Your product collects data. The law is about to audit how.
India's DPDP Rules are live. Most products have compliance gaps across consent, user rights, retention, and breach handling. We audit your product and implement the fixes before enforcement begins.
₹250 Cr
MAX PENALTY ·
SECURITY SAFEGUARDS
₹200 Cr
MAX PENALTY · BREACH
NOTIFICATION
13 May 2027
FULL ENFORCEMENT
DEADLINE
Source: DPDP Act 2023, Schedule. Data Protection Board of India.
A privacy policy is not compliance.
Most legacy consent is already invalid under DPDP's verifiable-consent standard. Pre-ticked boxes and buried opt-ins won't pass muster. The law requires clear, explicit, and revocable consent, and it must be technically auditable.
The obligations are engineering problems, not legal problems. Consent flows, rights portals, and breach detection are code, not documents. A privacy policy tells users what you do. Compliance means building the systems that prove you do it.
The enforcement window is real and closing. Full enforcement begins 13 May 2027. The Data Protection Board is live. Penalties are not theoretical; they are enumerated in the statute.
"We don't hand you a checklist. We ship the fix into your product."
Audit
Map every point where personal data is collected, processed, stored, or shared. Identify gaps against DPDP Rules 2025 and prioritise them by regulatory risk.
Gap Report
A scored compliance report showing: Regulatory obligation, Risk severity, Affected systems, Recommended remediation, Engineering effort
Engineering Sprint
Consent flows, withdrawal mechanisms, rights request workflows, breach response systems, and compliance controls implemented directly into your product.
Evidence Pack
Audit-ready documentation, implementation records, policies, and evidence required during regulatory review.
Three tiers. Fixed scope. No surprises.
Every tier is a defined deliverable, not an open-ended retainer. Pricing is shared on the discovery call.
Audit
Discover what needs fixing
- Data flow mapping
- Gap analysis report against DPDP Rules 2025
- Prioritised fix roadmap
- One readout session
Compliance Sprint
Audit + implementation
- Everything in Audit
- Consent flow built and shipped
- DPDP-compliant privacy notice and T&Cs
- Data principal rights portal
- Breach notification runbook
- Retention and erasure automation
- 30 days post-launch support
Enterprise
Multi-product or multi-entity
- Everything in Sprint
- Multi-product or multi-entity scope
- Significant Data Fiduciary readiness check
- DPO handoff documentation
- Optional ongoing retainer
Pricing shared on the discovery call. The Audit tier is the natural first step; it scopes the Sprint.
How we're different
Most DPDP providers stop before implementation.
DPDP is enforced against what your product does, not what your documents say.
| Requirement | Legal Advisor | Audit Provider | GetDpdpCompliant.com |
|---|---|---|---|
| Explain DPDP obligations | ✓ | ✓ | ✓ |
| Review policies and notices | ✓ | Partial | ✓ |
| Audit product data flows | ✗ | ✓ | ✓ |
| Identify technical gaps | ✗ | Partial | ✓ |
| Design consent architecture | ✗ | Partial | ✓ |
| Build rights-request workflows | ✗ | ✗ | ✓ |
| Implement compliance controls | ✗ | ✗ | ✓ |
| Ship changes into production | ✗ | ✗ | ✓ |
| Create audit evidence pack | Partial | Partial | ✓ |
Most providers can tell you what DPDP requires. Some can identify where you're exposed. Very few can implement the systems required to comply.
DPDP is ultimately enforced against what your product does, not what your documents say.
That's why we focus on the implementation layer: consent systems, rights management, retention controls, breach workflows, and audit evidence.
Built by the team behind Smoketrees Digital, a product engineering company that has spent years implementing analytics, consent systems, customer data infrastructure, and workflow automation for digital businesses.
Scope check
Are you likely covered by DPDP?
If you checked even two of these boxes, there is a strong chance your product has DPDP obligations.
Check your readiness score →Your business probably qualifies if it:
Built for product companies.
Typically hired by
Audit
Data flow mapping and gap analysis against DPDP Rules 2025
Sprint
Consent flows, rights portal, and breach systems built and shipped
Handoff
Evidence pack and documentation ready for your audit trail
Frequently asked questions
Start here
Don't know where you stand? Find out in 10 questions.
Answer 10 questions about your product. We analyse your gaps and send a personalised DPDP compliance report to your inbox.
No pitch. No invoice. Just a gap report.