1. Overview
dcomply is a subscription platform that operationalises India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules 2025 for organisations that collect or process personal data of Indian residents. It gives you the workflows, forms, registers, notifications and evidence trails that the DPDP Board and your auditors will ask for — without you writing any of it from scratch.
The platform is a hosted SaaS: you sign up, choose the pieces you need, and start using them the same day. You can embed our consent widget on your website, publish your privacy notice, receive Data Subject Rights (DSR) requests, and file breach notifications — all from the same tenant workspace.
Who this manual is for
- Founders / CEOs deciding whether dcomply covers your DPDP obligations.
- DPOs, compliance officers, and IT heads who will operate the platform day-to-day.
- Auditors and legal reviewers validating the evidence trail before sign-off.
- Consultants managing DPDP compliance on behalf of multiple client companies.
How to read this manual
Sections 2–5 explain the business decisions you make before you start — what DPDP demands, which plan and modules cover them, how to buy, and how roles work. Sections 6 onwards are operational: one section per module, showing exactly where to click and what happens. Section 31 gives you five common scenarios end-to-end, e.g. "customer emails us asking to delete their data — what do we do?"
https://app.dcomply.in, you can append the path in each section (for example /dsr-management) to reach the exact screen described.
2. What the DPDP Act actually requires
The DPDP Act and Rules impose obligations on every "Data Fiduciary" — any organisation that decides why and how personal data of Indian residents is processed. The obligations fall into eleven working areas. dcomply has one or more modules for each.
| DPDP obligation | Section / Rule | Covered by module(s) |
|---|---|---|
| Give the data principal a clear, itemised notice before collecting data | S.5, Rule 3 | Consent Notice Builder, Multilingual Notice |
| Take a specific, free, informed, unambiguous consent for each purpose | S.6, Rule 3 | Consent Widgets, QR Physical Consent |
| Let the data principal withdraw consent as easily as they gave it | S.6(4), S.7 | Consent Withdrawal, public withdraw page |
| Erase / update personal data on the principal's request within a defined SLA | S.11 (access), S.12 (correction), S.12(3) (erasure), S.14 (nomination) | DSR Portal + Data Principal Portal |
| Notify the Data Protection Board within 72 hours of a personal-data breach | S.8(6), Rule 7 | Breach Notification, DPA Filings |
| Verify parental consent when processing children's data (under 18) | S.9, Rule 11 | Children's Data |
| Retain personal data only as long as necessary; erase after that | S.8(7), Rule 8 | Data Retention Auto-Delete |
| Keep an internal Record of Processing Activities (ROPA) | S.8, Rule 5 | ROPA / Processing Activities |
| Restrict cross-border transfers to countries the government has approved | S.16 | Cross-Border Transfers |
| If notified a Significant Data Fiduciary — perform DPIA, appoint DPO, audit annually | S.10, Rule 12 | SDF Determination + DPIA |
| Provide a grievance redressal mechanism | S.13(3) | Grievance / Redressal |
3. Pricing & plan selection
dcomply has three ways to buy: a tiered plan that bundles slots for compliance packs, a set of industry-specific packs, or individual modules à la carte. Most customers pick a tier because it works out cheaper than assembling à la carte, but the choice is entirely yours.
3.1 Tiered plans
Each tier gives you a number of "pack slots" — pick that many industry packs from the six available. All tiers include unlimited users, AI compliance advisor credits, unlimited DSR volume, and access to the executive report.
Starter
- 1 pack slot
- 500 AI credits/mo
- Best for solo founders
Professional
- 3 pack slots
- 1,200 AI credits/mo
- Recommended for SMBs
Business
- 5 pack slots
- 2,000 AI credits/mo
Enterprise
- All packs + all modules
- 3,500 AI credits/mo
Agency
- Everything in Enterprise
- Multi-client console
- 10 clients included, ₹500/mo per extra
3.2 The six industry packs
| Pack | Standalone price | What's in it |
|---|---|---|
| Data Privacy | ₹5,999/mo | Consent, DSR, Policy Generator, DPIA, Gap Assessment, DPDP AI Advisor, Breach Notification, Children's Data, Consent Notices, ROPA |
| Corporate | ₹11,999/mo | Everything in Data Privacy + MCA, Labour, POSH, EHS, ESG, Company Secretarial, Grievances, DPIIT, Compliance Alerts & Monitor, Evidence Locker |
| Finance | ₹9,999/mo | GST, Tax Calendar, IFC, Financial Risk, RBI, SEBI, LODR, IRDAI, Scheduled Reports |
| Legal | ₹9,999/mo | Legal Matters, Contracts, IP Assets, Government Notices, Licenses, Legal Docs, Audit Reports, Engagement Letters |
| Security | ₹11,999/mo | Risk Register, Vendor Risk, ISO/SOC2, VA, Phishing, CERT-In, AI/Website/PII/SAST scans, Evidence Locker |
| Sector | ₹9,999/mo | FSSAI, RERA, Healthcare, E-Commerce, GDPR, CCPA |
3.3 Which plan for DPDP?
- If you only need DPDP compliance and nothing else: Starter tier + Data Privacy pack. Total ₹12,999/month.
- If your Data Privacy pack doesn't include the specific DPDP module you need (see the "Bundled?" column in section 3.4), add that module à la carte for ₹1,499–₹2,499/month each.
- If you're an SME or larger and also need HR, MCA, or ESG modules: Professional with Data Privacy + Corporate + one more. ₹29,999/month.
- If you're a compliance consultant serving multiple client companies: Agency tier — includes 10 client slots.
3.4 DPDP module matrix — bundled vs à la carte
Not every DPDP module is inside the Data Privacy pack by default. The table below shows exactly what's bundled and what needs to be added separately.
| DPDP module | In Data Privacy pack? | À-la-carte price |
|---|---|---|
| Consent Widgets | Yes | ₹1,499/mo |
| DSR Portal | Yes | ₹1,499/mo |
| Breach Notification | Yes | ₹2,499/mo |
| Children's Data | Yes | ₹1,499/mo |
| DPIA | Yes | ₹2,499/mo |
| Gap Assessment | Yes | ₹1,499/mo |
| ROPA | Yes | ₹2,499/mo |
| Consent Notice Builder | Yes | ₹1,499/mo |
| Policy Generator | Yes | ₹1,499/mo |
| DPDP AI Advisor | Yes | ₹2,499/mo |
| Data Retention Auto-Delete | No — add separately | ₹2,499/mo |
| Cross-Border Transfers | No — add separately | ₹2,499/mo |
| SDF Determination | No — add separately | ₹1,499/mo |
| Multilingual Consent Notice | No — add separately | ₹2,499/mo |
| Data Principal Portal | No — add separately | ₹1,499/mo |
| Consent Manager Registration | No — add separately | ₹2,499/mo |
| Right to Nomination | No — add separately | ₹1,499/mo |
| DPA Filings register | No — add separately | ₹1,499/mo |
| QR Physical Consent | No — add separately | ₹1,499/mo |
| Consent Version Registry | No — add separately | ₹1,499/mo |
| Consent Withdrawal Management | No — add separately | ₹1,499/mo |
Enterprise and Agency tiers include every module above without add-ons.
4. How to buy and activate
4.1 The three ways to reach checkout
- No-signin checkout (fastest). From
dcomply.in/pricing, pick a tier, click "Buy". You'll be redirected to/buy/{tier}, pay through Razorpay, and receive an activation email with a licence key. - Sign up first, then subscribe. Create your tenant workspace, then upgrade from the in-app Subscription page.
- Talk to sales for Enterprise/Agency with custom terms — [email protected].
4.2 The no-signin flow — step by step
- Choose the tier on the marketing site pricing page.
- Enter company name, GSTIN (optional), and billing email.
- Choose monthly or annual (annual is ~15% cheaper).
- Complete Razorpay payment (UPI, cards, netbanking, wallets).
- Receive a licence key by email (usually within 60 seconds).
- Click the link — you'll land on
/activate/{key}. Set your admin password. Your tenant is created. - You're auto-signed in and taken to the Onboarding wizard (see section 6).
4.3 Adding modules à la carte after activation
- Sign in as tenant admin.
- Go to Settings → Subscription → Marketplace (or
/subscription/marketplace). - Filter modules by category (Data Privacy, Security, etc.) and click Add module.
- Razorpay charges pro-rata for the current billing cycle; the module unlocks immediately.
4.4 Billing details you should know
- All prices are exclusive of 18% GST (added at checkout).
- Auto-renewal via Razorpay recurring subscriptions is on by default; can be disabled from Settings → Subscription.
- You get a GST invoice by email within 24 hours of each successful charge, and can download historic invoices from Settings → Subscription → Invoices.
- Cancellation is honoured at the end of the current billing cycle — no partial-month refunds, but no lock-in either.
- Enterprise customers may pay by NEFT/RTGS on quarterly cycles — request from sales.
5. User roles and access
dcomply has five roles. Every action in the platform is gated by the role you've assigned to the user.
| Role | Who this is | What they can do |
|---|---|---|
| Super Admin | Platform owner (dcomply team). Not a role you assign. | Everything, across all tenants. Skip. |
| Admin | Your DPO, IT head, or founder. Default for the person who signs up. | Everything within your tenant — create clients, run DSRs, publish notices, invite users, manage billing. |
| Consultant | External DPO or agency-side operator. | Same as Admin except cannot manage users or invoices. |
| Viewer | Auditors, board members, legal reviewers. | Read-only across all modules — great for evidence review. |
| Client | Your customer (data principal) — signed in on the Data Principal Portal. | See only their own DSRs, consent history, and documents. Provisioned via a portal token. |
5.1 Adding a new user
- Go to Settings → Users → Invite.
- Enter email + name, pick a role.
- They receive an activation email; on first sign-in they set their own password + optional TOTP two-factor.
5.2 Provisioning a client portal token (for Data Principal Portal)
Go to Clients → {client} → Portal token and click Generate. Send the resulting URL (/portal/{token}) to the data principal — they can now see their consent history, submit DSRs, and file grievances from a single page. See section 19.
6. First-time setup — the onboarding wizard
When you sign in for the first time you're taken through a 5-step wizard. You can skip it and return later from Settings → Onboarding, but doing it end-to-end gives you a working, gap-scored tenant in about 15 minutes.
Step 1 — Welcome
Overview of what the wizard does. Click Get Started.
Step 2 — Company profile
- Legal name, brand name, CIN (validated), GSTIN (validated).
- Registered state / UT — 35 dropdown options; drives regional-language notice defaults.
- Industry (10 options) — drives which regulatory alerts fire (RBI vs SEBI vs IRDAI vs generic).
- Company size bucket — used to determine SDF candidature.
Step 3 — Select regulations / modules
Check the boxes for the DPDP modules relevant to your business. This is only about visibility — you can always turn them on later from the sidebar.
Step 4 — Invite team (optional)
Add colleagues with role assignments. You can skip and do this from Settings later.
Step 5 — Done
Click Finish. You're taken to the main dashboard. The tenant's onboarding_completed_at is set so the wizard never re-appears.
- Run Gap Assessment — 15-minute questionnaire, produces a compliance score.
- Publish your Consent Notice at
/notice/{slug}. - Get the DSR public form URL from the DSR Portal page and add it to your website footer.
7. Consent Management
Consent Widgets
DPDP S.6 • ₹1,499/mo • In Data Privacy pack Public- Purpose
- A drop-in JavaScript widget you embed on your website / product to record free, specific, informed, unambiguous consent for each processing purpose. Every consent event is captured with IP, user-agent, timestamp, and hash-signed consent proof so you can prove what the principal actually saw.
- URL prefix
/consent-widgets- Public embed API
GET /api/consent/widget/{widgetId}/settings,POST /api/consent/record,POST /api/consent/withdraw
7.1 Creating a consent widget
- Go to Consent → Widgets → New Widget.
- Give it a name (e.g. "Main website — desktop"), pick the tenant client it maps to.
- Add Purposes: each purpose is a separate opt-in checkbox on the widget. Typical set: "Website analytics", "Marketing emails", "Personalised ads", "WhatsApp updates". Every purpose has an Optional / Required flag and a plain-language description shown to the data principal.
- Pick display language(s). If you have Multilingual Notice enabled (section 17), the widget auto-detects browser language and switches between the versions.
- Save. Copy the Embed Code from the widget detail page — it's a one-line
<script>tag.
7.2 Embedding on your website
Paste the embed code just before </body> on every page. When a visitor first loads the site, the widget shows a floating banner. Once they accept or reject, their choices sync to your dcomply tenant in real time and appear at /consent/dashboard/{widgetId}.
7.3 Purpose audit trail
Every purpose change (widget config edit, principal accepts / withdraws) is logged. Go to Consent → Widgets → {id} → Purpose audit. Downloadable as CSV for annual audit.
7.4 Real-time webhooks
For each widget you can register outbound webhooks (Settings → Webhooks). Events fired: consent.given, consent.withdrawn. Payload is signed with your webhook secret. Use this to sync consent state to your CRM / CDP / marketing tool in real time — pair with Connectors (section 27) for zero-code sync to Zoho CRM, LeadSquared, etc.
7.5 Public withdrawal page
Data principals can withdraw consent from a self-service URL: /consent/withdraw?visitor_id=xxx&widget_id=yyy. You expose this URL in your privacy notice. When a withdrawal is submitted, the platform runs consent propagation across every connected data source — see section 27.5.
7.6 Reconsent campaigns (Consent Version Registry)
Whenever you change your privacy policy or add a new purpose, use Consent Versions → New version → Send reconsent to email every past consenter a fresh link (/consent/reconsent/{token}) where they can accept the new terms. WhatsApp bulk reconsent is available for tenants with the WhatsApp Business connector enabled.
8. DSR Portal — Data Subject Rights
DSR Portal
DPDP S.11–14 • ₹1,499/mo • In Data Privacy pack Public- Purpose
- Public form + admin console for every data principal right: Access (S.11), Correction (S.12), Erasure (S.12(3)), Portability (S.11), Nomination (S.14). Enforces the DPDP Rule 7 90-day SLA and produces the audit trail regulators expect.
- URL prefix (public)
/dsr/{clientSlug}- URL prefix (admin)
/dsr-management
8.1 Setting up your DSR intake URL
- Go to DSR → All requests in the admin console.
- The banner at the top shows your Public DSR request form URL — copy it (looks like
https://app.dcomply.in/dsr/your-organisation). - Add this URL to your website footer under a link labelled "Data protection rights" or "Contact our DPO". Also include it in your privacy notice.
8.2 What the data principal experiences
- Opens the DSR URL → sees a form with 5 request-type options (Access, Correction, Erasure, Portability, Nomination).
- Fills in email, phone, and — for identity verification — uploads a masked ID proof (PDF/JPG/PNG, ≤5 MB).
- Submits. They receive a verification email containing a link (
/dsr/verify/{token}). - Click verifies their identity; the request moves from new to verified in your queue.
- They can track status any time at
/dsr/track/{token}.
8.3 What you (the tenant admin) do
- Get a notification email of the new DSR.
- Sign in → DSR → All requests → click the eye icon.
- Review the ID proof. If it looks legitimate, mark identity Verified.
- Depending on request type:
- Access / Portability: click Generate data package — the system compiles a JSON + PDF of everything you hold on that principal (searches your connected data sources — see section 27), signs it, and offers a download link. The principal downloads from
/dsr/download/{token}. - Erasure: click Fulfil across sources — the DsrOrchestrator fans the request out to every connected MySQL, PostgreSQL, MongoDB, S3, Zoho CRM, etc., that has a matching PII record for this principal. Each source shows per-record progress (pending → running → done, or blocked with reason). Every erasure writes to the tamper-evident evidence log.
- Correction: manually update the record where it lives (your CRM, DB, etc.), then mark the DSR complete with proof.
- Nomination: registers a nominee under S.14 who will exercise rights after the principal's death or incapacity.
- Access / Portability: click Generate data package — the system compiles a JSON + PDF of everything you hold on that principal (searches your connected data sources — see section 27), signs it, and offers a download link. The principal downloads from
- Upload a written response letter (auto-generated draft available) and click Mark completed.
- The principal is emailed the completion notice with the download / receipt.
8.4 SLA tracking & overdue queue
DPDP Rule 7 sets a 90-day maximum SLA (most implementations aim for 30). The SLA dashboard (/dsr/sla-dashboard) shows priority levels — urgent (>75 days), high (>60), normal — and separately queues overdue requests. Automated reminder emails fire at D-75 and D-89. See Overdue tab or /dsr-management/overdue.
8.5 Appeal handling
If you reject a request the principal can file an appeal via /dsr/appeal/{token}. Appeals appear at DSR → Appeals; you have 30 days to respond. Unresolved appeals can be escalated to the Data Protection Board via the DPB Appeal Tracker.
8.6 Evidence & audit
Every DSR keeps: original request, identity proof (encrypted at rest), verification token expiry, all status transitions with timestamps + operator email, response letter, downloadable proof PDF. Everything is exportable to CSV for annual audit at DSR → Export register.
9. Breach Notification
Breach Notification
DPDP S.8(6), Rule 7 • ₹2,499/mo • In Data Privacy pack- Purpose
- Guided workflow to notify the Data Protection Board of India within the 72-hour statutory window and, in parallel, CERT-In within the 6-hour window mandated by the CERT-In Directions 2022 for cybersecurity incidents.
- URL prefix
/breach-notifications+/certin-breach-notifications+/dpa-filings
9.1 Recording a breach
- Go to Breach Notifications → New.
- Fill in: date & time of discovery, category (unauthorised access / data loss / integrity / ransomware / misconfiguration), severity, affected record count, description.
- Save as a draft. The record is created with status investigating.
- As the investigation progresses, update the draft — the platform tracks who edited what.
9.2 Meeting the 72-hour DPB notification deadline
- Open the breach → click Generate DPB notification.
- The platform pre-fills the format prescribed by Rule 7 (breach details, affected principals, mitigation steps, contact of DPO).
- If you have Anthropic Claude AI credits available, click AI-generate narrative — Claude drafts the narrative section based on the fields you've filled.
- Review, edit, download PDF, submit to DPB via their portal, then click Mark DPA sent — you'll upload the DPB acknowledgement number.
- Click Mark principals sent once affected data principals are notified.
9.3 CERT-In 6-hour reporting
If the incident meets any of CERT-In's 20 categories of reportable incidents (from the 28 April 2022 Directions), open CERT-In Breach Notifications → New. The form uses CERT-In's format. A background command monitors CERT-In deadlines every 30 minutes and alerts if any incident approaches the 6-hour mark unfiled.
9.4 DPA Filings register
Every regulator submission (DPB, CERT-In, sector regulator like RBI/SEBI) is tracked in the DPA Filings register with status Submit → Acknowledged → Rejected / Closed. Each filing keeps the submission PDF, ack number, and any regulator correspondence.
9.5 Retention rule
Per Rule 7, breach notification records must be retained. The platform blocks deletion of any breach record where notified_at is set, and shows an inline warning explaining the retention obligation.
10. Children's Data
Children's Data
DPDP S.9, Rule 11 • ₹1,499/mo • In Data Privacy pack- Purpose
- Register + workflow for verifying parental consent, blocking profiling of children (S.9(3)), and tracking review windows for every child record.
- URL prefix
/children-data
10.1 When you need this module
If you knowingly process personal data of anyone under 18 — EdTech schools, gaming, kid-focused e-commerce, health apps used by families — you must have verifiable parental consent before you can process, and you must never behavioural-profile them (S.9(3)).
10.2 Workflow
- Add a Children's Record per child: child ID reference, DOB, parent contact, verification method (DigiLocker Aadhaar OTP, government-approved token, in-person, etc.).
- System flags whether the verification method meets Rule 11(2) — age-verification-strong vs weak.
- Every 12 months the platform flags the record for review — parents change, minors turn 18 (auto-graduate to adult consent).
- Reports available: overdue review, pending parental consent, weak verification.
11. DPIA — Data Protection Impact Assessment
DPIA
DPDP S.10 + Rule 12 • ₹2,499/mo • In Data Privacy pack- Purpose
- Structured impact assessment for high-risk processing activities. Required for Significant Data Fiduciaries; recommended for any high-risk processing regardless of SDF status.
- URL prefix
/dpias, DPO consultation register at/dpia-dpo-consultations
11.1 Creating a DPIA
- Go to DPIA → New assessment.
- Describe the processing (purpose, data categories, retention, principals affected).
- Score risk against 8 dimensions: children involved, sensitive categories, cross-border, profiling, automated decisions, volume, novel tech, vulnerable subjects.
- Document mitigations for each identified risk.
- Mark DPO consulted once your DPO reviews.
- Download the finalised PDF for regulator submission if requested.
11.2 Auto-suggestions from ROPA
The ROPA-DPIA triggers screen (/ropa-dpia-triggers) scans your Processing Activities register and auto-suggests DPIAs where a ROPA row involves sensitive categories, children, cross-border, or profiling.
12. ROPA — Record of Processing Activities
Processing Activities (ROPA)
DPDP S.8, Rule 5 • ₹2,499/mo • In Data Privacy pack- Purpose
- The internal register every Data Fiduciary must maintain of every processing activity, its lawful basis, categories of data, retention, and any linked DPIA.
- URL prefix
/ropa
12.1 What each ROPA entry contains
- Activity name (e.g. "Customer onboarding KYC")
- Purpose (linked to consent purpose)
- Lawful basis: Consent (S.6) / Legitimate use (S.7) / Legal obligation / Public interest
- Data categories: name / email / phone / Aadhaar / financial / health / children / other
- Data principals: customers / employees / vendors / job applicants
- Retention period + legal basis for it
- Cross-border transfers (linked to Cross-Border Transfers module)
- Processors involved (linked to Vendor / Processor DPA module)
- Security measures
- Whether a DPIA is required / done
12.2 Visual data-flow map
From any ROPA entry, click Save flow map to plot the data journey visually — source system → your systems → processors → cross-border destinations. Great for regulator briefings.
13. Data Retention Auto-Delete
Data Retention
DPDP S.8(7), Rule 8 • ₹2,499/mo • Add à la carte- Purpose
- Retention policy register with automated flagging + optional automated deletion once a retention period expires.
- URL prefix
/data-retention
13.1 Recording a retention policy
- Go to Data Retention → New policy.
- Pick the data category + processing activity.
- Set retention period (months / years) and the legal basis (e.g. "IT Act 8-year audit trail", "RBI KYC 5-year", "internal HR policy").
- Optional: attach a legal hold — pauses auto-deletion for litigation / investigation.
13.2 What happens at expiry
Nightly at 02:30 IST the data-retention:auto-delete command scans policies for records past their retention window and flags them for review. Actual deletion is manual (click Confirm) unless you enable auto-execute — a safety default.
13.3 Legal holds
If a record is under legal hold (subpoena, dispute), Legal Holds tab lets you pin it. Auto-delete skips held records and shows a warning in the DSR fulfilment flow if the principal asks for erasure of a held record.
14. Cross-Border Transfers
Cross-Border Transfers
DPDP S.16 • ₹2,499/mo • Add à la carte- Purpose
- Register every transfer of personal data outside India, with the safeguard type used, expiry, and — if the destination country is not on the government's approved list — the specific mitigation.
- URL prefix
/cross-border-transfers
14.1 Common use cases
- Storing customer data in AWS us-east-1 / Google Cloud europe-west1 — transfer.
- Sending prospect data to a US-based CRM — transfer.
- Using an EU-based email service — transfer.
14.2 Workflow
- New transfer: destination country, processor / recipient, data categories, volume, safeguard type (SCC / adequacy / consent / contract).
- If SCC-based, use the built-in SCC generator — produces a signed PDF template mapped to DPDP Rule 15.
- The DPB Approvals sub-register tracks any approvals you've filed with the Data Protection Board.
- The Country Approvals register mirrors the government's whitelist so you can check destination eligibility at a glance.
15. SDF Determination — Significant Data Fiduciary
SDF Determination
DPDP S.10 • ₹1,499/mo • Add à la carte- Purpose
- Self-assessment tool that scores your organisation on the 5 SDF criteria (volume of personal data, sensitivity, risk to India's sovereignty/electoral democracy, public order, other risks). If you are notified as an SDF, this module also tracks DPO appointment, mandatory audit schedule, and DPB declaration filings.
- URL prefix
/sdf-determination
15.1 SDF obligations at a glance
- Appoint an India-resident DPO (S.10(2)(a))
- Perform DPIA + audit annually (S.10(2)(c))
- Independent data auditor sign-off (S.10(2)(d))
15.2 Workflow
- Run the assessment questionnaire — 20 questions.
- See your SDF score + likelihood.
- If notified as SDF: enter the notification date in DPB Declarations.
- Add your DPO in DPO Appointments — platform generates the appointment letter.
- Set the annual audit date in Audit Schedules — platform reminds T-60 / T-30 / T-7 days.
16. Gap Assessment
Gap Assessment
DPDP-wide • ₹1,499/mo • In Data Privacy pack- Purpose
- The single-most-important starting point. Runs an 8-section questionnaire mapped to every DPDP obligation and returns a percentage compliance score, penalty exposure estimate, and a prioritised remediation checklist.
- URL prefix
/gap-assessments
16.1 The 8 sections
- Notice & consent (S.5–S.7)
- Children's data (S.9)
- Data principal rights (S.11–S.14)
- Data fiduciary obligations (S.8)
- Security (S.8(4))
- Breach notification (S.8(6))
- Cross-border (S.16)
- Significant Data Fiduciary (S.10)
16.2 Output
- Percentage compliance score (0–100)
- Penalty exposure in rupees — calculated from S.33 penalty tables against your identified gaps
- Ranked remediation list — "Do these 5 things next to reduce exposure by ₹X"
- Downloadable PDF for the board / auditor
- Assignable to team members with SLAs
17. Consent Manager Registration
Consent Manager Registration
DPDP S.2(9) • ₹2,499/mo • Add à la carte- Purpose
- Track third-party Consent Managers (DEPA-style) your organisation relies on. Registration status, technical/security capabilities, expiry.
- URL prefix
/consent-manager
Add each CM you rely on — Sahamati account aggregators for financial data, ONDC-style CMs for e-commerce, etc. The platform tracks registration validity and flags CMs pending re-approval.
18. Multilingual Notice
Multilingual Consent Notice
DPDP Rule 3(1) & 3(2) • ₹2,499/mo • Add à la carte- Purpose
- Produce your privacy notice in all 22 scheduled Indian languages (Rule 3(1)) plus accessible formats — audio, Braille, screen-reader-compatible — for persons with disabilities (Rule 3(2)).
- URL prefix
/multilingual-consent
18.1 Producing a translation
- Go to Multilingual → New notice.
- Start from a template in the library or paste your English notice.
- Click Translate — AI translates into any language(s) you select. Human review is strongly recommended before publishing.
- Toggle Accessible formats: generate audio (MP3), Braille (BRF file), screen-reader HTML.
- Publish to
/notice/{slug}. Your embedded consent widget auto-serves the correct language based on the visitor's browser language.
19. Data Principal Portal
Data Principal Portal
DPDP S.12 • ₹1,499/mo • Add à la carte Public- Purpose
- Single sign-in page where a data principal sees everything you hold about them — consent history, DSRs filed, grievances open, documents shared — and can exercise rights.
- URL prefix
/portal/{token}
Generate a token from Clients → {client} → Portal token. Send the URL to the principal. They can bookmark it — one URL to interact with every right.
20. Vendor / Processor DPA
Vendor Risk (Processor DPA Tracker)
DPDP S.8(2) • ₹3,999/mo • In Security pack- Purpose
- Every processor (vendor who touches personal data on your behalf) must have a DPA (Data Processing Agreement) with you. This module registers vendors, generates DPAs, tracks contract validity, sub-processor notifications, and processor audits.
- URL prefix
/vendor-risk
Workflow
- Register each vendor: name, service, criticality (high / medium / low), start date, DPA reference number.
- Use the DPA generator to produce a DPDP-compliant DPA PDF from a template.
- Update the vendor to Approved once contract is signed.
- Track sub-processor notifications: if the vendor engages a sub-processor, the notification is logged.
- Schedule processor audits — annual for critical vendors.
21. Grievance & Redressal
Grievance / Redressal
DPDP S.13(3) • ₹1,499/mo • In Corporate pack Public- Purpose
- Public grievance form + admin queue + auto-escalation past 30-day DPDP deadline + DPB appeal tracker.
- Public form
/grievance/{clientSlug}- Admin queue
/grievances
Anyone (customer or not) can file a grievance. You get an email + in-app alert. Failing to acknowledge within 30 days auto-escalates the grievance internally and lets the principal appeal to the DPB — tracked in /dpdp/dpb-appeals.
22. Right to Nomination (S.14)
Nomination
DPDP S.14 • ₹1,499/mo • Add à la carte- Purpose
- Register a data principal's nominee — someone who inherits their DPDP rights when they die or become incapacitated. Handled through the same DSR portal but tracked separately.
- URL prefix
/nomination
23. QR Physical Consent
QR Physical Consent
DPDP S.6 • ₹1,499/mo • Add à la carte- Purpose
- For retail, QSR, hospital reception, event registration — anywhere a physical touchpoint collects personal data. Print a QR poster; anyone who scans it sees your notice and captures consent digitally.
- URL prefix
/consent/qr
Create QR codes for each location. Scans go to the same public consent notice URL as your website, but the source is tagged so you can filter analytics by physical location.
24. Consent Notice Builder
Consent Notice Builder
DPDP Rule 3 • ₹1,499/mo • In Data Privacy pack Public- Purpose
- Templated builder for the itemised notice required by Rule 3 — categories of data, purposes, rights, DPO contact, grievance mechanism. Publishes to a permanent public URL you can link from your privacy policy.
- URL prefix
/consent-notices- Public URL
/notice/{slug}
25. Policy Generator & Analyzer
Policy Generator
In Data Privacy pack- Purpose
- Produces a DPDP-compliant Privacy Policy PDF + HTML, with variants for child-facing services (S.9) and educational-technology vendors.
- URL prefix
/policy-generator
Privacy Policy Analyzer
₹2,499/mo • Add à la carte- Purpose
- Upload your existing privacy policy — AI runs a clause-by-clause review, flags DPDP gaps, estimates S.33 penalty exposure, and suggests revised wording.
- URL prefix
/policy-analyses
26. DPDP AI Advisor
DPDP AI Advisor
₹2,499/mo • In Data Privacy pack- Purpose
- RAG-grounded conversational Q&A over the DPDP Act, Rules 2025, and sector-specific guidance for 13 industries. Ask "does S.16 apply to my Delhi–Frankfurt data transfer?" and get a cited answer.
- URL prefix
/dpdp-advisor
Uses your monthly AI credits. Every response cites the relevant DPDP section or rule so you can verify.
27. Connectors, Data Map & DSR fulfilment
This is the "make the DPDP loop actually close" part. Connectors let dcomply reach into your operational systems (databases, CRMs, storage buckets, spreadsheets) to (a) discover where personal data lives, (b) execute DSR exports and erasures on demand, and (c) propagate consent withdrawal to marketing tools.
27.1 The connector catalogue
77 tiles across 11 categories: Cloud Storage, CRM & Sales, Communication, Productivity, Accounting & Finance, Dev & Security, HR & People, Customer Support, Marketing & CDP, Identity & SSO, In-platform. Each tile shows Available / Coming Soon status.
27.2 Which connectors are fully functional today
| Connector | Discovery | DSR Export | DSR Erasure | Consent Sync |
|---|---|---|---|---|
| MySQL | ✓ | ✓ | ✓ | — |
| PostgreSQL | ✓ | ✓ | ✓ | — |
| MongoDB | ✓ | ✓ | ✓ | — |
| AWS S3 | ✓ | ✓ | ✓ | — |
| Google Sheets | ✓ | ✓ | ✓ | — |
| Zoho CRM | ✓ | ✓ | ✓ | ✓ Email_Opt_Out |
| LeadSquared | ✓ | ✓ | ✓ | ✓ DoNotEmail |
| Razorpay | ✓ | ✓ | Anonymise* | — |
| Tally | ✓ | ✓ | Anonymise* | — |
| WhatsApp Business | ✓ | — | — | — |
*Razorpay and Tally erasure strips PII fields but retains the ledger entry — RBI and Income Tax law require 5–8 year retention.
27.3 Connecting a data source (worked example — MySQL)
- Go to Connectors → MySQL → Configure. You arrive at
/discovery/sources/create?adapter=mysql. - Fill in host, port, database, and a read-only MySQL username / password.
- Click Save + test. If auth works, status flips to Connected.
- Click Run scan. The Discovery service walks your tables, classifies columns by PII type (email, mobile, Aadhaar, PAN, name, address, health, financial, etc.), and writes to the Data Map.
- Open Data Map (
/discovery) to browse discovered assets.
27.4 Enabling DSR erasure on the source
For safety, DSR erasure requires a separate credential with UPDATE/DELETE privileges — never the read-only one.
- Open the source detail page (
/discovery/sources/{id}). - Scroll to Erasure credentials.
- Enter a write-capable MySQL user's credentials. Save.
- Erasure is now enabled — reflected in the DPDP capabilities strip.
27.5 Erasure strategy per table
By default every erasure nullifies PII columns while leaving the row intact — this preserves referential integrity (orders still exist, they just no longer identify the customer). You can override per table:
- Nullify (default) — set PII columns to NULL, keep row.
- Delete row — physical row DELETE.
- Skip — do not touch this table (useful for accounting tables you must retain).
- Crypto-shred (S3 versioned buckets) — delete every version so no recoverable copy remains.
Add rules from the same source detail page → Erasure rules.
27.6 The DSR fulfilment orchestrator
When a verified DSR of type erasure or access is opened at /dsr-management/{id}, an admin clicks Fulfil across sources. Behind the scenes:
- The orchestrator lists every connected source whose adapter supports the required capability.
- One task row is created per (DSR × source) in
dsr_fulfilment_tasks. - Each task is queued via
DsrFulfilmentJob. The adapter locates matching records for the subject identifier, then executes export or erasure. - Per-source progress appears live in the "Connector Fulfilment" panel — Pending → Running → Done (or Blocked / Failed with reason).
- Every source touch writes to the tamper-evident
source_evidence_log— hash-chained so any tampering breaks the chain.
27.7 Consent propagation
When a data principal withdraws consent via /consent/withdraw or the Data Principal Portal, the ConsentPropagator service fans the withdrawal out to every connected source that supports consent sync. Today: Zoho CRM (Email_Opt_Out=true) and LeadSquared (DoNotEmail=1, DoNotCall=1). The record is auto-excluded from future marketing sends. Every sync attempt is logged in consent_sync_log.
28. Trust Badge & public compliance page
Show your customers you take DPDP seriously — embed a live compliance badge on your website.
- Go to Trust Badge (
/trust-badge) and generate a token. - Copy the badge SVG URL (
/badge/{token}) and paste it into your website footer. - The badge links to a public compliance page (
/trust/{token}) that shows your live compliance score, active modules, and last-audit date. No sign-in required.
29. Compliance Score & Health
At /compliance-score the dashboard aggregates signals from every module — open DSRs vs SLA, breach filings pending, DPIAs overdue, consent widget health, retention policy coverage — into a single 0–100 score. Snapshots are saved so you can chart improvement.
The Compliance Health dashboard (/compliance-health) drills into red/amber/green per obligation.
30. Executive Reports & Investor Pack
- Executive Report (
/executive-report) — one-page board-ready snapshot: score, gap trend, DSR volume, breaches, penalty exposure. Downloadable PDF. - Investor Pack (
/investor-pack/download) — fuller compliance narrative for due diligence. - Data Export (
/data-export) — DPDP-compliant self-export of everything the platform holds about your tenant.
31. Recipes — five common scenarios end-to-end
Recipe 1: "A customer emailed asking to delete their data. What now?"
- Point them to your public DSR URL (from your privacy notice footer) instead of processing over email — creates the audit trail regulators want.
- Once they submit, verify their identity in the admin queue.
- Click Fulfil across sources — every connected system that has their record is scrubbed.
- Send the auto-generated response letter.
- Total time: 10–15 minutes admin effort + a few minutes queue execution.
Recipe 2: "We had a data breach yesterday afternoon. Are we compliant?"
- Immediately open Breach Notification → New and record what you know.
- If cybersecurity in nature, in parallel open CERT-In Breach Notification — 6-hour clock.
- Investigate for the next 24–48 hours, updating the draft.
- By hour 60–70, click Generate DPB notification. Review, submit to DPB via their portal, upload the ack.
- Send affected principals the breach notice (email templates auto-populated).
- Log all remedial actions in the same breach record — becomes your evidence file.
Recipe 3: "We're launching a new product feature that processes children's data"
- Add the processing activity to ROPA — flag Children = Yes.
- System auto-suggests creating a DPIA — accept.
- Fill in the DPIA. Consult DPO. Mark reviewed.
- Update the Consent Notice to disclose the child-data processing.
- Configure parental verification in Children's Data before turning the feature on.
- Publish.
Recipe 4: "Our privacy policy is 3 years old. Update & get everyone to re-consent"
- Policy Analyzer: upload current policy, get gap list.
- Policy Generator: produce new policy, revise per analyzer suggestions.
- Consent Versions: register the new version.
- Click Send reconsent — sends every past consenter an email link to accept the new terms.
- Optional: WhatsApp bulk reconsent for principals who opted in via WhatsApp.
- Track completion rate on the Consent Versions dashboard.
Recipe 5: "The auditor is coming next week. Prepare everything."
- Run a fresh Gap Assessment. Download PDF.
- Download Executive Report PDF.
- Export the DSR register CSV (past 12 months).
- Export the Consent register CSV (widget dashboard).
- Export the ROPA CSV.
- Give the auditor a read-only user (Viewer role) — they see everything without risk of edits.
- Show them the Evidence log and, if they wish, click Verify chain integrity — a single-click proof that the audit trail hasn't been tampered with.
32. Glossary
- Data Fiduciary
- Organisation that decides why and how personal data is processed. (You.)
- Data Principal
- The individual whose personal data is processed. (Your customers, employees.)
- Data Processor
- A vendor who processes personal data on your behalf.
- SDF
- Significant Data Fiduciary — a Fiduciary notified by the government as high-impact under S.10.
- DSR
- Data Subject Rights request — access, correction, erasure, portability, nomination.
- DPB / DPBI
- Data Protection Board of India — the regulator.
- DPO
- Data Protection Officer — mandatory for SDFs.
- ROPA
- Record of Processing Activities.
- DPIA
- Data Protection Impact Assessment.
- DPA
- Data Processing Agreement — the contract between you and a Processor.
- Consent Manager
- A DEPA-style third party that holds and manages consent on behalf of the principal.
- PII
- Personally Identifiable Information.
- Nullify
- Erasure strategy: set PII columns to NULL, keep the row.
- Crypto-shred
- Erasure strategy: delete every version of an object so no recoverable copy remains.
33. Support & contact
- Email: [email protected]
- WhatsApp: available to Enterprise / Agency customers
- In-app: use the floating help widget (bottom-right on every page) — searches the knowledge base + escalates to human support
- Response SLA: 4 business hours for Enterprise, 1 business day for Business, 2 business days for others