BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationDPDP Documentation Pack

Documentation

DPDP Documentation Pack

The full artifact set a DPDP engagement actually needs: the notice, the consent and withdrawal design, the data inventory, the retention schedule, the vendor contracts, the breach plan, and the rights-request process. Every artifact is built from your actual data flows, drafted for your business rather than assembled from a template with your logo dropped in.

The full artifact set a real DPDP engagement needs: the notice, the consent and withdrawal design, the data inventory, the retention schedule, the vendor contracts, the breach plan, and the rights-request process. Every piece is built from your actual data flows and drafted for your business.

Most of what a DPDP-compliant company needs isn't one document. It's seven, each answering a different question, and each one only works if it's built from the others. A privacy notice that doesn't match your retention schedule, or a vendor contract that doesn't match your breach plan, creates the exact paper trail that fails a review. This is the pack that gets built as one connected set.

None of this is enforceable yet: the Rules that give these documents legal weight commence in May 2027. Building the set now means you're not assembling it from scratch under deadline pressure, and it means you're ready the day a customer's procurement team asks for your data-processing terms, which tends to arrive first.

Scope

What's included

  • The notice stands on its own, itemises what you collect against why you collect it, and states how to withdraw consent, exercise rights, and complain to the Board, exactly what Rule 3 asks for and a footer policy almost never delivers.

  • The consent design covers how consent is captured, how withdrawal stays as easy as giving it, and what record you need to meet the burden of proof, which section 6(10) places on you as the Data Fiduciary.

  • The vendor agreements carry the Rule 6(1) safeguard list as binding contract terms on your processors: encryption, access control, logging, backups, one-year minimum retention on logs, and the security-safeguard clause itself.

  • The breach plan and its templates exist before anything happens. Rule 7 gives you a window measured in hours for the Board report, which is not survivable if you're drafting the template during the incident.

Specifics

The details

Why seven documents and not one master file

A privacy notice, a consent flow, a vendor contract, and a breach plan each get read by a different audience under different pressure. A visitor reads the notice in ten seconds. A procurement officer reads the vendor contract line by line before signing anything. Folding all of it into one document either drowns the notice in legal text it can't carry, per Rule 3(a), or leaves the vendor contract too thin to actually bind anyone. Seven focused documents, built from one shared data inventory, do the job each one is actually asked to do.

What each artifact is built against

ArtifactBuilt against
Privacy noticeRule 3(a) standalone requirement, Rule 3(b)(i)-(ii) itemisation, Rule 3(c)(i)-(iii) the three required links
Consent and withdrawal designSection 6(1) consent standard, 6(4) withdrawal parity, 6(10) burden of proof
Record of processing (data inventory)The base map every other artifact is drafted from
Retention and erasure scheduleSection 8(7)-(8) purpose-no-longer-served test, Rule 8(2) forty-eight-hour notice, Rule 8(3) one-year floor
Vendor data-processing agreementsSection 8(2) valid-contract requirement, Rule 6(1)(f) processor-contract clause
Breach response plan and templatesSection 8(6), Rule 7(1) and 7(2) intimation tracks
Rights-request and grievance SOPSections 11 to 14, Rule 14(1) published means, Rule 14(3) ninety-day response ceiling, Rule 9 published contact

There's no fixed statutory retention period for an ordinary company. The Third Schedule's flat three-year figure applies only to an e-commerce entity with 2 crore or more registered users, an online gaming intermediary with 50 lakh or more, or a social media intermediary with 2 crore or more. Everyone else works from the purpose-no-longer-served test in section 8(7)-(8), and that's what your schedule gets built on unless you're actually in one of those three brackets.

Process

How it works

Step 1 of 4

Map your data

Vendors, processors, internal systems, and where consent actually gets collected today.

Map your data

Vendors, processors, internal systems, and where consent actually gets collected today.

Common mistakes founders make

  • Folding the privacy notice into the general terms of use, which fails Rule 3(a)'s requirement that it be understandable independently of everything else on the page.
  • Drafting a breach response plan without the Board and Data Principal intimation templates already written, then trying to write them for the first time inside the seventy-two-hour Rule 7(2) window.
  • Assuming a Data Processing Agreement alone satisfies section 8(2) without the Rule 6(1) safeguards actually written into it as binding clauses.
  • Publishing a retention schedule with a flat number of years that was never checked against whether the Third Schedule's three classes actually apply to the business.

Clarifications

Frequently asked questions

If you only need the notice and its consent-screen copy, our privacy notice drafting service covers that on its own at a lower ticket. This pack is for when you need the full set built together.

Only if you're an e-commerce, online gaming, or social media business past the registered-user thresholds in the Third Schedule. Everyone else gets the purpose-no-longer-served test from section 8(7)-(8), applied to your actual data.

They bind your vendors to the Rule 6(1) safeguards contractually, which is what section 8(2) requires of you as the Data Fiduciary. Whether the vendor's own systems actually meet those safeguards is something only the vendor can confirm. A contract can't guarantee it on its own.

Whoever can actually answer a data-principal's questions, whether or not you formally appoint a Data Protection Officer. Rule 9 requires the contact be published and repeated in every response to a rights request.

Related

Learn more

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

Record of processing activities (RoPA)
A catalogue of what personal data a business holds, why, where it's stored, and who inside and outside the company can access it.
Data Processing Agreement (DPA)
A contract with a vendor or processor who handles personal data on the business's behalf, making the business's security and breach obligations binding on that vendor too.
Consent Manager
A separately registered intermediary through which a person can give, manage, and withdraw consent. Registering to become one opens in November 2026; using one is not mandatory for an ordinary business.
Data Protection Board
The body that hears DPDP complaints and can direct remedial measures or impose penalties. Its inquiry and penalty powers commence in May 2027.