DPDP Implementation
From roadmap to live controls, built by the team behind the platform.
SARC's practice and the DataSurity engineering team put DPDP into your systems: consent live on every channel, a rights portal in your brand, vendors under contract and retention carried out. Each obligation is signed off only when it's live and the evidence is on the platform.
- 40 years with India's regulated enterprises
Trusted by leading enterprises
Four situations we're usually called into
You have a roadmap to deliver
A gap assessment, ours or another firm's, has told you what to fix. Now it needs doing, across teams that already have day jobs.
May 2027 is close
Consent, rights, notices and vendor contracts have to be live on every channel when substantive obligations apply. That takes design, engineering and change across the business, and internal teams already have day jobs.
Your systems need real integration
Consent and rights have to work inside your apps, CRM, core systems and branches, which takes engineers as well as advisers.
A group needs one programme
Several entities, shared functions and inter-company flows need one plan, one set of registers and one standard of delivery.
Nine things that go live
Every deliverable runs on DataSurity under your ownership, so nothing depends on a consultant's spreadsheet once the programme ends.
Consent on every channel
Web, app, branch, call centre and partner journeys capturing consent per purpose, with withdrawal reaching your systems.
Notices people can read
Section 5 notices in the languages your customers use, translations reviewed by a person, versions tracked.
A rights portal in your brand
Access, correction, erasure, nomination and grievances, routed to named owners with the clock visible.
Legacy customers re-noticed
Section 5(2) campaigns to everyone whose data you held before the Act, with every answer recorded.
Vendors under contract
DPDP clauses in processor contracts, vendor questionnaires completed, and each vendor's role recorded.
Retention put into effect
Retention rules agreed per record class and deletion carried through systems, backups and vendors.
Breach response on both clocks
A playbook for the CERT-In six hours and the DPDP report to the Board, tested in a tabletop exercise.
Trained owners and teams
Role-based training for data owners, front-line staff and the privacy team, with completion tracked.
Live registers and a programme view
The processing record, lawful-basis and vendor registers, and a dashboard of what is live and what is left.
How the programme is delivered
Every obligation signed off only when it's live
Many firms call a policy "done". We sign off an obligation only when it works in your systems and the evidence sits on the platform. These are the sign-off tests.
- Notice
Itemised notices in a language people choose (s.5)
Every notice published, versioned and shown before collection on each in-scope channel
- Consent
Free, specific, withdrawable consent (s.6)
Records flowing from every in-scope channel, and one withdrawal traced through to each connected system
- Legitimate uses
Processing without consent only for listed uses (s.7)
Each use recorded against its clause in the register, with its notice
- Legacy data
A fresh notice to people whose data you held before the Act (s.5(2))
Campaigns sent to the full legacy base, with every answer recorded
- Rights and grievances
Access, correction, erasure, nomination, grievance (s.11 to s.14)
A test request of each type closed end to end, with its certificate
- Processors
Processing by processors only under contract (s.8(2))
Every in-scope processor with DPDP clauses signed and its questionnaire completed
- Safeguards
Reasonable security safeguards (s.8(5), Rule 6)
Priority fixes closed by your IT team and confirmed by a rescan
- Breach
Intimation to the Board and affected people (s.8(6), Rule 7)
Playbook approved and a tabletop exercise run with leadership
- Retention
Erase when the purpose ends, unless law requires retention (s.8(7))
Rules approved per record class, and the first deletion run confirmed in systems and with vendors
- Children
Verifiable parental consent, no tracking or targeted ads (s.9)
Age gate live on flagged journeys, and a parental consent journey tested
- Significant Data Fiduciaries
DPO, DPIA, independent audit (s.10)
DPIA drafted with you, and audit evidence ready for an independent auditor
Implemented the way your sector works
- Consent inside lending apps before any device permission fires, in line with RBI's digital lending rules.
- Branch and assisted journeys captured by staff, with the same records as digital channels.
- Co-lending and partner flows given their own notices and lawful basis.
Implemented on DataSurity
The programme is built on the platform your teams will run afterwards, by the people who built it.
- Consent ManagementNotices, consent capture and withdrawal go live on every channel.
- Data Principal Rights PortalRequests and grievances run under your brand, with owners and clocks.
- Data Journey MappingRegisters built during the programme become the ones your teams keep current.
- Data Discovery & ClassificationScans confirm where personal data sits and show what has been fixed.
Everything implemented runs on DataSurity under your ownership, with SARC available for ongoing support or DPO as a Service.
Trusted by leaders across industries
“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”
Rakesh G
Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

Frequently asked questions
Do we need a gap assessment first?
It helps, because implementation should start where the risk is. If you've had an assessment from another firm, we map its findings to our framework and plan from there. If you haven't, a focused assessment runs as the first phase of the programme.
How much of our IT team's time does this take?
Integration needs your application owners for the systems in scope: typically your website, apps, CRM and core platforms. Our engineers do the build work alongside them, using DataSurity's SDK, APIs and webhooks. We agree each integration's effort upfront, wave by wave.
Do you draft the notices, policies and contracts?
Yes. Our practice drafts notices, policies, procedures and DPDP clauses for processor contracts, and reviews them with your legal team before anything goes live. Every document is versioned on the platform.
Will the rollout disrupt the business?
Changes go live in waves, one business line or channel at a time, with each wave tested before the next begins. Customer-facing changes such as new consent screens are designed with your business teams so journeys stay smooth.
How do you decide an obligation is done?
Each one has a sign-off test agreed at the start: notices shown on every channel, a withdrawal traced to each system, a test rights request closed with its certificate, vendor clauses signed. The evidence is recorded on DataSurity, so your next assessment or audit starts from proof. After sign-off, SARC can stay on for support or as your DPO function.
We're a group of companies. Can one programme cover all of us?
Yes. One plan covers every entity, with shared functions implemented once and each flow between sister companies given its own basis and notice. Each company stays a separate Data Fiduciary with its own records.




