DPDP compliance hub
Everything the DPDP Act asks of you, in one workbench.
The Act is short because it delegates detail to rules, which misleads people into thinking compliance is light. Most of its weight sits in five obligations, and each one is a workflow rather than a document.
Run these as workflows, not a spreadsheet
- Data inventory and mappingFind the personal data nobody documented, including the exports and the backups.Open it
- Retention and deletionA period per category, and deletion that actually runs rather than a policy that says it should.Open it
- Consent and noticeFree, specific, informed and withdrawable, propagating to your processors.Open it
- Data principal rightsAccess, correction, erasure, grievance and nomination, each with a clock on it.Open it
- Breach notificationTo the Board and to affected individuals, on a trigger that is not the CERT-In one.Open it
- Penalty exposureAn order of magnitude for the board, and the mitigations that reduce it most.Open it
One thing worth stating plainly, because it catches organisations out: the DPDP breach obligation is separate from the six hour CERT-In duty and is triggered differently. Build one detection and triage process, then run separate reporting paths off it.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












