Personal data mapping
Automated discovery and classification of personal data across your systems, so you know exactly what you hold and where.
DPDPA compliance means meeting India's Digital Personal Data Protection Act 2023 and DPDP Rules 2025 - mapping personal data, managing consent, honouring user-rights requests, and being able to notify a breach within the required window. It applies to every business processing Indian residents' personal data, with no exemption for company size.
If any of these describe your business, DPDPA applies - regardless of company size or sector.
You collect names, emails, phone numbers or any personal data from Indian residents - customers, employees or website visitors.
You use third-party tools (CRM, analytics, payment processors) that store personal data on your behalf.
You don't have a documented process for handling a user's request to access or delete their data.
You've never mapped exactly where personal data lives across your systems and vendors.
Every item below is scoped against your gap assessment findings - nothing is sold as a default bundle.
Automated discovery and classification of personal data across your systems, so you know exactly what you hold and where.
Consent capture, withdrawal and audit logs that meet DPDP Rules 2025 requirements.
A working process for access, correction and deletion requests, with response tracking.
Ongoing DPO-level guidance, whether or not you've appointed one internally.
A tested playbook so a real incident doesn't become the first time you've run the process.
Review of Section 8 & 9 obligations across every third party that touches your data.
Yes. Unlike some data protection laws, DPDPA has no exemption for company size - if you process personal data of Indian residents, it applies.
Non-compliance risk includes penalties up to ₹250 crore per violation, in addition to reputational and contractual risk with enterprise customers who now require compliance proof.
Varies by current maturity, but most programmes move from gap assessment to a working baseline within one quarter, with continuous oversight after.
We diagnose first. Where technology is recommended, it's the documented outcome of that diagnosis - never the starting point of the conversation.
2-hour workshop with your team. Written report, prioritised action plan. Diagnosis first - no product pitch.