1. Home
  2. /
  3. Services
  4. /
  5. DPDP Compliance
NewDPDP Compliance Services

DPDP compliance, made provable

End-to-end readiness for the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, from gap assessment through consent architecture to the security safeguards Section 8(5) actually demands, evidenced clause by clause.

Fixed-scope feesSecurity engineers, not only advisors24-hour response commitment
The five layers we buildSec. 8(5) highlighted
0102030405
Maximum penalty
₹250 Cr
Failure to keep reasonable security safeguards, Sec. 8(5)
Hard deadline
13 May 2027
Full compliance for every data fiduciary
Time to clarity
3 weeks
From kickoff to a risk-ranked gap register
Our commitment
24 hours
Response time on every engagement

Aligned to

DPDP Act 2023ISO 27001SOC 2NIST CSFPCI DSSGDPRCISDORA
The challenge

Most DPDP programmes are being sold as a consent banner and a policy refresh. That covers the visible half of the Act and leaves the expensive half untouched.

₹250 crore

The Act's largest penalty is not for a missing notice. It is for failing to keep reasonable security safeguards under Section 8(5), an engineering obligation that sits outside what any consent tool can deliver.

The second problem is evidence. A control you cannot demonstrate on the day the Board asks is a control you do not have. We build the compliance layer and the security layer together, and we document both to the standard our ISO 27001 and SOC 2 work already meets.

Where the law stands

Three phases. One is already behind you

MeitY notified the DPDP Rules on 13 November 2025 and staged commencement across eighteen months. Knowing which obligations are live decides what you build first.

Phase 1 · In force
13 Nov 2025
Live now

Definitions apply and the Data Protection Board of India is constituted. Data principals can already lodge complaints.

Phase 2
13 Nov 2026
—

The Board can inquire and levy penalties. Consent Manager registration opens. Technical work should be substantially done by here.

Phase 3
13 May 2027
—

Notice, consent, rights, retention, cross-border transfer and breach obligations apply in full to every data fiduciary.

Your exposure

What the Act charges you for

The Schedule prices each failure separately, and penalties are levied per instance. Two of the top three are engineering problems, not paperwork.

₹250 Cr
Failure to take reasonable security safeguards to prevent a personal data breach
Sec. 8(5)
₹200 Cr
Failure to notify the Board and affected data principals of a breach
Sec. 8(6)
₹200 Cr
Breach of obligations relating to children's data and verifiable parental consent
Sec. 9
₹150 Cr
Breach of the additional obligations of a Significant Data Fiduciary
Sec. 10
₹50 Cr
Any other breach of the Act or the Rules made under it
Schedule

Figures are the maximums set out in the Schedule to the Digital Personal Data Protection Act, 2023. The Data Protection Board of India determines the amount for each instance. This page is general information and not legal advice.

Our methodology

How we approach it

Five phases in a fixed order. You cannot write a notice before you know what you collect, and you cannot promise erasure before something enforces it.

Step 01

Discover

Stakeholder interviews, automated PII scanning, system inventory and applicability analysis.

2–4 weeks
Step 02

Design

Consent architecture, notice set, retention schedule, rights workflows and security target state.

3–5 weeks
Step 03

Implement

Our engineers build alongside your team: consent, DSR portal, encryption, logging, erasure jobs.

6–14 weeks
Step 04

Verify

Mock rights request, mock breach drill, VAPT retest and an evidence pack indexed by clause.

2–3 weeks
Step 05

Sustain

Quarterly reviews, new-feature privacy checks, DPO retainer and annual re-attestation.

Ongoing
What's included

Six engagements. Take one, or let us sequence them

Every engagement ships a named deliverable and an evidence pack built to withstand regulatory scrutiny on day one.

01 · Assessment2–3 weeks

Gap Assessment & Readiness Audit

We test current practice against every obligation that binds you, ranked by penalty exposure rather than ease of closure, then tell you what to fix first and what can wait.

  • Applicability and SDF determination
  • Data discovery, PII scan and RoPA
  • Control-by-control gap register
  • Risk-ranked remediation roadmap
  • Board-ready summary deck
03 · Core practice5–8 weeks

DPIA & Risk Management

Impact assessment plus the safeguards it demands. This is where Section 8(5) lives, the clause behind the ₹250 crore line, and where our security engineering does the work a consent tool cannot.

  • DPIA methodology and first assessments
  • Sec. 8(5) safeguards: encryption, access control, logging
  • VAPT of applications, APIs and cloud configuration
  • Processor and vendor risk assessment
  • Retention and erasure controls
  • Evidence pack mapped clause by clause
04 · Enablement2–3 weeks

Training & Awareness Program

One session for everyone, deeper modules for the four teams that actually touch personal data: engineering, support, HR and marketing.

  • Organisation-wide DPDP awareness session
  • Role-based modules for four teams
  • Knowledge checks and completion records
  • Handling guide for frontline staff
  • Refresher content for new joiners
05 · Sec. 8(6)3–4 weeks

Breach Response Planning

You must intimate affected principals and the Board without delay, then file full particulars within 72 hours. That is a drill, not a policy document.

  • Incident response plan tuned to DPDP timelines
  • Severity and notification decision tree
  • Pre-drafted Board and data principal intimations
  • Tabletop exercise with engineering and legal
  • Post-incident forensics runbook
06 · RetainerAnnual

DPO as a Service

A named privacy officer on retainer: rights requests, Board correspondence, quarterly reviews and customer security questionnaires. Required in India for Significant Data Fiduciaries under Sec. 10.

  • Named officer with defined SLAs
  • Rights request handling and escalation
  • Quarterly posture review and reporting
  • Regulatory and Board correspondence
  • Annual readiness attestation
Outcomes

What you get, and who it's for

Every artifact is indexed against the clause it satisfies, so an auditor, an enterprise customer or the Board can be answered from one folder.

Deliverables

Handed over on completion, in editable and signed formats.

  • DPDP Gap Assessment Report
  • Record of Processing Activities (RoPA)
  • Consent architecture and notice set
  • Privacy policy and internal policy suite
  • Section 8(5) safeguards evidence pack
  • Breach response runbook and drill report
  • Retention schedule and erasure job specifications
  • Processor register and agreement templates
  • OrbCyber DPDP readiness attestation

Who should use this

Built for organisations that meet one or more of these.

  • Collect personal data of individuals in India, at any scale
  • Already hold ISO 27001 or SOC 2 and want the DPDP delta only
  • Face DPDP clauses in enterprise or BFSI customer contracts
  • Operate in edtech, gaming or consumer apps reachable by minors
  • Are likely to be notified as a Significant Data Fiduciary
  • Transfer personal data outside India
  • Have no in-house privacy function and need one on retainer
Why OrbCyber

A partner, not a vendor

The same principles that run our ISO 27001 and SOC 2 engagements, applied to India's data protection regime.

01

Security-led

The Act's biggest penalty is a controls failure. We are a security firm first, so Section 8(5) is home ground rather than a subcontract.

02

Audit-ready

Every artifact is built to withstand regulatory scrutiny on day one, indexed against the clause it satisfies.

03

Build or buy

We implement whichever consent platform fits your architecture: yours, a third party's, or OrbCyber Consent. The gap assessment is priced and delivered before any platform decision.

04

AI + human

Platform automates evidence collection and continuous monitoring; senior consultants make the judgement calls.

FAQ

Frequently asked questions

The questions that come up on almost every first call.

The deadline is May 2027. Why start now?

Because the work consumes most of the runway. A mid-market programme runs 16–20 weeks of our time plus your engineering capacity, and the technical items (consent architecture, erasure automation, vendor agreements) have long tails. From 13 November 2026 the Board can inquire and levy penalties, so the practical window is shorter than the headline date suggests.

We already hold ISO 27001 or SOC 2. How much carries over?

A useful share of the Section 8(5) safeguards (access control, encryption, logging, incident response) maps across, and our unified control library credits it rather than re-doing it. What does not map is the consent and purpose layer: itemised notice, granular consent, withdrawal, rights fulfilment, purpose-linked retention and children's data. That is usually where the real work sits.

How do we know whether we are a Significant Data Fiduciary?

The central government notifies SDFs based on factors including volume and sensitivity of data, risk to data principals, and impact on the sovereignty and integrity of India. There is no self-registration. We assess your likelihood during the gap assessment and, where it is close, recommend building to the SDF bar anyway. The additional obligations are a DPO in India, an independent data auditor and periodic DPIAs.

Is there a government DPDP certificate?

No. The Act does not create a statutory certification for data fiduciaries. What we issue is an OrbCyber readiness attestation, an independent statement of your posture against the Act and Rules, with the evidence behind it. It is built for enterprise procurement, diligence and insurance conversations.

Do you act as the auditor?

No. We prepare you and support you through independent audit, exactly as we do on ISO 27001 and SOC 2. Independence matters, and it matters more where the Act requires an independent data auditor for Significant Data Fiduciaries.

Do you sell consent management software?

Yes. We build OrbCyber Consent, our own consent management platform. We keep the advice honest by sequencing it: the gap assessment and roadmap are scoped and delivered before any platform decision, and they are priced the same whether or not you licence ours. If a third-party platform fits your architecture better, we will implement that instead. Licence fees are always quoted separately from consulting fees, never bundled into a single number.

Take the next step

Ready to strengthen your security posture?

Book a free 30-minute consultation. No slides, just a working conversation about your DPDP gaps and roadmap.