDP Compliance Support System

Whoever runs your DPDP programme runs it here.

Consent, rights, breach, vendors and audit evidence in one place — with the proof assembling itself as you work.

No login. No card. Five minutes to your exposure in rupees.

Indicative output — based on your inputs.

41 / 100
High risk
Estimated DPDP penalty exposure
268Cr to 537Cr

Indicative only. Actual penalties are at the Board’s discretion.

Sound familiar?

How most people find out

The same question, asked three ways, by people who have just realised the Act applies to them.

Hospital or clinic

You hold patient records, your receptionist collects them on paper, and you have never called anyone a Data Fiduciary.

SaaS or platform

An enterprise customer attached a DPDP questionnaire to your renewal and you have four days to answer it.

HR, staffing or payroll

You hold candidate CVs, your clients’ employee payroll, and your own staff files — and they are not the same problem.

5,000+
consent templates, legally vetted
353
questions in the assessment
10
modules on the platform
0
personal records we hold
Every
section of the Act mapped
The position today

What’s coming, and what it costs

₹250 crore
The largest penalty in the Act, for failing to protect personal data you already hold. Breach reporting, children’s data and vendor failures carry their own penalties on top of it.
DPDP Act 2023, Schedule
72 hours
From the moment you know about a breach, the Board expects the full picture. The first intimation is due immediately; the detail follows within 72 hours.
DPDP Rules 2025, Rule 7
Until the phase-in period ends. Organisations that start now set their own pace. Those that wait will be working to someone else’s.
Rules notified 14 November 2025
No threshold
The Act applies whether you are twenty people or twenty thousand. No revenue floor, no headcount minimum, no exemption for being small.
DPDP Act 2023
The honest bit

“We’ve got this covered.”

Most organisations have the left-hand column. Fewer have the right.

You already haveWhat usually isn’t there yet
A consent tick-box in your HIMS, CRM or ERPAn itemised Rule 3 notice, in the languages the Act requires, as easy to withdraw as it was to give
A named DPO and a grievance email addressA queue with clocks on it, so nothing quietly runs past its deadline
A legal team that knows the Act coldA portal your customers can actually use — no account, no fee
Customer data across fourteen systemsA way to find every one of them holding a single person’s data, so erasure is real and not asserted
Records. Somewhere.Proof a regulator can verify independently, without trusting you

Your team isn’t the gap. The system is.

Who it makes stronger

We take the manual work off your team.

TeamStays theirsComes off their desk
DPO & complianceThe decisions, the accountability, the conversation with the BoardChasing deadlines across five modules, building the inventory by hand, remembering which clock is running
Legal & counselThe legal positions, the risk calls, the sign-offDrafting every notice from scratch, versioning them, translating them, re-checking each against the clause
IT & securityThe architecture and the security postureBuilding consent capture, building a rights portal, pulling data together for every request — and being asked to hold data they never wanted
Consultants & CAsThe advice, and the client relationshipRebuilding the same assessment for every client, chasing documents at audit, keeping a hundred spreadsheets current
Founder & CFOHow much risk the business chooses to carryNot knowing what that risk actually is

Nobody here gets replaced. They stop doing this by hand.

The platform

One platform, end to end

DPDP compliance software that diagnoses what is missing, fixes it in the order that matters, and produces the proof.

01 — FREE

Diagnose

Answer questions about how your organisation actually works. Get a score, a ranked gap list and your penalty exposure in rupees. Five minutes, no login.

02 — GUIDED

Fix

Close gaps in the order of what they cost you. Consent, rights, breach, vendors, data mapping — each guided, each carrying the clause it satisfies.

03 — EVIDENCE

Prove

Every action writes itself to the record as it happens. The audit pack is generated, not assembled the week before.

One data model

Declare a system once and every module reads it. Add a module later and there is nothing to migrate and nothing to re-enter.

Installs in an afternoon

A script tag for consent, a signed link for the rights portal, an API for everything else. No agents on your servers, no database connections.

Metadata only

We record which systems exist, what categories they hold and what was consented to. Your customers’ records never leave the systems they are already in.

Hosted in India

Data at rest, backups included, stays in-country — which is the answer your procurement team will need in writing.

The platform

Ten modules. One platform.

Start with one. Add another whenever you like — one data model underneath, so there is nothing to migrate and nothing to re-enter.

Compliance Suite

Six modules — live

DPDP Scorecard

Live

Automated gap assessment with penalty exposure in rupees and a phased remediation plan.

Consent Management

Live

Rule 3 notices in the Eighth Schedule languages, a lightweight widget, and an append-only consent log.

DSR Automation

Live

Access, correction, erasure and nomination — identity-verified and SLA-tracked end to end.

Data Registry

Live

Your record of processing, pre-filled rather than blank. Metadata only — never the data itself.

Breach Management

Live

Declare, scope and notify against the Rule 7 clock — the Board and the people affected.

Vendor Governance

Live

Processor register, DPA status and risk scoring — sharing blocks when a DPA lapses.

AI Suite

Four modules — coming soon

AI Consent Drafter

Coming soon

Generates a Rule 3 notice from your actual processing, in plain language. How the drafter works

Policy Gap Detector

Coming soon

Reads your existing policies and flags where they fall short of the Act. What it finds

Evidence Packager

Coming soon

Assembles the audit pack and writes the plain-English summary that goes on top. What it writes

Compliance Copilot

Coming soon

Answers “are we allowed to do this?” with the clause it relied on. What it answers

Evidence, not assertions

Anyone can verify your compliance. Including you.

Every consent, withdrawal and breach action is written to an append-only log the database itself will not let anyone edit. Each evidence pack carries a SHA-256 manifest that a regulator, an auditor or a customer can re-verify independently — without an account, and without taking our word for it.

packconsent-evidence-2026-Q2.zip
generated2026-07-14 09:12 IST
records184,205 consent events
manifesta3f9c1e07b4d2a68f5c19e3b7d0a4f82c6b5e918d7a2c4f0e6b3d9a1c8f5e207
Verified — unchanged since generation
Services

Your team, or ours

Run it with your own team or bring in our techno-legal consultants — both work in the same system. DPDP compliance solutions you end up owning, not renting.

Assess

Find out where you stand

A consultant-grade picture of your exposure, built on the assessment engine rather than on three weeks of interviews.

  • Gap Assessment
  • Data Discovery & RoPA build
  • DPIA & SDF readiness
Operate

Have it run for you

A named DPO and a team who work your queues day to day — or who sit alongside yours and take the load off it.

  • DPO as a Service
  • Privacy Operations, managed
  • Notices, policies & consent drafting
  • DPA & contract review
Assure

Be ready when you’re asked

The evidence, the drills and the paperwork that turn a Board question or a customer audit into a short conversation.

  • Breach readiness & response
  • Audit readiness & support
  • Training & certification

How an engagement starts: a discovery call, a scoped proposal, a named lead, and delivery on the platform. When the engagement ends, you keep the system it ran on.

Book a call
The free DPDP Scorecard

A consultant-grade gap assessment, free.

Yours to keep, whether or not you buy anything.

01

Your score

Where you stand across every DPDP obligation, and what the band actually means.

02

What’s missing

Every gap, ranked — each with the section it comes from and the penalty attached to it.

03

What to do about it

A phased plan: 0–30 days, 30–90 days, 90+ days. With owners, so it can actually be assigned.

Pricing

What it costs depends on what you hold

Three things move the number, and you can work out where you sit on all three before speaking to anyone.

01

How many people

A single-location clinic and a lender with two million customers owe the same obligations and carry very different volumes of them.

02

How much estate

Systems, entities, and the processors acting on your behalf. Ten vendors is a different exercise from a hundred, and it is the number most businesses underestimate.

03

How much you want carried

Run it with your own team and the platform is most of the cost. Hand us the function and the services are. Most people land somewhere in between.

We would rather scope it than publish a table you have to reverse-engineer. Start with the free Scorecard — five minutes, no account, and it tells you the size of your own problem before anybody quotes you for it.

Questions

Frequently asked

We already have a DPO and a legal team. What does this add?

The machinery they don’t have. A portal your customers can use without an account, a queue that tracks every deadline, a map of which systems hold one person’s data so erasure is real, and evidence anyone can verify. Your team keeps the judgement — this removes the manual work underneath it.

Can you provide the people as well as the platform?

Yes. We have empanelled lawyers, Data Protection Officers and security specialists who can run your programme or work alongside your team — as a named DPO, on a gap assessment, or drafting notices and processor agreements. They work in the same platform, and you keep it when the engagement ends.

Our CRM already captures consent. Isn’t that enough?

It captures a tick. The Act asks for more: an itemised notice describing each purpose, in plain language, available in the required languages, with withdrawal as easy as giving — and a record you can produce years later showing exactly what was agreed, when, and to what. Most systems capture the tick and none of the rest.

What is the maximum penalty under the DPDP Act?

The Act’s Schedule sets penalties by the obligation breached. The largest single item is ₹250 crore, for failing to take reasonable security safeguards. Breach-notification and children’s-data failures carry up to ₹200 crore, Significant Data Fiduciary duties up to ₹150 crore, and most other breaches up to ₹50 crore.

How quickly must we report a personal data breach?

Under Rule 7 of the DPDP Rules 2025 you must inform the Data Protection Board without delay on becoming aware of a breach, and follow it with detailed particulars within 72 hours. Affected Data Principals must also be informed without delay. The 72 hours is the deadline for the full account, not for the first intimation.

Do you store our customers’ personal data?

Some of it, and only where the obligation cannot be met without it — which is a more useful answer than a flat no. The Data Registry, the map of your estate, holds metadata and nothing else: which systems exist, what categories they hold, who owns them. It never holds a record about a person. Consent and rights are necessarily different, because §6(10) makes you able to demonstrate a particular person consented, and §11 makes you answer that person — neither is possible without a record of them. So the consent log and the rights queue do hold one. We keep it minimal, identifiers are stored as hashes, and where a contact address is needed to reply to somebody it is encrypted at rest. Everything sits in India, and your operational databases stay where they are — we never copy them.

Where is our data hosted?

On infrastructure in India. Data at rest, backups included, stays in-country.

Is DPDP Act compliance mandatory for a company our size?

There is no revenue or headcount threshold. The Act applies to anyone processing digital personal data in India, and to anyone outside India processing it to offer goods or services here. A ten-person clinic and a listed hospital chain owe the same core duties — notice, consent, security, breach reporting, and honouring rights requests. What changes with size is the volume of work, which is the part DPDP compliance software takes off you.

Is DPDP compliance in India different from GDPR?

The shape is familiar; the detail is not. DPDP compliance India turns on things the GDPR does not have — legitimate uses under §7 instead of six lawful bases, verifiable parental consent for everyone under 18, a breach report to the Board inside 72 hours with no severity threshold below which you may stay quiet, and a blacklist for transfers abroad rather than an adequacy list. There is also no data portability right here. Tooling built for the GDPR maps onto this badly, which is why ours is built against the Act’s own sections.

Can we start with just one module?

Yes. Most organisations start with the free Scorecard, then take on Consent or DSR first depending on where their exposure is largest. Modules share one data model, so adding another later needs no migration. Buying a DPDP solution one obligation at a time is the sensible way round — it is also why nothing here is sold as an all-or-nothing suite.

Get a free DPDP consultation

Thirty minutes with a specialist about your own obligations. Not a product pitch.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Find out where you stand.

Five minutes, free, and you keep the report either way.