The platform

Ten modules. One record of the truth.

A DPDP compliance platform covering every penalised obligation end to end, with every module reading the same map of your systems.

Check your DPDP score — free Book a demo Five minutes, no login, no card.
ISO 27001 certified Hosted in India — data at rest and backups Registry holds metadata — structure, not records
Sound familiar?

How many places is one person in?

The number is always higher than the first answer, and every obligation in the Act depends on it.

Hospital or clinic

A patient appears in the HIS, in billing, in pathology, in the pharmacy log, and on a paper case sheet at the counter.

SaaS or platform

A user appears in your production database, your CRM, your support desk, your analytics tool, and last week’s CSV export.

HR, staffing or payroll

A candidate appears in the ATS, in the background-check vendor, in payroll if hired, and in a recruiter’s local spreadsheet.

Coverage

Every obligation, and what meets it

The provisions that carry a penalty, each mapped to the module that meets it. The test for any DPDP automation platform: does every one have something behind it?

§8(5)₹250 Cr

Keep the personal data you hold secure, with safeguards that are reasonable for what it is.

Data Registry
§8(6) · Rule 7₹200 Cr

Tell the Board without delay when a breach happens, and give the full particulars within 72 hours.

Breach Management
§9₹200 Cr

Get verifiable consent from a parent before processing any child’s data.

Consent Management
§10 · Rule 13₹150 Cr

If you are named a Significant Data Fiduciary: impact assessments, annual audit, algorithmic diligence.

Data Registry
§6₹50 Cr

Take consent that is free, specific and informed — and as easy to withdraw as it was to give.

Consent Management
§5 · Rule 3₹50 Cr

Give an itemised notice, in plain language, in the languages the Act requires.

Consent Management
§11–14 · Rule 14₹50 Cr

Let people see, correct, erase and nominate — and answer their grievances within the period.

DSR Automation
§8(2)₹50 Cr

Stay accountable for every processor acting on your behalf, under a written contract.

Vendor Governance

Penalties are the maximums in the Act’s Schedule and are assessed per contravention.

How it works

Diagnose. Fix. Prove.

The same three movements, whichever module you are in.

01 — FREE

Diagnose

Find out what is missing, ranked by what it costs you rather than by what is easiest to fix.

02 — GUIDED

Fix

Close each gap with the clause it satisfies attached, so the work and the reason stay together.

03 — EVIDENCE

Prove

Every action writes itself to the record as it happens. The pack is generated, not assembled.

Why one platform

Declare a system once. Everything else reads it.

Point tools each keep their own copy of your estate, so one system gets described five times and drifts four ways. Here there is one record.

You declare, once
Hospital Information System Database · hosted in India · owner: IT Director
Patient identityHealth recordsBilling
Everything below is calculated from it
  • Retention & erasure knows what lives there and for how long §8(7)
  • A rights request knows to look there for that person §11–14
  • A breach knows who was affected, in minutes §8(6)
  • Vendor scope knows which processors touch it §8(2)
  • Cross-border checks know it sits in India §16
  • Your RoPA writes itself as you go §8(5)
The part everyone dreads

Confirming a map, not drawing one

Building a record of processing from a blank spreadsheet is what turns DPDP into a six-month project. You start from something already filled in.

01

300+ systems recognised

Pick your hospital system, your CRM, your HRMS from a catalogue that already knows what they typically hold and how sensitive it is. Indian and global, by sector.

02

A starter pack for your sector

A hospital starts with the categories, activities and retention norms a hospital has — then edits what is different, rather than beginning at nothing.

03

Metadata, never records

We hold the shape of your estate — which systems, which categories, which purposes. No agents on your servers, no database credentials, no copies of anyone’s data.

End to end

Every module, start to finish

Not a list of features — the whole obligation, from the first moment it applies to the evidence you hand over at the end.

Live

Consent Management

§5§6§9Rule 3
  1. Draft the notice
  2. Publish & embed
  3. Capture consent
  4. Handle withdrawal
  5. Prove it later

Start from a vetted template rather than a blank page, publish it behind a compliance gate that will not let a non-compliant notice go live, and collect consent through a widget, a QR code, a call centre or a CSV import — all writing to the same append-only log. Withdrawal is one tap and lands in a queue with the clock already running. How consent management works

app.ruleexpert.in/consent/notices
The consent notices screen, listing published notices with their versions and status.
app.ruleexpert.in/consent/withdrawals
The withdrawal queue, each request showing how long it has been open against its service level.
Live

DSR Automation

§11§12§13§14Rule 14
  1. Request arrives
  2. Identity verified
  3. Find the data
  4. Act on it
  5. Close with evidence

Your customers file from a branded portal with no account and no fee. Identity is verified before anything is disclosed. The request then fans out across every system your registry says holds that person’s data — which is what turns erasure from a promise into something you can show. Clocks run from the moment it lands. How rights requests are handled

app.ruleexpert.in/dsr
The rights request queue, each request showing its type and the days remaining.
Live

Breach Management

§8(6)Rule 7
  1. Declare
  2. Scope who is affected
  3. Tell the Board
  4. Tell the people
  5. File the pack

The hard part of a breach is not the form, it is knowing who was in it. Because the registry already knows what each system holds, the affected cohort is derived rather than guessed. Both Rule 7 obligations are tracked separately — the immediate intimation and the full particulars at 72 hours — so neither is missed while attention is on the other. How a breach is scoped and filed

app.ruleexpert.in/breach
The breach management screen showing a confirmed incident with the number of people affected.
Live

Vendor Governance

§8(2)
  1. Register the processor
  2. Record the DPA
  3. Check the scope
  4. Watch the expiry
  5. Block on lapse

You stay accountable for every processor acting on your behalf, so the register tracks the agreement as well as the relationship. When a DPA expires or a vendor is found handling more than it was contracted for, sharing to that vendor is flagged and blocked rather than quietly continuing. How processors are governed

app.ruleexpert.in/consent/vendors
The vendor register showing each processor, the status of its data-processing agreement and whether sharing is blocked.
Live

Data Registry

§8(5)§8(7)§10§16
  1. Declare systems
  2. Confirm categories
  3. Map activities
  4. Set retention
  5. Flag residency

This is the map everything else reads. You are confirming rather than authoring: pick your systems from a catalogue that already knows what they typically hold, adjust what is different about yours, and the record of processing assembles itself. Metadata only — the records themselves never move. How the registry is built

app.ruleexpert.in/registry/catalog
The data catalogue, listing categories of personal data and how well each is covered.
app.ruleexpert.in/registry/activities
Processing activities, each showing the systems involved and the legal basis relied on.
Live

Retention & erasure

§8(7)Rule 8
  1. Set the schedule
  2. Watch what ages out
  3. Give notice
  4. Erase
  5. Keep the log

Data that has done its job has to go, but not everything can be erased on request — a live grievance or a statutory hold outranks it. Legal holds are honoured automatically, the pre-erasure notice goes out before anything is destroyed, and the audit trail of what was erased survives the erasure itself.

app.ruleexpert.in/consent/retention
The retention and erasure screen, showing what is retained, what is due notice and what is ready to erase.
Data handling

What we hold, and what we never do

The architecture is the point. We can govern your data precisely because we do not keep a copy of it.

What we store

  • Which systems exist, who owns them, where they are hosted
  • Which categories of personal data each one holds
  • What was consented to, when, through which channel
  • A hashed identifier so a rights request can be matched
  • The audit trail of every action taken in the platform

What we never store

  • Your customers’ names, numbers, addresses or records
  • Patient files, transactions, learner records — none of it
  • Aadhaar numbers, in any form
  • Database credentials or connection strings
  • Anything an agent on your servers would collect. There is no agent
ISO 27001 certifiedIndependently assessed information-security management.
Hosted in IndiaData at rest and backups stay in-country.
Append-only auditThe database refuses edits and deletions on the log — not policy, enforcement.
Re-authentication to exportEvidence downloads need the password again, and expire.

Not sure which obligations apply to you?

Answer a few questions about how your organisation works and get a ranked gap list with your exposure in rupees — free, and yours to keep.

Who works in it

Four kinds of people, four kinds of access

Your DPO

Sees everything, owns the queues, signs off the evidence. The account that answers to the Board.

Your team

Department owners confirm what their own systems hold and answer the questions that belong to them — nothing more.

Your consultant

An external adviser — ours or your own — works inside your tenant, with what they do recorded as theirs.

Your auditor

Receives an evidence pack they can verify independently, without an account and without asking you for anything.

Getting started

Live in an afternoon. Useful in a week.

This is not a six-month implementation, and you do not need every module on day one.

DAY ONE

Know where you stand

Run the free Scorecard, declare your first systems from the catalogue, and publish a notice from a vetted template. No procurement needed to get this far.

WEEK ONE

Turn on collection

Drop the consent widget onto your site, publish the rights portal link, and start the queues. One script tag and one signed link.

FIRST QUARTER

Close the gaps in order

Work the phased plan — vendors, retention, breach readiness — with the evidence assembling itself as you go. Re-score whenever you want to see the movement.

Questions

Evaluating the platform

How long before we are actually using it?

The Scorecard takes five minutes and needs no login. From signing up, a first consent notice can be live the same afternoon — you pick a vetted template, fill in your details and publish. The registry and the phased plan are the work of the first week or two, and you are confirming a pre-filled map rather than drawing one from nothing.

What does DPDP compliance automation actually do here?

It does the work that has a clock on it. A retention date arrives and the pre-erasure notice goes out on its own; a consent is withdrawn and every downstream purpose stops; a rights request lands and the tasks fan out to each system that holds the person’s data; a breach is declared and the 72-hour Board clock starts running with the filing half-drafted. What DPDP compliance automation does not do is decide anything a person should be deciding — approving an erasure, judging a grievance, signing a Board filing. Those stay with your named people, and the platform records who did them and when. That line is the difference between privacy automation you can defend to the Board and a system that acted on its own and left nobody accountable.

Do you need access to our customer data?

No, and this is deliberate. We hold the shape of your estate — which systems you run, what categories of data they hold, which purposes they serve, who owns them. No agents on your servers, no database credentials, no copies of anyone’s records. The one exception is consent itself, where we hold the record of what was agreed, and the person is identified by a one-way hash rather than by name.

Where does it run, and who can see our information?

On infrastructure in India — data at rest and backups both stay in-country, which is what makes the residency conversation short. We are ISO 27001 certified. Inside your account, access is by role, and the audit log is append-only at the database level: the system will refuse an edit or a delete on it, which is enforcement rather than policy.

Do we have to map every system before anything works?

No. Consent, rights requests and breach logging all work from day one. The registry makes them better — a rights request that knows which systems to look in, a breach that knows who was affected — so most teams do it in the first month. You can start with the two or three systems that matter and grow the map as you go.

Does it connect to the systems we already run?

Over 300 systems are recognised out of the box — Indian and global, by sector — so you pick your hospital system, CRM or HRMS from a catalogue that already knows what it typically holds and how sensitive that is. Which of those you connect live, versus declare and manage, depends on your stack; that is a conversation for the demo rather than a claim on a page.

Can our consultant, DPO or auditor work inside it?

Yes. External advisors get their own access to the account they are engaged on, and an auditor gets a read-only view with the evidence and its hashes. That matters for Rule 13, which requires an independent data auditor — they need to verify your programme without us or you standing between them and the record.

What happens to our evidence if we stop using RuleExpert?

You take it with you. The evidence pack is a set of ordinary files — the audit log, the notices and their versions, withdrawal and grievance records, vendor coverage — with a SHA-256 manifest anyone can re-verify independently. It is designed to be readable and checkable without our software, because evidence that only works inside one vendor’s product is not much use in front of the Board.

Which modules are live today?

All ten compliance modules on this page are live and in use: consent, data principal rights, breach, vendor governance, data registry, retention and erasure, assessments, audit and evidence, the scorecard and the trust centre. The AI suite is in development and marked as such wherever it appears — we would rather show you a shipping product than a roadmap.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

See it against your own estate.

Start with the free Scorecard, or have someone walk you through the platform with your systems on the screen.