DataSurity

DPDP Implementation

From roadmap to live controls, built by the team behind the platform.

SARC's practice and the DataSurity engineering team put DPDP into your systems: consent live on every channel, a rights portal in your brand, vendors under contract and retention carried out. Each obligation is signed off only when it's live and the evidence is on the platform.

  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION
  • 40 years with India's regulated enterprises

Trusted by leading enterprises

  • Indiabulls Securities
  • KDSG Super-Speciality Hospital
  • Modicare
  • Express Inn Hotels & Resorts
  • Econo Broking
  • DAMS
  • Freesia by Express Inn
  • MBL
  • Trident Group
  • Dhani
  • Indiabulls Asset Reconstruction
Use cases

Four situations we're usually called into

  • You have a roadmap to deliver

    A gap assessment, ours or another firm's, has told you what to fix. Now it needs doing, across teams that already have day jobs.

  • May 2027 is close

    Consent, rights, notices and vendor contracts have to be live on every channel when substantive obligations apply. That takes design, engineering and change across the business, and internal teams already have day jobs.

  • Your systems need real integration

    Consent and rights have to work inside your apps, CRM, core systems and branches, which takes engineers as well as advisers.

  • A group needs one programme

    Several entities, shared functions and inter-company flows need one plan, one set of registers and one standard of delivery.

Deliverables

Nine things that go live

Every deliverable runs on DataSurity under your ownership, so nothing depends on a consultant's spreadsheet once the programme ends.

  • Consent on every channel

    Web, app, branch, call centre and partner journeys capturing consent per purpose, with withdrawal reaching your systems.

  • Notices people can read

    Section 5 notices in the languages your customers use, translations reviewed by a person, versions tracked.

  • A rights portal in your brand

    Access, correction, erasure, nomination and grievances, routed to named owners with the clock visible.

  • Legacy customers re-noticed

    Section 5(2) campaigns to everyone whose data you held before the Act, with every answer recorded.

  • Vendors under contract

    DPDP clauses in processor contracts, vendor questionnaires completed, and each vendor's role recorded.

  • Retention put into effect

    Retention rules agreed per record class and deletion carried through systems, backups and vendors.

  • Breach response on both clocks

    A playbook for the CERT-In six hours and the DPDP report to the Board, tested in a tabletop exercise.

  • Trained owners and teams

    Role-based training for data owners, front-line staff and the privacy team, with completion tracked.

  • Live registers and a programme view

    The processing record, lawful-basis and vendor registers, and a dashboard of what is live and what is left.

Methodology

How the programme is delivered

Scope

Every obligation signed off only when it's live

Many firms call a policy "done". We sign off an obligation only when it works in your systems and the evidence sits on the platform. These are the sign-off tests.

AreaWhat the Act asksHow we sign it off
  • Notice

    Itemised notices in a language people choose (s.5)

    Every notice published, versioned and shown before collection on each in-scope channel

  • Consent

    Free, specific, withdrawable consent (s.6)

    Records flowing from every in-scope channel, and one withdrawal traced through to each connected system

  • Legitimate uses

    Processing without consent only for listed uses (s.7)

    Each use recorded against its clause in the register, with its notice

  • Legacy data

    A fresh notice to people whose data you held before the Act (s.5(2))

    Campaigns sent to the full legacy base, with every answer recorded

  • Rights and grievances

    Access, correction, erasure, nomination, grievance (s.11 to s.14)

    A test request of each type closed end to end, with its certificate

  • Processors

    Processing by processors only under contract (s.8(2))

    Every in-scope processor with DPDP clauses signed and its questionnaire completed

  • Safeguards

    Reasonable security safeguards (s.8(5), Rule 6)

    Priority fixes closed by your IT team and confirmed by a rescan

  • Breach

    Intimation to the Board and affected people (s.8(6), Rule 7)

    Playbook approved and a tabletop exercise run with leadership

  • Retention

    Erase when the purpose ends, unless law requires retention (s.8(7))

    Rules approved per record class, and the first deletion run confirmed in systems and with vendors

  • Children

    Verifiable parental consent, no tracking or targeted ads (s.9)

    Age gate live on flagged journeys, and a parental consent journey tested

  • Significant Data Fiduciaries

    DPO, DPIA, independent audit (s.10)

    DPIA drafted with you, and audit evidence ready for an independent auditor

Sector expertise

Implemented the way your sector works

  • Consent inside lending apps before any device permission fires, in line with RBI's digital lending rules.
  • Branch and assisted journeys captured by staff, with the same records as digital channels.
  • Co-lending and partner flows given their own notices and lawful basis.
Platform

Implemented on DataSurity

The programme is built on the platform your teams will run afterwards, by the people who built it.

Client perspectives

Trusted by leaders across industries

“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”

Rakesh G

Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

FAQs

Frequently asked questions

Do we need a gap assessment first?

It helps, because implementation should start where the risk is. If you've had an assessment from another firm, we map its findings to our framework and plan from there. If you haven't, a focused assessment runs as the first phase of the programme.

How much of our IT team's time does this take?

Integration needs your application owners for the systems in scope: typically your website, apps, CRM and core platforms. Our engineers do the build work alongside them, using DataSurity's SDK, APIs and webhooks. We agree each integration's effort upfront, wave by wave.

Do you draft the notices, policies and contracts?

Yes. Our practice drafts notices, policies, procedures and DPDP clauses for processor contracts, and reviews them with your legal team before anything goes live. Every document is versioned on the platform.

Will the rollout disrupt the business?

Changes go live in waves, one business line or channel at a time, with each wave tested before the next begins. Customer-facing changes such as new consent screens are designed with your business teams so journeys stay smooth.

How do you decide an obligation is done?

Each one has a sign-off test agreed at the start: notices shown on every channel, a withdrawal traced to each system, a test rights request closed with its certificate, vendor clauses signed. The evidence is recorded on DataSurity, so your next assessment or audit starts from proof. After sign-off, SARC can stay on for support or as your DPO function.

We're a group of companies. Can one programme cover all of us?

Yes. One plan covers every entity, with shared functions implemented once and each flow between sister companies given its own basis and notice. Each company stays a separate Data Fiduciary with its own records.

Knowledge resources

Put your roadmap into operation.

Tell us where you are today, and we'll plan the programme with you.

  • DPDP Act
  • DPDP Rules
  • RBI
  • SEBI
  • IRDAI
  • CERT-In
  • PMLA
  • NIST CSF 2.0
  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION

We use these details to respond to your request and send what you asked for. See our privacy notice.