The DPDP Rules are phasing in through 2026 and 2027. Organisational compliance is mandatory by 13 May 2027.

What this means for you

Data protection that fits the way your business actually runs.

Most small and medium businesses hold more personal data than anyone realises, spread across spreadsheets, WhatsApp, a CRM and half a dozen tools nobody reviewed. We find all of it, fix what needs fixing, and leave your team with a record they can maintain.

The compliance timeline
Aug 2023
The Act passed

The DPDP Act became law. Almost all of the operational detail was left to rules made under it.

In force
The regulator and the definitions

The Data Protection Board exists and the core definitions already apply to your business.

2026
The rules phase in

Obligations commence in stages rather than all at once. The consent manager machinery comes into effect ahead of the rest.

May 2027
Substantive obligations apply

The point most organisations are working towards, and the point from which you have to be able to show your position rather than describe it.

Find the data

We work through your admin consoles, drives, messaging tools and vendor list until every place personal data sits is written down.

See where you stand

A status quo analysis tells you what your current notices, consents, contracts and controls actually do, as against what they claim to do.

Fix it properly

We draft the notices, policies, procedures and contract terms your business needs, then support your team while they go live.

Prove it later

You finish with a dated evidence pack, a trained team and a review calendar, so you can answer questions long after we leave.

Who this is for

Built for businesses without a compliance department.

Large companies hire a data protection team. Everyone else has a founder, an operations lead and an overloaded finance person. The work below is scoped for that reality. Pick the closest match to see where personal data usually sits.

Consultancies, agencies, clinics, training providers, professional firms and anyone selling time rather than stock.

Where personal data usually sits
SystemWhat it holdsWhat usually needs attention
Email and shared drivesClient lists, proposals, scanned identity documents, signed contractsFormer staff still hold access, and nothing is ever deleted
WhatsAppClient conversations, group broadcasts, documents sent by clientsBusiness data sits on personal phones with no record of consent
CRM or spreadsheetLeads, enquiry forms, call notes, follow up historyLeads collected years ago are still contacted, with no basis recorded
HR and payrollEmployee records, bank details, identity proofs, attendanceNo retention rule, so records of staff who left in 2019 are still live
SubcontractorsFreelancers and partner firms handling your client dataContracts say nothing about data protection responsibilities

Your business will not match any of these exactly, and that is the point. The engagement is shaped around what you actually run, not around a template of what a business your size is assumed to have.

What we usually find

The same gaps turn up in almost every first assessment.

None of these come from carelessness. They come from a business growing faster than anyone had time to document. Recognising several of them is normal, and it is a good reason to start.

Nobody can list every place personal data sits

The founder knows the CRM, the operations lead knows the drive, and nobody knows about the forms a departed intern set up. Until the list exists, every other control is guesswork.

The privacy policy describes a different company

It was copied from a template or from a competitor, it has not been touched since the website was built, and it does not describe what the business now collects or who it now shares data with.

Consent is bundled, pre ticked or simply assumed

A single checkbox covers terms, marketing and data sharing at once, or there is no checkbox at all. There is no record of who agreed to what, and no way for anyone to change their mind.

Marketing runs on lists with no origin

Numbers were imported from an old database, collected at an event three years ago, or bought from a vendor. When someone asks how you got their number, there is no answer on file.

Former staff and former vendors still have access

Offboarding covers the laptop and the email account but misses the shared drive, the WhatsApp group, the analytics dashboard and the vendor portal.

Vendor contracts say nothing about data

Your courier, payroll provider, marketing agency and support tool all handle personal data on your behalf. The contracts cover price and delivery, and stop there.

Nothing is ever deleted

There is no retention rule, so the business holds every record it has ever created. That is storage you pay for, and exposure you carry, for data you no longer use.

There is no plan for the bad day

If a laptop is lost or an account is compromised tomorrow morning, no one knows who to call first, what to check, what to write down or who has to be told.

Honest comparison

A tool, a report, or a programme. They are not the same purchase.

Most businesses looking at this are choosing between buying a consent tool, commissioning a one-off report, and running a proper programme. Here is the comparison as we would make it, including the places where a tool genuinely wins.

What each option actually gives you
What you need A consent tool on its own A one-off report Working with us
A written record of every place personal data sits No Yes Yes
A reasoned position on each activity, not just a findings list No Varies Yes
Notices, policies and procedures drafted for you No Rarely Yes
Consent captured and logged inside your product Yes No We specify it, your tool runs it
Notices in regional languages Sometimes Rarely Yes
A grievance process that has been tested, not just written No No Yes
Data protection terms for your vendor contracts No Varies Yes
A dated evidence pack you can produce on request Consent logs only The report itself Yes
Something that keeps working after handover While you pay No Review calendar, plus optional periodic review
One accountable point of contact No Yes Yes
Cost after the first year Recurring licence None, and nothing maintained Optional only

Where a tool genuinely wins

If you need consent captured on a website or inside an app, logged against a timestamp and a notice version, a platform does that far better than a consultant can. We will not pretend otherwise, and we will not try to sell you a spreadsheet instead.

What a platform cannot do is tell you what to collect consent for. It does not know which of your activities need consent, which sit on another basis, what your courier does with the data afterwards, or when any of it should be deleted. Bought first, it gets configured around guesses, and a confidently logged record of the wrong consent is worse than no record at all.

So we stay platform neutral. We tell you whether you need one, help you choose, specify exactly what it must capture, and check it once it is live. We take no referral fee from any of them, which is why the recommendation is sometimes that your existing setup is already enough.

Where we differ from a one-off report

A report tells you what is wrong. It is then your problem to turn thirty findings into thirty documents, which is where most compliance projects quietly stop.

We draft the documents. Notices, policies, procedures, consent text and vendor contract terms arrive written for your business, and we stay with you while they go live rather than handing over a list and invoicing.

We are also honest about the ongoing part. We are not a subscription. What continues after we leave is an evidence pack your team maintains and a review calendar telling them what to check and when. If you would rather have us check it with you, a periodic review is available and it is genuinely optional. We would rather you did not need us.

Already bought a tool? Good. We work with what you have rather than replacing it, and part of the engagement is checking whether it is configured around your actual processing or around assumptions. That check costs a great deal less than the licence already does.

The engagement

Step by step, end to end, scoped to your business.

The work runs as a sequence of named steps, each closing with documents your team keeps. How many steps apply, and how deep each one goes, depends on what you run and what you already have. We agree that before anything starts.

Intake and engagement

We confirm there is no conflict, agree the scope in writing, name the people responsible on your side, and set the interview schedule.

Discovery and mapping

Interviews across functions, a written record of every processing activity, and diagrams showing how data moves from collection to deletion.

Gap assessment

We test what your current notices, consents, contracts and access controls actually achieve, and record where practice and paperwork have drifted apart.

Compliance Support

We write the notices, policies, procedures, contract terms and consent flows your business needs. You receive drafts, not a list of recommendations.

Implementation support

A ticket level plan your developers or vendors can work from, with us reviewing as each item goes live rather than after everything breaks.

Training, assurance and close out

Training for the people who touch personal data, a test of whether the new processes hold, and a close out pack with the open items written down.

Breach response

A plan for the bad day: who acts in the first hours, what gets written down, who has to be told and how quickly. We draft the notification letters in advance and run one practice exercise with your team.

Requests from customers and staff

People can ask to see their data, correct it, or have it deleted. We build the process that receives, checks and actions those requests inside the timelines, with response templates ready, then test it end to end before handover.

More than one framework

If you serve customers outside India, a second set of rules applies to the same systems. We build one set of controls and record how it answers each framework, so you run one programme rather than two.

Why us

A technology practice, not a law firm.


The hardest data protection problems in a small or medium business are rarely questions of interpretation. They are questions of fact. How many systems hold customer data. Which tools did the team start using without telling anyone. Who still has access to the drive. Nobody can answer those from a legal opinion.So our work produces registers, maps, drafted documents and a dated record of what you did, rather than advice you then have to implement alone. An opinion tells you what is expected. A record shows what you did about it. We also keep the scope honest. A business of thirty people does not need the control set of a bank, and we will not sell one. Where a cheaper tool or no tool at all is the right answer, that is what the report says. Engagements end with your team running the work. We do not design the engagement to leave you dependent on us.

Common questions

What business owners ask us first.

No. The obligations follow the data, not the headcount. A fifteen person business holding customer phone numbers and employee records carries the same basic duties as a large company. What changes is proportion. Your controls should match your size and risk, which is exactly what the scoping step decides.

Most of the load falls in discovery, where we need interviews with the people who actually use each system. After that your team reviews drafts and makes decisions. Implementation needs developer or vendor time, which we scope in advance so it does not arrive as a surprise.

A tool collects consent. It does not tell you what you are collecting consent for, whether consent is the right basis for that activity, what your vendors do with the data afterwards, or how you delete it later. Tools help once the underlying map and decisions exist. Bought first, they usually end up configured around guesses.

We write them. Notices, policies, procedures, consent text and the data protection terms for your vendor contracts arrive as drafts prepared for your business, which your team then reviews and adopts. A list of recommendations you have to turn into documents yourself is not a deliverable.

Then more than one framework applies to the same systems. We build a single control set and record how it answers each framework, so you run one programme rather than two. That gets agreed in the applicability step, before any drafting starts.

You hold the evidence pack, the trained team and a review calendar telling you what to check and when. If you would rather not run it alone, we can stay on for a set number of hours each month, with a named person who already knows your systems, to check new tools before they go live, handle requests as they arrive, keep the record current and be reachable when something goes wrong. That is optional and priced separately. The work is built so you can run it without us.

Start here

Thirty minutes, and you will know where you stand.

Tell us what your business runs on. We will tell you which gaps matter most, whether or not you decide to work with us.