DPDP Compliance Starts With Evidence
From 13 May 2027 you must be able to prove how your organisation handles personal data. A policy document is not proof. Allied Boston runs the independent readiness assessment that tells you where you stand.
Until full compliance is required - 13 May 2027
Get DPDP Compliant
Book a DPDP readiness call
What the DPDP Act requires, and what it costs to get wrong.
The DPDP Act, 2023 and the DPDP Rules, 2025 give every Indian organisation one set of rules for personal data. If you decide why and how it is processed - customers, employees, partners - you are a Data Fiduciary, and from 13 May 2027 you must be able to evidence how you handle it. There is no turnover or headcount threshold to fall below.
Does the DPDP Act apply to us?
- You hold customer, user or subscriber records
- You employ people in India, or hire them
- You run a website, app or contact centre that collects data
- You market to individuals, or profile them
- You use cloud, BPO, analytics or agency partners
- You serve Indian users from outside India
The Act also reaches data you collected before the Rules were notified, if you are still processing it.
Six obligations, and the evidence each one needs
Each one is a question the Data Protection Board can put to you. The acceptable answer is a record, not a policy document.
Notice at collection
An itemised notice at every collection point - web, app, contact centre, in-person, partner-assisted - in the scheduled languages.
Consent and withdrawal
Free, specific, informed consent with a verifiable record. Withdrawal must be as easy as giving it, and must reach every downstream system.
Data principal rights
Access, correction, erasure and grievance redressal, fulfilled to a defined timeline, with an auditable record of every response.
Retention and erasure
Data erased once the purpose is served or consent withdrawn - across core systems, CRM, HRMS, data lakes, backups and vendor environments.
Safeguards and breach response
Reasonable security safeguards, and the ability to notify the Board and every affected individual within the mandated window.
Processors and SDF duties
DPDP-compliant contracts with every processor, plus DPIA, audit and DPO duties if you are notified a Significant Data Fiduciary.
What non-compliance costs
Penalties are assessed per instance and not capped in aggregate. These are the maximums set out in the Schedule; the Board determines the amount in each case.
Maximum penalty for failure to take reasonable security safeguards - Section 8(5).
Maximum penalty for failure to notify a breach, and for breach of the children's data obligations - Sections 8(6) and 9.
Where the deadlines fall
Six stages. One defensible position.
The 6A methodology is how we run every DPDP engagement. Each stage has a defined output you can put in front of a board or a regulator, so you always know where you are and what it has produced.
Assess
Data discovery across systems, channels and vendors. We establish what personal data you hold, where it came from and where it goes.
Analyse
Gap analysis against the Act and the Rules, cross-mapped to the ISO, sectoral and contractual controls you already operate.
Architect
Notice and consent journeys, retention schedules, rights workflows, breach playbook and governance roles, designed to fit how you run.
Apply
Implementation alongside your legal, IT and business teams - drafting, configuring, re-papering contracts, closing the register.
Assure
Independent validation that each control operates and is evidenced, including DPIAs where the Act requires them.
Advance
Periodic review, processor reassessment, training and change triggers for every new product, vendor or market.
Most organisations engage us at A1-A2 to establish the true position, then decide how much of A3-A6 to run with us.
Book A Discovery CallCertified expertise across privacy, security and audit.
DPDP readiness requires more than a single area of expertise. It brings together data privacy, information security, governance, risk and audit.
Our engagements are supported by certified professionals with recognised credentials across these disciplines, including expertise in privacy management, information security, audit and cybersecurity.
Whether your organisation is just beginning its DPDP journey, has already completed an initial assessment, or is working toward full implementation, our team can support you at every stage. We help organisations assess their current position, identify compliance gaps, prioritise remediation, strengthen privacy and security controls, and build a practical roadmap toward sustained DPDP readiness.
The result is a structured, multidisciplinary approach designed to make DPDP compliance practical, defensible and aligned with your organisation’s operational realities.
Not ready for a call? Find out where you stand first.
Ten questions drawn from the assessments we run, scored across the six domains the Act is enforced on. Each question maps to the provision it comes from.
At the end you will be asked for your name, work email, phone and designation to unlock your score and your top three gaps.