Documentation
The full artifact set a DPDP engagement actually needs: the notice, the consent and withdrawal design, the data inventory, the retention schedule, the vendor contracts, the breach plan, and the rights-request process. Every artifact is built from your actual data flows, drafted for your business rather than assembled from a template with your logo dropped in.
The full artifact set a real DPDP engagement needs: the notice, the consent and withdrawal design, the data inventory, the retention schedule, the vendor contracts, the breach plan, and the rights-request process. Every piece is built from your actual data flows and drafted for your business.
Most of what a DPDP-compliant company needs isn't one document. It's seven, each answering a different question, and each one only works if it's built from the others. A privacy notice that doesn't match your retention schedule, or a vendor contract that doesn't match your breach plan, creates the exact paper trail that fails a review. This is the pack that gets built as one connected set.
None of this is enforceable yet: the Rules that give these documents legal weight commence in May 2027. Building the set now means you're not assembling it from scratch under deadline pressure, and it means you're ready the day a customer's procurement team asks for your data-processing terms, which tends to arrive first.
Scope
The notice stands on its own, itemises what you collect against why you collect it, and states how to withdraw consent, exercise rights, and complain to the Board, exactly what Rule 3 asks for and a footer policy almost never delivers.
The consent design covers how consent is captured, how withdrawal stays as easy as giving it, and what record you need to meet the burden of proof, which section 6(10) places on you as the Data Fiduciary.
The vendor agreements carry the Rule 6(1) safeguard list as binding contract terms on your processors: encryption, access control, logging, backups, one-year minimum retention on logs, and the security-safeguard clause itself.
The breach plan and its templates exist before anything happens. Rule 7 gives you a window measured in hours for the Board report, which is not survivable if you're drafting the template during the incident.
Specifics
A privacy notice, a consent flow, a vendor contract, and a breach plan each get read by a different audience under different pressure. A visitor reads the notice in ten seconds. A procurement officer reads the vendor contract line by line before signing anything. Folding all of it into one document either drowns the notice in legal text it can't carry, per Rule 3(a), or leaves the vendor contract too thin to actually bind anyone. Seven focused documents, built from one shared data inventory, do the job each one is actually asked to do.
| Artifact | Built against |
|---|---|
| Privacy notice | Rule 3(a) standalone requirement, Rule 3(b)(i)-(ii) itemisation, Rule 3(c)(i)-(iii) the three required links |
| Consent and withdrawal design | Section 6(1) consent standard, 6(4) withdrawal parity, 6(10) burden of proof |
| Record of processing (data inventory) | The base map every other artifact is drafted from |
| Retention and erasure schedule | Section 8(7)-(8) purpose-no-longer-served test, Rule 8(2) forty-eight-hour notice, Rule 8(3) one-year floor |
| Vendor data-processing agreements | Section 8(2) valid-contract requirement, Rule 6(1)(f) processor-contract clause |
| Breach response plan and templates | Section 8(6), Rule 7(1) and 7(2) intimation tracks |
| Rights-request and grievance SOP | Sections 11 to 14, Rule 14(1) published means, Rule 14(3) ninety-day response ceiling, Rule 9 published contact |
There's no fixed statutory retention period for an ordinary company. The Third Schedule's flat three-year figure applies only to an e-commerce entity with 2 crore or more registered users, an online gaming intermediary with 50 lakh or more, or a social media intermediary with 2 crore or more. Everyone else works from the purpose-no-longer-served test in section 8(7)-(8), and that's what your schedule gets built on unless you're actually in one of those three brackets.
Process
Step 1 of 4
Map your data
Vendors, processors, internal systems, and where consent actually gets collected today.
Common mistakes founders make
Clarifications
If you only need the notice and its consent-screen copy, our privacy notice drafting service covers that on its own at a lower ticket. This pack is for when you need the full set built together.
Only if you're an e-commerce, online gaming, or social media business past the registered-user thresholds in the Third Schedule. Everyone else gets the purpose-no-longer-served test from section 8(7)-(8), applied to your actual data.
They bind your vendors to the Rule 6(1) safeguards contractually, which is what section 8(2) requires of you as the Data Fiduciary. Whether the vendor's own systems actually meet those safeguards is something only the vendor can confirm. A contract can't guarantee it on its own.
Whoever can actually answer a data-principal's questions, whether or not you formally appoint a Data Protection Officer. Rule 9 requires the contact be published and repeated in every response to a rights request.
Related
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Tell us about your partners and business and we'll take it from there.
Get a Quote
Skip the hassle — have us do it for you. We do it best.