Solutions Platform About Perspectives
All solutions

DPDP compliance that runs inside your estate — and leaves a record

Find where personal data sits, take consent that will stand up, answer every request on the statutory clock, and keep a hash-chained record of all of it. Deployed in your cloud or on your premises. Nothing copies out.

Wekalp — DPDP Stack. One deployment inside the data fiduciary's own infrastructure. Not a registered Consent Manager under S.6(7).

Problem Statement

The Act is not a policy document. It is a set of questions your systems have to answer on demand

Nobody can say where personal data sits

It accumulated over years across systems bought by different people for different reasons. The IT head names systems the CFO has never heard of, and the reverse. A one-time assessment is right on the day it is delivered and wrong within a month.

Consent is implied, and cannot be shown

"By using this site you agree" was the norm. The Act asks for a clear yes, per purpose, in a language the person reads — and a record of which notice they saw, in which version, on which date.

Your vendors hold the data. You hold the liability

Payroll bureaus, OTAs, brokers, TPAs, ed-tech platforms. Under S.8(1) their lapse is yours, whatever the contract says — and most contracts were written before the Act.

Seventy-two hours starts before you know

A breach has to reach the Board and every affected person inside 72 hours, with detail. Whose data, which system, since when — that work cannot begin at hour zero. It needs an inventory that already exists.

Engagement Model

Five stages. One team. No handoffs.

The usual model splits DPDP into an assessment by one firm, an implementation by a vendor, and operation by whoever is left. We collapse that into five stages with the same team through all of them. The people who assess are the people who build and review.

The usual model
Assessmentone firm
Implementationa vendor
Operationwhoever is left
With Wekalp
  1. 01Exposure sessionFree
  2. 02Gap and data session2–3 weeks per entity
  3. 03Advisory layer4–8 weeks
  4. 04Implementation services4–8 weeks
  5. 05Operate and reviewOngoing

One team, one letter, one accountability — a strong partnership with our legal advisory partner firm

/ 01

Exposure session

Cost
Free
Output
Exposure note + starting point

We read your published privacy policy, your cookies and one data journey the way a complainant or an assessor would. You leave with a findings note on what is visible from outside, and a view of which entity to start with.

/ 02

Gap and data session

Duration
2–3 weeks per entity
Output
Register + phased plan

A questionnaire-led session with your IT and business leads, and the platform's first read of the systems that allow it. What you hold, where it sits, who touches it, what paper covers it. You get a phased plan: what is fixed first, what it costs, what depends on what.

/ 03

Advisory layer

Duration
4–8 weeks
Output
A notice set, a contract set, a retention schedule and a procedure — all versioned, all recorded on the platform against the version served.
  • Notices and purposes for every collection point, in the languages the people concerned read.
  • Processor terms for every vendor that touches data; bilateral terms where the counterparty is a fiduciary in its own right.
  • The intra-group basis for shared systems.
  • The retention schedule.
  • Legitimate-use positions for employment and statute, written down.
  • The breach response procedure, and who holds which role in it.
/ 04

Implementation services

Duration
4–8 weeks
Output
Consent surfaces live; the registers populated; the ledger recording from day one

The instance deployed in your estate.

  • Read-only connectors for the systems that allow them; the metadata upload for those that do not.
  • Notices loaded and versioned; purposes configured; the consent widget on your forms, the cookie banner on your sites, the preference centre live.
  • The rights and incident queues with statutory deadlines attached.
  • The processor register populated from the contract set.
  • Per-entity permissions for groups.
/ 05

Operate and review

Duration
Ongoing
Output
A record the Board can weigh

Same team, sized down. The platform runs the obligations that have clocks. The advisory partner reviews the registers on a cadence and reports to your board. New systems, vendors and purposes arrive as register entries, not as a new project. Where an independent assessment is required by the Act, it is arranged as a separate line.

The consent surfaces go live first. The breach response is then rehearsed as a drill on the platform — the advisory procedure run against the software, with the outbound interlock on — before any of it is real.

One team, one letter, one accountability — from the exposure session through the periodic review. The fair question is how a small team covers what a law firm, a consultancy and three vendors used to. The next section is the answer.

Solution Highlights

Take consent that will stand up, and keep the record that proves it did

Discovery findings: 4,218 fields tagged PAN in customers.pan_no pass the check digit; the PAN-shaped invoices.ref_no fails it and is rejected

Discovery, read-only, inside your network

Scans registered systems for personal data and records metadata only — table, column, tag, confidence. No credential and no value leaves your estate. Aadhaar, PAN and GSTIN are validated by check digit, so a PAN-shaped invoice number is not a false alarm.

Systems register: ERP scanned read-only and in the register, a group-wide HR system that cannot be scanned with quarterly attestation, and a finance shared drive validated by monthly upload

A register of every system, including the ones you cannot scan

Group HRMS, vendor SaaS, the spreadsheet estate: registered with an owner and a reason, so the inventory is honest about its own edges.

Customer notice version 3 with three purposes in English, Hindi and Marathi, its content hash, and a v2 to v3 change of two clauses

Notices you can version, in the languages your customers read

Every notice carries a version and a content hash. A consent record points at the exact text the person saw.

Consent choices for a loyalty programme and marketing communications, each a separate decision, with a hashed receipt written for the decision

Consent at every touchpoint, purpose by purpose

An embeddable widget for forms and onboarding. Each purpose is a separate decision; legitimate uses are shown as information, not switches. The receipt is written to the ledger the moment the form is submitted.

Tag status: essential and analytics running, marketing and video embed blocked

Cookies that wait for a yes

Only essential tags run before a choice. Analytics, marketing and third-party embeds stay blocked until the visitor allows them — and the page shows which tags actually executed.

Preference centre: see, change or withdraw consent, verified by a one-time code sent to the registered mobile number

A preference centre the person controls

See everything you agreed to, change any of it, withdraw all of it. Authenticated by one-time code. Withdrawal is as easy as consent, which is what S.6(4) requires.

Processor register: payroll bureau Tier 1 with contract on file, insurer as independent fiduciary Tier 2 needing bilateral terms, marketing agency Tier 3 with assessment sent

Processors, tiered by what they can reach

Every external party that touches personal data, with the systems and datasets it can reach and a tier derived from the most sensitive of them. The register your vendor contracts should have been built from.

Erasure request with 18 days left, and an incident Board notice with 71 hours 12 minutes remaining

Requests and incidents on the statutory clock

One queue for access, correction and erasure requests, assessments and exceptions. An incident register with the CERT-In and Data Protection Board deadlines already attached, so the 72 hours are counted from the moment someone raises it.

Hash-chained events from consent granted to notice served to withdrawn, exported as a signed Q3 evidence pack

A ledger that is its own evidence

Every consent, withdrawal, task and decision is an event in a hash-chained ledger, exportable and signed. When the question is asked — by an auditor, by counsel, by the Board — the answer is a file, not a reconstruction.

If you are looking for DPDP compliance that goes beyond a gap report and a consent banner — contact us

Delivered with our legal advisory partner firm, who advise on notices, contracts and the periodic review. Production deployments run within the data fiduciary's own infrastructure.