4

Settings

Organisation profile, people, modules and the integrations that feed them.

Core

Compliance coreAlways on

Compliance register, processing register, risk register, evidence vault, audit trail and reporting. Always on — every other module writes into it.

Data Principal Rights

Access, correction, erasure, nomination and grievance handling with the statutory clocks. Paired with the public Data Principal portal.

DPIA

Data Protection Impact Assessments and algorithmic due diligence. Required annually for a Significant Data Fiduciary.

DischargesS.10R.12

Service lines

The eleven service lines. Codes match the procurement line items so a buyer can map the product onto a rate contract without a translation table.

DPDP Gap Assessment & AuditSL-01

Map data flows, test every processing activity against the Act, and produce a risk-rated gap register with a remediation roadmap.

Data Protection Officer as-a-ServiceSL-02

A named DPO, an advisory queue with response SLAs, regulatory monitoring, and the monthly reporting the role is expected to produce.

Consent Management PlatformSL-03

Granular, purpose-bound consent with multilingual notices, one-click withdrawal, an immutable artefact trail, and Consent Manager interoperability.

Data Discovery & ClassificationSL-04

Find personal data everywhere it lives, classify it, bind it to consent and purpose, and drive retention and erasure from that binding.

Personal Data Access AssuranceSL-05

Watch every identity that touches personal data, baseline normal behaviour, and cut off access when it deviates.

DischargesS.8(4)R.6
Training & Awareness ProgrammeSL-06

Role-based bilingual curriculum, phishing simulation, certification, and department-level completion evidence.

Breach Response & NotificationSL-07

Round-the-clock intake, a war-room with the statutory clocks running, and both Board and Data Principal notifications drafted from real impact data.

DischargesS.8(6)S.27R.7
Data Loss PreventionSL-08

Classification-driven enforcement across email, endpoint, cloud, web, API and database — the last-mile control when everything else fails.

Personal Data Intelligent Processing GuardSL-09

Inspect prompts and outputs across every AI system, including shadow AI, and enforce consent and purpose at the model boundary.

DischargesS.6S.8(4)S.9
Database Activity MonitoringSL-10

Full session context on every query against a personal-data table, with tamper-resistant audit and mass-read detection.

DischargesS.8(4)R.6R.7
Digital Personal Data Access GatewaySL-11

Browser-layer inspection of the rendered page and the full redirect chain, blocking data entry into deceptive sites.

DischargesS.8(4)R.6