Services
Fixed-scope, documented engagements. Every deliverable is designed to stand up to scrutiny โ by your board, your auditors, or the Data Protection Board of India.
DPDP Gap Assessment
A structured review of how your organisation collects, stores, shares and deletes personal data, mapped against applicable provisions of the DPDP Act and Rules. You receive a plain-English findings report and a prioritised remediation roadmap.
Consent & Notice Framework
Drafting of itemised privacy notices (in English and, where required, scheduled Indian languages), consent capture and withdrawal flows for your websites, apps and forms, and a consent register that evidences who consented to what, when.
Data Principal Rights Workflows
Working procedures for handling access, correction, and erasure requests and grievances within defined timelines โ request intake, identity verification, fulfilment, and response templates your team can actually follow.
Retention & Secure Erasure Policy
Purpose-linked retention schedules and documented, verifiable erasure procedures appropriate to the relevant systems, processors, backups and legal-retention requirements.
Breach-Response Readiness
A personal data breach response plan covering detection, containment, and the mandatory intimation to the Data Protection Board and affected data principals โ with drills, templates and escalation matrices prepared before you ever need them.
Ongoing Compliance Support
Retainer-based support: vendor and data processor contract reviews, periodic compliance health checks, staff awareness training, and assistance with Significant Data Fiduciary obligations (DPO support, data audits, impact assessments) if notified.
Take the private readiness self-check View illustrative deliverables
How an engagement works
A defined sequence with visible decisions, owners and evidence.
Included when scoped
Interviews, documentation review, data-flow mapping, control assessment, templates, registers, workshops and evidence review.
Specialists may still be needed
Legal opinions, representation, penetration testing, forensic investigation and specialist security implementation are not implied unless expressly included with appropriately qualified professionals.
Start with the gap assessment
It answers the two questions every leadership team asks first: what applies to us, and how exposed are we today?
Request a proposal