BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationDPDP Readiness Assessment

Documentation

DPDP Readiness Assessment

We map what personal data you collect, why, and where it moves, then check that against the DPDP Act and Rules: notice, consent, vendor contracts, security safeguards, breach readiness, retention, and rights handling. You get a written report that ranks every gap by how much it matters, already interpreted for you.

You get a written report that names every gap between what you actually do with personal data and what the DPDP Act and Rules require, ranked by how much each one matters. Not a checklist you fill in yourself. A document someone read your business to write.

Nothing in the DPDP Act is enforceable yet. The operative Rules, notice, consent, security, breach notification, retention, and rights, commence in May 2027, and the Board's inquiry and penalty powers commence the same day. A company that has done nothing so far is not currently non-compliant and not currently exposed to a penalty. We won't tell you otherwise to make a sale.

Building a full documentation set takes months. A customer's procurement team can also ask you to sign a data-processing addendum well before May 2027 arrives. The assessment is where you find out how much work you actually have, before either deadline is close enough to rush.

Scope

What's included

  • We work from what you actually tell us about your product and your data flows. The report states plainly where you stand on each requirement, without scoring you against a generic rubric you can't act on.

  • Gaps get sequenced by exposure and effort, checked against the May 2027 commencement date, so you get a clear order to work through.

  • The data-flow summary becomes the base document for everything you'd build after this: the notice, the consent design, the vendor contracts. Nobody redoes that mapping work twice.

Specifics

The details

What the assessment actually checks

AreaWhat we check it against
NoticeRule 3: standalone, itemised, with the consent-withdrawal and rights links it requires
ConsentSection 6: free, specific, informed, unconditional, with an affirmative action
Processor contractsSection 8(2): a processor engaged only under a valid contract
Security safeguardsRule 6(1): encryption, access control, logging, backups, log retention, the processor-contract clause, and organisational measures
Breach readinessRule 7: both intimation tracks, to affected people and to the Board
Retention and erasureSection 8(7)-(8) and Rule 8: the purpose-no-longer-served test, matched to your actual data
Rights handlingSections 11 to 14 and Rule 14: access, correction, erasure, grievance, nomination, and the ninety-day response ceiling

If you're a large e-commerce, online gaming, or social media business past the registered-user thresholds in the Third Schedule, we flag that separately, since a fixed three-year retention period applies to those three classes and nobody else. Most clients aren't in that bracket, and we don't pretend they are to make the report sound heavier.

What we don't do

This is documentation and compliance facilitation. We don't give legal advice, we don't represent you before the Data Protection Board, and we don't implement the Rule 6 security controls ourselves. Encryption, access control, and logging are your engineering team's work. We tell you exactly what has to be true and document that it is, which is a different job from building it.

Process

How it works

Step 1 of 4

Tell us about your data

What you collect, why, and where it moves, in your own words.

Tell us about your data

What you collect, why, and where it moves, in your own words.

Common mistakes founders make

  • Assuming DPIIT startup recognition already exempts you from something under DPDP, when the section 17(3) exemption power has never been notified.
  • Assuming there's a small-company exemption of any kind. There isn't one, on turnover or on headcount.
  • Treating a footer privacy policy as the notice the Rules require, when Rule 3(a) specifically demands something understandable on its own.
  • Concluding that because nothing is enforceable until May 2027, there's nothing worth doing now, when the build genuinely takes months and a customer's contract can arrive earlier.

Clarifications

Frequently asked questions

No. The operative DPDP Rules commence in May 2027, and the Board's penalty powers commence the same day. Nothing about doing this assessment now means you were previously in breach of anything.

A full documentation set takes months to build properly, and a larger customer's procurement team can hand you a data-processing addendum to sign long before May 2027. Starting the assessment now means you're not doing all of it at once, under pressure.

We flag whether you might eventually be notified as one, based on scale, but we don't build SDF-level documentation, DPIAs, or algorithmic audits unless you're actually notified. No SDF list has been notified as of this writing.

We'll tell you what Rule 6(1) requires and where your current setup falls short of it. Building the encryption, access control, and logging itself is your engineering team's job.

Recognition on its own doesn't currently reduce anything under DPDP. The Act has a startup-exemption power at section 17(3), but it hasn't been notified, so it changes nothing yet.

Related

Learn more

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

Data Fiduciary
The DPDP Act term for whoever determines the purpose and means of processing personal data. Almost any company with a signup form is one.
Data Principal
The individual the personal data is about.
Significant Data Fiduciary
A Data Fiduciary the Central Government separately notifies as significant under section 10, based on scale and risk. Not a self-assessment by size, and nobody has been notified yet.
Gap assessment
A structured comparison of what a business actually does against what a law requires, naming each place the two don't match.