Skip to main content

Threatsys One suite

DPDP 360Setup · Operate · Automate · Prove

Manage consent, data principal rights, grievance redressal, privacy notices, DPIAs, vendor risk and compliance evidence in one unified DPDP compliance platform.

Built in

  • Consent management
  • Data principal rights
  • Grievance SLA tracking
  • DPIA automation
Open the console
01

Setup

Discovery of where personal data actually sits, then the record of processing built from what systems do rather than what people remember.

02

Operate

Consent, notice, rights requests and grievances run as workflows with clocks attached, so an SLA is measured rather than hoped for.

03

Automate

Retention enforced, deletion propagated, vendor privacy assessments scheduled rather than remembered.

04

Prove

An immutable audit trail and an evidence vault, because under the Act the burden of demonstrating compliance sits with you.

What it is actually for

  • Are we compliant with the DPDP Act?

    A question with no honest answer until you know what personal data you hold and why, which most organisations do not.

  • Can we prove consent?

    Not whether you collect it, but whether you can reproduce what a specific person agreed to, months later, under challenge.

  • Are we meeting rights SLAs?

    Access, correction and erasure requests arriving by email, handled by whoever notices, with no clock running.

  • Could we notify a breach in time?

    The failure is rarely detection. It is that nobody is clear who may declare a breach at 2am.

How it usually goes

  • Re-badged foreign privacy tools built for GDPR, not the DPDP Act
  • Consent captured but not reproducible after the fact
  • Retention policies no system enforces
  • Notice in English only, on a page nobody reads

With DPDP 360

  • Built for the DPDP Act and the draft Rules as written
  • Consent artifacts stored immutably and retrievable per person
  • Deletion that reaches analytics copies, not just the primary store
  • Notices in Indian languages, at the point of collection

What is in the console

  • Consent management

    Capture, withdrawal and the full lifecycle, with an artifact per person you can produce on demand.

  • PII discovery

    Finding personal data across systems, including the analytics copies and exports nobody remembers.

  • Processing register

    Records of processing built from discovery, kept current as systems change.

  • Rights and grievance

    Requests intake, identity verification, fulfilment and the statutory clock.

  • DPIA workflows

    Impact assessments triggered by the processing that warrants them, with a template and worked examples.

  • Breach workflow

    Notification to the Board and to affected people, run as a timed workflow rather than an email chain.

  • Vendor and DPA

    Processor obligations, sub-processor visibility and contract terms tracked per vendor.

  • Multilingual notices

    Notice content in Indian languages, since a notice nobody can read is not notice.

How a rollout runs

  1. 01

    Discover

    Weeks 1 to 4

    Data discovery across systems. Unblocked today regardless of where the Rules land, and everything else sequences off it.

  2. 02

    Design

    Weeks 4 to 8

    Consent model, retention schedule, notice content and the rights process agreed before anything is built.

  3. 03

    Build

    Months 2 to 4

    Consent capture, deletion that actually propagates, rights tooling and processor addenda issued.

  4. 04

    Operate

    Ongoing

    Breach process rehearsed, re-consent completed where the basis was unclear, and evidence accumulating.

Choose how it is deployed

This is usually the first question a regulated buyer asks, and it changes the compliance position as much as the price. Pick one to see what it means for you.

A dedicated instance rather than a shared one, in the region you nominate, operated by us. This is what regulated entities usually land on: the operational burden stays with us, but your data sits alone and the boundary is easy to describe to an auditor.

Choose this when

  • Banking, capital markets and insurance
  • An auditor who asks where exactly the data sits
  • Contractual isolation requirements from your own customers

Effort and cost

Higher than shared cloud, and usually the answer when a regulator is involved.

What people ask before the first call

Why not use a GDPR tool we already have?

Because the obligations differ in ways that matter. The DPDP Act has no lawful basis framework, has its own consent and notice requirements, and treats children's data more strictly. Re-badged foreign tooling tends to model GDPR and leave the India specific duties as free text fields.

The Rules are not fully notified. Should we wait?

No. Discovery, the record of processing and your vendor inventory are unblocked today and everything else sequences off them. Waiting simply compresses the work into whatever transition period you are eventually given.

Can it prove consent for a specific person?

That is the point of it. Consent artifacts are stored immutably and retrievable per Data Principal, because under the Act the burden of demonstrating consent sits with you and a screenshot of your current banner will not discharge it.

Does it handle notices in Indian languages?

Yes. Notice content is managed in multiple Indian languages, since a notice somebody cannot read is not notice in any meaningful sense.

What about deletion in our analytics copies?

Deletion propagates to the systems we are connected to, and the discovery step is specifically designed to find the analytics copies, exports and test environments people forget. Those are usually where the retention problem actually lives.

Works with the rest of the suite

With GRC 360 on, privacy controls sit inside the same control set as everything else rather than in a parallel programme. With AI SOC 360 on, a security incident that touches personal data raises the DPDP notification workflow automatically.

See DPDP 360 against your own environment.

Thirty minutes, your frameworks, your findings. Not a canned demo.