DataSurity

DPO as a Service

The person the Act asks you to name, and the team behind them.

SARC's privacy team takes on the standing duties of the Act with you: grievances and rights requests answered on time, notices and registers kept current, breaches handled on both clocks and your Board kept informed. For Significant Data Fiduciaries, we support the DPO you appoint.

  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION
  • 40 years with India's regulated enterprises

Trusted by leading enterprises

  • Indiabulls Securities
  • KDSG Super-Speciality Hospital
  • Modicare
  • Express Inn Hotels & Resorts
  • Econo Broking
  • DAMS
  • Freesia by Express Inn
  • MBL
  • Trident Group
  • Dhani
  • Indiabulls Asset Reconstruction
Use cases

Where the service fits

  • You need a contact point the Act requires

    Every Data Fiduciary must publish someone who can answer questions about its processing. Most don't need a formal DPO, but they do need this, run properly.

  • You may be a Significant Data Fiduciary

    Your appointed DPO will need a team behind them for DPIAs, audit readiness, Board reporting and daily operations.

  • Your privacy lead has moved on

    Grievances, rights requests and reporting can't pause while you hire. A team with the full record picks up at once, and hands over cleanly when you're ready.

  • Your programme is live and needs running

    After implementation, someone has to keep notices current, review new vendors and products, and answer every request on time.

Deliverables

What the service delivers, month after month

A team and a platform stand behind the role, so the function never depends on one person, and every action is on record.

  • A published contact point

    The person Section 8(9) requires, answering questions about your processing through your own channels.

  • Grievances answered on time

    Every grievance handled within your published timeline, before anyone needs to go to the Board.

  • Rights requests closed with evidence

    Access, correction, erasure and nomination requests verified, routed to owners and closed.

  • Monthly privacy report

    Requests, grievances, incidents, vendor changes and open actions, for management.

  • Quarterly Board update

    Posture, risks and decisions needed, in the form a Board or Audit Committee reads.

  • Registers and notices kept current

    Changes to processing, vendors and products reflected in the registers and notices as they happen.

  • Breach response on both clocks

    Coordination from the first alert, with CERT-In and DPDP intimations drafted for your approval.

  • Privacy reviews for new products and vendors

    Each launch and each new processor reviewed before it goes live, with DPIA support for SDFs.

  • Yearly reassessment and training

    A reassessment against last year's baseline and refresher training for owners and teams.

Methodology

The service calendar

Scope

The duties of the Act, run on your behalf

The service covers what every Data Fiduciary owes, and the added support a Significant Data Fiduciary's DPO needs.

DutyWhat the Act asksHow we run it
  • Contact point

    Publish someone who can answer questions on processing (s.8(9))

    SARC's privacy team answers through your channels and in your name

  • Grievance mechanism

    An effective way to redress grievances (s.8(10), s.13)

    Every grievance tracked and answered within your published timeline

  • Rights

    Access, correction, erasure, nomination (s.11, s.12, s.14)

    Requests verified, routed to owners and closed with evidence

  • Notices

    Notices that match what you actually do (s.5)

    Notices updated as processing, products and vendors change

  • Processors

    Processing by processors only under contract (s.8(2))

    New vendors reviewed and contracts checked before onboarding

  • Breach

    Intimation to the Board and affected people (s.8(6), Rule 7)

    Response coordinated on the DPDP and CERT-In clocks

  • SDF: the DPO

    An India-based DPO who represents the SDF and answers to its Board (s.10(2)(a))

    We support the DPO you appoint with a full team and the platform

  • SDF: DPIA and audit

    Periodic DPIA and independent audit (s.10(2)(c))

    DPIA prepared with you, audit evidence made ready for an independent auditor

Sector expertise

With your sector's rules in view

  • Privacy grievances kept separate from service complaints, each on its own clock.
  • Lending partners and collection agencies reviewed before and after onboarding.
  • Board updates aligned with the reporting your RBI governance already expects.
Platform

Recorded on DataSurity

The service runs on the same platform as your programme, so every action is recorded where it belongs.

Client perspectives

Trusted by leaders across industries

“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”

Rakesh G

Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

FAQs

Frequently asked questions

Do we need a Data Protection Officer under the DPDP Act?

A formal DPO is required only if the government designates you a Significant Data Fiduciary. Every Data Fiduciary, though, must publish contact details for someone who can answer questions about its processing, and must run an effective grievance mechanism. This service covers both.

We may be an SDF. Can SARC be our DPO?

The Act requires an SDF's DPO to be based in India, to represent the SDF and to answer to its Board. We recommend appointing an internal officer to hold that role, with SARC's team and DataSurity doing the daily work behind them. Take legal advice on your specific structure. It's the safest model, and the one that holds up if the Board asks who is accountable.

What do you need from our organisation?

An internal sponsor, access to DataSurity, and data owners who act on the tickets we route to them. We don't need access to your production data. Requests are fulfilled by your owners, and we coordinate and evidence the work.

What happens if there's a breach out of hours?

A response path runs from the first alert. We coordinate triage with your IT and security teams, keep the CERT-In and DPDP clocks, and draft the intimations for your approval. You stay the decision-maker. We make sure nothing is missed.

If SARC runs our DPO function, who audits us?

For a Significant Data Fiduciary, the independent audit should be done by a different firm, so it stays independent. We prepare the evidence and support the auditor. We don't audit work we've run ourselves.

How is this different from hiring a part-time DPO?

A part-time officer is one person, with one person's hours and memory. Here a team covers legal, security and operations, every grievance and request runs on a clock in DataSurity, and the full record belongs to your organisation. If you later bring the function in-house or move it elsewhere, you take all of it with you.

Knowledge resources

Put your privacy office in experienced hands.

Tell us about your organisation, and we'll propose the right level of support.

  • DPDP Act
  • DPDP Rules
  • RBI
  • SEBI
  • IRDAI
  • CERT-In
  • PMLA
  • NIST CSF 2.0
  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION

We use these details to respond to your request and send what you asked for. See our privacy notice.