Skip to main content

DPDP Act Compliance: Gap Analysis, Solutions and Continuous Compliance

Data Services
  • Gap analysis
  • Consent and notice
  • Data principal rights
  • Continuous compliance
What we deliver

DPDP Compliance, in Three Stages

We work with organisations that hold personal data as Data Fiduciaries under India's Digital Personal Data Protection Act, 2023 (the DPDP Act). The engagement starts with a gap analysis of what personal data you collect, why, where it goes and who can reach it; then implements the notice, consent, rights, retention and security controls the Act requires; then keeps them running and evidenced as your processing changes.

Stage 1 - Gap analysis and readiness assessment

  • Role determination: Data Fiduciary, Data Processor, or both, per processing activity
  • Assessment against every obligation the Act places on that role
  • Significant Data Fiduciary exposure, and what it would add
  • Findings rated by risk and effort, as a phased remediation roadmap
  • A baseline report your board and your counsel can both read

Personal data discovery and mapping

  • Inventory of personal data across applications, databases, files and SaaS
  • Records of processing: purpose, lawful basis, retention, recipients
  • Data flow maps, including processors, sub-processors and cross-border transfers
  • Shadow copies: exports, reports, backups, analytics and test environments
  • Children's and other sensitive processing identified and separated

Stage 2 - Notice and consent implementation

  • Itemised notice at the point of collection, in the languages the Act allows
  • Consent that is free, specific, informed, unconditional and unambiguous
  • Withdrawal as easy as giving consent, and propagated downstream
  • Verifiable parental consent for children's data where it applies
  • Consent records kept as evidence, and Consent Manager integration when required

Data principal rights fulfilment

  • Request intake for access, correction, completion, updating and erasure
  • Identity verification, routing, service levels and audit trail
  • Erasure that reaches processors, backups and derived copies
  • Grievance redressal, with escalation and published response times
  • Nomination handling, and a rights dashboard for the operations team

Security safeguards and breach response

  • Reasonable security safeguards: encryption, access control, segregation, logging
  • Retention rules enforced in the systems, not written in a policy alone
  • Processor contracts, due diligence and onward-transfer terms
  • Breach detection, containment and a rehearsed notification playbook
  • Notification packs prepared for the Board and for affected Data Principals

Stage 3 - Continuous compliance

  • Periodic re-assessment as products, vendors and processing change
  • Data Protection Impact Assessment and audit support for Significant Data Fiduciaries
  • Data Protection Officer support, or augmentation of the one you have
  • Awareness training for the teams that actually touch personal data
  • A standing evidence pack: records, logs, DPIAs, contracts, incident history
Why Bitchief

Why Bitchief for DPDP Compliance

An assessment that is scoped to your processing, and remediation that is built in your systems rather than filed in a folder.

Assessment first

The gap analysis is scoped to your actual processing activities, not to a generic checklist, so the roadmap that follows is yours.

Engineering, not only paperwork

Consent capture, retention jobs, access control, logging and erasure are implemented in the systems that hold the data. Policy alone is not a control.

Alongside your counsel

Legal interpretation stays with your lawyers. We own the technical and operational build, and give them something concrete to opine on.

Evidence an auditor accepts

Records of processing, consent logs, DPIA output, contracts and incident history, maintained as a pack rather than reassembled under pressure.

ISO 27001:2022 certified delivery

The team doing the work runs an information security management system that is itself certified and audited.

We already run the estate

Identity, endpoints, databases, backup and privileged access are services we deliver, so the controls land where the data actually lives.

Questions

DPDP Act Compliance Questions

What organisations ask us before an engagement starts.

What does the DPDP Act actually require us to do?

In short: tell people what you are collecting and why, in an itemised notice; rely on valid consent or one of the legitimate uses the Act sets out; collect no more than the purpose needs; keep it accurate; erase it when the purpose is served or consent is withdrawn; protect it with reasonable security safeguards; honour requests for access, correction and erasure; run a grievance redressal route; bind your processors by contract; and report a personal data breach to the Data Protection Board of India and to the people affected.

Are we a Data Fiduciary or a Data Processor?

It depends on the processing, not on the company, and most organisations are both. You are a Data Fiduciary where you decide the purpose and means of processing, and a Data Processor where you process on someone else's instructions. The gap analysis settles this activity by activity, because the obligations that follow are different.

What is a Significant Data Fiduciary, and what changes if we are one?

The Central Government may notify an organisation, or a class of them, as a Significant Data Fiduciary on factors including the volume and sensitivity of the personal data it processes and the risk to Data Principals. That brings additional duties: a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments and audits. We assess the exposure and cost that would add before it is notified, not after.

Do we need consent for employee personal data?

Not for everything. The Act sets out legitimate uses that do not run on consent, including processing for purposes of employment and for safeguarding the employer from loss or liability. The work is to establish which of your processing sits there and which needs consent, and to document that determination - not to assume either answer across the whole of HR.

Can we still transfer personal data outside India?

Yes, subject to any restriction the Central Government notifies in respect of a particular country or territory, and to any sectoral law that is stricter. What matters in practice is knowing where your data goes: the mapping stage documents every processor, sub-processor and cloud region, so a restriction can be answered with a change rather than a search.

What happens if we do not comply?

The Data Protection Board of India can inquire into a breach of the Act and impose monetary penalties set out in its Schedule, the highest of which is up to INR 250 crore for failing to take reasonable security safeguards to prevent a personal data breach. The practical exposure is usually wider than the penalty: breach notification obliges you to tell the people affected.

Start with a DPDP gap assessment

Tell us what personal data you hold and where, and we will scope a gap analysis against the DPDP Act - then a roadmap you can fund in phases.