Digital Personal Data Protection Act / India / engineering, not advisory

DPDP compliance, built into your product

Consultants hand you a 47-point checklist. We ship the code. Consent infrastructure, rights automation, retention pipelines and breach workflow — built into the system that holds the data, not documented alongside it.

13 Nov 2026 Consent Manager obligations live under Rule 4 — enforcement and penalties begin Milestone one
13 May 2027 Full compliance deadline for the operative obligations Milestone two
₹250 Cr Ceiling on penalties per contravention Downside
₹2,100+ Cr Transacted on a platform we built to these obligations, FY 2025–26 UnlistedZone · Fintech
A policy document does not delete a record. A pipeline does.

Compliance you can demonstrate, not compliance you can describe

What we build

Five pieces of infrastructure. Each one is code that runs, with an audit trail behind it.

Consent management infrastructure

Capture, versioning, withdrawal and a complete audit trail. Consent is not a boolean column — it is a versioned record of what was asked, in what language, against which purpose, and what the data principal answered. When the purpose changes, prior consent does not silently carry over.

Data principal rights, automated

Access, correction and erasure requests handled by the system rather than by a support inbox. A rights request that depends on somebody remembering to run a query is a rights request you will miss the statutory clock on. Ours resolve against the data model and return a receipt.

Retention and deletion pipelines that actually delete

Scheduled erasure that reaches the replicas, the backups, the search index, the analytics warehouse and the log lines — not just the primary row. Most “deletion” implementations soft-delete a record and leave five copies standing. That is the gap an inquiry finds.

Breach detection and 72-hour notification workflow

Detection wired to the systems that would actually show a breach, and a notification workflow that assembles the intimation to the Board and to affected data principals inside the window. The clock is short enough that the workflow has to exist before the incident, not after.

Consent Manager integration

Integration with registered Consent Managers under Rule 4, live from 13 November 2026 — so consent captured through a Consent Manager and consent captured in your own flow resolve to one authoritative record rather than two that disagree.

Why engineering rather than advisory

A compliance audit produces a gap list. Someone still has to build the consent versioning, wire the erasure into the warehouse, and make the breach workflow fire. That build is the entire cost and the entire risk, and it is the part a checklist stops at.

We come at it from the other side. Every obligation in the Act resolves to something specific in a data model — a purpose field, a version chain, a deletion job, an audit table, a retention clock. We build those, in your stack, and hand you a system that can demonstrate compliance on request instead of asserting it in a PDF.

The question a regulator asks is not “what is your policy?” It is “show me this person’s data, and show me it is gone.”

We built this for ourselves first

We built this for UnlistedZone — a platform that moved over ₹2,100 crore in FY 2025–26 under financial-sector data obligations, where the consent record, the retention clock and the audit trail are not optional and never were.

That platform runs on the same accounting and data core as the rest of our portfolio, which means the consent, rights and retention layers were built to sit beside an existing system without destabilising it — the adapter discipline described on the AI development page. Same engineering, your stack.

The dates that matter

The operative obligations arrive in two steps. Build time runs backwards from the second one.

13 Nov 2026
Consent Manager obligations commence under Rule 4. Enforcement and penalties begin.
13 May 2027
Full compliance deadline for the operative obligations of the Act and Rules.
₹250 crore
Maximum penalty per contravention, for failure to take reasonable security safeguards to prevent a personal data breach.
72 hours
The window in which a breach intimation workflow has to already work. Which means it has to be built well before.

Dates reflect the notified implementation schedule of the DPDP Act and Rules. This page describes engineering work, not legal advice — your counsel determines which obligations apply to you, and we build to that.

The deadline is
a build schedule,
not a filing date.

Capacity: 2–3 engagements per year

Talk about your exposure →

Tell us what data you hold, what your stack is, and which date you are building towards. Budget range, timeline and IP terms are on the form.