DPDP implementation date13 May 2027Review the requirements
dpdpsuite
India's data protection programme

Prepare your organisation for 13 May 2027.

DPDP Suite combines implementation support with software for data discovery, control ownership, Data Principal requests, breach response and compliance evidence.

Managed service or deployment in your AWS accountIndian identifiers are masked in findings and reports
Product previewsample workspace
Connected sources 4 live
Production S33,412 files
scanning
Customer database84 tables
complete
KYC repository1,208 documents
complete
Payments APIsource code
complete
India-native PII inventory
Risk exposure64high
Aadhaar128
PAN94
Bank accounts61
Mobile numbers284

Raw values are not stored in findings or reports. Only masked evidence is retained.

13 May 2027

The implementation window is now a delivery programme.

The principal operational rules covering notices, security safeguards, breach reporting, retention, children’s data, Data Principal rights and cross-border transfers take effect eighteen months after publication of the Rules.

Read the official notification
01

Establish the baseline

Identify systems, processing activities, processors, notices and current controls.

02

Close priority gaps

Assign accountable owners and implement the required legal, technical and operational measures.

03

Test operations

Exercise request handling, grievance management, breach response and evidence production before the deadline.

DiscoveryFiles, object storage, databases and source code
GovernanceRoPA, DPIA, processors, controls and evidence
OperationsConsent, rights requests, grievances and incidents
ReportingOwners, activity history and evidence exports
Product workflow

What teams do in the product

The same workspace holds scanner findings, processing records, control work, data-principal requests, incidents and supporting documents.

01

Scan systems for Indian personal-data identifiers

Scan documents, object storage, supported cloud databases and source code. Aadhaar findings use checksum validation; reports retain masked findings rather than the full value.

Aadhaar checksumPANUPI & bankingCloud & code
Current scope14 deterministic identifier types in the current scanner
Live data inventory
Customer DB42 fieldshigh
KYC documents1,208 fileshigh
Marketing CRM18 fieldsmedium
Product analytics9 eventslow
02

Assess controls and assign remediation

Review each DPDP control, attach supporting material, name an owner and set the next action. Processing activities, DPIAs and processor records use the same workspace.

39 controlsRoPADPIAEvidence
Current scope39 controls grouped into 10 assessment domains
Control coverage
67/100
03

Handle rights requests, consent and grievances

Publish a request form, verify the requester, assign fulfilment work and retain the response history. Notice versions and consent records remain available alongside the request.

Rights portalConsent ledgerNotice versionsSLA tracking
Current scopeOne public privacy centre for each workspace
Privacy centre

How can we help?

1Access my data
2Correct my data
3Erase my data
4Raise a grievance
04

Keep one record for each personal-data breach

Record affected systems and data, assign response tasks, draft notices and preserve the decision timeline. The workspace tracks the detailed-report deadline.

72-hour clockTimelineDraft noticesEvidence pack
Current scope72-hour detailed-report timer and response checklist
Incident command
41:18:22report window remaining

3 of 5 response milestones complete

05

Track implementation work with the product record

Assessment findings become assigned implementation tasks. Legal, security and engineering reviewers can work against the same control and supporting evidence.

Gap assessmentImplementationTrainingManaged ops
Current scopeAssessment, implementation and review in one workspace
Implementation plan
01Discover & assesscomplete
02Design controlscomplete
03Implement workflowsin progress
04Test & operateplanned
Know DPDP

Read the law. Understand the obligation. Start the work.

Our companion knowledge service provides the full DPDP Act and Rules in a searchable format, with practical tools for common first steps.

The DPDP Act, by chapter

Read all nine chapters and move directly to the section relevant to your question.

Open the Act

The 2025 Rules

Review the implementation detail for notices, safeguards, breach reporting, retention and rights.

Explore the Rules

Policy analysis

Check an existing privacy policy and identify provisions that require closer review.

Analyse a policy

Notice drafting

Create a first working draft of a personal data notice from your processing context.

Draft a notice

Know DPDP supports initial understanding. Legal interpretation and implementation decisions should be reviewed in the context of your organisation.

Advisory and implementation

From readiness assessment to operating capability

Our work is organised around decisions, accountable owners and verifiable completion. The product provides the working record for the programme.

01

Executive readiness review

Establish applicability, exposure and the decisions required from management.

Scope this work
02

Data and control assessment

Map processing, review notices and processors, assess controls and prioritise remediation.

Scope this work
03

Implementation programme

Configure workflows, update documentation, implement agreed controls and prepare operating teams.

Scope this work
04

Managed privacy office

Provide structured support for requests, grievances, incidents, evidence reviews and programme governance.

Scope this work
Evidence and activity history

Findings, decisions and documents stay linked

Each control record can hold its owner, status, remediation, reviewer and supporting files. Scanner findings and operational workflows can be included in the same report.

  • Checksum and format validation for Indian identifiers
  • Masked scanner findings in reports
  • Named owners and timestamped activity
  • Exportable assessment and evidence records
sample workspace · report check
$ dpdp report check --workspace sample
> checking controls, owners and evidence files
✓ assessed controls included
✓ owners and review dates included
! open actions listed as open
✓ report package ready

Full scanner matches: excluded
Commercial model

Software, services and private deployment

Subscription and service scope depend on the systems, business units, workflows and hosting model included in the engagement.

Assessment

Fixed project

A documented view of current systems, processing and control gaps.

  • System and process interviews
  • DPDP control assessment
  • Data-flow review
  • Prioritised action register
  • Management readout
Scope an assessment
Implementation

Scoped programme

Configuration and remediation work delivered with your internal owners.

  • Software subscription
  • Workspace configuration
  • Notice and policy support
  • Control implementation
  • Team training and handover
Scope implementation
Private deployment

Enterprise agreement

A dedicated deployment for organisations with infrastructure requirements.

  • Deployment in your AWS account
  • SSO and access configuration
  • Custom data connectors
  • Sector-specific control work
  • Operational support
Discuss deployment
Start with a focused discussion

What must your organisation have in place by May 2027?

Share your current position and the systems in scope. We will recommend the appropriate starting point: an executive readiness review, detailed assessment, implementation programme or product demonstration.

Start on WhatsAppor submit the form
Discussions can include legal, security, product and operations Managed cloud and private AWS deployment are available
WhatsAppWA