India's DPDP Act Compliance
India's Digital Personal Data Protection Act is now in force. We help you meet its consent, notice and breach obligations.
What is DPDPA?
The Digital Personal Data Protection Act, 2023 (DPDPA) governs the processing of digital personal data in India, setting out obligations for data fiduciaries - the entities that determine how and why personal data is processed.
It requires clear notice and consent, purpose limitation, reasonable security safeguards, data breach notification, and rights for the data principal (the individual) to access, correct and erase their data. The Data Protection Board of India oversees enforcement.
What's included
Data Mapping
Data mapping across digital personal data processing activities.
Consent & Notice Review
Consent and notice mechanism review.
Obligation Gap Assessment
Data fiduciary obligation gap assessment.
Security Safeguards
Reasonable security safeguards implementation.
Breach Notification Design
Data breach notification procedure design.
Data Principal Rights
Data principal rights request handling process.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
ISO 27701
Privacy Information Management System, extending ISO 27001 for GDPR/DPDPA alignment.
Learn more →Questions we get asked first
Who counts as a data fiduciary under DPDPA?
Any entity that alone or with others determines the purpose and means of processing digital personal data - which covers most businesses that hold customer or employee data digitally.
How is DPDPA different from GDPR?
They share core ideas - consent, purpose limitation, breach notification - but DPDPA has India-specific mechanics, including the Data Protection Board and its own consent-manager framework.
What counts as a reportable breach?
DPDPA requires data fiduciaries to notify the Data Protection Board and affected data principals of personal data breaches; we help define your internal threshold and notification workflow before an incident forces the question.
Ready to get audit-ready for DPDPA?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
