Consulting & managed services

We do the work. You keep the decisions.

Ten services across three stages. Take the whole programme, or the one piece your team has run out of hours for.

Get a free consultation See all ten services Or check your DPDP score first — free, five minutes, no account.
Sound familiar?

Who is doing this at your place?

The Act assumes somebody owns this. In most businesses in scope, nobody does.

Hospital or clinic

Your administrator already runs admissions, billing and the NABH file. This is now also theirs.

SaaS or platform

Your CTO is the security team, the privacy team and the person answering the customer questionnaire.

HR, staffing or payroll

Whoever handles payroll has become responsible for candidate, employee and client data at once.

Who this is for

Somebody at your place just inherited this

They are almost never a privacy specialist, and it is almost never the only thing on their desk.

01

They already have a job

The administrator running admissions and the NABH file. The CTO who is also the security team. The person who does payroll. DPDP arrived on top of that.

02

The statute is new to everyone

The Rules were notified in November 2025. Nobody has ten years of DPDP practice, and most advice circulating is GDPR with the country name swapped.

03

The work is front-loaded

Mapping an estate, drafting notices, papering vendors — heavy once, light forever after. Hiring permanently for a temporary volume of work is the wrong shape.

So the offer is hands, not a replacement. We carry the volume while it is heavy and hand back something your own people can run — a different business from becoming the department you outsourced it to.

The difference that matters

What you are holding when we leave

This is the question to ask every provider you are considering, and the one the market answers worst.

01

Buy software alone

You own a product with nothing in it. No tool is going to walk your premises and find the paper register at reception or the spreadsheet on a recruiter’s laptop.

02

Buy consulting alone

You end with a report. It was accurate the week it was written, and it starts ageing the day the consultants leave, because nothing is keeping it current.

03

What we do instead

Our consultants populate the platform. The register, the notices, the agreements and the schedules go into software you keep — so the day we leave is the day it starts running.

That is the whole argument, and it is the test worth applying to any DPDP compliance services quote you are given. A document describes what was true once; a system stays true because your team uses it.

Stage one · Assess

Find out what you are actually carrying

Nothing else can be scoped honestly until this exists. It is also the cheapest stage and the one you keep regardless.

01

DPDP Gap Assessment

Twelve obligation areas read against the provisions that create them — your notices, contracts, safeguards and processes — plus a readiness score, your exposure and a phased roadmap. You keep all of it whether or not anything follows.

02

Data Discovery & RoPA

Every place personal data sits — including the paper register and the local spreadsheet no scan finds — turned into a register and a record of processing that your team maintains afterwards rather than re-commissions.

03

DPIA & SDF Readiness

Whether you are likely to be named a Significant Data Fiduciary, and the Rule 13 impact assessment if you are. Most businesses are not, and finding that out early saves you buying obligations you do not owe.

Stage two · Operate

The work that runs every week

This is where a compliance programme is either alive or decorative, and where most of the hours actually go.

01

DPO as a Service

A named, reachable person holding the function and reporting to you. Worth knowing first that a Data Protection Officer is required only of a Significant Data Fiduciary — for everyone else this is a capacity decision, not a legal one.

02

Privacy Operations

Running the queues day to day: rights requests inside their window, grievances against the ninety-day period, retention and erasure on schedule, minors approaching eighteen. The part nobody budgets for and everybody discovers.

03

Notices, Policies & Consent

Rule 3 notices drafted in the languages your customers read, purpose-by-purpose consent design that separates §6 consent from §7 legitimate use, and the published policy brought into line with both.

04

DPA & Contract Review

§8(2) processing agreements written for your actual supplier list, and a large vendor’s own paper read for the clauses it is missing. You stay accountable for every processor, so the paper has to be right.

Stage three · Assure

Being able to prove it, on the day

§33(2) makes what you did — and how promptly — an express factor in any penalty. This stage is about being able to show it.

01

Breach Readiness & Response

The playbook before, and us on call for the first hour during. We scope it against your registry, draft the intimation and prepare the Board filing while your team contains it.

02

Audit Readiness & Support

The evidence pack, the covering narrative, and someone in the room. Rule 13 puts an independent auditor in front of a Significant Data Fiduciary every twelve months.

03

Training & Certification

The receptionist taking consent at a counter needs different training from the person who answers a rights request. Both need to have been trained, and you need to be able to show that they were.

Start with the assessment. Everything else depends on it.

You get the register, the readiness score and the roadmap, and you keep them whether or not anything else follows.

Or take all three

Ninety days to a defensible position

The three stages run in sequence. Each ends in something you could put in front of a regulator, an insurer or your board.

1

Assess — days 0 to 30

Your documents read against the Act, your people interviewed, your premises walked, and the register, record of processing, readiness score and exposure that come out of it. You finish this stage knowing what you are carrying, which is not where most businesses start.

2

Operate — days 30 to 75

Notices drafted and published, consent designed purpose by purpose, retention schedules with a legal basis behind each entry, vendor agreements in place, and the accountable contact published where people can find it.

3

Assure — days 75 to 90

Breach playbook wired to the clock, the evidence pack generating, your people trained on the parts they actually touch, and the first audit-ready position you have had.

4

Hand over — and step back

We train whoever owns it, watch them run a cycle, and reduce. Some clients keep a light retainer; some need nothing. Both are successful outcomes, and we will tell you which one you are heading for.

The division of labour

Ours to carry, yours to decide

Getting this line right is what makes the arrangement work, and it is not the line most outsourcing sells you.

01

We do the volume

Walking the estate, drafting twenty notices, translating them, papering forty vendors. Work that is heavy once and needs a specialist reading of a new statute.

02

You set the lawful basis

Whether a purpose runs on consent or a legitimate use is a decision about your business and you live with the consequence. We show you what follows from each.

03

You approve what publishes

Notices, policies, filings. Everything going to a customer or a regulator carries a name from your organisation, and the record shows whose.

04

We are on call for the bad day

A breach at nine at night is not the moment to read Rule 7 for the first time. That is when an outside team earns its retainer.

05

You keep the register

Every record we create is yours, in your tenant, exportable. Nothing about leaving us is designed to be difficult.

Who turns up

Lawyers and engineers, not a reseller

DPDP work sits between a legal question and a systems question, and most firms can only answer one of them.

01

Empanelled privacy lawyers

Indian counsel reading the Act and the Rules rather than adapting a GDPR view of them. They draft the notices, the policies and the processing agreements.

02

Techno-legal consultants

The people who walk your operation and map it. A lawyer alone will not find the paper register at your counter or the spreadsheet on a recruiter’s laptop.

03

The platform behind them

Everything they produce lands in software you keep, built and maintained by us rather than licensed from somebody else.

Questions

About working with us

Are you asking us to replace our team?

No, and we would rather you did not. The work DPDP creates is front-loaded — mapping an estate, drafting notices, papering vendors — and light forever after. Hiring a permanent role for a temporary volume is the wrong shape, and so is outsourcing a function your own people could run once it is set up. We carry the heavy part and hand back something your team operates. If we have done it properly, you need less of us each year.

Do we have to take all ten services?

No, and a DPDP consultant who insists otherwise is selling a programme rather than solving your problem. Most clients take the Assess stage first, because until somebody has walked your operation and written down where personal data actually sits, anything either of us says about your obligations is a guess. After that the common pattern is one or two Operate services — usually notices and vendor agreements — with the rest handled in-house. The full ninety-day programme is for businesses that want to be done in one pass.

What do we keep when the engagement ends?

A populated system, not a report. The register of where personal data sits, the published notices and their versions, the processing agreements, the retention schedules and the audit trail — all in your own tenant, all exportable. Worth asking every provider you consider: buy software alone and you own an empty product; buy consulting alone and you own a document that starts ageing the day they leave.

Do we have to appoint a Data Protection Officer?

Almost certainly not. A formal DPO based in India is required of a Significant Data Fiduciary under §10 — an organisation the government designates as one. Everyone else must publish contact details for a person who can answer questions about their handling of personal data, and that can be someone you already employ. Be careful of anyone quoting for a mandatory DPO appointment before establishing whether you are an SDF, and check the section they cite for it.

Can you work with our existing lawyer or IT provider?

Yes, and it is usually the better arrangement. Your lawyer knows your contracts and your IT provider knows your systems; neither typically has time to become a DPDP specialist. We supply the machinery, the evidence trail and the specialist reading, and brief them. Where you would rather not involve anyone else, we can do all of it.

What does it cost?

It depends on the size of your estate and which of the ten you want us to carry, and we would rather scope it than quote a number that turns out wrong in either direction. For context, full programmes for Significant Data Fiduciaries are quoted across this market in the tens of lakhs and up — most businesses reading this are not SDFs and should not be paying anything like that. Start with the free readiness score, or with the gap assessment.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Find out what you are carrying.

A free consultation with people who do this daily, or five minutes with the Scorecard first — no login, no card, and the number is yours either way.