India’s Digital Personal Data Protection Act changes how every business collects, stores and answers for personal data. We turn the Act — and the Rules as they take shape — into a working programme your Board can stand behind, without a full-time hire.
The DPDP Act 2023 makes your organisation a Data Fiduciary — accountable for every piece of personal data you process about Indian data principals. In practice that means consent-first notices in clear language, a lawful basis for each use, a working grievance-redressal channel, honouring data-principal rights (access, correction, erasure and nomination), and being ready to notify the Data Protection Board of India if a breach occurs.
How far you go depends on what you are. Most businesses are ordinary Data Fiduciaries; those the government notifies as Significant Data Fiduciaries (SDFs) carry heavier duties — a mandatory India-based DPO answerable to the Board, independent data audits and Data Protection Impact Assessments. We place you correctly, then build only what your tier needs.
Discrete workstreams you can take on their own or fold into an ongoing retainer.
Plain-language notices, itemised consent, and a withdrawal path that’s as easy as giving consent — with proof captured for every interaction.
A working channel for access, correction, erasure and nomination requests, with response SLAs that meet statutory timelines.
Records of processing and a lawful-basis register — the evidence base the Act expects you to maintain and produce.
A decision tree and pre-drafted notifications so a breach is met with a plan, not a scramble, within the timelines the Board sets.
If you’re notified as an SDF: a named India-based DPO, independent audit support and DPIA programme, mapped to Board accountability.
Verifiable parental-consent flows and tighter controls where you process children’s or high-sensitivity data.
A quick way to place yourself, then confirm it with a readiness assessment.
If notified as an SDF — on data volume, sensitivity and risk — you must appoint an India-based DPO answerable to the Board and run audits and DPIAs. Non-negotiable.
Notice, consent, grievance redressal, rights handling and breach duties apply to all Data Fiduciaries, whatever your size — startups included.
Enterprise buyers, ISO 27701 / SOC 2 and investors increasingly treat a documented DPDP programme as table stakes for the deal to close.
Not a policy PDF that gathers dust — a running programme with owners, evidence and a reporting cadence.
We confirm whether you’re an ordinary fiduciary or an SDF, so you build exactly what your tier requires — no more, no less.
Notices, consent capture and withdrawal wired into your product and back office, with proof retained for regulators.
RoPA, DPIAs where triggered, breach playbook and a KPI dashboard your Board can read at a glance.
The Act sets the duties of Data Fiduciaries, the rights of Data Principals, consent and notice standards, breach-notification obligations to the Data Protection Board of India, and enhanced duties for Significant Data Fiduciaries including a mandatory DPO. As the DPDP Rules are finalised, we track the detail — consent-manager registration, timelines and thresholds — and fold changes into your programme so you stay current rather than caught out. This is decision-support, not legal advice.
Most engagements fold into a single accountable retainer — usually 40–60% below the cost of a full-time hire. See how the tiers map to your scope.
An SDF is a Data Fiduciary the central government notifies as significant, based on factors like the volume and sensitivity of personal data processed and the risk to data principals. SDFs must appoint an India-based DPO answerable to the Board, conduct independent data audits and carry out Data Protection Impact Assessments.
If you process the personal data of individuals in India, you’re a Data Fiduciary and the core duties — notice, consent, grievance redressal, rights handling and breach readiness — apply regardless of size. The heavier SDF duties only apply if you’re notified as one.
A mandatory, India-based DPO answerable to the Board is required for Significant Data Fiduciaries. Other organisations aren’t obliged to appoint one, but a named DPO — including a fractional one — is the practical way to run and evidence the programme.
You need to be able to notify the Data Protection Board of India and affected data principals within the timelines set under the Act and Rules. We build a breach decision tree and pre-drafted notifications so the response is fast and defensible.
A strong GDPR programme gives you a head start — much of the RoPA, DPIA and rights machinery carries over. DPDP still has India-specific requirements (SDF duties, an India-based DPO, grievance redressal, local breach reporting) that we layer on top rather than rebuild.
No pitch, no obligation — just a clear read on where you stand and what an engagement would cover.