Personal data mapping
An inventory of what personal data you collect, why, where it is stored and who it is shared with.
Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 changes how every Indian business collects and uses personal data, with heavy penalties for failures such as inadequate security safeguards. We turn the law into concrete changes to your forms, systems, contracts and processes.
What this covers
Typical timeline
Assessment in 2–4 weeks; remediation phased over 2–6 months depending on the number of systems.
Who it is for
We do more than write policies: we map where personal data flows in your applications, fix consent capture, implement access controls and encryption, and build a breach response process that meets the notification requirements, working alongside your legal advisers.
Discuss your requirementBusinesses collecting customer data through websites, apps and forms
Fintech, healthcare, education and HR platforms handling sensitive data
Companies processing personal data on behalf of their clients
Organisations that may be notified as significant data fiduciaries
Capabilities
An inventory of what personal data you collect, why, where it is stored and who it is shared with.
Clear notices and consent capture in your forms and apps, with records you can produce on request.
Processes and tooling for access, correction, erasure and grievance requests within defined timelines.
Encryption, access control, logging and masking implemented as reasonable security safeguards.
An incident process for detecting, assessing and notifying personal data breaches to the Board and affected people.
Data processing terms for vendors and clients, plus retention and deletion schedules.
How we work
You always know what happens next, who is responsible and what you will receive at each stage.
Typical timeline
Assessment in 2–4 weeks; remediation phased over 2–6 months depending on the number of systems.
Data flows, systems, vendors and current practices are mapped.
Practices are compared with the Act and the notified Rules.
Prioritised fixes across legal, process and technology.
Consent, rights handling, safeguards and contracts are updated.
Records, policies and staff training demonstrate ongoing compliance.
Deliverables
Frameworks & tools
We recommend tools based on your scale, budget and existing systems, not on what is fashionable. Every choice is explained in the proposal.
Engagement models
A scoped test with a severity-rated report, developer walkthrough and one free retest after you fix the findings.
Gap assessment, policy and control implementation, evidence collection and audit support across a fixed timeline.
Quarterly testing, release-based retests and on-call advisory for teams that ship often.
How pricing works: Security work is priced on scope: number of applications, APIs, user roles, IPs or cloud accounts. You get a fixed quote after a short scoping call. Company audits start at ₹25,000.
Get a quoteFAQs
Yes. It applies to any business processing digital personal data in India, regardless of size, although some obligations are heavier for significant data fiduciaries notified by the government.
The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, with other failures carrying different maximums. Actual penalties depend on the nature and severity of the breach.
The DPDP Rules notified in 2025 phase obligations in over a transition period. We map the dates that apply to your organisation and plan remediation so you are ready before they take effect.
No. Much of the work is technical: knowing where data sits, capturing consent in your apps, securing and deleting data on time and detecting breaches. That is why we combine legal inputs with engineering.
Keep exploring
Get ready for ISO/IEC 27001:2022 certification: gap analysis, risk assessment, policies, Annex A controls…
ExploreMeet the CERT-In directions: 6-hour incident reporting, 180-day log retention in India, NTP time sync, a…
ExploreBusiness agreements drafted and reviewed: NDAs, service and vendor contracts, founders and shareholders…
ExploreSecure your AI: LLM red teaming, prompt-injection and data-leak testing, AI governance for the DPDP Act…
ExploreOn-site meetings across Delhi NCR and Haryana from our Rohtak office; remote delivery across India.
Reply within one business day
Share a few details. A senior specialist reviews them and schedules a call to discuss scope, timeline and cost, with no obligation.
Receive preliminary project architecture, pricing tiers, and timeline estimates within 15 minutes under strict NDA.