Ten services across three stages. Take the whole programme, or the one piece your team has run out of hours for.
The Act assumes somebody owns this. In most businesses in scope, nobody does.
Your administrator already runs admissions, billing and the NABH file. This is now also theirs.
Your CTO is the security team, the privacy team and the person answering the customer questionnaire.
Whoever handles payroll has become responsible for candidate, employee and client data at once.
They are almost never a privacy specialist, and it is almost never the only thing on their desk.
The administrator running admissions and the NABH file. The CTO who is also the security team. The person who does payroll. DPDP arrived on top of that.
The Rules were notified in November 2025. Nobody has ten years of DPDP practice, and most advice circulating is GDPR with the country name swapped.
Mapping an estate, drafting notices, papering vendors — heavy once, light forever after. Hiring permanently for a temporary volume of work is the wrong shape.
So the offer is hands, not a replacement. We carry the volume while it is heavy and hand back something your own people can run — a different business from becoming the department you outsourced it to.
This is the question to ask every provider you are considering, and the one the market answers worst.
You own a product with nothing in it. No tool is going to walk your premises and find the paper register at reception or the spreadsheet on a recruiter’s laptop.
You end with a report. It was accurate the week it was written, and it starts ageing the day the consultants leave, because nothing is keeping it current.
Our consultants populate the platform. The register, the notices, the agreements and the schedules go into software you keep — so the day we leave is the day it starts running.
That is the whole argument, and it is the test worth applying to any DPDP compliance services quote you are given. A document describes what was true once; a system stays true because your team uses it.
Nothing else can be scoped honestly until this exists. It is also the cheapest stage and the one you keep regardless.
Twelve obligation areas read against the provisions that create them — your notices, contracts, safeguards and processes — plus a readiness score, your exposure and a phased roadmap. You keep all of it whether or not anything follows.
Every place personal data sits — including the paper register and the local spreadsheet no scan finds — turned into a register and a record of processing that your team maintains afterwards rather than re-commissions.
Whether you are likely to be named a Significant Data Fiduciary, and the Rule 13 impact assessment if you are. Most businesses are not, and finding that out early saves you buying obligations you do not owe.
This is where a compliance programme is either alive or decorative, and where most of the hours actually go.
A named, reachable person holding the function and reporting to you. Worth knowing first that a Data Protection Officer is required only of a Significant Data Fiduciary — for everyone else this is a capacity decision, not a legal one.
Running the queues day to day: rights requests inside their window, grievances against the ninety-day period, retention and erasure on schedule, minors approaching eighteen. The part nobody budgets for and everybody discovers.
Rule 3 notices drafted in the languages your customers read, purpose-by-purpose consent design that separates §6 consent from §7 legitimate use, and the published policy brought into line with both.
§8(2) processing agreements written for your actual supplier list, and a large vendor’s own paper read for the clauses it is missing. You stay accountable for every processor, so the paper has to be right.
§33(2) makes what you did — and how promptly — an express factor in any penalty. This stage is about being able to show it.
The playbook before, and us on call for the first hour during. We scope it against your registry, draft the intimation and prepare the Board filing while your team contains it.
The evidence pack, the covering narrative, and someone in the room. Rule 13 puts an independent auditor in front of a Significant Data Fiduciary every twelve months.
The receptionist taking consent at a counter needs different training from the person who answers a rights request. Both need to have been trained, and you need to be able to show that they were.
You get the register, the readiness score and the roadmap, and you keep them whether or not anything else follows.
The three stages run in sequence. Each ends in something you could put in front of a regulator, an insurer or your board.
Your documents read against the Act, your people interviewed, your premises walked, and the register, record of processing, readiness score and exposure that come out of it. You finish this stage knowing what you are carrying, which is not where most businesses start.
Notices drafted and published, consent designed purpose by purpose, retention schedules with a legal basis behind each entry, vendor agreements in place, and the accountable contact published where people can find it.
Breach playbook wired to the clock, the evidence pack generating, your people trained on the parts they actually touch, and the first audit-ready position you have had.
We train whoever owns it, watch them run a cycle, and reduce. Some clients keep a light retainer; some need nothing. Both are successful outcomes, and we will tell you which one you are heading for.
Getting this line right is what makes the arrangement work, and it is not the line most outsourcing sells you.
Walking the estate, drafting twenty notices, translating them, papering forty vendors. Work that is heavy once and needs a specialist reading of a new statute.
Whether a purpose runs on consent or a legitimate use is a decision about your business and you live with the consequence. We show you what follows from each.
Notices, policies, filings. Everything going to a customer or a regulator carries a name from your organisation, and the record shows whose.
A breach at nine at night is not the moment to read Rule 7 for the first time. That is when an outside team earns its retainer.
Every record we create is yours, in your tenant, exportable. Nothing about leaving us is designed to be difficult.
DPDP work sits between a legal question and a systems question, and most firms can only answer one of them.
Indian counsel reading the Act and the Rules rather than adapting a GDPR view of them. They draft the notices, the policies and the processing agreements.
The people who walk your operation and map it. A lawyer alone will not find the paper register at your counter or the spreadsheet on a recruiter’s laptop.
Everything they produce lands in software you keep, built and maintained by us rather than licensed from somebody else.
No, and we would rather you did not. The work DPDP creates is front-loaded — mapping an estate, drafting notices, papering vendors — and light forever after. Hiring a permanent role for a temporary volume is the wrong shape, and so is outsourcing a function your own people could run once it is set up. We carry the heavy part and hand back something your team operates. If we have done it properly, you need less of us each year.
No, and a DPDP consultant who insists otherwise is selling a programme rather than solving your problem. Most clients take the Assess stage first, because until somebody has walked your operation and written down where personal data actually sits, anything either of us says about your obligations is a guess. After that the common pattern is one or two Operate services — usually notices and vendor agreements — with the rest handled in-house. The full ninety-day programme is for businesses that want to be done in one pass.
A populated system, not a report. The register of where personal data sits, the published notices and their versions, the processing agreements, the retention schedules and the audit trail — all in your own tenant, all exportable. Worth asking every provider you consider: buy software alone and you own an empty product; buy consulting alone and you own a document that starts ageing the day they leave.
Almost certainly not. A formal DPO based in India is required of a Significant Data Fiduciary under §10 — an organisation the government designates as one. Everyone else must publish contact details for a person who can answer questions about their handling of personal data, and that can be someone you already employ. Be careful of anyone quoting for a mandatory DPO appointment before establishing whether you are an SDF, and check the section they cite for it.
Yes, and it is usually the better arrangement. Your lawyer knows your contracts and your IT provider knows your systems; neither typically has time to become a DPDP specialist. We supply the machinery, the evidence trail and the specialist reading, and brief them. Where you would rather not involve anyone else, we can do all of it.
It depends on the size of your estate and which of the ten you want us to carry, and we would rather scope it than quote a number that turns out wrong in either direction. For context, full programmes for Significant Data Fiduciaries are quoted across this market in the tens of lakhs and up — most businesses reading this are not SDFs and should not be paying anything like that. Start with the free readiness score, or with the gap assessment.
Real client quotes, attributed by role and sector — we never name a client.
Working across
A free consultation with people who do this daily, or five minutes with the Scorecard first — no login, no card, and the number is yours either way.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.