Scope of work
- Data mapping and Records of Processing Activities (RoPA)
- DPDP-compliant privacy notices, consent flows, and preference centres
- Data Processing Agreements (DPAs) with vendors and sub-processors
- Data Principal request workflows (access, correction, erasure)
- Breach response playbook and Board-of-DPDP notification templates
- Data Protection Officer (DPO) advisory and training
- Cross-border transfer assessments (SCCs, adequacy)
Deliverables
- Data inventory and RoPA
- Website privacy notice, cookie banner, and consent manager configuration
- DPA templates and vendor register
- DPDP compliance dashboard and residual-risk memo
Timeline
01. Discovery
Week 1–2Data mapping across products, HR, and vendors.
02. Framework
Week 3–5Notices, consent, DPAs, and internal SOPs.
03. Rollout
Week 6–8Training, DPO onboarding, and breach drill.
Timelines are indicative. Regulatory processing times and third-party responses may vary.
Frequently asked questions
Is the DPDP Act in force?
The Act is enacted; operative provisions and the Data Protection Board are being notified in phases. We help you get compliance-ready ahead of hard deadlines.
Do we need a DPO?
Significant Data Fiduciaries must appoint a DPO. Even where optional, most enterprises assign a DPO or privacy lead as a governance best practice.
How do we handle child data?
Verifiable parental consent is required for users under 18. We design age-gating and consent workflows accordingly.
Related services
Explore adjacent workstreams we handle under the same single-window engagement.
Company Incorporation & Startup Setup
From idea to legally incorporated entity — done right, once.
Trademark Registration & Brand Protection
Own your name, logo, and tagline — before someone else does.
Vendor & Supplier Contract Advisory
Bulletproof contracts with the third parties your business depends on.
Ready to get started?
Book a consultation with Vrushali Borade to discuss your requirements and get a fixed-scope proposal.
