DPDP full compliance: 13 May 2027. The Data Protection Board is already accepting complaints. 254 days → Book a scoping call

DPDP ACT, 2023 & DPDP RULES, 2025

Moving Compliance at the Speed of Business

Sentinel runs your DPDP compliance programme end to end — discovery, documentation, evidence, and continuous monitoring. Every legal position is reviewed and signed by an independent law firm.

Powered by technology. Assured by real lawyers.

Sentinel does the discovery, drafting and monitoring. Independent law firms review and sign the legal positions.

The runway is shorter than it looks.

The Rules were notified on 13 November 2025. Enforcement did not wait for the compliance deadline — the Board has been constituted and taking complaints since day one.

  1. 13 Nov 2025

    Board constituted. Complaints can be filed.

  2. 13 Nov 2026

    Consent Manager registration opens. Penalty provisions become operative.

  3. 13 May 2027

    Full compliance. No grace period has been indicated.

Discovery alone takes most organisations a quarter.

Every obligation, keyed to the rule that creates it.

Sentinel encodes the DPDP Act and Rules 3 to 16 as a machine-readable obligation model. We map it against your actual systems, not a generic checklist — so you get a register that says which obligations apply to you, which don't, who owns each one, and what evidence closes it.

Scoped out is a status, not a blank. Every exclusion is reasoned and signed.

A compliance record that doesn't go stale the week after you sign it.

New vendor in the expense feed. New OAuth grant in Workspace. New column in a production table. New tracker on the marketing site. Sentinel watches for the changes that quietly break your register and opens a task with an owner. Where you have no systems to connect, scheduled attestation does the same job — a three-question check to each system owner, every quarter.

We augment the programme with AI so monitoring runs continuously between reviews. The legal call is always a lawyer's.

Three stages. Start with the first.

  1. 01 — Assess

    Six to eight weeks, fixed fee. We scope your obligations, discover where personal data actually lives, build your processing register, and run a gap assessment against the notified Rules. Ends with a signed applicability opinion and a costed roadmap.

    • applicability_opinion.pdf
    • processing_register.xlsx
    • gap_report.pdf
  2. 02 — Implement

    Notices, consent architecture, rights workflows, retention schedules, vendor agreements, breach runbook, security control mapping. You take only the modules the assessment says you need.

    • privacy_notice_v3.docx
    • dpa_template.docx
    • breach_runbook.pdf
  3. 03 — Sustain

    Continuous monitoring, quarterly attestation, regulatory watch, and a mock inquiry each cycle that produces the evidence pack a regulator would ask for — and tells you what you can't actually produce.

    • evidence_pack.zip
    • drift_log
    • mock_inquiry_score

Built for how you actually process data.

  • B2B SaaS

    Enterprise procurement is already asking. Turn a deal blocker into a trust page.

  • D2C & consumer

    Consent architecture is engineering work. Withdrawal propagation takes months.

  • BFSI, insurance, health

    DPDP sits on top of RBI, IRDAI and SEBI. One register, not three.

  • Indian subsidiary of a global group

    You already have a GDPR programme. We map the delta, not a rebuild.

  • NGOs & Section 8 companies

    There is no non-profit exemption. Most boards don't know this yet.

You don't buy a dashboard. You buy the record.

  • Signed applicability opinion
  • Processing register
  • Gap assessment and roadmap
  • Privacy notices in Eighth Schedule languages
  • Retention schedule
  • Vendor processing agreements
  • Breach response runbook
  • Rights fulfilment procedures
  • Evidence pack

Each one reviewed and approved before it goes live.

Are you a Significant Data Fiduciary?

Designation is made by the Central Government based on data volume, sensitivity, risk to data principals, and national impact. If it applies to you, so do additional obligations — an India-based Data Protection Officer, periodic Data Protection Impact Assessments, and an independent audit.

Talk to our SDF team

The five things people say before they start.

Skip the pitch.

Give us an hour. We'll run a live applicability review on your actual processing and show you the register we'd build — before you commit to anything.