DPDP ACT, 2023 & DPDP RULES, 2025
Moving Compliance at the Speed of Business
Sentinel runs your DPDP compliance programme end to end — discovery, documentation, evidence, and continuous monitoring. Every legal position is reviewed and signed by an independent law firm.
Powered by technology. Assured by real lawyers.
Sentinel does the discovery, drafting and monitoring. Independent law firms review and sign the legal positions.
The runway is shorter than it looks.
The Rules were notified on 13 November 2025. Enforcement did not wait for the compliance deadline — the Board has been constituted and taking complaints since day one.
-
13 Nov 2025
Board constituted. Complaints can be filed.
-
13 Nov 2026
Consent Manager registration opens. Penalty provisions become operative.
-
13 May 2027
Full compliance. No grace period has been indicated.
Discovery alone takes most organisations a quarter.
Every obligation, keyed to the rule that creates it.
Sentinel encodes the DPDP Act and Rules 3 to 16 as a machine-readable obligation model. We map it against your actual systems, not a generic checklist — so you get a register that says which obligations apply to you, which don't, who owns each one, and what evidence closes it.
Scoped out is a status, not a blank. Every exclusion is reasoned and signed.
Software can tell you what's missing.
It can't tell you what it means.
Compliance platforms disclaim legal advice, and their guidance hedges where it matters most. Sentinel doesn't. Drafts go to an empanelled law firm for review inside the platform. What you get back is a signed position you can put in front of a board, an auditor, or the Board of India.
Every approval is attributed. Who signed it, when, and against what facts.
A compliance record that doesn't go stale the week after you sign it.
New vendor in the expense feed. New OAuth grant in Workspace. New column in a production table. New tracker on the marketing site. Sentinel watches for the changes that quietly break your register and opens a task with an owner. Where you have no systems to connect, scheduled attestation does the same job — a three-question check to each system owner, every quarter.
We augment the programme with AI so monitoring runs continuously between reviews. The legal call is always a lawyer's.
Three stages. Start with the first.
-
01 — Assess
Six to eight weeks, fixed fee. We scope your obligations, discover where personal data actually lives, build your processing register, and run a gap assessment against the notified Rules. Ends with a signed applicability opinion and a costed roadmap.
- applicability_opinion.pdf
- processing_register.xlsx
- gap_report.pdf
-
02 — Implement
Notices, consent architecture, rights workflows, retention schedules, vendor agreements, breach runbook, security control mapping. You take only the modules the assessment says you need.
- privacy_notice_v3.docx
- dpa_template.docx
- breach_runbook.pdf
-
03 — Sustain
Continuous monitoring, quarterly attestation, regulatory watch, and a mock inquiry each cycle that produces the evidence pack a regulator would ask for — and tells you what you can't actually produce.
- evidence_pack.zip
- drift_log
- mock_inquiry_score
Built for how you actually process data.
-
B2B SaaS
Enterprise procurement is already asking. Turn a deal blocker into a trust page.
-
D2C & consumer
Consent architecture is engineering work. Withdrawal propagation takes months.
-
BFSI, insurance, health
DPDP sits on top of RBI, IRDAI and SEBI. One register, not three.
-
Indian subsidiary of a global group
You already have a GDPR programme. We map the delta, not a rebuild.
-
NGOs & Section 8 companies
There is no non-profit exemption. Most boards don't know this yet.
You don't buy a dashboard. You buy the record.
- Signed applicability opinion
- Processing register
- Gap assessment and roadmap
- Privacy notices in Eighth Schedule languages
- Retention schedule
- Vendor processing agreements
- Breach response runbook
- Rights fulfilment procedures
- Evidence pack
Each one reviewed and approved before it goes live.
Are you a Significant Data Fiduciary?
Designation is made by the Central Government based on data volume, sensitivity, risk to data principals, and national impact. If it applies to you, so do additional obligations — an India-based Data Protection Officer, periodic Data Protection Impact Assessments, and an independent audit.
Talk to our SDF teamThe five things people say before they start.
Good — that reduces the security work substantially, and we cross-map your existing evidence rather than duplicating it. But DPDP obligations around notice, consent, data principal rights, retention and children's data have no equivalent in either standard. Those are net new.
DPDP has no small-business threshold. Applicability turns on whether you process digital personal data of individuals in India, not on your size or revenue.
Also no exemption. A Section 8 company processing donor and beneficiary data is a Data Fiduciary with the same core obligations as a listed company.
They should keep handling it — Sentinel is how they handle it faster. We do the discovery, drafting and evidence work; your counsel or ours reviews and signs. If you'd like us to work alongside your existing advisers, that's the normal arrangement.
No. Vettam builds and runs the platform and the programme. Legal opinions are issued by independent empanelled law firms on their own letterhead.
Skip the pitch.
Give us an hour. We'll run a live applicability review on your actual processing and show you the register we'd build — before you commit to anything.
Retention beyond purpose needs a stated basis. Cap this at 90 days and key it to the erasure trigger, or state the legal obligation that requires the longer period.