India Digital Personal Data Protection Act · Enforcement 13 May 2027

Your product collects data. The law is about to audit how.

India's DPDP Rules are live. Most products have compliance gaps across consent, user rights, retention, and breach handling. We audit your product and implement the fixes before enforcement begins.

₹250 Cr

MAX PENALTY ·

SECURITY SAFEGUARDS

₹200 Cr

MAX PENALTY · BREACH

NOTIFICATION

13 May 2027

FULL ENFORCEMENT

DEADLINE

Source: DPDP Act 2023, Schedule. Data Protection Board of India.

Check your compliance score

A privacy policy is not compliance.

Most legacy consent is already invalid under DPDP's verifiable-consent standard. Pre-ticked boxes and buried opt-ins won't pass muster. The law requires clear, explicit, and revocable consent, and it must be technically auditable.

The obligations are engineering problems, not legal problems. Consent flows, rights portals, and breach detection are code, not documents. A privacy policy tells users what you do. Compliance means building the systems that prove you do it.

The enforcement window is real and closing. Full enforcement begins 13 May 2027. The Data Protection Board is live. Penalties are not theoretical; they are enumerated in the statute.

Time remainingThe deadline is fixed. Every sprint cycle you don't spend on DPDP is a sprint cycle you'll need under pressure in 2026.
"We don't hand you a checklist. We ship the fix into your product."

Audit

Map every point where personal data is collected, processed, stored, or shared. Identify gaps against DPDP Rules 2025 and prioritise them by regulatory risk.

Gap Report

A scored compliance report showing: Regulatory obligation, Risk severity, Affected systems, Recommended remediation, Engineering effort

Engineering Sprint

Consent flows, withdrawal mechanisms, rights request workflows, breach response systems, and compliance controls implemented directly into your product.

Evidence Pack

Audit-ready documentation, implementation records, policies, and evidence required during regulatory review.

Three tiers. Fixed scope. No surprises.

Every tier is a defined deliverable, not an open-ended retainer. Pricing is shared on the discovery call.

Audit

Discover what needs fixing


  • Data flow mapping
  • Gap analysis report against DPDP Rules 2025
  • Prioritised fix roadmap
  • One readout session
MOST CHOSEN

Compliance Sprint

Audit + implementation


  • Everything in Audit
  • Consent flow built and shipped
  • DPDP-compliant privacy notice and T&Cs
  • Data principal rights portal
  • Breach notification runbook
  • Retention and erasure automation
  • 30 days post-launch support

Enterprise

Multi-product or multi-entity


  • Everything in Sprint
  • Multi-product or multi-entity scope
  • Significant Data Fiduciary readiness check
  • DPO handoff documentation
  • Optional ongoing retainer

Pricing shared on the discovery call. The Audit tier is the natural first step; it scopes the Sprint.

How we're different

Most DPDP providers stop before implementation.

DPDP is enforced against what your product does, not what your documents say.

RequirementLegal AdvisorAudit ProviderGetDpdpCompliant.com
Explain DPDP obligations
Review policies and noticesPartial
Audit product data flows
Identify technical gapsPartial
Design consent architecturePartial
Build rights-request workflows
Implement compliance controls
Ship changes into production
Create audit evidence packPartialPartial

Most providers can tell you what DPDP requires. Some can identify where you're exposed. Very few can implement the systems required to comply.

DPDP is ultimately enforced against what your product does, not what your documents say.

That's why we focus on the implementation layer: consent systems, rights management, retention controls, breach workflows, and audit evidence.

Built by the team behind Smoketrees Digital, a product engineering company that has spent years implementing analytics, consent systems, customer data infrastructure, and workflow automation for digital businesses.

Scope check

Are you likely covered by DPDP?

If you checked even two of these boxes, there is a strong chance your product has DPDP obligations.

Check your readiness score →

Your business probably qualifies if it:

Collects user registrations
Uses analytics tools
Stores customer information
Sends marketing emails
Uses CRM systems
Runs a mobile app
Accepts online payments
Tracks user behaviour
Uses third-party SaaS tools
Processes personal data of Indian residents

Built for product companies.

Typically hired by

FoundersCTOsProduct LeadersCompliance TeamsEngineering Leads
01

Audit

Data flow mapping and gap analysis against DPDP Rules 2025

02

Sprint

Consent flows, rights portal, and breach systems built and shipped

03

Handoff

Evidence pack and documentation ready for your audit trail

Frequently asked questions

Start here

Don't know where you stand? Find out in 10 questions.

Answer 10 questions about your product. We analyse your gaps and send a personalised DPDP compliance report to your inbox.

Start the readiness check →

No pitch. No invoice. Just a gap report.