India’s DPDP Compliance Support System
Whoever runs your DPDP programme runs it here.
Consent, rights, breach, vendors and audit evidence in one place — with the proof assembling itself as you work.
Check your score — free Book a demo
No login. No card. Five minutes to your exposure in rupees.
Indicative output — based on your inputs.
Indicative only. Actual penalties are at the Board’s discretion.
How most people find out
The same question, asked three ways, by people who have just realised the Act applies to them.
You hold patient records, your receptionist collects them on paper, and you have never called anyone a Data Fiduciary.
An enterprise customer attached a DPDP questionnaire to your renewal and you have four days to answer it.
You hold candidate CVs, your clients’ employee payroll, and your own staff files — and they are not the same problem.
The position today
What’s coming, and what it costs
₹250 crore
The largest penalty in the Act, for failing to protect personal data you already hold. Breach reporting, children’s data and vendor failures carry their own penalties on top of it.
DPDP Act 2023, Schedule
72 hours
From the moment you know about a breach, the Board expects the full picture. The first intimation is due immediately; the detail follows within 72 hours.
DPDP Rules 2025, Rule 7
Until the phase-in period ends. Organisations that start now set their own pace. Those that wait will be working to someone else’s.
Rules notified 14 November 2025
No threshold
The Act applies whether you are twenty people or twenty thousand. No revenue floor, no headcount minimum, no exemption for being small.
DPDP Act 2023
The honest bit
“We’ve got this covered.”
Most organisations have the left-hand column. Fewer have the right.
| You already have | What usually isn’t there yet |
|---|---|
| A consent tick-box in your HIMS, CRM or ERP | An itemised Rule 3 notice, in the languages the Act requires, as easy to withdraw as it was to give |
| A named DPO and a grievance email address | A queue with clocks on it, so nothing quietly runs past its deadline |
| A legal team that knows the Act cold | A portal your customers can actually use — no account, no fee |
| Customer data across fourteen systems | A way to find every one of them holding a single person’s data, so erasure is real and not asserted |
| Records. Somewhere. | Proof a regulator can verify independently, without trusting you |
Your team isn’t the gap. The system is.
Who it makes stronger
We take the manual work off your team.
| Team | Stays theirs | Comes off their desk |
|---|---|---|
| DPO & compliance | The decisions, the accountability, the conversation with the Board | Chasing deadlines across five modules, building the inventory by hand, remembering which clock is running |
| Legal & counsel | The legal positions, the risk calls, the sign-off | Drafting every notice from scratch, versioning them, translating them, re-checking each against the clause |
| IT & security | The architecture and the security posture | Building consent capture, building a rights portal, pulling data together for every request — and being asked to hold data they never wanted |
| Consultants & CAs | The advice, and the client relationship | Rebuilding the same assessment for every client, chasing documents at audit, keeping a hundred spreadsheets current |
| Founder & CFO | How much risk the business chooses to carry | Not knowing what that risk actually is |
Nobody here gets replaced. They stop doing this by hand.
Already drafted, already reviewed
5,000+ consent notice templates, vetted by our legal team.
Across industries and purposes — hospital admission, student enrolment, KYC onboarding, delivery tracking, employee records, marketing. Each one written against the section it has to satisfy, and reviewed by practising counsel before it ever reaches you.
Your legal team edits rather than drafts. That is usually the difference between a notice programme taking a quarter and taking a fortnight.
- Written to the clause — every template carries the provision it satisfies
- Purpose-specific — not one notice stretched to cover everything you do
- Counsel-reviewed — by lawyers who practise Indian data protection
- Kept current — updated as the Rules and guidance move
The platform
One platform, end to end
DPDP compliance software that diagnoses what is missing, fixes it in the order that matters, and produces the proof.
01 — FREE
Diagnose
Answer questions about how your organisation actually works. Get a score, a ranked gap list and your penalty exposure in rupees. Five minutes, no login.
02 — GUIDED
Fix
Close gaps in the order of what they cost you. Consent, rights, breach, vendors, data mapping — each guided, each carrying the clause it satisfies.
03 — EVIDENCE
Prove
Every action writes itself to the record as it happens. The audit pack is generated, not assembled the week before.
One data model
Declare a system once and every module reads it. Add a module later and there is nothing to migrate and nothing to re-enter.
Installs in an afternoon
A script tag for consent, a signed link for the rights portal, an API for everything else. No agents on your servers, no database connections.
Metadata only
We record which systems exist, what categories they hold and what was consented to. Your customers’ records never leave the systems they are already in.
Hosted in India
Data at rest, backups included, stays in-country — which is the answer your procurement team will need in writing.
The platform
Ten modules. One platform.
Start with one. Add another whenever you like — one data model underneath, so there is nothing to migrate and nothing to re-enter.
Compliance Suite
Six modules — live
DPDP Scorecard
Live
Automated gap assessment with penalty exposure in rupees and a phased remediation plan.
Consent Management
Live
Rule 3 notices in the Eighth Schedule languages, a lightweight widget, and an append-only consent log.
DSR Automation
Live
Access, correction, erasure and nomination — identity-verified and SLA-tracked end to end.
Data Registry
Live
Your record of processing, pre-filled rather than blank. Metadata only — never the data itself.
Breach Management
Live
Declare, scope and notify against the Rule 7 clock — the Board and the people affected.
Vendor Governance
Live
Processor register, DPA status and risk scoring — sharing blocks when a DPA lapses.
AI Suite
Four modules — coming soon
AI Consent Drafter
Coming soon
Generates a Rule 3 notice from your actual processing, in plain language. How the drafter works
Policy Gap Detector
Coming soon
Reads your existing policies and flags where they fall short of the Act. What it finds
Evidence Packager
Coming soon
Assembles the audit pack and writes the plain-English summary that goes on top. What it writes
Compliance Copilot
Coming soon
Answers “are we allowed to do this?” with the clause it relied on. What it answers
Evidence, not assertions
Anyone can verify your compliance. Including you.
Every consent, withdrawal and breach action is written to an append-only log the database itself will not let anyone edit. Each evidence pack carries a SHA-256 manifest that a regulator, an auditor or a customer can re-verify independently — without an account, and without taking our word for it.
packconsent-evidence-2026-Q2.zip
generated2026-07-14 09:12 IST
records184,205 consent events
manifesta3f9c1e07b4d2a68f5c19e3b7d0a4f82c6b5e918d7a2c4f0e6b3d9a1c8f5e207
Verified — unchanged since generation
Services
Your team, or ours
Run it with your own team or bring in our techno-legal consultants — both work in the same system. DPDP compliance solutions you end up owning, not renting.
Assess
Find out where you stand
A consultant-grade picture of your exposure, built on the assessment engine rather than on three weeks of interviews.
- Gap Assessment
- Data Discovery & RoPA build
- DPIA & SDF readiness
Operate
Have it run for you
A named DPO and a team who work your queues day to day — or who sit alongside yours and take the load off it.
- DPO as a Service
- Privacy Operations, managed
- Notices, policies & consent drafting
- DPA & contract review
Assure
Be ready when you’re asked
The evidence, the drills and the paperwork that turn a Board question or a customer audit into a short conversation.
- Breach readiness & response
- Audit readiness & support
- Training & certification
How an engagement starts: a discovery call, a scoped proposal, a named lead, and delivery on the platform. When the engagement ends, you keep the system it ran on.
The free DPDP Scorecard
A consultant-grade gap assessment, free.
Yours to keep, whether or not you buy anything.
01
Your score
Where you stand across every DPDP obligation, and what the band actually means.
02
What’s missing
Every gap, ranked — each with the section it comes from and the penalty attached to it.
03
What to do about it
A phased plan: 0–30 days, 30–90 days, 90+ days. With owners, so it can actually be assigned.
Pricing
What it costs depends on what you hold
Three things move the number, and you can work out where you sit on all three before speaking to anyone.
01
How many people
A single-location clinic and a lender with two million customers owe the same obligations and carry very different volumes of them.
02
How much estate
Systems, entities, and the processors acting on your behalf. Ten vendors is a different exercise from a hundred, and it is the number most businesses underestimate.
03
How much you want carried
Run it with your own team and the platform is most of the cost. Hand us the function and the services are. Most people land somewhere in between.
We would rather scope it than publish a table you have to reverse-engineer. Start with the free Scorecard — five minutes, no account, and it tells you the size of your own problem before anybody quotes you for it.
Questions
Frequently asked
We already have a DPO and a legal team. What does this add?
The machinery they don’t have. A portal your customers can use without an account, a queue that tracks every deadline, a map of which systems hold one person’s data so erasure is real, and evidence anyone can verify. Your team keeps the judgement — this removes the manual work underneath it.
Can you provide the people as well as the platform?
Yes. We have empanelled lawyers, Data Protection Officers and security specialists who can run your programme or work alongside your team — as a named DPO, on a gap assessment, or drafting notices and processor agreements. They work in the same platform, and you keep it when the engagement ends.
Our CRM already captures consent. Isn’t that enough?
It captures a tick. The Act asks for more: an itemised notice describing each purpose, in plain language, available in the required languages, with withdrawal as easy as giving — and a record you can produce years later showing exactly what was agreed, when, and to what. Most systems capture the tick and none of the rest.
What is the maximum penalty under the DPDP Act?
The Act’s Schedule sets penalties by the obligation breached. The largest single item is ₹250 crore, for failing to take reasonable security safeguards. Breach-notification and children’s-data failures carry up to ₹200 crore, Significant Data Fiduciary duties up to ₹150 crore, and most other breaches up to ₹50 crore.
How quickly must we report a personal data breach?
Under Rule 7 of the DPDP Rules 2025 you must inform the Data Protection Board without delay on becoming aware of a breach, and follow it with detailed particulars within 72 hours. Affected Data Principals must also be informed without delay. The 72 hours is the deadline for the full account, not for the first intimation.
Do you store our customers’ personal data?
Some of it, and only where the obligation cannot be met without it — which is a more useful answer than a flat no. The Data Registry, the map of your estate, holds metadata and nothing else: which systems exist, what categories they hold, who owns them. It never holds a record about a person. Consent and rights are necessarily different, because §6(10) makes you able to demonstrate a particular person consented, and §11 makes you answer that person — neither is possible without a record of them. So the consent log and the rights queue do hold one. We keep it minimal, identifiers are stored as hashes, and where a contact address is needed to reply to somebody it is encrypted at rest. Everything sits in India, and your operational databases stay where they are — we never copy them.
Where is our data hosted?
On infrastructure in India. Data at rest, backups included, stays in-country.
Is DPDP Act compliance mandatory for a company our size?
There is no revenue or headcount threshold. The Act applies to anyone processing digital personal data in India, and to anyone outside India processing it to offer goods or services here. A ten-person clinic and a listed hospital chain owe the same core duties — notice, consent, security, breach reporting, and honouring rights requests. What changes with size is the volume of work, which is the part DPDP compliance software takes off you.
Is DPDP compliance in India different from GDPR?
The shape is familiar; the detail is not. DPDP compliance India turns on things the GDPR does not have — legitimate uses under §7 instead of six lawful bases, verifiable parental consent for everyone under 18, a breach report to the Board inside 72 hours with no severity threshold below which you may stay quiet, and a blacklist for transfers abroad rather than an adequacy list. There is also no data portability right here. Tooling built for the GDPR maps onto this badly, which is why ours is built against the Act’s own sections.
Can we start with just one module?
Yes. Most organisations start with the free Scorecard, then take on Consent or DSR first depending on where their exposure is largest. Modules share one data model, so adding another later needs no migration. Buying a DPDP solution one obligation at a time is the sensible way round — it is also why nothing here is sold as an all-or-nothing suite.
Thirty minutes with a specialist about your own obligations. Not a product pitch.
What compliance teams tell us
Real client quotes, attributed by role and sector — we never name a client.
DPDP, explained properly
DPDP in India: The Complete Guide to Data Protection Compliance, DPDP Guidelines and Automated Compliance Management (2026)
3 September 2026 · 35 min read DPDP ActHealthcare Vendor Governance Under India’s DPDP Act: The Complete 2026–27 Compliance Framework
27 August 2026 · 32 min read DPDP ActDPDP vs GDPR Compliance Tool: What’s Actually Different, and What a Tool Needs to Handle Both
26 August 2026 · 34 min readWorking across
Find out where you stand.
Five minutes, free, and you keep the report either way.
Check your score — free Get a free DPDP consultation Book a demo


