Methodology

From first conversation to compliant product.

An engineering-led compliance engagement. We map, diagnose, build, prove, and sustain DPDP readiness directly in your product, not in a document you'll never open again.

Map

Understanding your data landscape

TimelineWeek 1–2

We start with a complete personal data inventory: what you collect, where it lives, who has access, and which third parties receive it. This becomes the foundation of your data flow diagram, a visual record of every touch point between your product and personal data.

Deliverables

Personal data inventory
Data flow diagram
Third-party processor mapping
Lawful basis assessment

Diagnose

Scoring every gap against the statute

TimelineWeek 2–3

Every gap is evaluated against DPDP Rules 2025. Consent mechanisms, rights fulfilment, security safeguards, retention policies, and breach readiness, each scored and prioritised. You receive a clear roadmap: what's critical, what's compliance debt, and what can wait.

Deliverables

Gap analysis report scored against DPDP Rules 2025
Prioritised fix roadmap
Risk exposure estimate
Remediation briefing call

Build

Compliance shipped as code

TimelineWeek 3–10
Core engineering phase

This is where compliance becomes engineering. We build consent flows that meet verifiable-consent standards. We ship a data principal rights portal so users can request, update, or delete their data. We implement retention automation and write the breach notification runbook, all integrated into your product.

Deliverables

DPDP-compliant consent flows
Data principal rights portal
Breach notification runbook
Privacy notice and terms rewrite
Retention and erasure automation

Prove

Traceable evidence for any auditor

TimelineWeek 10–12

Documentation is evidence. We compile a compliance evidence pack that traces every control, every flow, and every retention policy back to its implementation. We also deliver a formal data protection assessment, the record that shows regulators how your product meets each DPDP obligation.

Deliverables

Compliance evidence pack
Data protection assessment document
Audit trail documentation
Control mapping matrix

Sustain

Staying compliant as your product evolves

TimelineOngoing
Optional retainer

Compliance is not one-and-done. We offer an optional retainer for quarterly health checks as your product evolves, and prepare you for Consent Manager readiness, the technical standard expected by the Board.

Deliverables

Quarterly compliance health checks
Consent Manager readiness review
Regulatory update briefings
On-call advisory hours

Engagement tiers

Tier
Duration
Includes
Audit Only
1–2 weeks
Data mapping, gap analysis, prioritised roadmap
Compliance Sprint
4–8 weeks
Audit + full engineering implementation + evidence pack
Enterprise
8–14 weeks
Sprint + multi-product scope + DPO handoff + retainer

We implement compliance at the technical and product layer. For formal legal opinions, we recommend pairing this engagement with your legal counsel. The two work best together.

Ready to start? Book a free 30-minute discovery call.

Take the readiness check