We turn your gaps into working compliance: notices, consent, policies, contracts and a breach plan written for how your product actually works, and rolled out with your team in 4 to 6 weeks.
| Deliverable | What it covers | Law |
|---|---|---|
| Privacy notices | Standalone, plain-language notices for each point of collection, itemising the data and the purposes | S. 5 · Rule 3 |
| Consent design and records | Consent wording, withdrawal as easy as giving consent, and a record of who agreed to what | S. 6 |
| Data protection policy | Internal rules for collection, access, sharing and use, with named owners | S. 8 |
| Security safeguards map | Encryption, access control, logging and backups mapped to your stack | S. 8(5) · Rule 6 |
| Retention and erasure schedule | How long each data type is kept, what triggers erasure, and log retention of at least one year | S. 8(7) · Rule 8 |
| Breach response playbook | Who does what in the first hours, user notices, and the 72-hour report to the Board | S. 8(6) · Rule 7 |
| Processor agreements | Data processing terms for your cloud, CRM, payments and other vendors | S. 8(2) |
| Rights and grievance procedure | Request routes, identity checks and a response workflow within 90 days | Ss. 11 to 14 · Rule 14 |
| Published privacy contact | The business contact of the person who answers questions about your processing | Rule 9 |
| Team training | One live session for founders and everyone who handles customer data | S. 8 |
We start from your readiness check (or an assessment you already have), confirm priorities and agree who on your side owns each change.
Notices, policies, contracts and the breach playbook, drafted around your real data flows rather than a template.
We specify the changes to sign-up, consent and settings screens. Your developers build them and we review before release.
A live training session, a breach drill on paper, and a handover pack with every document and its owner.
We recommend it, because the pack is scoped from the gaps it finds. If you already have a recent DPDP assessment from elsewhere, we can start from that instead.
No. Every notice, policy and contract is drafted around your actual data flows, vendors and product screens. Templates are where most DPDP gaps come from.
We specify the changes to sign-up, consent and settings screens in writing. Your developers make them, and we review the result before it goes live.
Yes. We set the consent approach for cookies, analytics and advertising tags, including a banner with a genuine reject option, the way legismith.com runs its own.
Compliance has to keep up with your product. Privacy Care, from ₹10,000 per month, keeps the documents current and handles rights requests, grievances and breaches as they come.
Tell us about your product, your main vendors and roughly how many users you have. You will get a fixed-fee quote for the compliance pack within 24 hours.
Prefer chat? WhatsApp us.
General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.
We use essential cookies to run this website and keep our enquiry forms secure. With your permission we would also like to use analytics cookies, to see how the site is used, and advertising cookies, to measure our Google Ads. These collect your IP address, device and browser details and the pages you visit, and share them with Google and Cloudflare. You can change or withdraw your choice at any time using Cookie settings at the bottom of every page, or write to [email protected].
Disclaimer: Under the Bar Council of India rules, advocates may not advertise or solicit work. This website only shares general information on intellectual property. It is not an advertisement, a solicitation or legal advice, and using it does not create a lawyer–client relationship.