Home / Services / DPDP readiness
service 04 — compliance

DPDP readiness you can actually operate.

India's Digital Personal Data Protection Act is now the baseline for anyone handling personal data of Indian residents — with penalties that reach ₹250 crore per breach category. We turn the Act's obligations into concrete technical and organizational controls: mapped, implemented, and documented. And when ISO 27001 is on your roadmap, we run the independent internal audits the standard demands.

DPDP Act2023 + Draft Rules
ISO 27001Internal audits
EvidenceDocumented as built

Compliance that lives in your systems, not in a binder.

Most DPDP offerings stop at a policy pack — documents that describe safeguards nobody implemented. We come at it from the engineering side: we find where personal data actually lives in your systems, fix how it's collected, stored, shared and deleted, and only then write the documentation, so the paper matches reality.

Because we build and security-test production systems ourselves, the safeguards we recommend are ones we've implemented ourselves, not theoretical best practice.

What the engagement covers

  • Data mapping — an inventory of what personal data you hold, where it flows, who touches it, and which processors it reaches.
  • Gap analysis — your current state measured against DPDP obligations: notice and consent, purpose limitation, data-principal rights, security safeguards, retention and erasure.
  • Consent & rights flows — implementing notice, consent capture, withdrawal, and access/correction/erasure requests in your actual product, not just your privacy policy.
  • Technical safeguards — encryption, access control, logging and monitoring aligned to the Act's "reasonable security safeguards" duty — verified offensively if paired with a VAPT.
  • Breach-response readiness — a tested notification playbook for the Data Protection Board and affected users, before you ever need it.
  • Documentation & evidence — policies, records of processing, and processor agreements that reflect what's actually deployed.

ISO 27001 internal audit

ISO 27001 requires internal audits at planned intervals — conducted by someone independent of the area being audited. For most teams that means an outsider, and that's a service we run end to end, whether you're preparing for first certification or keeping an existing certificate healthy. For teams on Sprinto, Vanta, Drata or Scrut who need this before Stage 2, it now has a dedicated engagement: the 5-day internal audit, fixed-fee and signed by a CQI/IRCA-certified Lead Auditor.

  • Audit programme & plan — a risk-based internal audit plan covering your ISMS scope, aligned to clause 9.2 and your certification calendar.
  • Controls assessment — sampling and testing of Annex A controls as actually operated — not just as written in the Statement of Applicability.
  • Findings & corrective actions — nonconformities and observations with clear evidence, severity, and practical corrective-action guidance your team can close.
  • Certification-ready reporting — an internal audit report and management-review inputs your certification body will accept at stage 2 and surveillance audits.
  • Technical depth — because we test systems offensively, our audits probe whether controls actually work, not only whether a policy document exists.

How it runs

  • Map — two to three weeks of discovery across systems, teams and vendors.
  • Assess — a prioritised gap report: what fails, what's at risk, what to fix first.
  • Remediate — we implement the technical fixes with your team, or hand your developers an actionable plan.
  • Document — evidence pack assembled as controls go live, kept current if you pair this with our annual audit program.
// questions we hear

Before you ask.

Does DPDP even apply to us?

If you process digital personal data of individuals in India — customers, users, employees — it almost certainly does, whether you're a startup or an enterprise, and regardless of where your servers sit. Obligations scale with your role and volume; the gap assessment establishes exactly which duties apply to you.

Is this legal advice?

No — we're engineers, not a law firm, and we're explicit about that boundary. We deliver the technical and organizational implementation: data maps, safeguards, consent flows, breach playbooks, and evidence. Where legal interpretation is needed, we work alongside your counsel and give them accurate ground truth about your systems to opine on.

How long does readiness take?

The gap assessment typically takes two to four weeks depending on how many systems and vendors are involved. Remediation depends on what it finds — some teams close their gaps in a month, others phase it over quarters. You'll have a realistic, prioritised timeline after the assessment, not before.

We already did ISO 27001 — are we covered?

Partly. ISO 27001 gives you a strong security-management backbone, but DPDP adds data-principal rights, consent mechanics, breach notification to the Data Protection Board, and India-specific processing duties that ISO doesn't touch. The assessment maps what your existing certification already covers so you only build what's missing.

Can you run our ISO 27001 internal audit?

Yes — that's a standing service. The standard requires internal audits by someone independent of the work being audited, which is hard to staff internally. We plan and execute the audit across your ISMS scope, test Annex A controls as they actually operate, document nonconformities with corrective-action guidance, and deliver a report your certification body will accept — before first certification or on your surveillance cycle.

// before the board asks

₹250 crore is an expensive way to learn your gaps.

A gap assessment is a fraction of a fine — and unlike a fine, it comes with a fix list.

Start the assessment →