Cyber Security & Risk Advisory

DPDP Act Compliance

Data protection compliance that holds up before the Data Protection Board asks.

What This Is

A new compliance layer, with real penalties attached

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 create a completely new compliance obligation covering how you collect, use, store and protect personal data — with penalties running up to ₹250 crore for serious violations, and a 72-hour breach notification clock that starts the moment you know something's gone wrong.

We help you understand exactly where you stand as a Data Fiduciary, close the gaps that matter, and build compliance that survives scrutiny — not a policy document that just sits in a folder.

Start a DPDP Readiness Assessment
Data Fiduciary Categories

Your obligations scale with how much personal data you handle.

Significant Data Fiduciary
Data Fiduciary
Data Processor
Joint Fiduciary
Limited Scope
Coverage

What we cover

A complete compliance program, not just a policy template.

gap_assessment.sh

DPDP Gap Assessment

Review current data practices against DPDP Act and Rules requirements to find exactly where you stand.

consent_arch.sh

Consent Architecture

Design compliant consent collection, notice language, and withdrawal mechanisms.

dpia.sh

Data Protection Impact Assessment

A formal DPIA for high-risk processing activities, as required for Significant Data Fiduciaries.

breach_response.sh

Breach Response Planning

A response plan built around the 72-hour Data Protection Board notification requirement.

vendor_dpdp.sh

Data Processor Agreements

Contracts and oversight for every vendor who touches personal data on your behalf.

dpo_support.sh

DPO Advisory Support

Ongoing advisory support for your Data Protection Officer function, in-house or outsourced.

What You'll Receive

What a gap assessment finding looks like

Every gap in your assessment is rated by regulatory exposure and paired with a specific remediation step.

Below is an illustrative example of a single finding.

No Verifiable Consent Mechanism for Data Collection High
Regulatory Exposure
High
Description

Website and app forms collect personal data without a DPDP-compliant notice or a clear, itemised consent mechanism, relying instead on a generic privacy policy link.

Illustrative example only — for demonstration of report format, not an actual finding from a client engagement.

How We Work

Our compliance methodology

The same structured path, scoped to your data footprint.

01

Data Mapping

Identify every place personal data enters, moves through, and leaves your organisation.

02

Gap Assessment

Compare current practices against DPDP Act and Rules requirements.

03

Policy & Consent Design

Build compliant notices, consent flows, and internal policies.

04

Technical Safeguards

Implement the security measures the Act expects for the data you hold.

05

Audit & Certification

Formal DPDP audit and documentation, especially for Significant Data Fiduciaries.

Compliance Mapping

Frameworks we align with

DPDP compliance often overlaps with these — we account for all of them where relevant.

DPDP Act 2023 DPDP Rules 2025 ISO 27701 GDPR (cross-border) SEBI CSCRF
Common Questions

Frequently asked questions

Does the DPDP Act apply to my business?

Yes, if you process digital personal data of individuals in India — this applies broadly regardless of whether you're B2B or B2C, since employee, vendor and customer data all count.

What's a Significant Data Fiduciary, and does that apply to us?

It's a category the government notifies based on volume and sensitivity of data processed, carrying stricter obligations like mandatory audits and a DPO. We'll assess whether this applies to you.

What happens if we have a data breach?

You must notify the Data Protection Board and affected individuals within 72 hours — which means your response plan needs to be ready before an incident happens, not built during one.

Do we need a Data Protection Officer?

Mandatory for Significant Data Fiduciaries, and good practice for most other organisations handling meaningful volumes of personal data.

How is this different from our existing cybersecurity work?

VAPT and similar services protect against unauthorised technical access. DPDP compliance covers the legal and policy side of how you're allowed to collect and use data — the two are complementary and often bundled together.

Not sure where you stand under the DPDP Act?

Tell us about your data practices and we'll scope a readiness assessment.

Get in Touch
← Back to

Cyber Security & Risk Advisory

See all offerings — VAPT, information system audit, risk advisory and forensic audit.