Digital Personal Data Protection Act, 2023 · Digital Personal Data Protection Rules, 2025

The DPDP compliance operating system

Discover where personal data actually is. Bind it to a consent and a purpose. Enforce that binding across every channel it can leave by. Honour the rights of the people it belongs to — and produce, on any given afternoon, the evidence a regulator would ask for.

23
Act sections tracked
15
Rules tracked
11
Service lines
₹250 Cr
Highest penalty ceiling
Why this is one product and not eleven

Discovery is the source of truth. Everything else consumes it.

A DLP policy that matches regular expressions blocks spreadsheets and misses the database. A monitoring tool that does not know which columns hold personal data records every query equally. An AI guardrail that cannot see a purpose cannot tell a legitimate prompt from an unlawful one. Each of these tools fails in the same way for the same reason: it does not know what the data is.

Classification and consent metadata flow from Discovery into every enforcement point, and incidents flow back the other way into Breach Response. That relationship is the product. Bought separately, these are eleven dashboards; built together, they are one compliance posture.

1

Discover and classify

Databases, SaaS, email, file shares, chat, AI platforms — down to table and column.

2

Bind to consent and purpose

Every element carries the artefact that authorises it and the purpose that limits it.

3

Enforce and evidence

Five enforcement points read that binding; every action they take becomes evidence.

Eleven service lines

Activate what you need. Discovery first, because the rest depends on it.

SL-01

Assessment & Audit

Gap assessment against every operative clause, with a risk-rated gap register and a remediation roadmap that names an owner for each item.

SL-02

DPO as-a-Service

A qualified Data Protection Officer on a four-hour response clock, plus regulatory watch and Board liaison.

SL-03

Consent Management

Bilingual notices, purpose-bound consent artefacts, one-click withdrawal, and the propagation map that proves it took effect.

SL-04

Discovery & Classification

The source of truth. Find personal data across databases, SaaS, email, file shares and AI platforms, then classify it down to the column.

SL-05

Access Assurance

Who touched personal data, whether they should have, and automatic response when the answer is no.

SL-06

Training & Awareness

Role-based bilingual curriculum with certification, plus phishing simulation that measures behaviour rather than recall.

SL-07

Breach Response

A 24×7 retainer and a war-room with the statutory clocks running: one hour to acknowledge, four to assess, seventy-two to the Board.

SL-08

Data Loss Prevention

Policies driven by classification rather than regular expressions, across email, endpoint, cloud, web and database.

SL-09

AI Processing Guard

Prompt inspection, output control and shadow-AI discovery, with consent and purpose validated before a model sees the data.

SL-10

Database Activity Monitoring

Every query against personal data, with the service account resolved back to the human behind it.

SL-11

Access Gateway

Browser-level prevention: the moment before regulated data is typed into an untrusted form is the moment to intervene.

Traceable to the statute

Every screen cites the clause it satisfies

The clause registry holds all 38 operative obligations of the Act and the Rules as first-class records — each with its obligation text, who it applies to, which module discharges it, what evidence it requires, and its penalty ceiling. Readiness is computed from that coverage, not asserted.

When a regulator asks how you satisfy Section 8(4), the answer is a screen with the evidence attached, not a policy document written eighteen months ago.

What non-compliance costs

  • ₹250 croreFailure to take reasonable security safeguards
  • ₹200 croreFailure to notify a personal data breach
  • ₹200 croreBreach of obligations relating to children's data
  • ₹150 croreBreach of additional obligations of a Significant Data Fiduciary
  • ₹50 croreBreach of any other provision

Penalties are per instance of breach as determined by the Data Protection Board of India, having regard to the nature and gravity of the breach, the nature of the data affected, and whether any mitigating action was taken.

Three front doors

The same underlying record, seen from three sides. A consent withdrawn in the citizen portal appears in the console's propagation map within seconds.

Fiduciary Console

For the DPO, the compliance team and the data owners. Every obligation, every piece of evidence, every clock.

Open the console

Data Principal Portal

For the citizen or customer. See consents, withdraw one, exercise a right, file a grievance — in English or Hindi.

Open the portal

Oversight Console

For a nodal agency or a group head office. Portfolio readiness, SLA monitoring, escalations across every entity.

Open oversight

Built for both markets

Government departments

  • Nodal-agency oversight across every department on one rate contract
  • Bilingual notices and portal, Eighth Schedule languages
  • SLA monitoring with penalties computed from the contract schedule
  • Legitimate-use grounds for subsidy, benefit and service delivery
  • Seven-year evidence retention as standard

Enterprises

  • Group head-office view across business units
  • Significant Data Fiduciary pack: DPIA, audit, algorithmic due diligence
  • Processor and sub-processor registry with DPA status
  • Cross-border transfer register
  • White-label branding per tenant

Start with the question a regulator would ask first

Where is your personal data, and what authorises you to hold it? The onboarding assessment takes about ten minutes and ends with a readiness score you can defend — including whether you are a Significant Data Fiduciary, which most organisations get wrong in one direction or the other.