Documentation
We map what personal data you collect, why, and where it moves, then check that against the DPDP Act and Rules: notice, consent, vendor contracts, security safeguards, breach readiness, retention, and rights handling. You get a written report that ranks every gap by how much it matters, already interpreted for you.
You get a written report that names every gap between what you actually do with personal data and what the DPDP Act and Rules require, ranked by how much each one matters. Not a checklist you fill in yourself. A document someone read your business to write.
Nothing in the DPDP Act is enforceable yet. The operative Rules, notice, consent, security, breach notification, retention, and rights, commence in May 2027, and the Board's inquiry and penalty powers commence the same day. A company that has done nothing so far is not currently non-compliant and not currently exposed to a penalty. We won't tell you otherwise to make a sale.
Building a full documentation set takes months. A customer's procurement team can also ask you to sign a data-processing addendum well before May 2027 arrives. The assessment is where you find out how much work you actually have, before either deadline is close enough to rush.
Scope
We work from what you actually tell us about your product and your data flows. The report states plainly where you stand on each requirement, without scoring you against a generic rubric you can't act on.
Gaps get sequenced by exposure and effort, checked against the May 2027 commencement date, so you get a clear order to work through.
The data-flow summary becomes the base document for everything you'd build after this: the notice, the consent design, the vendor contracts. Nobody redoes that mapping work twice.
Specifics
| Area | What we check it against |
|---|---|
| Notice | Rule 3: standalone, itemised, with the consent-withdrawal and rights links it requires |
| Consent | Section 6: free, specific, informed, unconditional, with an affirmative action |
| Processor contracts | Section 8(2): a processor engaged only under a valid contract |
| Security safeguards | Rule 6(1): encryption, access control, logging, backups, log retention, the processor-contract clause, and organisational measures |
| Breach readiness | Rule 7: both intimation tracks, to affected people and to the Board |
| Retention and erasure | Section 8(7)-(8) and Rule 8: the purpose-no-longer-served test, matched to your actual data |
| Rights handling | Sections 11 to 14 and Rule 14: access, correction, erasure, grievance, nomination, and the ninety-day response ceiling |
If you're a large e-commerce, online gaming, or social media business past the registered-user thresholds in the Third Schedule, we flag that separately, since a fixed three-year retention period applies to those three classes and nobody else. Most clients aren't in that bracket, and we don't pretend they are to make the report sound heavier.
This is documentation and compliance facilitation. We don't give legal advice, we don't represent you before the Data Protection Board, and we don't implement the Rule 6 security controls ourselves. Encryption, access control, and logging are your engineering team's work. We tell you exactly what has to be true and document that it is, which is a different job from building it.
Process
Step 1 of 4
Tell us about your data
What you collect, why, and where it moves, in your own words.
Common mistakes founders make
Clarifications
No. The operative DPDP Rules commence in May 2027, and the Board's penalty powers commence the same day. Nothing about doing this assessment now means you were previously in breach of anything.
A full documentation set takes months to build properly, and a larger customer's procurement team can hand you a data-processing addendum to sign long before May 2027. Starting the assessment now means you're not doing all of it at once, under pressure.
We flag whether you might eventually be notified as one, based on scale, but we don't build SDF-level documentation, DPIAs, or algorithmic audits unless you're actually notified. No SDF list has been notified as of this writing.
We'll tell you what Rule 6(1) requires and where your current setup falls short of it. Building the encryption, access control, and logging itself is your engineering team's job.
Recognition on its own doesn't currently reduce anything under DPDP. The Act has a startup-exemption power at section 17(3), but it hasn't been notified, so it changes nothing yet.
Related
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Tell us about your partners and business and we'll take it from there.
Get a Quote
Skip the hassle — have us do it for you. We do it best.