Skip to main content

DPDP Act Readiness

Establish your position under India's Digital Personal Data Protection Act, 2023. We map the personal data you hold, on what basis, and the duties that attach to you as a Data Fiduciary — and separate what is in force from what is not.

Engagement brief

Governance, Risk & Compliance
Frameworks
India DPDP Act 2023GDPRISO/IEC 27001ISO/IEC 27002

Coverage that maps to real risk.

Personal data inventory and processing-purpose register
Notice, consent, withdrawal, and Consent Manager interfaces
Data Principal rights: access, correction, erasure, nomination
Verifiable guardian consent for children and persons with disabilities
Breach reporting and Significant Data Fiduciary duties

How the engagement runs.

A disciplined, repeatable arc — so results are comparable and defensible.

  1. 01

    Applicability review: Data Fiduciary role and exemptions

  2. 02

    Data discovery and purpose mapping across your estate

  3. 03

    Gap assessment against the Act and notified Rules

  4. 04

    Remediation design for notice, consent, rights, and retention

  5. 05

    Reporting, evidence pack, and readiness debrief

What you walk away with.

Personal data inventory and processing-purpose register
Obligation-by-obligation gap assessment and remediation plan
Breach runbook with the Board notification path
Executive readiness summary for leadership

Every finding is rated on the CVSS severity scale:

  • CRITICAL9.0–10.0
  • HIGH7.0–8.9
  • MEDIUM4.0–6.9
  • LOW0.1–3.9
  • INFO0.0

Questions we hear a lot.

No. The Act has no certification scheme, and the Data Protection Board inquires into breaches rather than certifying anyone. We prepare you, test the controls, and leave the evidence.

Tell us about your environment and we'll come back with a fixed scope, timeline, and price.