Technology & Business Consulting
Information Security & Data Privacy
The Digital Personal Data Protection Act, 2023 turned privacy from a policy document into an operating discipline: notices, itemised consent, retention limits, rights requests with deadlines. We build programmes where these run as routine — not as a scramble before an audit.
Scope of work
Privacy you can demonstrate, not just declare.
We practise what we advise: this website itself runs itemised consent with receipted artifacts, purpose-wise retention and a live rights channel. The same engineering-and-governance pairing is what we bring to client programmes.
- Data inventory and mapping: what personal data exists, where it flows, who touches it
- DPDP Act 2023 gap assessment and remediation roadmap — notices, consent, retention, grievance
- Consent architecture design: purpose taxonomies, artifact records, withdrawal symmetry
- ISMS establishment and ISO 27001-aligned control frameworks
- Data Principal rights operations: intake, verification, fulfilment within statutory windows
- Processor governance: contracts, registers and periodic review of every third party touching personal data
- Breach readiness: runbooks, notification templates and rehearsals
Could you answer a rights request tomorrow morning?
If that question raises more questions, a structured gap assessment is the right first step.
Discuss this service All services