Operate · DPO as a Service

DPO as a Service

A named person who answers what customers ask and closes grievances on the statutory clock — alongside your team, not instead of it.

Talk to us What the person actually does A DPO is mandatory only for Significant Data Fiduciaries. The job is not.
Before anyone sells you one

Most businesses do not need a DPO

They need the thing a DPO does. Two different provisions, and only one of them applies to everybody.

§10

The title, for Significant Data Fiduciaries

Section 10(2)(a) requires an SDF to appoint a Data Protection Officer — an individual, based in India, responsible to the board, and the point of contact for grievance redressal. It applies only once the government designates you. Most businesses are not designated, and anyone telling you otherwise has not read section 10(1).

§8(9)

The function, for everyone else

Section 8(9) requires every Data Fiduciary to publish the contact details of a Data Protection Officer if applicable, or of a person who is able to answer questions from data principals about the processing of their personal data. There is no exemption for being small. The moment you publish a notice, you have named someone.

Which is why the honest version of this service is not “we will be your DPO”. It is that a named person has to exist, be findable, and actually answer — and that in most companies the name on the notice belongs to somebody who was never given the time, the process or the authority to do it.

What we actually do

How this works, month to month

A named individual, a process behind them, and an escalation path to whoever in your business owns the decision.

1

We put a named person on your notice

A real individual, published under section 8(9), reachable by the people whose data you hold. Not a shared mailbox and not a form nobody monitors.

2

We take what arrives, and start the clock

Grievances, rights requests, awkward questions from customers. Logged on the day they arrive rather than the day somebody reads them, because that is when the period runs from.

3

We answer, or we escalate to you

Most of it we close. What needs a business decision — a refusal, a purpose you have not agreed, a vendor who will not co-operate — comes to you with a recommendation.

4

We leave a record and report it

Every request, every decision, every date. Plus a short written summary your board can be shown, which is what makes the ninety-day period a fact rather than a hope.

Where your business is a Significant Data Fiduciary the shape changes and step one becomes yours rather than ours — the Act names an individual answerable to your board. The rest of the work is identical, and it is the larger part.

The job itself

What does that person actually have to do?

None of them is optional, and the penalty for the largest sits at fifty crore under the Act’s Schedule.

§8(9)₹50 Cr

Be published and reachable. A contact that bounces, or a form nobody monitors, is the same as no contact at all.

Named
§13 · Rule 14(3)₹50 Cr

Run grievance redressal and close each one within ninety days. Readily available means, not a best-efforts intention.

90 days
§11–14₹50 Cr

Answer rights requests — access, correction, erasure, nomination — which means knowing where the person appears across every system.

Rights
§8(6) · Rule 7₹200 Cr

Make the breach call. Three duties, two of them due without delay, and the judgement about what counts happens under time pressure.

Breach
§5 · Rule 3₹50 Cr

Keep the notice true. Every new purpose, vendor or category makes what you published a little less accurate than what you do.

Notice
§8(2)₹50 Cr

Hold the processors to their contracts. You remain accountable for what they do with data you handed them.

Vendors
§13 · Rule 14(3)

The grievance is where this gets tested

Not because grievances are frequent, but because of what section 13(3) does with the ones you never answered.

01

The person must go to you first

Section 13(3) requires a data principal to exhaust your redressal before approaching the Data Protection Board. Your process is the first instance, whether or not you built one.

02

Ninety days is the outer limit

Rule 14(3) sets the period for responding. It is a ceiling on a response, not a licence to take three months, and a complaint about your silence starts the moment it lapses.

03

Silence is the evidence

When it reaches the Board, what it carries is your record of handling it. An unanswered grievance arrives with nothing on your side of the file.

This is the practical reason a shared mailbox fails. Not that nobody reads it — somebody usually does — but that nothing starts a clock, nothing records what was decided, and nobody can later show what happened between the day it arrived and the day it was closed.

How the engagement works

Two shapes, and which one you get is not our choice

The Act decides it. If you are a Significant Data Fiduciary, we cannot be your DPO — and any firm that says otherwise should be asked why.

A

We are the named contact

For a business that has not been designated. Our named individual goes on your notice under section 8(9), receives what comes in, runs the grievance and rights process on the statutory clock, and escalates to you where a decision is yours to make. You get the function without hiring for it.

B

We support your DPO

For a Significant Data Fiduciary. Section 10(2)(a) names an individual, based in India, responsible to your board. A firm is not an individual and a service contract is not a line of accountability to your directors. So the appointment is yours; the process, the clock, the drafting and the board pack are ours.

Whether a contracted individual can satisfy “responsible to the Board of Directors” is a question worth putting to your own counsel. What is not in doubt is the direction of the accountability: it runs to your board, not to whoever you bought the service from.

What the work looks like

A month, in the things that actually arrive

Four of these are your own statutory duties. The other two arrive because of somebody else’s, and they still land on the same desk.

An ex-employee wants their file deleted

Section 12(1) gives the erasure right over data processed on consent, including section 7(a). An HR file usually runs on section 7(i) employment instead — outside that right altogether. Saying so correctly is the job; saying no without knowing why is not.

Marketing wants to use the customer list

For something the notice does not cover, and section 7 offers no legitimate use for marketing. The useful answer is not no — it is what would have to change first, and how long that takes.

A vendor emails about an incident

Vague, reassuring, and not obviously a breach. But the definition reaches loss of availability, there is no materiality threshold, and under section 8(2) it is still your breach. Rule 7’s clocks may already be running.

A new tool went live without anyone asking

It collects personal data for a purpose your notice never stated, which is a section 5 problem before it is anything else. Found in a review, or found by a regulator — those are the two ways this surfaces.

A customer’s procurement sends a questionnaire

Not your obligation — theirs. Section 8(2) keeps them accountable for you, so they ask. Forty questions, two weeks, and a box headed “name your Data Protection Officer”. The deal moves at the speed of whoever answers it.

The board wants one page

Governance rather than law: reporting to your directors is only a statutory duty for a Significant Data Fiduciary, and Rule 13’s report goes to the regulator. Boards ask anyway, and somebody has to write it.

Alongside your team, not instead of it.

Your legal, IT and HR people keep doing what they do. We take the part that has a statutory clock on it and no obvious owner.

Questions

About DPOs and outsourcing them

Does every company under the DPDP Act need a DPO?

No. Section 10(2)(a) makes appointing a Data Protection Officer an obligation of Significant Data Fiduciaries, and you only become one when the Central Government designates you under section 10(1). What binds everybody is section 8(9): publish the business contact details of a DPO if applicable, or of a person who is able to answer a data principal's questions about the processing of their personal data. So the honest position is that most businesses need the person and the process, not the title — and a vendor who tells you the title is compulsory is selling from a reading of the Act that is not there.

Can you be our DPO if we are a Significant Data Fiduciary?

No, and we would rather say so than take the engagement. Section 10(2)(a) describes an individual, based in India, responsible to your board of directors and acting as the point of contact for grievance redressal. A firm is not an individual, and a services contract does not create a line of accountability to your directors. What we can do is support the person you appoint — the process, the statutory clocks, the drafting, the evidence and the board reporting — which is most of the workload and none of the accountability.

What happens if we simply do not answer a grievance?

Section 13 gives the data principal a right to readily available means of grievance redressal, and Rule 14(3) sets ninety days for you to respond. Section 13(3) then requires them to exhaust that route before approaching the Data Protection Board — which means the matter reaches the Board carrying your handling of it. An unanswered grievance arrives with nothing on your side of the file, and a failure to observe your obligations under the Act sits at fifty crore on the Schedule.

An ex-employee has asked us to delete everything. Do we have to?

Usually not all of it, and the reason matters more than the answer. Section 12(1) gives the right of correction and erasure over personal data for the processing of which the person previously gave consent, including consent under section 7(a). An employment record is normally processed under section 7(i) instead, which places it outside that right rather than merely excused from it. Where the erasure right does attach, section 12(3) still permits retention that is necessary for the specified purpose or for compliance with any law — and section 8(7) says the same from your side. Note also that the right of access under section 11 is not limited this way, so "we cannot delete it" is never an answer to "show me what you hold". Getting this distinction right, in writing, is exactly the work.

We already have someone doing this part-time. Is that enough?

Often it is, and if so we will tell you. The question is not seniority but whether the work has a defined process, a clock that starts when something arrives, and a record of what was decided. Most part-time arrangements fail on the third — the answers get given, usually well, and six months later nobody can evidence that they were. That is a fixable problem and it does not always need an outside person.

How is this different from just hiring a privacy manager?

It is cheaper until the volume justifies a hire, and it starts working immediately rather than in three months. It is also narrower: an employee absorbs the ambiguous work nobody assigned, and a service does what the scope says. Where you have steady volume, an internal hire is usually the better answer and we will help you brief the role rather than compete with it.

Do you work with our existing legal counsel?

Yes, and it works better that way. Counsel owns the legal position; we own the operating rhythm — the intake, the clocks, the records, the escalations and the board pack. The work that goes wrong is rarely the legal analysis. It is the fortnight where nobody realised a clock was running.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Someone already has this job.

Whoever is named on your privacy notice is who the Act expects to answer. The question is whether they have the time, the process and the authority to do it.