Industry Coverage

DPDP compliance built for your industry.

The obligations are the same. The data flows, the sharing chains, and the risks are not. We bring industry context to every engagement so compliance lands in the right place, not just on paper.

Sensitive data + long sharing chains

Health Insurance

SDF Risk

Your TPA sees everything. So does the regulator.

Health insurers process diagnoses, prescriptions, and claims across a chain of processors — TPAs, hospitals, wellness partners, analytics vendors. Every link needs a contract. Every consent needs to be verifiable. We build the infrastructure that makes that possible.

Key obligations

Verifiable consent for sensitive health data
Data processing agreements with TPAs and processors
Breach notification within 72 hours
Retention limits on claims and medical records

Penalty exposure

Up to ₹250 crore

See full guide →

KYC, account aggregators, credit data

Fintech and Lending

SDF Risk

Financial data flows need consent at every step.

NBFCs, lending platforms, and wealth apps process KYC, account-aggregator feeds, and credit history. Consent chains are long. Purpose limitation is strict. And RBI scrutiny amplifies DPDP exposure. We map every data flow and build consent and rights infrastructure that holds up.

Key obligations

Purpose-limited consent for KYC and credit data
Account aggregator compliance alignment
Data principal rights portal for customers
Processor contracts with DSPs, bureaus, and analytics partners

Penalty exposure

Up to ₹250 crore

See full guide →

Children's data — highest protection tier

EdTech and LMS

If your platform has learners under 18, the stakes are different.

DPDP gives children's data its own protection tier: verifiable parental consent, no behavioural tracking, no targeted advertising. Most edtechs are nowhere near compliant on this. We build the consent verification flows, parental rights portal, and tracking guardrails that the statute requires.

Key obligations

Verifiable parental consent for users under 18
No behavioural tracking or profiling of minors
No targeted advertising to children
Age verification mechanism

Penalty exposure

Up to ₹200 crore per violation

See full guide →

Customer PII, payment data, marketing consent

E-commerce and D2C

Checkout consent is not marketing consent.

D2C brands collect customer data at checkout, then use it for remarketing, segmentation, and analytics. Those are different purposes and DPDP requires separate, specific consent for each. We untangle your consent flows, update your privacy notices, and build the rights portal your customers can actually use.

Key obligations

Purpose-specific consent at checkout and post-purchase
Marketing opt-in separated from transactional consent
Data deletion and correction request handling
Third-party marketing vendor agreements

Penalty exposure

Up to ₹250 crore

See full guide →

Employee data across multiple client organisations

HR Tech and Payroll

You process employee data for dozens of companies. Each one is your liability.

HR platforms, payroll processors, and staffing tools act as Data Processors for their clients — who are the Fiduciaries. That means airtight data processing agreements, strict purpose limitation, and breach response procedures that cover every client. We build the infrastructure and documentation that makes that viable at scale.

Key obligations

Data processing agreements for every client
Purpose limitation on employee personal data
Breach notification runbook covering sub-processors
Retention and erasure automation post-offboarding

Penalty exposure

Up to ₹250 crore

See full guide →

Buyer KYC, financial data, broker sharing chains

Real Estate and Proptech

Lead databases shared across brokers and lenders are a compliance liability.

Real estate platforms collect KYC, financial details, and location preferences, then share them across broker networks and lending partners. Under DPDP, every handoff needs a lawful basis and a contract. We map your data flows and build the agreements and consent infrastructure that cover your entire distribution chain.

Key obligations

Lawful basis for lead data sharing with brokers
Processor contracts with lending and valuation partners
Data principal rights for buyers and sellers
Retention limits on stale lead data

Penalty exposure

Up to ₹250 crore

See full guide →

Not listed here?

If your product collects personal data from Indian users, the DPDP Act applies. We have worked across healthcare, fintech, SaaS, gaming, real estate, and manufacturing. If your sector is not listed, the engagement is the same. The data flows are different.

Enforcement begins 13 May 2027. The build takes months.

Take the readiness check