Pune · serving all India Mon–Fri, 9:30–18:30 IST
01

DPDPA Gap Assessment

A 4-to-6 week structured diagnostic that maps your current data practices against every applicable clause of the DPDPA. You receive a prioritised remediation roadmap with effort, cost and risk estimates — usable by your board and your auditors.

4–6 weeks Fixed-fee
  • Personal data inventory
  • Data flow mapping across systems
  • Clause-by-clause compliance scoring
  • Prioritised roadmap with cost estimates
  • Board-ready executive summary
02

Implementation & Remediation

We translate the gap assessment into working artefacts: privacy notices that hold up legally and read well, consent flows that work in your apps, retention schedules engineers can enforce, and a breach response playbook tested through tabletop exercises.

8–12 weeks T&M, capped
  • Privacy notices & consent text
  • Data retention schedules
  • Breach response playbooks
  • Data Principal rights workflows
  • Third-party processor agreements
03

DPO-as-a-Service

For organisations classified as Significant Data Fiduciaries, the DPDPA requires the appointment of a Data Protection Officer based in India and accountable to the board. Our retainer model gives you a qualified, dedicated DPO without the cost of an in-house hire.

Annual retainer Named officer
  • Named DPO accountable to your board
  • Monthly compliance reporting
  • Data Principal grievance handling
  • Regulator liaison & response
  • Quarterly board briefings
04

Training & Awareness

Compliance is a people problem before it's a paperwork problem. We deliver role-based training tailored to boards, frontline staff, engineering teams and HR — with completion certificates that form part of your audit evidence.

2–4 weeks Hindi · English · Marathi
  • Board-level governance workshops
  • Frontline staff modules
  • Engineering & product deep-dives
  • HR & recruiting privacy training
  • LMS-ready content packs
05

Independent Data Audits

Annual independent audits performed against the DPDPA and its supporting rules. We produce a documented evidence pack that can withstand regulator scrutiny, customer due diligence, and board review — and we tell you what to fix before anyone else asks.

6–8 weeks Annual cadence
  • Full-scope DPDPA audit
  • Sample-based control testing
  • Evidence pack for regulators
  • Management action report
  • Year-on-year maturity tracking
06

Risk & Impact Assessments

Data Protection Impact Assessments for new products, vendor onboarding and high-risk processing — with documented sign-off your board can defend if challenged by the Data Protection Board.

2–4 weeks per DPIA Per assessment
  • Product launch DPIAs
  • Vendor & third-party assessments
  • High-risk processing reviews
  • Cross-border transfer assessments
  • Remediation recommendations
Not sure where to start?

Most clients begin with
a 2-week scoping call.

Schedule a call