~/services/dpdpService
India DPDP Act readiness
A readiness assessment against the Indian Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The Rules were notified on 13 November 2025 and the substantive obligations take effect on 13 May 2027, so there is a defined window to get ready. We assess how you handle personal data as a Data Fiduciary and tell you what has to change before that date.
What this covers
- Full coverage of the DPDP Act, 2023 and the DPDP Rules, 2025, assessed against how you actually process personal data
- Your role and exposure: Data Fiduciary, Data Processor, and whether you cross the Significant Data Fiduciary threshold
- Consent and notice, which the Rules require to be standalone, itemised and in plain language
- Data Principal rights: access, correction, erasure, nomination and grievance redressal
- Security safeguards, retention and erasure obligations, and the contracts binding your processors
- Breach response against the two-stage Rule 7 timeline: the Board without delay, the detailed report within 72 hours
- Children data and verifiable parental consent, wherever your product reaches users under 18
- The additional Significant Data Fiduciary duties: annual DPIA and data protection audit, an India-resident Data Protection Officer, and algorithmic due diligence
- Every applicable obligation is assessed, not a selected subset
What you receive
- Role and applicability assessment
- Obligation-by-obligation gap assessment
- Consent, notice and rights review
- Breach response readiness review
- Remediation roadmap ahead of 13 May 2027
Scope your India DPDP Act readiness engagement.
A 30 minute scoping call, then a fixed price. No discovery questionnaire, no pressure to buy.