Data protection that fits the way your business actually runs.
Most small and medium businesses hold more personal data than anyone realises, spread across spreadsheets, WhatsApp, a CRM and half a dozen tools nobody reviewed. We find all of it, fix what needs fixing, and leave your team with a record they can maintain.
The DPDP Act became law. Almost all of the operational detail was left to rules made under it.
The Data Protection Board exists and the core definitions already apply to your business.
Obligations commence in stages rather than all at once. The consent manager machinery comes into effect ahead of the rest.
The point most organisations are working towards, and the point from which you have to be able to show your position rather than describe it.
Find the data
We work through your admin consoles, drives, messaging tools and vendor list until every place personal data sits is written down.
See where you stand
A status quo analysis tells you what your current notices, consents, contracts and controls actually do, as against what they claim to do.
Fix it properly
We draft the notices, policies, procedures and contract terms your business needs, then support your team while they go live.
Prove it later
You finish with a dated evidence pack, a trained team and a review calendar, so you can answer questions long after we leave.
Built for businesses without a compliance department.
Large companies hire a data protection team. Everyone else has a founder, an operations lead and an overloaded finance person. The work below is scoped for that reality. Pick the closest match to see where personal data usually sits.
Consultancies, agencies, clinics, training providers, professional firms and anyone selling time rather than stock.
| System | What it holds | What usually needs attention |
|---|---|---|
| Email and shared drives | Client lists, proposals, scanned identity documents, signed contracts | Former staff still hold access, and nothing is ever deleted |
| Client conversations, group broadcasts, documents sent by clients | Business data sits on personal phones with no record of consent | |
| CRM or spreadsheet | Leads, enquiry forms, call notes, follow up history | Leads collected years ago are still contacted, with no basis recorded |
| HR and payroll | Employee records, bank details, identity proofs, attendance | No retention rule, so records of staff who left in 2019 are still live |
| Subcontractors | Freelancers and partner firms handling your client data | Contracts say nothing about data protection responsibilities |
Online stores, direct to consumer brands, retailers with loyalty programmes and anyone running paid acquisition.
| System | What it holds | What usually needs attention |
|---|---|---|
| Store platform | Customer accounts, order history, delivery addresses, phone numbers | Account deletion is not actually possible from the customer side |
| Marketing tools | Email lists, WhatsApp broadcast lists, abandoned cart data | Lists are bought, imported or scraped with no consent record |
| Advertising pixels | Browsing behaviour shared with advertising platforms | Tracking starts before anyone agrees to it |
| Logistics and payments | Customer details passed to couriers and payment providers | No written data terms with the parties receiving the data |
| Support channels | Complaints, returns, call recordings, chat transcripts | Recordings are kept indefinitely and nobody was told they are recorded |
Software companies, app developers and technology teams, including those serving customers outside India.
| System | What it holds | What usually needs attention |
|---|---|---|
| Production database | End user accounts, profile data, usage records | Engineers hold standing production access with no logging |
| Analytics and logging | Device identifiers, location, session recordings, error reports | Logs capture far more personal data than the product needs |
| Cloud and hosting | Backups, storage buckets, staging copies of live data | Test environments run on real customer data |
| Third party services | Payment, messaging, support and infrastructure providers | Nobody has listed which vendors receive personal data, or on what terms |
| AI features | Prompts, uploaded content and conversations sent to model providers | Features shipped before anyone read the provider's data terms |
Schools, coaching centres, member associations, trusts, foundations and community organisations.
| System | What it holds | What usually needs attention |
|---|---|---|
| Admission and enrolment | Applicant records, family details, identity documents | Paper and digital records held forever with no stated purpose |
| Records about children | Student information, photographs, attendance, assessment | Parental permission is assumed rather than captured and recorded |
| Member and donor lists | Contact details, contribution history, volunteer records | Lists shared with partners and funders with no written terms |
| Communication groups | WhatsApp groups run by staff and volunteers | Contact details circulate to everyone in the group by default |
| Photographs and media | Event photography, published case studies, social media posts | No permission on file, and no way to withdraw it later |
Your business will not match any of these exactly, and that is the point. The engagement is shaped around what you actually run, not around a template of what a business your size is assumed to have.
The same gaps turn up in almost every first assessment.
None of these come from carelessness. They come from a business growing faster than anyone had time to document. Recognising several of them is normal, and it is a good reason to start.
The founder knows the CRM, the operations lead knows the drive, and nobody knows about the forms a departed intern set up. Until the list exists, every other control is guesswork.
It was copied from a template or from a competitor, it has not been touched since the website was built, and it does not describe what the business now collects or who it now shares data with.
A single checkbox covers terms, marketing and data sharing at once, or there is no checkbox at all. There is no record of who agreed to what, and no way for anyone to change their mind.
Numbers were imported from an old database, collected at an event three years ago, or bought from a vendor. When someone asks how you got their number, there is no answer on file.
Offboarding covers the laptop and the email account but misses the shared drive, the WhatsApp group, the analytics dashboard and the vendor portal.
Your courier, payroll provider, marketing agency and support tool all handle personal data on your behalf. The contracts cover price and delivery, and stop there.
There is no retention rule, so the business holds every record it has ever created. That is storage you pay for, and exposure you carry, for data you no longer use.
If a laptop is lost or an account is compromised tomorrow morning, no one knows who to call first, what to check, what to write down or who has to be told.
A tool, a report, or a programme. They are not the same purchase.
Most businesses looking at this are choosing between buying a consent tool, commissioning a one-off report, and running a proper programme. Here is the comparison as we would make it, including the places where a tool genuinely wins.
| What you need | A consent tool on its own | A one-off report | Working with us |
|---|---|---|---|
| A written record of every place personal data sits | No | Yes | Yes |
| A reasoned position on each activity, not just a findings list | No | Varies | Yes |
| Notices, policies and procedures drafted for you | No | Rarely | Yes |
| Consent captured and logged inside your product | Yes | No | We specify it, your tool runs it |
| Notices in regional languages | Sometimes | Rarely | Yes |
| A grievance process that has been tested, not just written | No | No | Yes |
| Data protection terms for your vendor contracts | No | Varies | Yes |
| A dated evidence pack you can produce on request | Consent logs only | The report itself | Yes |
| Something that keeps working after handover | While you pay | No | Review calendar, plus optional periodic review |
| One accountable point of contact | No | Yes | Yes |
| Cost after the first year | Recurring licence | None, and nothing maintained | Optional only |
Where a tool genuinely wins
If you need consent captured on a website or inside an app, logged against a timestamp and a notice version, a platform does that far better than a consultant can. We will not pretend otherwise, and we will not try to sell you a spreadsheet instead.
What a platform cannot do is tell you what to collect consent for. It does not know which of your activities need consent, which sit on another basis, what your courier does with the data afterwards, or when any of it should be deleted. Bought first, it gets configured around guesses, and a confidently logged record of the wrong consent is worse than no record at all.
So we stay platform neutral. We tell you whether you need one, help you choose, specify exactly what it must capture, and check it once it is live. We take no referral fee from any of them, which is why the recommendation is sometimes that your existing setup is already enough.
Where we differ from a one-off report
A report tells you what is wrong. It is then your problem to turn thirty findings into thirty documents, which is where most compliance projects quietly stop.
We draft the documents. Notices, policies, procedures, consent text and vendor contract terms arrive written for your business, and we stay with you while they go live rather than handing over a list and invoicing.
We are also honest about the ongoing part. We are not a subscription. What continues after we leave is an evidence pack your team maintains and a review calendar telling them what to check and when. If you would rather have us check it with you, a periodic review is available and it is genuinely optional. We would rather you did not need us.
Already bought a tool? Good. We work with what you have rather than replacing it, and part of the engagement is checking whether it is configured around your actual processing or around assumptions. That check costs a great deal less than the licence already does.
Step by step, end to end, scoped to your business.
The work runs as a sequence of named steps, each closing with documents your team keeps. How many steps apply, and how deep each one goes, depends on what you run and what you already have. We agree that before anything starts.
Intake and engagement
We confirm there is no conflict, agree the scope in writing, name the people responsible on your side, and set the interview schedule.
Discovery and mapping
Interviews across functions, a written record of every processing activity, and diagrams showing how data moves from collection to deletion.
Gap assessment
We test what your current notices, consents, contracts and access controls actually achieve, and record where practice and paperwork have drifted apart.
Compliance Support
We write the notices, policies, procedures, contract terms and consent flows your business needs. You receive drafts, not a list of recommendations.
Implementation support
A ticket level plan your developers or vendors can work from, with us reviewing as each item goes live rather than after everything breaks.
Training, assurance and close out
Training for the people who touch personal data, a test of whether the new processes hold, and a close out pack with the open items written down.
Breach response
A plan for the bad day: who acts in the first hours, what gets written down, who has to be told and how quickly. We draft the notification letters in advance and run one practice exercise with your team.
Requests from customers and staff
People can ask to see their data, correct it, or have it deleted. We build the process that receives, checks and actions those requests inside the timelines, with response templates ready, then test it end to end before handover.
More than one framework
If you serve customers outside India, a second set of rules applies to the same systems. We build one set of controls and record how it answers each framework, so you run one programme rather than two.
A technology practice, not a law firm.
The hardest data protection problems in a small or medium business are rarely questions of interpretation. They are questions of fact. How many systems hold customer data. Which tools did the team start using without telling anyone. Who still has access to the drive. Nobody can answer those from a legal opinion.So our work produces registers, maps, drafted documents and a dated record of what you did, rather than advice you then have to implement alone. An opinion tells you what is expected. A record shows what you did about it. We also keep the scope honest. A business of thirty people does not need the control set of a bank, and we will not sell one. Where a cheaper tool or no tool at all is the right answer, that is what the report says. Engagements end with your team running the work. We do not design the engagement to leave you dependent on us.
What business owners ask us first.
No. The obligations follow the data, not the headcount. A fifteen person business holding customer phone numbers and employee records carries the same basic duties as a large company. What changes is proportion. Your controls should match your size and risk, which is exactly what the scoping step decides.
Most of the load falls in discovery, where we need interviews with the people who actually use each system. After that your team reviews drafts and makes decisions. Implementation needs developer or vendor time, which we scope in advance so it does not arrive as a surprise.
A tool collects consent. It does not tell you what you are collecting consent for, whether consent is the right basis for that activity, what your vendors do with the data afterwards, or how you delete it later. Tools help once the underlying map and decisions exist. Bought first, they usually end up configured around guesses.
We write them. Notices, policies, procedures, consent text and the data protection terms for your vendor contracts arrive as drafts prepared for your business, which your team then reviews and adopts. A list of recommendations you have to turn into documents yourself is not a deliverable.
Then more than one framework applies to the same systems. We build a single control set and record how it answers each framework, so you run one programme rather than two. That gets agreed in the applicability step, before any drafting starts.
You hold the evidence pack, the trained team and a review calendar telling you what to check and when. If you would rather not run it alone, we can stay on for a set number of hours each month, with a named person who already knows your systems, to check new tools before they go live, handle requests as they arrive, keep the record current and be reachable when something goes wrong. That is optional and priced separately. The work is built so you can run it without us.
Thirty minutes, and you will know where you stand.
Tell us what your business runs on. We will tell you which gaps matter most, whether or not you decide to work with us.