Services

Fixed-scope, documented engagements. Every deliverable is designed to stand up to scrutiny โ€” by your board, your auditors, or the Data Protection Board of India.

๐Ÿ”

DPDP Gap Assessment

A structured review of how your organisation collects, stores, shares and deletes personal data, mapped against applicable provisions of the DPDP Act and Rules. You receive a plain-English findings report and a prioritised remediation roadmap.

Typical scope: 2โ€“4 weeks ยท interviews, data map, scored findings and management roadmap. Final timing and fees follow an initial scoping call.

View service details

โœ๏ธ

Consent & Notice Framework

Drafting of itemised privacy notices (in English and, where required, scheduled Indian languages), consent capture and withdrawal flows for your websites, apps and forms, and a consent register that evidences who consented to what, when.

Typical scope: collection-point inventory, notice pack, consent register design and withdrawal workflow. Translation is separately scoped.

View service details

๐Ÿ™‹

Data Principal Rights Workflows

Working procedures for handling access, correction, and erasure requests and grievances within defined timelines โ€” request intake, identity verification, fulfilment, and response templates your team can actually follow.

Typical scope: intake form, verification steps, responsibility matrix, request register and response templates.

View service details

๐Ÿ—‚๏ธ

Retention & Secure Erasure Policy

Purpose-linked retention schedules and documented, verifiable erasure procedures appropriate to the relevant systems, processors, backups and legal-retention requirements.

Typical scope: retention schedule, deletion responsibility matrix, exception register and evidence checklist. Technical implementation is separately scoped.

๐Ÿšจ

Breach-Response Readiness

A personal data breach response plan covering detection, containment, and the mandatory intimation to the Data Protection Board and affected data principals โ€” with drills, templates and escalation matrices prepared before you ever need them.

Typical scope: response playbook, escalation matrix, notification templates and one tabletop exercise.

View service details

๐Ÿค

Ongoing Compliance Support

Retainer-based support: vendor and data processor contract reviews, periodic compliance health checks, staff awareness training, and assistance with Significant Data Fiduciary obligations (DPO support, data audits, impact assessments) if notified.

Typical scope: agreed monthly support hours and review calendar; legal opinions and specialist security testing are outside scope unless expressly included.

Who we work with: SMEs, professional practices, schools and ed-tech, healthcare providers, NBFCs and fintech partners, e-commerce sellers โ€” any organisation that processes personal data digitally in India and needs a defensible compliance position without a full-time privacy team.

Take the private readiness self-check View illustrative deliverables

How an engagement works

A defined sequence with visible decisions, owners and evidence.

1. ScopeEntities, systems, people and deliverables
2. MapReal data flows, processors and retention
3. AssessApplicable requirements and control evidence
4. RemediatePrioritised actions, owners and dates
5. EvidenceClosure review and maintained registers

Included when scoped

Interviews, documentation review, data-flow mapping, control assessment, templates, registers, workshops and evidence review.

Specialists may still be needed

Legal opinions, representation, penetration testing, forensic investigation and specialist security implementation are not implied unless expressly included with appropriately qualified professionals.

Start with the gap assessment

It answers the two questions every leadership team asks first: what applies to us, and how exposed are we today?

Request a proposal