The month-by-month work that keeps what you told people about their data true — long after the assessment is filed and forgotten.
No jargon. If the rest of this page disappeared, this section would still tell you whether you need it.
It is housekeeping for the personal information you hold. Every month, somebody has to check that what you published about your handling of people’s data still matches what your business actually does — and fix it where it has drifted. That is the whole service. We do that checking, on a fixed schedule, and leave behind a written record that it happened.
Where two of these overlap for you, we scope them as one engagement rather than as two invoices.
Nothing here is a mistake anybody made. These are ordinary business decisions that quietly change what the law requires of you.
A payroll tool, a chat widget, a scheduling app. Personal data now sits somewhere new, with a company you have no written data agreement with. Nobody thought of it as a legal event.
Marketing wants dates of birth, or a WhatsApp number. Thirty seconds of work, and your published privacy notice now describes something narrower than what you collect.
The parent’s permission was valid for a child. On a birthday it stops being the right basis, and nothing anywhere tells you. It is a date, not an event.
The laptop comes back; the login to the customer database does not get switched off. Access control is one of the safeguards the Rules actually name.
You said you keep candidate data for a year. Three years of it is still sitting there, because deleting on schedule needs somebody to have built the schedule.
A second location, a new market, a supplier who stores data abroad. Every one of those changes an answer you have already given in writing.
A gap assessment is a photograph. Six months later it is a photograph of a place that no longer exists — and the version a regulator or a customer will read is the one on your website today, not the one you were proud of in March.
Compliance work is not a list of capabilities. It is a set of things that must happen on a rhythm, and the rhythm is the product.
Anything a person has asked for is checked and moved along: requests to see, correct or delete their data, and complaints. Complaints carry a ninety-day legal deadline, and the clock starts the day the message arrives, not the day somebody reads it.
New suppliers, new forms, new tools, new places data is stored. Each one is checked against what your notice already says and what your contracts already cover, and anything that no longer matches becomes a short list of fixes with owners against them.
Who can reach personal data and whether they still should. Whether old records are actually being deleted on the schedule you published. Whether your suppliers’ data agreements are still in force, and whether an incident drill would work if you ran one.
A full re-read of your notices and policies against the Act and the Rules as they stand then, a refreshed readiness score you can compare to last year’s, and a written pack your board or your biggest customer can be shown without editing.
Some of the rhythm is ours; some is the law’s. The ninety days for complaints is Rule 14(3). Keeping a year of access logs is Rule 6. A twelve-month impact assessment and audit is Rule 13, and applies only if the government has designated you a Significant Data Fiduciary — most businesses are not, and we will tell you if you look like one.
The figures are the maximum penalties the Act’s Schedule sets for the provision named — a ceiling, not a forecast.
Your notice has to describe what you actually collect and why. Every new form and field is a chance for it to stop being true.
MonthlyNamed safeguards: encryption or masking, controls on who can get in, monitoring, backups, and logs kept for a year.
QuarterlyData has to actually be deleted when its reason for existing has gone. A retention policy nobody executes is a policy against you.
QuarterlyPeople can ask to see, correct or delete their data, or complain. Ninety days on the complaint, counted from arrival.
WeeklyEvery supplier touching personal data needs a written agreement, and you stay answerable for what they do with it.
MonthlyChildren’s data carries its own rules, and the child who was fifteen when you met them will not be fifteen forever.
MonthlyTwo pages you can read in five minutes, and a record underneath it that stands up if anybody asks for proof.
New suppliers, new data, new places it sits. Written plainly, so you can see whether we noticed the things you already knew about.
Done and closed, with the date. The point of a monthly note is that most months this is the longest section and nothing is asked of you.
The short list only you can decide — a supplier who will not sign, a purpose that needs a business call. Never more than a handful.
One score, tracked against last month, so a trend is visible without reading anything. Up is good; a flat line for three months is a conversation.
Each check leaves a dated record in your own tenant. Assembling proof afterwards is the expensive way; collecting it as it happens costs nothing extra.
You should not have to think about this. You should get two pages telling you that somebody did, and what they found.
Privacy operations is the recurring work; a DPO is the named person who answers for it. This service does the checking, updating and record-keeping on a schedule. The DPO service puts a named individual on your notice as the contact the law expects, and gives you someone to make the judgement calls — is this a breach, can we refuse this deletion, do we need fresh consent. Plenty of businesses buy both, and where they do we scope it as one engagement rather than two invoices. If you only buy one, buy the one that matches your problem: no owner, or no time.
Possibly, and we would rather establish that than sell you a monthly retainer you do not need. The Act has no small-business exemption, so the obligations exist — but at fifteen people they may amount to a couple of hours a quarter that your operations lead can absorb once somebody has set it up properly. That is a legitimate outcome of a first conversation, and a one-off engagement to build the routine is usually the better buy. Volume of personal data matters far more than headcount: a fifteen-person business holding two lakh patient records is not a small compliance problem.
The record has to live somewhere, and it lives in a tenant that belongs to you — your data, exportable, and yours to keep if you stop working with us. What you do not have to do is change how your business runs. We work with the systems you already use; nobody on your team needs a new login unless they want one, and system owners get a single signed link when we need something from them.
The first month is not a normal month. Before anything can be kept up to date it has to be made accurate once — which means knowing what personal data you hold and where, and reading your notices and supplier contracts against what is actually happening. If you have had a gap assessment recently we start from it. If not, that first pass is the real work and the monthly rhythm starts once it is done. Anyone promising a steady-state service from week one has skipped the part that makes it worth having.
You do not wait for the calendar. A suspected breach, a regulator's letter, a customer escalation or a data request that looks dangerous is handled when it arrives — the schedule governs the routine work, not the urgent kind. This matters more than it sounds under the DPDP Act, because the breach duties in Rule 7 run without delay and a seventy-two-hour clock does not care which week of the month it is.
Yes, and it is the part of the monthly note we care most about. Most of this market is paid to find you more obligations. The measure of whether this service is working is that the list of things needing your attention gets shorter, and that when a rule genuinely does not apply to you — a Significant Data Fiduciary duty, a children's requirement, a cross-border restriction — you are told so in writing rather than sold the work anyway.
Real client quotes, attributed by role and sector — we never name a client.
Working across
It is a habit. Most businesses do the project, file it, and find out eighteen months later that nobody kept it true.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.