DPDP Implementation Guidebook

A step-by-step guide for setting up Digital Personal Data Protection Act (2023) compliance for your Indian company — website, product, or entire system — using dcomply.
Version 1.1 Last updated: September 2026 Free · no email required See pricing →
Updated for DPDP Rules 2025 + 10 new modules (Sep 2026)

1. Overview

dcomply is a subscription platform that operationalises India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules 2025 for organisations that collect or process personal data of Indian residents. It gives you the workflows, forms, registers, notifications and evidence trails that the DPDP Board and your auditors will ask for — without you writing any of it from scratch.

The platform is a hosted SaaS: you sign up, choose the pieces you need, and start using them the same day. You can embed our consent widget on your website, publish your privacy notice, receive Data Subject Rights (DSR) requests, and file breach notifications — all from the same tenant workspace.

Who this manual is for

  • Founders / CEOs deciding whether dcomply covers your DPDP obligations.
  • DPOs, compliance officers, and IT heads who will operate the platform day-to-day.
  • Auditors and legal reviewers validating the evidence trail before sign-off.
  • Consultants managing DPDP compliance on behalf of multiple client companies.

How to read this manual

Sections 2–5 explain the business decisions you make before you start — what DPDP demands, which plan and modules cover them, how to buy, and how roles work. Sections 6 onwards are operational: one section per module, showing exactly where to click and what happens. Section 31 gives you five common scenarios end-to-end, e.g. "customer emails us asking to delete their data — what do we do?"

A note on precision Every module reference in this manual maps to a specific URL path in the platform. If your admin console URL is https://app.dcomply.in, you can append the path in each section (for example /dsr-management) to reach the exact screen described.

2. What the DPDP Act actually requires

The DPDP Act and Rules impose obligations on every "Data Fiduciary" — any organisation that decides why and how personal data of Indian residents is processed. The obligations fall into eleven working areas. dcomply has one or more modules for each.

DPDP obligationSection / RuleCovered by module(s)
Give the data principal a clear, itemised notice before collecting dataS.5, Rule 3Consent Notice Builder, Multilingual Notice
Take a specific, free, informed, unambiguous consent for each purposeS.6, Rule 3Consent Widgets, QR Physical Consent
Let the data principal withdraw consent as easily as they gave itS.6(4), S.7Consent Withdrawal, public withdraw page
Erase / update personal data on the principal's request within a defined SLAS.11 (access), S.12 (correction), S.12(3) (erasure), S.14 (nomination)DSR Portal + Data Principal Portal
Notify the Data Protection Board within 72 hours of a personal-data breachS.8(6), Rule 7Breach Notification, DPA Filings
Verify parental consent when processing children's data (under 18)S.9, Rule 11Children's Data
Retain personal data only as long as necessary; erase after thatS.8(7), Rule 8Data Retention Auto-Delete
Keep an internal Record of Processing Activities (ROPA)S.8, Rule 5ROPA / Processing Activities
Restrict cross-border transfers to countries the government has approvedS.16Cross-Border Transfers
If notified a Significant Data Fiduciary — perform DPIA, appoint DPO, audit annuallyS.10, Rule 12SDF Determination + DPIA
Provide a grievance redressal mechanismS.13(3)Grievance / Redressal
Penalty scale DPDP S.33 sets fines up to ₹250 crore per breach category. Failing to notify the DPB within 72 hours, failing to secure children's data, and failing to protect personal data are three of the highest-penalty categories. Every module below writes evidence to a permanent, tamper-evident audit log so you can demonstrate compliance at inspection.

3. Pricing & plan selection

dcomply has three ways to buy: a tiered plan that bundles slots for compliance packs, a set of industry-specific packs, or individual modules à la carte. Most customers pick a tier because it works out cheaper than assembling à la carte, but the choice is entirely yours.

3.1 Tiered plans

Each tier gives you a number of "pack slots" — pick that many industry packs from the six available. All tiers include unlimited users, AI compliance advisor credits, unlimited DSR volume, and access to the executive report.

Starter

₹12,999/mo
or ₹1,32,490/year
  • 1 pack slot
  • 500 AI credits/mo
  • Best for solo founders

Professional

₹29,999/mo
or ₹3,05,990/year
  • 3 pack slots
  • 1,200 AI credits/mo
  • Recommended for SMBs

Business

₹49,999/mo
or ₹5,09,990/year
  • 5 pack slots
  • 2,000 AI credits/mo

Enterprise

₹89,999/mo
or ₹9,17,990/year
  • All packs + all modules
  • 3,500 AI credits/mo

Agency

₹1,49,999/mo
or ₹15,29,990/year
  • Everything in Enterprise
  • Multi-client console
  • 10 clients included, ₹500/mo per extra

3.2 The six industry packs

PackStandalone priceWhat's in it
Data Privacy₹5,999/moConsent, DSR, Policy Generator, DPIA, Gap Assessment, DPDP AI Advisor, Breach Notification, Children's Data, Consent Notices, ROPA
Corporate₹11,999/moEverything in Data Privacy + MCA, Labour, POSH, EHS, ESG, Company Secretarial, Grievances, DPIIT, Compliance Alerts & Monitor, Evidence Locker
Finance₹9,999/moGST, Tax Calendar, IFC, Financial Risk, RBI, SEBI, LODR, IRDAI, Scheduled Reports
Legal₹9,999/moLegal Matters, Contracts, IP Assets, Government Notices, Licenses, Legal Docs, Audit Reports, Engagement Letters
Security₹11,999/moRisk Register, Vendor Risk, ISO/SOC2, VA, Phishing, CERT-In, AI/Website/PII/SAST scans, Evidence Locker
Sector₹9,999/moFSSAI, RERA, Healthcare, E-Commerce, GDPR, CCPA

3.3 Which plan for DPDP?

Recommendation for a "DPDP-only" tenant
  • If you only need DPDP compliance and nothing else: Starter tier + Data Privacy pack. Total ₹12,999/month.
  • If your Data Privacy pack doesn't include the specific DPDP module you need (see the "Bundled?" column in section 3.4), add that module à la carte for ₹1,499–₹2,499/month each.
  • If you're an SME or larger and also need HR, MCA, or ESG modules: Professional with Data Privacy + Corporate + one more. ₹29,999/month.
  • If you're a compliance consultant serving multiple client companies: Agency tier — includes 10 client slots.

3.4 DPDP module matrix — bundled vs à la carte

Not every DPDP module is inside the Data Privacy pack by default. The table below shows exactly what's bundled and what needs to be added separately.

DPDP moduleIn Data Privacy pack?À-la-carte price
Consent WidgetsYes₹1,499/mo
DSR PortalYes₹1,499/mo
Breach NotificationYes₹2,499/mo
Children's DataYes₹1,499/mo
DPIAYes₹2,499/mo
Gap AssessmentYes₹1,499/mo
ROPAYes₹2,499/mo
Consent Notice BuilderYes₹1,499/mo
Policy GeneratorYes₹1,499/mo
DPDP AI AdvisorYes₹2,499/mo
Data Retention Auto-DeleteNo — add separately₹2,499/mo
Cross-Border TransfersNo — add separately₹2,499/mo
SDF DeterminationNo — add separately₹1,499/mo
Multilingual Consent NoticeNo — add separately₹2,499/mo
Data Principal PortalNo — add separately₹1,499/mo
Consent Manager RegistrationNo — add separately₹2,499/mo
Right to NominationNo — add separately₹1,499/mo
DPA Filings registerNo — add separately₹1,499/mo
QR Physical ConsentNo — add separately₹1,499/mo
Consent Version RegistryNo — add separately₹1,499/mo
Consent Withdrawal ManagementNo — add separately₹1,499/mo

Enterprise and Agency tiers include every module above without add-ons.

4. How to buy and activate

4.1 The three ways to reach checkout

  1. No-signin checkout (fastest). From dcomply.in/pricing, pick a tier, click "Buy". You'll be redirected to /buy/{tier}, pay through Razorpay, and receive an activation email with a licence key.
  2. Sign up first, then subscribe. Create your tenant workspace, then upgrade from the in-app Subscription page.
  3. Talk to sales for Enterprise/Agency with custom terms — [email protected].

4.2 The no-signin flow — step by step

  1. Choose the tier on the marketing site pricing page.
  2. Enter company name, GSTIN (optional), and billing email.
  3. Choose monthly or annual (annual is ~15% cheaper).
  4. Complete Razorpay payment (UPI, cards, netbanking, wallets).
  5. Receive a licence key by email (usually within 60 seconds).
  6. Click the link — you'll land on /activate/{key}. Set your admin password. Your tenant is created.
  7. You're auto-signed in and taken to the Onboarding wizard (see section 6).

4.3 Adding modules à la carte after activation

  1. Sign in as tenant admin.
  2. Go to Settings → Subscription → Marketplace (or /subscription/marketplace).
  3. Filter modules by category (Data Privacy, Security, etc.) and click Add module.
  4. Razorpay charges pro-rata for the current billing cycle; the module unlocks immediately.

4.4 Billing details you should know

  • All prices are exclusive of 18% GST (added at checkout).
  • Auto-renewal via Razorpay recurring subscriptions is on by default; can be disabled from Settings → Subscription.
  • You get a GST invoice by email within 24 hours of each successful charge, and can download historic invoices from Settings → Subscription → Invoices.
  • Cancellation is honoured at the end of the current billing cycle — no partial-month refunds, but no lock-in either.
  • Enterprise customers may pay by NEFT/RTGS on quarterly cycles — request from sales.

5. User roles and access

dcomply has five roles. Every action in the platform is gated by the role you've assigned to the user.

RoleWho this isWhat they can do
Super AdminPlatform owner (dcomply team). Not a role you assign.Everything, across all tenants. Skip.
AdminYour DPO, IT head, or founder. Default for the person who signs up.Everything within your tenant — create clients, run DSRs, publish notices, invite users, manage billing.
ConsultantExternal DPO or agency-side operator.Same as Admin except cannot manage users or invoices.
ViewerAuditors, board members, legal reviewers.Read-only across all modules — great for evidence review.
ClientYour customer (data principal) — signed in on the Data Principal Portal.See only their own DSRs, consent history, and documents. Provisioned via a portal token.

5.1 Adding a new user

  1. Go to Settings → Users → Invite.
  2. Enter email + name, pick a role.
  3. They receive an activation email; on first sign-in they set their own password + optional TOTP two-factor.

5.2 Provisioning a client portal token (for Data Principal Portal)

Go to Clients → {client} → Portal token and click Generate. Send the resulting URL (/portal/{token}) to the data principal — they can now see their consent history, submit DSRs, and file grievances from a single page. See section 19.

6. First-time setup — the onboarding wizard

When you sign in for the first time you're taken through a 5-step wizard. You can skip it and return later from Settings → Onboarding, but doing it end-to-end gives you a working, gap-scored tenant in about 15 minutes.

Step 1 — Welcome

Overview of what the wizard does. Click Get Started.

Step 2 — Company profile

  • Legal name, brand name, CIN (validated), GSTIN (validated).
  • Registered state / UT — 35 dropdown options; drives regional-language notice defaults.
  • Industry (10 options) — drives which regulatory alerts fire (RBI vs SEBI vs IRDAI vs generic).
  • Company size bucket — used to determine SDF candidature.

Step 3 — Select regulations / modules

Check the boxes for the DPDP modules relevant to your business. This is only about visibility — you can always turn them on later from the sidebar.

Step 4 — Invite team (optional)

Add colleagues with role assignments. You can skip and do this from Settings later.

Step 5 — Done

Click Finish. You're taken to the main dashboard. The tenant's onboarding_completed_at is set so the wizard never re-appears.

What to do immediately after onboarding
  1. Run Gap Assessment — 15-minute questionnaire, produces a compliance score.
  2. Publish your Consent Notice at /notice/{slug}.
  3. Get the DSR public form URL from the DSR Portal page and add it to your website footer.

8. DSR Portal — Data Subject Rights

DSR Portal

DPDP S.11–14 • ₹1,499/mo • In Data Privacy pack Public
Purpose
Public form + admin console for every data principal right: Access (S.11), Correction (S.12), Erasure (S.12(3)), Portability (S.11), Nomination (S.14). Enforces the DPDP Rule 7 90-day SLA and produces the audit trail regulators expect.
URL prefix (public)
/dsr/{clientSlug}
URL prefix (admin)
/dsr-management

8.1 Setting up your DSR intake URL

  1. Go to DSR → All requests in the admin console.
  2. The banner at the top shows your Public DSR request form URL — copy it (looks like https://app.dcomply.in/dsr/your-organisation).
  3. Add this URL to your website footer under a link labelled "Data protection rights" or "Contact our DPO". Also include it in your privacy notice.

8.2 What the data principal experiences

  1. Opens the DSR URL → sees a form with 5 request-type options (Access, Correction, Erasure, Portability, Nomination).
  2. Fills in email, phone, and — for identity verification — uploads a masked ID proof (PDF/JPG/PNG, ≤5 MB).
  3. Submits. They receive a verification email containing a link (/dsr/verify/{token}).
  4. Click verifies their identity; the request moves from new to verified in your queue.
  5. They can track status any time at /dsr/track/{token}.

8.3 What you (the tenant admin) do

  1. Get a notification email of the new DSR.
  2. Sign in → DSR → All requests → click the eye icon.
  3. Review the ID proof. If it looks legitimate, mark identity Verified.
  4. Depending on request type:
    • Access / Portability: click Generate data package — the system compiles a JSON + PDF of everything you hold on that principal (searches your connected data sources — see section 27), signs it, and offers a download link. The principal downloads from /dsr/download/{token}.
    • Erasure: click Fulfil across sources — the DsrOrchestrator fans the request out to every connected MySQL, PostgreSQL, MongoDB, S3, Zoho CRM, etc., that has a matching PII record for this principal. Each source shows per-record progress (pending → running → done, or blocked with reason). Every erasure writes to the tamper-evident evidence log.
    • Correction: manually update the record where it lives (your CRM, DB, etc.), then mark the DSR complete with proof.
    • Nomination: registers a nominee under S.14 who will exercise rights after the principal's death or incapacity.
  5. Upload a written response letter (auto-generated draft available) and click Mark completed.
  6. The principal is emailed the completion notice with the download / receipt.

8.4 SLA tracking & overdue queue

DPDP Rule 7 sets a 90-day maximum SLA (most implementations aim for 30). The SLA dashboard (/dsr/sla-dashboard) shows priority levels — urgent (>75 days), high (>60), normal — and separately queues overdue requests. Automated reminder emails fire at D-75 and D-89. See Overdue tab or /dsr-management/overdue.

8.5 Appeal handling

If you reject a request the principal can file an appeal via /dsr/appeal/{token}. Appeals appear at DSR → Appeals; you have 30 days to respond. Unresolved appeals can be escalated to the Data Protection Board via the DPB Appeal Tracker.

8.6 Evidence & audit

Every DSR keeps: original request, identity proof (encrypted at rest), verification token expiry, all status transitions with timestamps + operator email, response letter, downloadable proof PDF. Everything is exportable to CSV for annual audit at DSR → Export register.

9. Breach Notification

Breach Notification

DPDP S.8(6), Rule 7 • ₹2,499/mo • In Data Privacy pack
Purpose
Guided workflow to notify the Data Protection Board of India within the 72-hour statutory window and, in parallel, CERT-In within the 6-hour window mandated by the CERT-In Directions 2022 for cybersecurity incidents.
URL prefix
/breach-notifications + /certin-breach-notifications + /dpa-filings

9.1 Recording a breach

  1. Go to Breach Notifications → New.
  2. Fill in: date & time of discovery, category (unauthorised access / data loss / integrity / ransomware / misconfiguration), severity, affected record count, description.
  3. Save as a draft. The record is created with status investigating.
  4. As the investigation progresses, update the draft — the platform tracks who edited what.

9.2 Meeting the 72-hour DPB notification deadline

  1. Open the breach → click Generate DPB notification.
  2. The platform pre-fills the format prescribed by Rule 7 (breach details, affected principals, mitigation steps, contact of DPO).
  3. If you have Anthropic Claude AI credits available, click AI-generate narrative — Claude drafts the narrative section based on the fields you've filled.
  4. Review, edit, download PDF, submit to DPB via their portal, then click Mark DPA sent — you'll upload the DPB acknowledgement number.
  5. Click Mark principals sent once affected data principals are notified.

9.3 CERT-In 6-hour reporting

If the incident meets any of CERT-In's 20 categories of reportable incidents (from the 28 April 2022 Directions), open CERT-In Breach Notifications → New. The form uses CERT-In's format. A background command monitors CERT-In deadlines every 30 minutes and alerts if any incident approaches the 6-hour mark unfiled.

9.4 DPA Filings register

Every regulator submission (DPB, CERT-In, sector regulator like RBI/SEBI) is tracked in the DPA Filings register with status Submit → Acknowledged → Rejected / Closed. Each filing keeps the submission PDF, ack number, and any regulator correspondence.

9.5 Retention rule

Per Rule 7, breach notification records must be retained. The platform blocks deletion of any breach record where notified_at is set, and shows an inline warning explaining the retention obligation.

10. Children's Data

Children's Data

DPDP S.9, Rule 11 • ₹1,499/mo • In Data Privacy pack
Purpose
Register + workflow for verifying parental consent, blocking profiling of children (S.9(3)), and tracking review windows for every child record.
URL prefix
/children-data

10.1 When you need this module

If you knowingly process personal data of anyone under 18 — EdTech schools, gaming, kid-focused e-commerce, health apps used by families — you must have verifiable parental consent before you can process, and you must never behavioural-profile them (S.9(3)).

10.2 Workflow

  1. Add a Children's Record per child: child ID reference, DOB, parent contact, verification method (DigiLocker Aadhaar OTP, government-approved token, in-person, etc.).
  2. System flags whether the verification method meets Rule 11(2) — age-verification-strong vs weak.
  3. Every 12 months the platform flags the record for review — parents change, minors turn 18 (auto-graduate to adult consent).
  4. Reports available: overdue review, pending parental consent, weak verification.

11. DPIA — Data Protection Impact Assessment

DPIA

DPDP S.10 + Rule 12 • ₹2,499/mo • In Data Privacy pack
Purpose
Structured impact assessment for high-risk processing activities. Required for Significant Data Fiduciaries; recommended for any high-risk processing regardless of SDF status.
URL prefix
/dpias, DPO consultation register at /dpia-dpo-consultations

11.1 Creating a DPIA

  1. Go to DPIA → New assessment.
  2. Describe the processing (purpose, data categories, retention, principals affected).
  3. Score risk against 8 dimensions: children involved, sensitive categories, cross-border, profiling, automated decisions, volume, novel tech, vulnerable subjects.
  4. Document mitigations for each identified risk.
  5. Mark DPO consulted once your DPO reviews.
  6. Download the finalised PDF for regulator submission if requested.

11.2 Auto-suggestions from ROPA

The ROPA-DPIA triggers screen (/ropa-dpia-triggers) scans your Processing Activities register and auto-suggests DPIAs where a ROPA row involves sensitive categories, children, cross-border, or profiling.

12. ROPA — Record of Processing Activities

Processing Activities (ROPA)

DPDP S.8, Rule 5 • ₹2,499/mo • In Data Privacy pack
Purpose
The internal register every Data Fiduciary must maintain of every processing activity, its lawful basis, categories of data, retention, and any linked DPIA.
URL prefix
/ropa

12.1 What each ROPA entry contains

  • Activity name (e.g. "Customer onboarding KYC")
  • Purpose (linked to consent purpose)
  • Lawful basis: Consent (S.6) / Legitimate use (S.7) / Legal obligation / Public interest
  • Data categories: name / email / phone / Aadhaar / financial / health / children / other
  • Data principals: customers / employees / vendors / job applicants
  • Retention period + legal basis for it
  • Cross-border transfers (linked to Cross-Border Transfers module)
  • Processors involved (linked to Vendor / Processor DPA module)
  • Security measures
  • Whether a DPIA is required / done

12.2 Visual data-flow map

From any ROPA entry, click Save flow map to plot the data journey visually — source system → your systems → processors → cross-border destinations. Great for regulator briefings.

13. Data Retention Auto-Delete

Data Retention

DPDP S.8(7), Rule 8 • ₹2,499/mo • Add à la carte
Purpose
Retention policy register with automated flagging + optional automated deletion once a retention period expires.
URL prefix
/data-retention

13.1 Recording a retention policy

  1. Go to Data Retention → New policy.
  2. Pick the data category + processing activity.
  3. Set retention period (months / years) and the legal basis (e.g. "IT Act 8-year audit trail", "RBI KYC 5-year", "internal HR policy").
  4. Optional: attach a legal hold — pauses auto-deletion for litigation / investigation.

13.2 What happens at expiry

Nightly at 02:30 IST the data-retention:auto-delete command scans policies for records past their retention window and flags them for review. Actual deletion is manual (click Confirm) unless you enable auto-execute — a safety default.

13.3 Legal holds

If a record is under legal hold (subpoena, dispute), Legal Holds tab lets you pin it. Auto-delete skips held records and shows a warning in the DSR fulfilment flow if the principal asks for erasure of a held record.

14. Cross-Border Transfers

Cross-Border Transfers

DPDP S.16 • ₹2,499/mo • Add à la carte
Purpose
Register every transfer of personal data outside India, with the safeguard type used, expiry, and — if the destination country is not on the government's approved list — the specific mitigation.
URL prefix
/cross-border-transfers

14.1 Common use cases

  • Storing customer data in AWS us-east-1 / Google Cloud europe-west1 — transfer.
  • Sending prospect data to a US-based CRM — transfer.
  • Using an EU-based email service — transfer.

14.2 Workflow

  1. New transfer: destination country, processor / recipient, data categories, volume, safeguard type (SCC / adequacy / consent / contract).
  2. If SCC-based, use the built-in SCC generator — produces a signed PDF template mapped to DPDP Rule 15.
  3. The DPB Approvals sub-register tracks any approvals you've filed with the Data Protection Board.
  4. The Country Approvals register mirrors the government's whitelist so you can check destination eligibility at a glance.

15. SDF Determination — Significant Data Fiduciary

SDF Determination

DPDP S.10 • ₹1,499/mo • Add à la carte
Purpose
Self-assessment tool that scores your organisation on the 5 SDF criteria (volume of personal data, sensitivity, risk to India's sovereignty/electoral democracy, public order, other risks). If you are notified as an SDF, this module also tracks DPO appointment, mandatory audit schedule, and DPB declaration filings.
URL prefix
/sdf-determination

15.1 SDF obligations at a glance

  • Appoint an India-resident DPO (S.10(2)(a))
  • Perform DPIA + audit annually (S.10(2)(c))
  • Independent data auditor sign-off (S.10(2)(d))

15.2 Workflow

  1. Run the assessment questionnaire — 20 questions.
  2. See your SDF score + likelihood.
  3. If notified as SDF: enter the notification date in DPB Declarations.
  4. Add your DPO in DPO Appointments — platform generates the appointment letter.
  5. Set the annual audit date in Audit Schedules — platform reminds T-60 / T-30 / T-7 days.

16. Gap Assessment

Gap Assessment

DPDP-wide • ₹1,499/mo • In Data Privacy pack
Purpose
The single-most-important starting point. Runs an 8-section questionnaire mapped to every DPDP obligation and returns a percentage compliance score, penalty exposure estimate, and a prioritised remediation checklist.
URL prefix
/gap-assessments

16.1 The 8 sections

  1. Notice & consent (S.5–S.7)
  2. Children's data (S.9)
  3. Data principal rights (S.11–S.14)
  4. Data fiduciary obligations (S.8)
  5. Security (S.8(4))
  6. Breach notification (S.8(6))
  7. Cross-border (S.16)
  8. Significant Data Fiduciary (S.10)

16.2 Output

  • Percentage compliance score (0–100)
  • Penalty exposure in rupees — calculated from S.33 penalty tables against your identified gaps
  • Ranked remediation list — "Do these 5 things next to reduce exposure by ₹X"
  • Downloadable PDF for the board / auditor
  • Assignable to team members with SLAs
Recommended cadence Run a Gap Assessment on Day 1, then monthly. Executive Report (section 30) charts the trend so you can show the board that compliance is improving.

17. Consent Manager Registration

Consent Manager Registration

DPDP S.2(9) • ₹2,499/mo • Add à la carte
Purpose
Track third-party Consent Managers (DEPA-style) your organisation relies on. Registration status, technical/security capabilities, expiry.
URL prefix
/consent-manager

Add each CM you rely on — Sahamati account aggregators for financial data, ONDC-style CMs for e-commerce, etc. The platform tracks registration validity and flags CMs pending re-approval.

18. Multilingual Notice

Multilingual Consent Notice

DPDP Rule 3(1) & 3(2) • ₹2,499/mo • Add à la carte
Purpose
Produce your privacy notice in all 22 scheduled Indian languages (Rule 3(1)) plus accessible formats — audio, Braille, screen-reader-compatible — for persons with disabilities (Rule 3(2)).
URL prefix
/multilingual-consent

18.1 Producing a translation

  1. Go to Multilingual → New notice.
  2. Start from a template in the library or paste your English notice.
  3. Click Translate — AI translates into any language(s) you select. Human review is strongly recommended before publishing.
  4. Toggle Accessible formats: generate audio (MP3), Braille (BRF file), screen-reader HTML.
  5. Publish to /notice/{slug}. Your embedded consent widget auto-serves the correct language based on the visitor's browser language.

19. Data Principal Portal

Data Principal Portal

DPDP S.12 • ₹1,499/mo • Add à la carte Public
Purpose
Single sign-in page where a data principal sees everything you hold about them — consent history, DSRs filed, grievances open, documents shared — and can exercise rights.
URL prefix
/portal/{token}

Generate a token from Clients → {client} → Portal token. Send the URL to the principal. They can bookmark it — one URL to interact with every right.

20. Vendor / Processor DPA

Vendor Risk (Processor DPA Tracker)

DPDP S.8(2) • ₹3,999/mo • In Security pack
Purpose
Every processor (vendor who touches personal data on your behalf) must have a DPA (Data Processing Agreement) with you. This module registers vendors, generates DPAs, tracks contract validity, sub-processor notifications, and processor audits.
URL prefix
/vendor-risk

Workflow

  1. Register each vendor: name, service, criticality (high / medium / low), start date, DPA reference number.
  2. Use the DPA generator to produce a DPDP-compliant DPA PDF from a template.
  3. Update the vendor to Approved once contract is signed.
  4. Track sub-processor notifications: if the vendor engages a sub-processor, the notification is logged.
  5. Schedule processor audits — annual for critical vendors.

21. Grievance & Redressal

Grievance / Redressal

DPDP S.13(3) • ₹1,499/mo • In Corporate pack Public
Purpose
Public grievance form + admin queue + auto-escalation past 30-day DPDP deadline + DPB appeal tracker.
Public form
/grievance/{clientSlug}
Admin queue
/grievances

Anyone (customer or not) can file a grievance. You get an email + in-app alert. Failing to acknowledge within 30 days auto-escalates the grievance internally and lets the principal appeal to the DPB — tracked in /dpdp/dpb-appeals.

22. Right to Nomination (S.14)

Nomination

DPDP S.14 • ₹1,499/mo • Add à la carte
Purpose
Register a data principal's nominee — someone who inherits their DPDP rights when they die or become incapacitated. Handled through the same DSR portal but tracked separately.
URL prefix
/nomination

23. QR Physical Consent

QR Physical Consent

DPDP S.6 • ₹1,499/mo • Add à la carte
Purpose
For retail, QSR, hospital reception, event registration — anywhere a physical touchpoint collects personal data. Print a QR poster; anyone who scans it sees your notice and captures consent digitally.
URL prefix
/consent/qr

Create QR codes for each location. Scans go to the same public consent notice URL as your website, but the source is tagged so you can filter analytics by physical location.

24. Consent Notice Builder

Consent Notice Builder

DPDP Rule 3 • ₹1,499/mo • In Data Privacy pack Public
Purpose
Templated builder for the itemised notice required by Rule 3 — categories of data, purposes, rights, DPO contact, grievance mechanism. Publishes to a permanent public URL you can link from your privacy policy.
URL prefix
/consent-notices
Public URL
/notice/{slug}

25. Policy Generator & Analyzer

Policy Generator

In Data Privacy pack
Purpose
Produces a DPDP-compliant Privacy Policy PDF + HTML, with variants for child-facing services (S.9) and educational-technology vendors.
URL prefix
/policy-generator

Privacy Policy Analyzer

₹2,499/mo • Add à la carte
Purpose
Upload your existing privacy policy — AI runs a clause-by-clause review, flags DPDP gaps, estimates S.33 penalty exposure, and suggests revised wording.
URL prefix
/policy-analyses

26. DPDP AI Advisor

DPDP AI Advisor

₹2,499/mo • In Data Privacy pack
Purpose
RAG-grounded conversational Q&A over the DPDP Act, Rules 2025, and sector-specific guidance for 13 industries. Ask "does S.16 apply to my Delhi–Frankfurt data transfer?" and get a cited answer.
URL prefix
/dpdp-advisor

Uses your monthly AI credits. Every response cites the relevant DPDP section or rule so you can verify.

27. Connectors, Data Map & DSR fulfilment

This is the "make the DPDP loop actually close" part. Connectors let dcomply reach into your operational systems (databases, CRMs, storage buckets, spreadsheets) to (a) discover where personal data lives, (b) execute DSR exports and erasures on demand, and (c) propagate consent withdrawal to marketing tools.

27.1 The connector catalogue

77 tiles across 11 categories: Cloud Storage, CRM & Sales, Communication, Productivity, Accounting & Finance, Dev & Security, HR & People, Customer Support, Marketing & CDP, Identity & SSO, In-platform. Each tile shows Available / Coming Soon status.

27.2 Which connectors are fully functional today

ConnectorDiscoveryDSR ExportDSR ErasureConsent Sync
MySQL✓✓✓—
PostgreSQL✓✓✓—
MongoDB✓✓✓—
AWS S3✓✓✓—
Google Sheets✓✓✓—
Zoho CRM✓✓✓✓ Email_Opt_Out
LeadSquared✓✓✓✓ DoNotEmail
Razorpay✓✓Anonymise*—
Tally✓✓Anonymise*—
WhatsApp Business✓———

*Razorpay and Tally erasure strips PII fields but retains the ledger entry — RBI and Income Tax law require 5–8 year retention.

27.3 Connecting a data source (worked example — MySQL)

  1. Go to Connectors → MySQL → Configure. You arrive at /discovery/sources/create?adapter=mysql.
  2. Fill in host, port, database, and a read-only MySQL username / password.
  3. Click Save + test. If auth works, status flips to Connected.
  4. Click Run scan. The Discovery service walks your tables, classifies columns by PII type (email, mobile, Aadhaar, PAN, name, address, health, financial, etc.), and writes to the Data Map.
  5. Open Data Map (/discovery) to browse discovered assets.

27.4 Enabling DSR erasure on the source

For safety, DSR erasure requires a separate credential with UPDATE/DELETE privileges — never the read-only one.

  1. Open the source detail page (/discovery/sources/{id}).
  2. Scroll to Erasure credentials.
  3. Enter a write-capable MySQL user's credentials. Save.
  4. Erasure is now enabled — reflected in the DPDP capabilities strip.

27.5 Erasure strategy per table

By default every erasure nullifies PII columns while leaving the row intact — this preserves referential integrity (orders still exist, they just no longer identify the customer). You can override per table:

  • Nullify (default) — set PII columns to NULL, keep row.
  • Delete row — physical row DELETE.
  • Skip — do not touch this table (useful for accounting tables you must retain).
  • Crypto-shred (S3 versioned buckets) — delete every version so no recoverable copy remains.

Add rules from the same source detail page → Erasure rules.

27.6 The DSR fulfilment orchestrator

When a verified DSR of type erasure or access is opened at /dsr-management/{id}, an admin clicks Fulfil across sources. Behind the scenes:

  1. The orchestrator lists every connected source whose adapter supports the required capability.
  2. One task row is created per (DSR × source) in dsr_fulfilment_tasks.
  3. Each task is queued via DsrFulfilmentJob. The adapter locates matching records for the subject identifier, then executes export or erasure.
  4. Per-source progress appears live in the "Connector Fulfilment" panel — Pending → Running → Done (or Blocked / Failed with reason).
  5. Every source touch writes to the tamper-evident source_evidence_log — hash-chained so any tampering breaks the chain.

27.7 Consent propagation

When a data principal withdraws consent via /consent/withdraw or the Data Principal Portal, the ConsentPropagator service fans the withdrawal out to every connected source that supports consent sync. Today: Zoho CRM (Email_Opt_Out=true) and LeadSquared (DoNotEmail=1, DoNotCall=1). The record is auto-excluded from future marketing sends. Every sync attempt is logged in consent_sync_log.

28. Trust Badge & public compliance page

Show your customers you take DPDP seriously — embed a live compliance badge on your website.

  1. Go to Trust Badge (/trust-badge) and generate a token.
  2. Copy the badge SVG URL (/badge/{token}) and paste it into your website footer.
  3. The badge links to a public compliance page (/trust/{token}) that shows your live compliance score, active modules, and last-audit date. No sign-in required.

29. Compliance Score & Health

At /compliance-score the dashboard aggregates signals from every module — open DSRs vs SLA, breach filings pending, DPIAs overdue, consent widget health, retention policy coverage — into a single 0–100 score. Snapshots are saved so you can chart improvement.

The Compliance Health dashboard (/compliance-health) drills into red/amber/green per obligation.

30. Executive Reports & Investor Pack

  • Executive Report (/executive-report) — one-page board-ready snapshot: score, gap trend, DSR volume, breaches, penalty exposure. Downloadable PDF.
  • Investor Pack (/investor-pack/download) — fuller compliance narrative for due diligence.
  • Data Export (/data-export) — DPDP-compliant self-export of everything the platform holds about your tenant.

31. Recipes — five common scenarios end-to-end

Recipe 1: "A customer emailed asking to delete their data. What now?"

  1. Point them to your public DSR URL (from your privacy notice footer) instead of processing over email — creates the audit trail regulators want.
  2. Once they submit, verify their identity in the admin queue.
  3. Click Fulfil across sources — every connected system that has their record is scrubbed.
  4. Send the auto-generated response letter.
  5. Total time: 10–15 minutes admin effort + a few minutes queue execution.

Recipe 2: "We had a data breach yesterday afternoon. Are we compliant?"

  1. Immediately open Breach Notification → New and record what you know.
  2. If cybersecurity in nature, in parallel open CERT-In Breach Notification — 6-hour clock.
  3. Investigate for the next 24–48 hours, updating the draft.
  4. By hour 60–70, click Generate DPB notification. Review, submit to DPB via their portal, upload the ack.
  5. Send affected principals the breach notice (email templates auto-populated).
  6. Log all remedial actions in the same breach record — becomes your evidence file.

Recipe 3: "We're launching a new product feature that processes children's data"

  1. Add the processing activity to ROPA — flag Children = Yes.
  2. System auto-suggests creating a DPIA — accept.
  3. Fill in the DPIA. Consult DPO. Mark reviewed.
  4. Update the Consent Notice to disclose the child-data processing.
  5. Configure parental verification in Children's Data before turning the feature on.
  6. Publish.

Recipe 4: "Our privacy policy is 3 years old. Update & get everyone to re-consent"

  1. Policy Analyzer: upload current policy, get gap list.
  2. Policy Generator: produce new policy, revise per analyzer suggestions.
  3. Consent Versions: register the new version.
  4. Click Send reconsent — sends every past consenter an email link to accept the new terms.
  5. Optional: WhatsApp bulk reconsent for principals who opted in via WhatsApp.
  6. Track completion rate on the Consent Versions dashboard.

Recipe 5: "The auditor is coming next week. Prepare everything."

  1. Run a fresh Gap Assessment. Download PDF.
  2. Download Executive Report PDF.
  3. Export the DSR register CSV (past 12 months).
  4. Export the Consent register CSV (widget dashboard).
  5. Export the ROPA CSV.
  6. Give the auditor a read-only user (Viewer role) — they see everything without risk of edits.
  7. Show them the Evidence log and, if they wish, click Verify chain integrity — a single-click proof that the audit trail hasn't been tampered with.

32. Glossary

Data Fiduciary
Organisation that decides why and how personal data is processed. (You.)
Data Principal
The individual whose personal data is processed. (Your customers, employees.)
Data Processor
A vendor who processes personal data on your behalf.
SDF
Significant Data Fiduciary — a Fiduciary notified by the government as high-impact under S.10.
DSR
Data Subject Rights request — access, correction, erasure, portability, nomination.
DPB / DPBI
Data Protection Board of India — the regulator.
DPO
Data Protection Officer — mandatory for SDFs.
ROPA
Record of Processing Activities.
DPIA
Data Protection Impact Assessment.
DPA
Data Processing Agreement — the contract between you and a Processor.
Consent Manager
A DEPA-style third party that holds and manages consent on behalf of the principal.
PII
Personally Identifiable Information.
Nullify
Erasure strategy: set PII columns to NULL, keep the row.
Crypto-shred
Erasure strategy: delete every version of an object so no recoverable copy remains.

33. Support & contact

  • Email: [email protected]
  • WhatsApp: available to Enterprise / Agency customers
  • In-app: use the floating help widget (bottom-right on every page) — searches the knowledge base + escalates to human support
  • Response SLA: 4 business hours for Enterprise, 1 business day for Business, 2 business days for others
Feedback on this manual If any section is unclear, incomplete, or contradicts the platform behaviour you're seeing, email [email protected] with the section number.