Consent, rights, breach, vendors and audit evidence in one place — with the proof assembling itself as you work.
No login. No card. Five minutes to your exposure in rupees.
Indicative output — based on your inputs.
Indicative only. Actual penalties are at the Board’s discretion.
The same question, asked three ways, by people who have just realised the Act applies to them.
You hold patient records, your receptionist collects them on paper, and you have never called anyone a Data Fiduciary.
An enterprise customer attached a DPDP questionnaire to your renewal and you have four days to answer it.
You hold candidate CVs, your clients’ employee payroll, and your own staff files — and they are not the same problem.
Most organisations have the left-hand column. Fewer have the right.
| You already have | What usually isn’t there yet |
|---|---|
| A consent tick-box in your HIMS, CRM or ERP | An itemised Rule 3 notice, in the languages the Act requires, as easy to withdraw as it was to give |
| A named DPO and a grievance email address | A queue with clocks on it, so nothing quietly runs past its deadline |
| A legal team that knows the Act cold | A portal your customers can actually use — no account, no fee |
| Customer data across fourteen systems | A way to find every one of them holding a single person’s data, so erasure is real and not asserted |
| Records. Somewhere. | Proof a regulator can verify independently, without trusting you |
Your team isn’t the gap. The system is.
| Team | Stays theirs | Comes off their desk |
|---|---|---|
| DPO & compliance | The decisions, the accountability, the conversation with the Board | Chasing deadlines across five modules, building the inventory by hand, remembering which clock is running |
| Legal & counsel | The legal positions, the risk calls, the sign-off | Drafting every notice from scratch, versioning them, translating them, re-checking each against the clause |
| IT & security | The architecture and the security posture | Building consent capture, building a rights portal, pulling data together for every request — and being asked to hold data they never wanted |
| Consultants & CAs | The advice, and the client relationship | Rebuilding the same assessment for every client, chasing documents at audit, keeping a hundred spreadsheets current |
| Founder & CFO | How much risk the business chooses to carry | Not knowing what that risk actually is |
Nobody here gets replaced. They stop doing this by hand.
Across industries and purposes — hospital admission, student enrolment, KYC onboarding, delivery tracking, employee records, marketing. Each one written against the section it has to satisfy, and reviewed by practising counsel before it ever reaches you.
Your legal team edits rather than drafts. That is usually the difference between a notice programme taking a quarter and taking a fortnight.
DPDP compliance software that diagnoses what is missing, fixes it in the order that matters, and produces the proof.
Answer questions about how your organisation actually works. Get a score, a ranked gap list and your penalty exposure in rupees. Five minutes, no login.
Close gaps in the order of what they cost you. Consent, rights, breach, vendors, data mapping — each guided, each carrying the clause it satisfies.
Every action writes itself to the record as it happens. The audit pack is generated, not assembled the week before.
Declare a system once and every module reads it. Add a module later and there is nothing to migrate and nothing to re-enter.
A script tag for consent, a signed link for the rights portal, an API for everything else. No agents on your servers, no database connections.
We record which systems exist, what categories they hold and what was consented to. Your customers’ records never leave the systems they are already in.
Data at rest, backups included, stays in-country — which is the answer your procurement team will need in writing.
Start with one. Add another whenever you like — one data model underneath, so there is nothing to migrate and nothing to re-enter.
Automated gap assessment with penalty exposure in rupees and a phased remediation plan.
Rule 3 notices in the Eighth Schedule languages, a lightweight widget, and an append-only consent log.
Access, correction, erasure and nomination — identity-verified and SLA-tracked end to end.
Your record of processing, pre-filled rather than blank. Metadata only — never the data itself.
Declare, scope and notify against the Rule 7 clock — the Board and the people affected.
Processor register, DPA status and risk scoring — sharing blocks when a DPA lapses.
Generates a Rule 3 notice from your actual processing, in plain language. How the drafter works
Reads your existing policies and flags where they fall short of the Act. What it finds
Assembles the audit pack and writes the plain-English summary that goes on top. What it writes
Answers “are we allowed to do this?” with the clause it relied on. What it answers
Every consent, withdrawal and breach action is written to an append-only log the database itself will not let anyone edit. Each evidence pack carries a SHA-256 manifest that a regulator, an auditor or a customer can re-verify independently — without an account, and without taking our word for it.
Run it with your own team or bring in our techno-legal consultants — both work in the same system. DPDP compliance solutions you end up owning, not renting.
A consultant-grade picture of your exposure, built on the assessment engine rather than on three weeks of interviews.
A named DPO and a team who work your queues day to day — or who sit alongside yours and take the load off it.
The evidence, the drills and the paperwork that turn a Board question or a customer audit into a short conversation.
How an engagement starts: a discovery call, a scoped proposal, a named lead, and delivery on the platform. When the engagement ends, you keep the system it ran on.
Book a callYours to keep, whether or not you buy anything.
Where you stand across every DPDP obligation, and what the band actually means.
Every gap, ranked — each with the section it comes from and the penalty attached to it.
A phased plan: 0–30 days, 30–90 days, 90+ days. With owners, so it can actually be assigned.
Three things move the number, and you can work out where you sit on all three before speaking to anyone.
A single-location clinic and a lender with two million customers owe the same obligations and carry very different volumes of them.
Systems, entities, and the processors acting on your behalf. Ten vendors is a different exercise from a hundred, and it is the number most businesses underestimate.
Run it with your own team and the platform is most of the cost. Hand us the function and the services are. Most people land somewhere in between.
We would rather scope it than publish a table you have to reverse-engineer. Start with the free Scorecard — five minutes, no account, and it tells you the size of your own problem before anybody quotes you for it.
The machinery they don’t have. A portal your customers can use without an account, a queue that tracks every deadline, a map of which systems hold one person’s data so erasure is real, and evidence anyone can verify. Your team keeps the judgement — this removes the manual work underneath it.
Yes. We have empanelled lawyers, Data Protection Officers and security specialists who can run your programme or work alongside your team — as a named DPO, on a gap assessment, or drafting notices and processor agreements. They work in the same platform, and you keep it when the engagement ends.
It captures a tick. The Act asks for more: an itemised notice describing each purpose, in plain language, available in the required languages, with withdrawal as easy as giving — and a record you can produce years later showing exactly what was agreed, when, and to what. Most systems capture the tick and none of the rest.
The Act’s Schedule sets penalties by the obligation breached. The largest single item is ₹250 crore, for failing to take reasonable security safeguards. Breach-notification and children’s-data failures carry up to ₹200 crore, Significant Data Fiduciary duties up to ₹150 crore, and most other breaches up to ₹50 crore.
Under Rule 7 of the DPDP Rules 2025 you must inform the Data Protection Board without delay on becoming aware of a breach, and follow it with detailed particulars within 72 hours. Affected Data Principals must also be informed without delay. The 72 hours is the deadline for the full account, not for the first intimation.
Some of it, and only where the obligation cannot be met without it — which is a more useful answer than a flat no. The Data Registry, the map of your estate, holds metadata and nothing else: which systems exist, what categories they hold, who owns them. It never holds a record about a person. Consent and rights are necessarily different, because §6(10) makes you able to demonstrate a particular person consented, and §11 makes you answer that person — neither is possible without a record of them. So the consent log and the rights queue do hold one. We keep it minimal, identifiers are stored as hashes, and where a contact address is needed to reply to somebody it is encrypted at rest. Everything sits in India, and your operational databases stay where they are — we never copy them.
On infrastructure in India. Data at rest, backups included, stays in-country.
There is no revenue or headcount threshold. The Act applies to anyone processing digital personal data in India, and to anyone outside India processing it to offer goods or services here. A ten-person clinic and a listed hospital chain owe the same core duties — notice, consent, security, breach reporting, and honouring rights requests. What changes with size is the volume of work, which is the part DPDP compliance software takes off you.
The shape is familiar; the detail is not. DPDP compliance India turns on things the GDPR does not have — legitimate uses under §7 instead of six lawful bases, verifiable parental consent for everyone under 18, a breach report to the Board inside 72 hours with no severity threshold below which you may stay quiet, and a blacklist for transfers abroad rather than an adequacy list. There is also no data portability right here. Tooling built for the GDPR maps onto this badly, which is why ours is built against the Act’s own sections.
Yes. Most organisations start with the free Scorecard, then take on Consent or DSR first depending on where their exposure is largest. Modules share one data model, so adding another later needs no migration. Buying a DPDP solution one obligation at a time is the sensible way round — it is also why nothing here is sold as an all-or-nothing suite.
Thirty minutes with a specialist about your own obligations. Not a product pitch.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Five minutes, free, and you keep the report either way.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.