A fixed-fee DPDP gap assessment for startups. We map the personal data you hold, test it against the DPDP Act and the DPDP Rules, 2025, and give you a ranked list of what to fix before 13 May 2027.
Every category of personal data you collect from users, customers and employees: the source, the purpose, where it is stored, who can see it and which vendors receive it.
Sign-up flows, forms, app permissions, cookies and marketing lists, tested against the notice requirements of rule 3 and the consent standard of section 6.
Cloud, CRM, payments, analytics and support tools: whether your contracts bind them to protect the data and delete it when the work ends.
The minimum safeguards in rule 6 (encryption, access control, logs, backups) and whether your team could notify users and the Board on time after a breach.
Erasure once the purpose ends, processing logs kept for at least one year, and the 48-hour advance notice that applies to listed sectors under rule 8.
How users exercise their rights and grievances (90 days under rule 14), whether children use your product, cross-border transfers, and signs you could be notified as a Significant Data Fiduciary.
A spreadsheet of every personal data category with its purpose, source, storage location, processors and retention period. It becomes the base for everything that follows.
Each gap tied to the section or rule it breaches, rated high, medium or low risk, with the reason in plain language.
The fixes in order, with an owner and effort for each, plus a fixed quote for the Compliance Pack if you would like us to do the work.
Your privacy policy, sign-up and enquiry forms, app screens that collect data, a list of the tools and vendors that receive personal data, and your key customer and vendor contracts. Most founders assemble it in an afternoon.
No. We work from documents, screenshots and your answers to our questionnaire. If a question can only be settled by looking at a system, we ask your team to show us on a call.
Usually yes. The DPDP Rules require a standalone notice at the point of collection, consent records, breach reporting, erasure schedules and a rights process. A privacy policy covers only part of that, and older policies rarely match the Rules.
The practice is led by our partners, Amar Gite and Santosh Sangle, and a partner walks you through the findings on the final call.
The check is built around the DPDP Act, and it flags where the GDPR asks for something different, so you can plan one set of documents that serves both wherever the law allows.
Tell us your company name, what your product does and roughly how many users you have. You will get a fixed-fee quote for the readiness check within 24 hours.
Prefer chat? WhatsApp us.
General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.
We use essential cookies to run this website and keep our enquiry forms secure. With your permission we would also like to use analytics cookies, to see how the site is used, and advertising cookies, to measure our Google Ads. These collect your IP address, device and browser details and the pages you visit, and share them with Google and Cloudflare. You can change or withdraw your choice at any time using Cookie settings at the bottom of every page, or write to [email protected].
Disclaimer: Under the Bar Council of India rules, advocates may not advertise or solicit work. This website only shares general information on intellectual property. It is not an advertisement, a solicitation or legal advice, and using it does not create a lawyer–client relationship.