Skip to content
DPDP Act 2023

DPDP Act Compliance India — Avoid ₹250 Cr Penalty | Free Audit

₹250 crore penalty per contravention. No grace period. Are you compliant?

Know exactly where you stand — assessment, remediation, and audit-ready package. Scope-based engagement.

7obligations covered
10 wksaudit-ready
AnnualSaaS monitoring
₹250 Crmax penalty
Per-stage engagementAll 7 obligationsSOC 2 + ISO 27001 readyContinuous monitoring

DPDP compliance means meeting the requirements of India’s Digital Personal Data Protection Act 2023 — the law that governs how every Indian business collects, stores, and processes personal data. Any company handling data of Indian residents must comply. Non-compliance carries penalties up to ₹250 crore per incident.

Quick check

Does DPDP apply to your business?

If any one of the following is true, you are a Data Fiduciary under the Act and obligations apply to you from May 13, 2027.

You collect name, email, phone, or address of Indian residents
Your app or website uses cookies or analytics on Indian users
You store login credentials or purchase history for Indian customers
Your vendors process Indian user data on your behalf
You run an HR system with employee personal data
You handle health, financial, or biometric data of any Indian citizen

Exemptions apply for personal or domestic use and certain government processing. Consult legal counsel for edge cases.

Schedule I

What DPDP Actually Requires

The Act defines 7 categories of obligations. Non-compliance with any single category can trigger the full ₹250 Crore penalty.

01

Reasonable Security Safeguards

Implement encryption, access controls, and vulnerability management proportionate to the data you process.

02

Consent Management

Obtain free, specific, informed consent with clear withdrawal mechanisms — in all 22 scheduled languages.

03

Data Principal Rights

Enable access, correction, and erasure requests with clear response mechanisms as prescribed by rules.

04

Breach Notification

Report personal data breaches to CERT-In within 6 hours and notify affected individuals without delay.

05

Data Fiduciary Obligations

Maintain processing records, conduct periodic audits, and appoint a Data Protection Officer if classified as Significant.

06

Retention Limits

Delete personal data when consent is withdrawn or the purpose is fulfilled — no indefinite storage.

07

Children's Data Protection

Obtain verifiable parental consent before processing data of individuals under 18. No behavioral tracking.

Your certification journey

We prepare you. The certifier stamps you.

Bachao.AI is not a certification body — and that’s intentional. We do the technical work so your certifying auditor (Big 4, CERT-In empanelled firm, or CPA for SOC 2) gets a clean evidence package.

01

Assessment

Scope call → infrastructure scan → gap report. Stage 1 engagement.

02

Full Gap Analysis

Technical + policy gaps mapped to DPDP, SOC 2, or ISO 27001 controls.

03

Remediation + Evidence

Fix controls. Collect audit evidence. Dashboard tracks progress.

04

Auditor-Ready Package

Hand to your certifying auditor. Clean, structured, defensible.

Bachao.AI does

Automated vulnerability scan of your infrastructure
Maps findings to DPDP + SOC 2 + ISO 27001 controls
Generates evidence documentation for auditors
Tracks remediation progress in dashboard
Connects you to empanelled vCISO if needed

Certifying body does

Reviews evidence package
Conducts independent audit
Issues DPDP readiness / SOC 2 / ISO 27001 certificate
Provides audit report for your customers/board

Empanelled firms: CERT-In empanelled auditors, Big 4, AICPA-licensed CPA firms (for SOC 2)

How we engage

Per-stage. Scoped to your situation.

No fixed packages. No subscriptions forced upfront. Each stage is scoped and priced based on your infrastructure, data volumes, and target framework. Most clients engage for all stages and move to continuous monitoring.

One-time engagement stages

Stage 1

Assessment

Full infrastructure scan + obligation mapping against DPDP Schedule I. Includes SOC 2 / ISO 27001 gap analysis if required. Deliverable: Gap report + prioritised remediation plan.

Stage 2

Remediation Support

Technical fixes, policy drafting (consent framework, breach response, retention schedule), and access control implementation. Scoped per number of findings and policy documents required.

Stage 3

Audit-Ready Package

Final consolidated evidence package: scan report, control mapping matrix, policy set, and remediation log. Structured for CERT-In empanelled auditors, Big 4, or SOC 2 CPA firms.

Recurring

Continuous compliance — SaaS

DPDP compliance is not a one-time event. The Board can audit you at any time. SOC 2 Type 2 requires 6–12 months of continuous evidence. Our monitoring subscription keeps you always-ready.

Monthly re-scans — catch new vulnerabilities as your product changes
Live compliance dashboard — always know your posture
Evidence vault — 12 months of scan history for SOC 2 Type 2 audits
Policy change alerts — notified when DPDP rules or Board guidance updates
Breach monitoring — dark web and credential exposure alerts
Annual audit-ready package refresh — ready for each certification cycle

Annual engagement · scoped per number of assets monitored

Scope call included. Every engagement starts with a 30-minute call to define scope, timelines, and what frameworks you need evidence for. Pricing is confirmed before any work begins.

Book a Scope Call →

How long does it take?

Audit-ready in 10 weeks, not 10 months.

Most businesses are fully ready for a certifying auditor within 8–10 weeks. Here’s the typical journey.

Week 1

Assessment

Automated infrastructure scan + obligation mapping. Scope call first to confirm assets, frameworks, and timeline. Gap report delivered end of week.

Week 2

Full Gap Analysis

Detailed mapping of your technical and policy gaps against all 7 DPDP obligations — and against SOC 2 / ISO 27001 if required. Evidence inventory created.

Weeks 3–8

Remediation

Fix vulnerabilities, draft required policies (consent framework, breach response plan, data retention schedule), implement access controls. Dashboard tracks every item to closure.

Week 10

Audit-Ready Package

Structured evidence package: remediated scan report, policy documents, control mapping matrix, and remediation log. Ready to hand to your certifying auditor.

Framework overlap

DPDP + SOC 2 Type 2: one assessment, two reports

SOC 2’s Common Criteria CC6–CC9 map almost directly to DPDP Schedule I obligations. If you’re pursuing both, your DPDP evidence package covers the majority of what your SOC 2 auditor needs.

DPDP Schedule I ObligationSOC 2 Criteria CoveredISO 27001 DomainOverlap
Reasonable Security SafeguardsCC6.1, CC6.6, CC6.7, CC6.8A.8 Technology ControlsHigh
Breach Notification (6-hour CERT-In)CC7.4 Incident Response, CC7.5 MitigationA.5.26 Response to incidentsHigh
Data Fiduciary Obligations (audits, DPO)CC4.1 Monitoring, CC9.2 Vendor RiskA.5.35 Independent reviewHigh
Retention Limits (deletion on purpose fulfilment)CC6.5 Disposal of logical assetsA.8.10 Information deletionMedium
Consent ManagementAvailability + Confidentiality criteriaA.5.34 Privacy, A.8.3 Information useMedium
Data Principal Rights (access, correction, erasure)Indirect — supports confidentialityA.5.34 Privacy obligationsPartial
Children's Data ProtectionAvailability + Confidentiality criteriaA.5.34 Privacy obligationsPartial

Bottom line for your auditor: The vulnerability scan report, breach response plan, access control evidence, and vendor risk assessment produced during DPDP compliance directly satisfy CC6, CC7, and CC9 of your SOC 2 Type 2 engagement. You are not starting from scratch.

What actually happens

Process & Deliverables

Every step is documented. Every deliverable is yours to keep and present to auditors, investors, or your board.

PThe Process

1

Automated infrastructure scan

We scan your web applications, APIs, cloud configuration, TLS/SSL setup, and security headers. No agent installed. No access to your database or source code.

2

AI-assisted finding validation

Raw scanner output is reviewed and validated. False positives are removed. Each finding is classified by severity (CVSS v3.1) with environmental context applied.

3

Obligation mapping

Every finding is mapped to the DPDP obligation it violates — and to the corresponding SOC 2 or ISO 27001 control if applicable.

4

Policy gap identification

We identify which required policies are missing or incomplete: consent framework, breach response plan, data retention schedule, vendor agreements.

5

Remediation tracking

Dashboard tracks every open item to closure. When a finding is fixed, the next scan confirms it. Remediation log is maintained for audit evidence.

DWhat You Receive

Executive Summary Report

BoardManagementLegal

Board-ready PDF: risk score, critical findings, compliance status across all 7 DPDP obligations, recommended actions. No technical jargon.

Technical Findings Annex

CTODev TeamIT

Full vulnerability list with CVSS scores, reproduction steps, affected URLs/parameters, and remediation code. Structured for your engineering team.

DPDP Control Mapping Matrix

DPOComplianceAuditor

Spreadsheet mapping each finding and policy gap to the specific DPDP Schedule I obligation — and to SOC 2 / ISO 27001 controls if applicable.

Evidence Package

AuditorLegalCertifying Body

Scan logs, remediation records, and policy templates structured for auditor review. Ready to present to CERT-In empanelled auditors, Big 4, or SOC 2 CPA firms.

Policy Templates

LegalDPOCompliance

Draft Privacy Policy, Consent Notice, Breach Response Procedure, and Data Retention Schedule — customisable, legally-informed starting points.

Compliance Dashboard Access

CTOCISOManagement

Live tracking of open items, remediation progress, and re-scan history. Always know your current compliance posture.

Scope: We scan assets you explicitly authorise — web applications, APIs, and cloud configuration (AWS/GCP/Azure). We do not scan endpoints, internal networks, or third-party SaaS tools. Physical security, social engineering, and employee awareness training are separate engagements available on request.

What others charge for DPDP compliance

Traditional compliance assessments are expensive and slow. Bachao.AI is typically 60–80% less — discuss your scope on a call.

VendorPriceBillingSource
Sprinto (DPDP module)Annual subscriptionannual platformspendflo.com
SISAEnterprise pricingfull compliancesisainfosec.com
Kratikal (compliance)Per-engagement feeper frameworkkratikal.com
Big 4 IndiaEnterprise pricingper assessmentIndustry estimates
Bachao.AIPer-stage · scope-basedassessment + SaaS

Prices indicative — actual quote scoped on a 30-minute call. No subscription, no hidden fees.

DPDP Enforcement Timeline

The clock is already ticking. There is no grace period after May 13, 2027.

1

Nov 2025

Board constituted

2

Nov 2026

Registration opens

3

May 13, 2027

Full enforcement

Time remaining until enforcement

--Days
--Hours
--Min
--Sec

The Penalties Are Real

₹250 Cr

Max penalty per contravention

DPDP Act 2023, Schedule I

No cap

No cumulative annual cap in the enacted Act

DPDP Act 2023 — penalties are per contravention

For a startup with ₹2 Crore revenue — a single ₹250 Crore penalty is 125 years of revenue.

Directors and KMPs are personally liable

Under DPDP Act Section 71, every person in charge of the company at the time of a contravention — including directors and Key Managerial Personnel — can be held personally liable alongside the company. The penalty is not limited to the corporate entity. Board-level sign-off on a compliance programme is not optional.

DPDP Act 2023, Section 71 — Offences by companies

DPDP Act 2023 — what compliance teams need next

DPDP Act Penalties — ₹250 Cr Breakdown by Violation

The DPDP Act 2023 prescribes penalties by category of failure, adjudicated by the Data Protection Board of India. The headline slabs:

  • Failure to take reasonable security safeguards — up to ₹250 crore per contravention
  • Failure to notify the Board / affected data principals of a breach — up to ₹200 crore
  • Failure of additional obligations of a Significant Data Fiduciary — up to ₹150 crore
  • Breach of obligations regarding children's personal data — up to ₹200 crore
  • Breach of voluntary undertaking — up to ₹10,000
  • Breach of any other provision — up to ₹50 crore

Do You Need a Data Protection Officer (DPO)?

Under the DPDP Act, every Data Fiduciary must designate a contact person reachable for questions about personal-data processing — and a Significant Data Fiduciary (SDF) must additionally appoint a Data Protection Officer based in India. SDF status is notified by the Central Government based on volume + sensitivity of data processed, risk to data-principal rights, and impact on the sovereignty of India. If you process bulk consumer data, run an Indian-resident platform at scale, or handle children's or financial data, plan for SDF designation. Bachao.AI partners with India-based DPO consultancies — hire one via our partner network and invite them as a Legal Partner user on your tenant. They satisfy the obligation without a full-time hire until scale justifies one. The DPO is your hired professional, not Bachao.AI.

72-Hour Breach Notification Workflow

The DPDP Rules require notification to the Data Protection Board and to affected data principals on becoming aware of a personal-data breach. CERT-In's parallel directions require incident reporting within 6 hours. Your incident response playbook needs both clocks built in. Bachao.AI ships a documented breach playbook + drafted notification templates for the Board and for affected principals, so your team isn't writing legal text under pressure during an incident.

DPDP Consent Manager Integration Checklist

The DPDP Act introduces Consent Managers — registered intermediaries that collect, withdraw, and re-consent on behalf of data principals. Your consent surfaces must integrate with at least one registered Consent Manager once the registry is operational. Bachao.AI's gap audit identifies every consent surface in your product, drafts compliant notice + consent text, and tracks Consent Manager integration readiness so you're not the last platform to integrate.

Free DPDP Gap Assessment — What You Get

Run a free Bachao.AI DPDP baseline against your stack. The AI agent inventories your personal-data fields, consent surfaces, and third-party processors; scores you against the seven Schedule I obligations; and ranks your remediation gaps by penalty exposure. Comparable consultancies (Sprinto, Kratikal, SISA, Big 4) are priced at enterprise subscription or per-engagement rates for the same gap-assessment scope — ours is free up front, and full implementation is pay-per-use at materially lower total cost. You decide from the executive summary whether to upgrade.

Request a Quote — DPDP Compliance

Tell us a bit about what you need scoped. Shouvik will review your details and reach out within 24 hours.

No pricing is shared here — this only sends your details to our team so we can scope a quote.

Don’t wait for enforcement.

May 13, 2027 is fixed. Your audit-ready package takes 10 weeks. Start now.

Book a Scope Call →

30-minute call. Scope confirmed. Pricing agreed before any work begins.

Disclaimer: Bachao.AI is not a legal firm or certification body. Our DPDP compliance assessment is a technical readiness check, not legal advice. Consult qualified legal counsel for compliance certification.

Find your vulnerabilitiesStart free scan →