Whoever runs your DPDP programme runs it here.
Consent, rights, breach, vendors and audit evidence in one place — with the proof assembling itself as you work.
No login. No card. Five minutes to your exposure in rupees.
Indicative output — based on your inputs.
Indicative only. Actual penalties are at the Board’s discretion.
How most people find out
The same question, asked three ways, by people who have just realised the Act applies to them.
You hold patient records, your receptionist collects them on paper, and you have never called anyone a Data Fiduciary.
An enterprise customer attached a DPDP questionnaire to your renewal and you have four days to answer it.
You hold candidate CVs, your clients’ employee payroll, and your own staff files — and they are not the same problem.
What’s coming, and what it costs
“We’ve got this covered.”
Most organisations have the left-hand column. Fewer have the right.
| You already have | What usually isn’t there yet |
|---|---|
| A consent tick-box in your HIMS, CRM or ERP | An itemised Rule 3 notice, in the languages the Act requires, as easy to withdraw as it was to give |
| A named DPO and a grievance email address | A queue with clocks on it, so nothing quietly runs past its deadline |
| A legal team that knows the Act cold | A portal your customers can actually use — no account, no fee |
| Customer data across fourteen systems | A way to find every one of them holding a single person’s data, so erasure is real and not asserted |
| Records. Somewhere. | Proof a regulator can verify independently, without trusting you |
Your team isn’t the gap. The system is.
We take the manual work off your team.
| Team | Stays theirs | Comes off their desk |
|---|---|---|
| DPO & compliance | The decisions, the accountability, the conversation with the Board | Chasing deadlines across five modules, building the inventory by hand, remembering which clock is running |
| Legal & counsel | The legal positions, the risk calls, the sign-off | Drafting every notice from scratch, versioning them, translating them, re-checking each against the clause |
| IT & security | The architecture and the security posture | Building consent capture, building a rights portal, pulling data together for every request — and being asked to hold data they never wanted |
| Consultants & CAs | The advice, and the client relationship | Rebuilding the same assessment for every client, chasing documents at audit, keeping a hundred spreadsheets current |
| Founder & CFO | How much risk the business chooses to carry | Not knowing what that risk actually is |
Nobody here gets replaced. They stop doing this by hand.
5,000+ consent notice templates, vetted by our legal team.
Across industries and purposes — hospital admission, student enrolment, KYC onboarding, delivery tracking, employee records, marketing. Each one written against the section it has to satisfy, and reviewed by practising counsel before it ever reaches you.
Your legal team edits rather than drafts. That is usually the difference between a notice programme taking a quarter and taking a fortnight.
- Written to the clause — every template carries the provision it satisfies
- Purpose-specific — not one notice stretched to cover everything you do
- Counsel-reviewed — by lawyers who practise Indian data protection
- Kept current — updated as the Rules and guidance move
One platform, end to end
DPDP compliance software that diagnoses what is missing, fixes it in the order that matters, and produces the proof.
Diagnose
Answer questions about how your organisation actually works. Get a score, a ranked gap list and your penalty exposure in rupees. Five minutes, no login.
Fix
Close gaps in the order of what they cost you. Consent, rights, breach, vendors, data mapping — each guided, each carrying the clause it satisfies.
Prove
Every action writes itself to the record as it happens. The audit pack is generated, not assembled the week before.
One data model
Declare a system once and every module reads it. Add a module later and there is nothing to migrate and nothing to re-enter.
Installs in an afternoon
A script tag for consent, a signed link for the rights portal, an API for everything else. No agents on your servers, no database connections.
Metadata only
We record which systems exist, what categories they hold and what was consented to. Your customers’ records never leave the systems they are already in.
Hosted in India
Data at rest, backups included, stays in-country — which is the answer your procurement team will need in writing.
Ten modules. One platform.
Start with one. Add another whenever you like — one data model underneath, so there is nothing to migrate and nothing to re-enter.
Compliance Suite
Six modules — liveDPDP Scorecard
LiveAutomated gap assessment with penalty exposure in rupees and a phased remediation plan.
Consent Management
LiveRule 3 notices in the Eighth Schedule languages, a lightweight widget, and an append-only consent log.
DSR Automation
LiveAccess, correction, erasure and nomination — identity-verified and SLA-tracked end to end.
Data Registry
LiveYour record of processing, pre-filled rather than blank. Metadata only — never the data itself.
Breach Management
LiveDeclare, scope and notify against the Rule 7 clock — the Board and the people affected.
Vendor Governance
LiveProcessor register, DPA status and risk scoring — sharing blocks when a DPA lapses.
AI Suite
Four modules — coming soonAI Consent Drafter
Coming soonGenerates a Rule 3 notice from your actual processing, in plain language. How the drafter works
Policy Gap Detector
Coming soonReads your existing policies and flags where they fall short of the Act. What it finds
Evidence Packager
Coming soonAssembles the audit pack and writes the plain-English summary that goes on top. What it writes
Compliance Copilot
Coming soonAnswers “are we allowed to do this?” with the clause it relied on. What it answers
Anyone can verify your compliance. Including you.
Every consent, withdrawal and breach action is written to an append-only log the database itself will not let anyone edit. Each evidence pack carries a SHA-256 manifest that a regulator, an auditor or a customer can re-verify independently — without an account, and without taking our word for it.
Your team, or ours
Run it with your own team or bring in our techno-legal consultants — both work in the same system. DPDP compliance solutions you end up owning, not renting.
Find out where you stand
A consultant-grade picture of your exposure, built on the assessment engine rather than on three weeks of interviews.
- Gap Assessment
- Data Discovery & RoPA build
- DPIA & SDF readiness
Have it run for you
A named DPO and a team who work your queues day to day — or who sit alongside yours and take the load off it.
- DPO as a Service
- Privacy Operations, managed
- Notices, policies & consent drafting
- DPA & contract review
Be ready when you’re asked
The evidence, the drills and the paperwork that turn a Board question or a customer audit into a short conversation.
- Breach readiness & response
- Audit readiness & support
- Training & certification
How an engagement starts: a discovery call, a scoped proposal, a named lead, and delivery on the platform. When the engagement ends, you keep the system it ran on.
Book a callA consultant-grade gap assessment, free.
Yours to keep, whether or not you buy anything.
Your score
Where you stand across every DPDP obligation, and what the band actually means.
What’s missing
Every gap, ranked — each with the section it comes from and the penalty attached to it.
What to do about it
A phased plan: 0–30 days, 30–90 days, 90+ days. With owners, so it can actually be assigned.
What it costs depends on what you hold
Three things move the number, and you can work out where you sit on all three before speaking to anyone.
How many people
A single-location clinic and a lender with two million customers owe the same obligations and carry very different volumes of them.
How much estate
Systems, entities, and the processors acting on your behalf. Ten vendors is a different exercise from a hundred, and it is the number most businesses underestimate.
How much you want carried
Run it with your own team and the platform is most of the cost. Hand us the function and the services are. Most people land somewhere in between.
We would rather scope it than publish a table you have to reverse-engineer. Start with the free Scorecard — five minutes, no account, and it tells you the size of your own problem before anybody quotes you for it.
Frequently asked
We already have a DPO and a legal team. What does this add?
The machinery they don’t have. A portal your customers can use without an account, a queue that tracks every deadline, a map of which systems hold one person’s data so erasure is real, and evidence anyone can verify. Your team keeps the judgement — this removes the manual work underneath it.
Can you provide the people as well as the platform?
Yes. We have empanelled lawyers, Data Protection Officers and security specialists who can run your programme or work alongside your team — as a named DPO, on a gap assessment, or drafting notices and processor agreements. They work in the same platform, and you keep it when the engagement ends.
Our CRM already captures consent. Isn’t that enough?
It captures a tick. The Act asks for more: an itemised notice describing each purpose, in plain language, available in the required languages, with withdrawal as easy as giving — and a record you can produce years later showing exactly what was agreed, when, and to what. Most systems capture the tick and none of the rest.
What is the maximum penalty under the DPDP Act?
The Act’s Schedule sets penalties by the obligation breached. The largest single item is ₹250 crore, for failing to take reasonable security safeguards. Breach-notification and children’s-data failures carry up to ₹200 crore, Significant Data Fiduciary duties up to ₹150 crore, and most other breaches up to ₹50 crore.
How quickly must we report a personal data breach?
Under Rule 7 of the DPDP Rules 2025 you must inform the Data Protection Board without delay on becoming aware of a breach, and follow it with detailed particulars within 72 hours. Affected Data Principals must also be informed without delay. The 72 hours is the deadline for the full account, not for the first intimation.
Do you store our customers’ personal data?
Some of it, and only where the obligation cannot be met without it — which is a more useful answer than a flat no. The Data Registry, the map of your estate, holds metadata and nothing else: which systems exist, what categories they hold, who owns them. It never holds a record about a person. Consent and rights are necessarily different, because §6(10) makes you able to demonstrate a particular person consented, and §11 makes you answer that person — neither is possible without a record of them. So the consent log and the rights queue do hold one. We keep it minimal, identifiers are stored as hashes, and where a contact address is needed to reply to somebody it is encrypted at rest. Everything sits in India, and your operational databases stay where they are — we never copy them.
Where is our data hosted?
On infrastructure in India. Data at rest, backups included, stays in-country.
Is DPDP Act compliance mandatory for a company our size?
There is no revenue or headcount threshold. The Act applies to anyone processing digital personal data in India, and to anyone outside India processing it to offer goods or services here. A ten-person clinic and a listed hospital chain owe the same core duties — notice, consent, security, breach reporting, and honouring rights requests. What changes with size is the volume of work, which is the part DPDP compliance software takes off you.
Is DPDP compliance in India different from GDPR?
The shape is familiar; the detail is not. DPDP compliance India turns on things the GDPR does not have — legitimate uses under §7 instead of six lawful bases, verifiable parental consent for everyone under 18, a breach report to the Board inside 72 hours with no severity threshold below which you may stay quiet, and a blacklist for transfers abroad rather than an adequacy list. There is also no data portability right here. Tooling built for the GDPR maps onto this badly, which is why ours is built against the Act’s own sections.
Can we start with just one module?
Yes. Most organisations start with the free Scorecard, then take on Consent or DSR first depending on where their exposure is largest. Modules share one data model, so adding another later needs no migration. Buying a DPDP solution one obligation at a time is the sensible way round — it is also why nothing here is sold as an all-or-nothing suite.
Thirty minutes with a specialist about your own obligations. Not a product pitch.
What compliance teams tell us
Real client quotes, attributed by role and sector — we never name a client.
DPDP, explained properly
DPDP Compliance Solution in India: How RuleExpert Helps Businesses Get Audit-Ready (2026 Guide)
19 September 2026 · 25 min read DPDP ActSignificant Data Fiduciary: What are those and Obligations Under the DPDP Rules
17 September 2026 · 16 min read DPDP ActWhat is Data Protection Board of India: Role and Process Explained
14 September 2026 · 18 min readWorking across
Find out where you stand.
Five minutes, free, and you keep the report either way.


