Skip to content

Every engagement lists its scope, timeline and fixed fee before checkout

Techluminate

DPDP Act Readiness Review

A practical gap assessment against India’s DPDP Act 2023, covering consent, retention, notices and breach procedures.

Timeline
15 working days
Deliverables
7 listed
Practice
Security & Compliance
Fixed fee
₹22,999
01Overview

What this engagement delivers

The Digital Personal Data Protection Act changes how Indian businesses must handle personal data, and many product teams have not yet mapped where that data resides. We inventory it across your database, analytics tools, support inbox, marketing platform and the spreadsheets on individual laptops. We then assess consent flows, retention practice and processor contracts against the Act and deliver a remediation plan with effort estimates. This is an engineering-led review rather than legal advice, and we identify clearly where legal counsel is needed.

02Deliverables 7 items

What you receive

  1. Personal data inventory across systems, vendors and storage locations
  2. Data flow maps showing collection, processing, sharing and deletion
  3. Gap assessment against DPDP Act obligations with severity ratings
  4. Consent notice and consent capture review with rewritten wording
  5. Retention schedule proposal by data category
  6. Data principal rights process covering access, correction and erasure
  7. Breach notification procedure and remediation plan with effort estimates
03Process

How the work runs, in 4 stages

  1. Stage 1: Discover

    Systems interviewed and personal data located, including shadow copies

  2. Stage 2: Map

    Flows documented from collection through to deletion

  3. Stage 3: Assess

    Practice compared against the Act clause by clause

  4. Stage 4: Plan

    Gaps prioritised with owners, effort and a suggested sequence

04Fit & inputs

Who it suits, and what we need from you

Ideal for

  • Indian companies holding customer personal data at any scale
  • Products with users in India expanding their data collection
  • Teams whose privacy policy was copied from another website years ago

What we need from you

  • Access to system owners for short interviews
  • Your current privacy policy, vendor list and consent screens
  • Someone senior enough to own the remediation plan afterwards

You provide these through the technical brief in your dashboard after checkout.

05Benefits

What changes for your team

  • 01

    A clear map of where personal data lives across your systems

  • 02

    Consent and retention practices you can defend, not merely assume

  • 03

    A prioritised plan in place of a vague sense of exposure

06FAQ

Questions about this engagement

No. It is a technical and process readiness review. We work alongside your legal counsel and flag anything needing their judgement.

The inventory and flow maps serve both. A full GDPR assessment adds scope and we will quote it.

Yes. Obligations scale with volume and sensitivity, but they start from the first data principal.

This is a remote engineering engagement — nothing is shipped physically. Work is delivered into systems you control. See delivery & handover and refunds & cancellation for the full terms.

Related engagements

Often considered alongside this one.

All Security & Compliance
Security & Compliance Popular

Web Application VAPT

A manual penetration test of your web application, with proof-of-concept evidence for each finding and a retest after remediation.

Manual penetration test covering authentication, authorisation and business logic

12 working days Scope published

Fixed fee · GST incl.

₹29,999

Security & Compliance TL-SEC-105

Secrets and Dependency Hygiene Sprint

Credentials committed to your repositories found and rotated, with automated scanning set up to stop new ones slipping in.

Full git history secret scan across up to 20 repositories

6 working days Scope published

Fixed fee · GST incl.

₹12,999

Security & Compliance TL-SEC-104

Cloud IAM Permissions Audit

Every identity in your cloud account reviewed against its actual usage, with over-permissioned roles tightened safely.

Inventory of every user, role, service account and access key

10 working days Scope published

Fixed fee · GST incl.

₹18,999

Security & Compliance TL-SEC-103

SOC 2 Evidence Groundwork

The technical controls and automated evidence collection a SOC 2 Type II audit requires, in place before the observation window begins.

Control gap assessment against the Trust Services Criteria you are scoping

30 working days Scope published

Fixed fee · GST incl.

₹44,999

Next step

Bring the problem. Leave with a defined plan.

Pick the engagement that matches what you need, or tell us about the system you are working on and we will point you to the right starting place.