Home/Services/DPDP Act Compliance

DPDP Act Compliance

DPDP Act compliance for Pune and PCMC businesses: a practical path, not a policy binder.

The Digital Personal Data Protection Act, 2023 puts real duties on any business that handles personal data of individuals in India. The Act allows penalties up to ₹250 crore. The Rules were notified on 13 November 2025, and the main obligations are due to apply from 13 May 2027, unless MeitY notifies otherwise.

That gives you a workable window. We help you use it: find where personal data sits in your business, fix what is weak, and build habits your staff can follow.

Where does your business stand today?

Answer five short questions with our DPDP assistant and get a readiness score. Free, no signup.

Key Dates

  • •13 November 2025: DPDP Rules notified.
  • •13 November 2026: provisions on consent managers start.
  • •13 May 2027: main duties of data fiduciaries apply, unless MeitY notifies otherwise.
  • •Dates can shift by notification. We check the official position before every engagement.

How we approach it

  1. 1. Gap assessmentWe compare what you do today against what the Act and Rules expect, and list the gaps in order of urgency.
  2. 2. Data mappingWe trace where personal data comes in, where it lives, who can see it, who it is shared with, and how long it is kept. Most businesses are surprised by how many copies exist.
  3. 3. Consent and notice reviewWe read your forms, website, app screens and paper sign-up sheets. Is the notice clear? Is consent specific? Can someone withdraw it as easily as they gave it?
  4. 4. Security safeguardsWe check access control, encryption, backups, logging, vendor access and device hygiene. Where technical testing is needed, we link it to our VAPT service.
  5. 5. Breach-response planWho decides something is a breach, who calls whom, what gets recorded, and who reports to the Board and to affected individuals. We write this as a one-page runbook and rehearse it once.
  6. 6. Staff trainingCompliance fails at the front desk, not in the policy document. We train your teams on what personal data is, what they can and cannot do with it, and how to report a mistake early.

Step-by-Step Timeline

  1. 1. Intro call. Understand your business and data types. About 30 to 45 minutes.
  2. 2. Gap assessment. Interviews, document and system review. Typically one to two weeks, depending on scope.
  3. 3. Data mapping. Data inventory and flow diagram. Typically one to two weeks, depending on scope.
  4. 4. Consent and notice fixes. Revised notices, forms, consent wording. Typically one to two weeks, depending on scope.
  5. 5. Safeguards and breach plan. Recommendations, runbook, rehearsal. Typically a few weeks, depending on scope.
  6. 6. Staff training. Sessions for relevant teams. Typically a day or two of sessions.
  7. 7. Handover. Final report and roadmap. Typically a few days.

Small businesses with few systems often finish faster. Larger ones with several locations take longer. We confirm after the intro call.

What You Receive

  • ✓Gap assessment report ranked by priority
  • ✓Personal data inventory and flow map
  • ✓Redrafted privacy notices and consent wording for your forms and website
  • ✓Security safeguards checklist with owner and action for each item
  • ✓Breach-response runbook and a contact sheet
  • ✓Staff training attendance records for your compliance file
  • ✓A 12-month roadmap to the May 2027 date and beyond

Who Is This For

  • →SMEs and MSMEs in Pune and PCMC holding customer, vendor and employee data in Tally, Excel, WhatsApp and email
  • →Manufacturers with dealer, vendor and employee records across ERP and portals
  • →Co-operative banks and societies with member KYC, loan and account data
  • →Hospitals and clinics with patient records, reports and billing details
  • →Schools, coaching classes, and service firms that collect data from parents, students or clients

What We Don't Do

We are not a law firm and do not give legal opinions. For contract clauses, cross-border questions or interpretation disputes, we will tell you when to involve a lawyer. We do not sell software or promise a "DPDP certificate", as none exists. We do not act as your Data Protection Officer, and we do not file anything with authorities on your behalf.

Related

Frequently Asked Questions

Does the DPDP Act apply to a small business?

If you process digital personal data of individuals in India, in most cases yes. Size does not exempt you by default. Certain classes of businesses may get relaxations through rules, so we check the current position for your case.

When do we have to comply?

The Rules were notified on 13 November 2025. Consent-manager provisions start from 13 November 2026, and the main duties apply from 13 May 2027, unless MeitY notifies otherwise. Starting early avoids a rush.

What counts as personal data in our business?

Anything that identifies a living person: names, phone numbers, email addresses, Aadhaar or PAN copies, photographs, medical details, bank details, employee records, CCTV footage. Data mapping usually finds more of it than owners expect.

Do we need a Data Protection Officer?

The Act requires a DPO or designated contact for certain categories of fiduciary, not for every business. We tell you what applies to you and who inside your team should own the role.

Is a privacy policy on the website enough?

No. A notice must be given at the point of collection, in clear language, and your actual practices must match it. A policy that says one thing while forms and staff do another is a risk in itself.

What happens if we have a data breach?

You need to detect it, contain it, and notify the Data Protection Board and affected individuals as the Rules require. The breach-response plan we build sets out who does what in the first hours.

Can you also test our systems?

Yes. We can add a VAPT engagement to check that your technical safeguards hold up.

Do you work with hospitals and co-operative banks?

Yes. These sectors handle sensitive data and often have sector rules alongside DPDP, so we scope them carefully and flag where sector regulators may add requirements.

Ready to Get Started?

Tell us about your requirements and we'll respond with a tailored proposal within 24 hours.