DPDPassure - DPDPA Compliance. Assured.
Book A Call
DPDP Act 2023 · DPDP Rules 2025 · India

DPDP Compliance Starts With Evidence

From 13 May 2027 you must be able to prove how your organisation handles personal data. A policy document is not proof. Allied Boston runs the independent readiness assessment that tells you where you stand.

--
Days
--
Hours
--
Minutes
--
Seconds
The DPDP Act is now fully operational. Enforcement is live.

Until full compliance is required - 13 May 2027

Get DPDP Compliant

Choose an option below to evaluate your exposure or schedule an expert session with our GRC team.
- OR -
Check Your Readiness

Book a DPDP readiness call

Please enter your name.
Please enter a valid work email address.
✓

Request received

A senior Allied Boston GRC consultant will call you within one working day. If it is urgent, write to dpdpassure@alliedboston.com.

While you wait, take the 3-minute readiness check →

Powered by
25+Years of experience
300+Man-years of expertise
1000+Clients
35+Frameworks
20+Countries
01 What and why DPDP

What the DPDP Act requires, and what it costs to get wrong.

The DPDP Act, 2023 and the DPDP Rules, 2025 give every Indian organisation one set of rules for personal data. If you decide why and how it is processed - customers, employees, partners - you are a Data Fiduciary, and from 13 May 2027 you must be able to evidence how you handle it. There is no turnover or headcount threshold to fall below.

Does the DPDP Act apply to us?

  • You hold customer, user or subscriber records
  • You employ people in India, or hire them
  • You run a website, app or contact centre that collects data
  • You market to individuals, or profile them
  • You use cloud, BPO, analytics or agency partners
  • You serve Indian users from outside India

The Act also reaches data you collected before the Rules were notified, if you are still processing it.

Six obligations, and the evidence each one needs

Each one is a question the Data Protection Board can put to you. The acceptable answer is a record, not a policy document.

Section 5

Notice at collection

An itemised notice at every collection point - web, app, contact centre, in-person, partner-assisted - in the scheduled languages.

Section 6

Consent and withdrawal

Free, specific, informed consent with a verifiable record. Withdrawal must be as easy as giving it, and must reach every downstream system.

Sections 11-14

Data principal rights

Access, correction, erasure and grievance redressal, fulfilled to a defined timeline, with an auditable record of every response.

Section 8(7)

Retention and erasure

Data erased once the purpose is served or consent withdrawn - across core systems, CRM, HRMS, data lakes, backups and vendor environments.

Sections 8(5)-8(6)

Safeguards and breach response

Reasonable security safeguards, and the ability to notify the Board and every affected individual within the mandated window.

Sections 8(2), 10

Processors and SDF duties

DPDP-compliant contracts with every processor, plus DPIA, audit and DPO duties if you are notified a Significant Data Fiduciary.

What non-compliance costs

Penalties are assessed per instance and not capped in aggregate. These are the maximums set out in the Schedule; the Board determines the amount in each case.

₹250 crore

Maximum penalty for failure to take reasonable security safeguards - Section 8(5).

₹200 crore

Maximum penalty for failure to notify a breach, and for breach of the children's data obligations - Sections 8(6) and 9.

Where the deadlines fall

November 2025DPDP Rules notified. Data Protection Board constituted and able to receive complaints.
November 2026Consent Manager registration and the related provisions commence.
13 May 2027Substantive obligations apply in full. No grace period has been announced.
02 How it works

Six stages. One defensible position.

The 6A methodology is how we run every DPDP engagement. Each stage has a defined output you can put in front of a board or a regulator, so you always know where you are and what it has produced.

A1

Assess

Data discovery across systems, channels and vendors. We establish what personal data you hold, where it came from and where it goes.

OutputData inventory and RoPA
A2

Analyse

Gap analysis against the Act and the Rules, cross-mapped to the ISO, sectoral and contractual controls you already operate.

OutputScored gap register
A3

Architect

Notice and consent journeys, retention schedules, rights workflows, breach playbook and governance roles, designed to fit how you run.

OutputRemediation blueprint
A4

Apply

Implementation alongside your legal, IT and business teams - drafting, configuring, re-papering contracts, closing the register.

OutputRemediated controls
A5

Assure

Independent validation that each control operates and is evidenced, including DPIAs where the Act requires them.

OutputEvidence pack
A6

Advance

Periodic review, processor reassessment, training and change triggers for every new product, vendor or market.

OutputSustained readiness

Most organisations engage us at A1-A2 to establish the true position, then decide how much of A3-A6 to run with us.

Book A Discovery Call
03 Who runs your assessment

Certified expertise across privacy, security and audit.

DPDP readiness requires more than a single area of expertise. It brings together data privacy, information security, governance, risk and audit.

Our engagements are supported by certified professionals with recognised credentials across these disciplines, including expertise in privacy management, information security, audit and cybersecurity.


Whether your organisation is just beginning its DPDP journey, has already completed an initial assessment, or is working toward full implementation, our team can support you at every stage. We help organisations assess their current position, identify compliance gaps, prioritise remediation, strengthen privacy and security controls, and build a practical roadmap toward sustained DPDP readiness.

The result is a structured, multidisciplinary approach designed to make DPDP compliance practical, defensible and aligned with your organisation’s operational realities.

04 Free readiness check

Not ready for a call? Find out where you stand first.

Ten questions drawn from the assessments we run, scored across the six domains the Act is enforced on. Each question maps to the provision it comes from.

10 questions ~3 minutes 6 domains No login, no payment
Start the readiness check

At the end you will be asked for your name, work email, phone and designation to unlock your score and your top three gaps.

DPDP full compliance in -- days - find your gaps before a regulator or a customer does.
Book A Discovery Call
DPDPassure — DPDPA Compliance. Assured.
Live webinar

DPDPA Simplified
Decoding India's DPDPA: A Practical Approach To Personal Data Protection

Oct
14
Wednesday, 14 October 2026
3:00 pm – 4:00 pm IST
Key speakers
SD
Mr. Santosh Desai
Head GRC, Allied Boston
VM
Gp. Capt. Mathew P. Varghese (Retd)
Principal Consultant, Allied Boston
GS
Ms. Gauri Saple
Principal Consultant, Allied Boston
Register For The Webinar
Powered by Secure & Comply Allied Boston