Exposure session
We read your published privacy policy, your cookies and one data journey the way a complainant or an assessor would. You leave with a findings note on what is visible from outside, and a view of which entity to start with.
Find where personal data sits, take consent that will stand up, answer every request on the statutory clock, and keep a hash-chained record of all of it. Deployed in your cloud or on your premises. Nothing copies out.
Wekalp — DPDP Stack. One deployment inside the data fiduciary's own infrastructure. Not a registered Consent Manager under S.6(7).
It accumulated over years across systems bought by different people for different reasons. The IT head names systems the CFO has never heard of, and the reverse. A one-time assessment is right on the day it is delivered and wrong within a month.
"By using this site you agree" was the norm. The Act asks for a clear yes, per purpose, in a language the person reads — and a record of which notice they saw, in which version, on which date.
Payroll bureaus, OTAs, brokers, TPAs, ed-tech platforms. Under S.8(1) their lapse is yours, whatever the contract says — and most contracts were written before the Act.
A breach has to reach the Board and every affected person inside 72 hours, with detail. Whose data, which system, since when — that work cannot begin at hour zero. It needs an inventory that already exists.
The usual model splits DPDP into an assessment by one firm, an implementation by a vendor, and operation by whoever is left. We collapse that into five stages with the same team through all of them. The people who assess are the people who build and review.
One team, one letter, one accountability — a strong partnership with our legal advisory partner firm
We read your published privacy policy, your cookies and one data journey the way a complainant or an assessor would. You leave with a findings note on what is visible from outside, and a view of which entity to start with.
A questionnaire-led session with your IT and business leads, and the platform's first read of the systems that allow it. What you hold, where it sits, who touches it, what paper covers it. You get a phased plan: what is fixed first, what it costs, what depends on what.
The instance deployed in your estate.
Same team, sized down. The platform runs the obligations that have clocks. The advisory partner reviews the registers on a cadence and reports to your board. New systems, vendors and purposes arrive as register entries, not as a new project. Where an independent assessment is required by the Act, it is arranged as a separate line.
The consent surfaces go live first. The breach response is then rehearsed as a drill on the platform — the advisory procedure run against the software, with the outbound interlock on — before any of it is real.
One team, one letter, one accountability — from the exposure session through the periodic review. The fair question is how a small team covers what a law firm, a consultancy and three vendors used to. The next section is the answer.
Scans registered systems for personal data and records metadata only — table, column, tag, confidence. No credential and no value leaves your estate. Aadhaar, PAN and GSTIN are validated by check digit, so a PAN-shaped invoice number is not a false alarm.
Group HRMS, vendor SaaS, the spreadsheet estate: registered with an owner and a reason, so the inventory is honest about its own edges.
Every notice carries a version and a content hash. A consent record points at the exact text the person saw.
An embeddable widget for forms and onboarding. Each purpose is a separate decision; legitimate uses are shown as information, not switches. The receipt is written to the ledger the moment the form is submitted.
Only essential tags run before a choice. Analytics, marketing and third-party embeds stay blocked until the visitor allows them — and the page shows which tags actually executed.
See everything you agreed to, change any of it, withdraw all of it. Authenticated by one-time code. Withdrawal is as easy as consent, which is what S.6(4) requires.
Every external party that touches personal data, with the systems and datasets it can reach and a tier derived from the most sensitive of them. The register your vendor contracts should have been built from.
One queue for access, correction and erasure requests, assessments and exceptions. An incident register with the CERT-In and Data Protection Board deadlines already attached, so the 72 hours are counted from the moment someone raises it.
Every consent, withdrawal, task and decision is an event in a hash-chained ledger, exportable and signed. When the question is asked — by an auditor, by counsel, by the Board — the answer is a file, not a reconstruction.
Delivered with our legal advisory partner firm, who advise on notices, contracts and the periodic review. Production deployments run within the data fiduciary's own infrastructure.