Client Compliance Portal

Live DPDP Compliance Visibility, for Your Board, Subsidiaries & CA Firm

Stop answering "are we DPDP compliant?" before every board meeting with a stale PDF. Give each client, subsidiary, or audit committee a secure portal link showing their live DPDP obligation scores, open DSRs, overdue alerts, and a downloadable evidence package, all in real time, white-labeled with your branding.

Try the live product
DPDP module-wise obligation scores Token access, no login required Downloadable evidence package
Client Compliance Portal. Live View
Client: Sharma Technologies Pvt Ltd
DPDP Compliance Score: 74 / 100  AMBER
─────────────────────────────────────
Consent Management    ████████░░ 82%
DSR Readiness         ██████░░░░ 61%
Breach Notification    █████████░ 91%
Gap Assessment        ██████░░░░ 63%
─────────────────────────────────────
Open DSRs: 3  |  Overdue Alerts: 1
Last scan: 2 hours ago  |  Token: Secure
Powered by dcomply — DPDP Act 2023 compliance tracking
The Problem

Three Compliance Visibility Gaps That Cost You Time and Credibility

Boards, auditors, and subsidiary HQ teams are asking harder DPDP questions, and the current answer is a PDF prepared the week before

Audit Committees Want Live DPDP Status, Not Monthly PDFs

Board members and audit committees are now asking "are we DPDP compliant?" before every meeting. The answer shouldn't require three days of data collection, but it does, because compliance status lives in five different places and nobody has a live view. By the time the board sees it, the data is already a week old.

CAs Managing 20+ Clients Have No Consolidated View

Switching between 20 client accounts to check compliance status, open DSRs, and overdue alerts takes half a working day every week. There is no master view. There is no way to see at a glance which clients are at risk, which DSR SLAs are about to breach, and which clients need urgent attention today, without opening each account individually.

Evidence Scattered When Auditors Ask for Proof

When the DPBI or an external auditor requests compliance evidence, assembling it takes days: consent audit logs from one system, DSR response records from another, the gap assessment PDF from six months ago. There is no single package. "We are DPDP compliant" means nothing without documented proof, and right now, producing that proof is a crisis response, not a button click.

Capabilities

Six Compliance-Specific Portal Capabilities. Not Generic SaaS Dashboards

DPDP Module-Wise Obligation Scores

Not a single opaque number, the portal shows compliance scores per DPDP obligation with a RAG (Red/Amber/Green) status for each: Consent Banner Compliance (Section 6), DSR Readiness (Sections 11–14), Breach Notification Readiness (Section 8(6)), Privacy Notice Completeness (Section 5), and PII Discovery Coverage. Your client, board, or subsidiary HQ can see exactly which DPDP obligations are met, which are at risk, and which are breached, without asking your team to explain it.

Live Alert Feed. Actionable Issues, Not Just Scores

A real-time feed of compliance events that require attention: "DSR #147 overdue. 30-day DPDP SLA breached (Section 12)", "Consent banner missing on checkout page (scan: today 14:22)", "Breach notification workflow untested for 90 days (Section 8(6) risk)". Not a summary statistic, specific, timestamped, actionable alerts the client or board can read and understand without compliance training. New alerts appear within minutes of detection.

DSR Submission Portal. Direct to DPDP Workflow

The client portal includes a public DSR submission URL for the client's Data Principals (their own customers or employees) to submit Data Subject Requests, access, correction, erasure, nomination, and portability under DPDP Sections 11–14. Each submission flows directly into dcomply's DSR workflow with an automatic 30-day SLA countdown as required under the Act. The portal shows the live DSR submission URL, the count of open requests, and which SLAs are approaching or breached.

Compliance Evidence Package. Auditor-Ready Download

One-click download of the complete DPDP compliance evidence package: consent audit log (PDF, with timestamps and records of each consent obtained, modified, or withdrawn), DSR response records (all DSRs with request date, response date, and outcome), gap assessment report (current obligation-by-obligation status), and website scan history (all scanner results with dates). Everything an auditor, DPBI investigator, or board needs in a single package, no assembly required, available any time from the portal.

Token-Based Secure Access with Expiry & IP Restriction

Each client or subsidiary gets a unique token URL, no MCA login friction, no account creation, no shared credentials. Configurable expiry: 7 days for one-time auditor access, 30 or 90 days for ongoing board visibility, or permanent for group company HQ access. Optional IP restriction locks the portal to specific IP ranges, suitable for sharing with audit committees or external auditors who require access control evidence. Tokens can be revoked instantly from your dashboard at any time.

Multi-Client Master Dashboard + White-Label for Consultancies

For CAs and compliance consultancies managing 10–50 corporate clients: a single master dashboard showing all clients' DPDP compliance scores, overdue alert counts, open DSR counts, and upcoming deadlines, at a glance, without switching accounts. Sort by risk level to see which clients need attention today. White-label the portal with your firm's logo, colors, and custom domain, your clients see your brand throughout, not dcomply's. Ideal for managed compliance engagements where the CA is the face of the service.

Who Uses the Client Portal

Three Use Cases, One Platform

CAs & Compliance Consultancies. Managing 10–50 Corporate Clients

You manage DPDP compliance for multiple corporate clients, each with their own website, DSR workflow, and gap assessment. The client portal gives each client a self-service view, reducing inbound status queries, while the master dashboard lets you see risk across your full book of clients in one screen.

  • One master view, all client DPDP scores at a glance
  • White-label with your firm's name and logo
  • Reduce status-update calls from clients by 80%
  • Evidence package ready when clients need it for audits
Group Companies. Subsidiary-Level Visibility for HQ

Your HQ compliance team needs to see DPDP status across 5–15 subsidiaries without logging into each account. The client portal gives HQ a read-only live view per subsidiary, obligation scores, open alerts, DSR pipeline, without any access to subsidiary operational data.

  • Live DPDP scores per subsidiary, no manual consolidation
  • IP-restricted access, only HQ networks can view
  • Permanent token for ongoing HQ monitoring
  • Consolidated evidence package for group-level audit
Enterprises. Board & Audit Committee Live DPDP Status

Board directors and audit committees are asking DPDP compliance questions before every meeting. Instead of a PDF prepared three days before the meeting, give your board a live portal link they can check at any time, showing current obligation scores, open alerts, and the evidence package.

  • Live scores, data is current at time of viewing, not last month
  • 30-day or 90-day token, refreshed each quarter
  • No login friction for board members
  • One-click evidence package download before every meeting
How It Works

From Client Record to Live Portal in 3 Minutes

Enable the portal from any client page. dcomply generates a secure token URL, configures access controls, and the portal is live, reflecting all compliance data in real time.

Step 1. Enable portal from the client management page

Toggle the portal on from your client record in dcomply. Choose the access mode: token only, token with IP restriction, or token with expiry. A unique secure token URL is generated instantly, no additional setup.

Step 2. Configure expiry and access controls

Set token expiry (7 / 30 / 90 days or permanent). Optionally restrict access to specific IP addresses, useful for external auditors operating from a known network or for board members on a corporate VPN. Apply white-label settings if you are a consultancy delivering a branded portal.

Step 3. Share the link, no credentials required

Send the portal URL to your client's board contact, the subsidiary HQ team, or the external auditor. They open the link and see a live DPDP compliance dashboard instantly, obligation scores, alert feed, open DSRs, without creating an account or managing passwords.

Step 4. Portal updates in real time as you work

Every scan you run, every DSR you close, every gap you resolve, the portal reflects it within minutes. The board or client always sees current compliance status, not a snapshot from last month's report. When alerts are triggered, they appear in the live alert feed immediately.

Step 5. Client downloads evidence package on demand

When an auditor or the DPBI requests compliance documentation, the client clicks "Download Evidence Package" from the portal. It generates a ZIP containing the consent audit log PDF, DSR response records, gap assessment report, and website scan history, ready in under 30 seconds, no manual assembly.

DPDP Coverage

DPDP Obligations Tracked in the Portal

Each obligation score is mapped to the specific section of the DPDP Act 2023 that creates the requirement

Consent Banner Compliance (Section 6), is a valid DPDP-compliant consent notice present on every page that processes personal data?
DSR Readiness (Sections 11–14), is there a functioning DSR submission channel, and are all requests being responded to within 30 days?
Breach Notification Readiness (Section 8(6)), is there a tested breach notification workflow capable of notifying the DPA and affected Data Principals within the prescribed period?
Privacy Notice Completeness (Section 5), does the privacy notice include all mandatory elements: purpose, categories of data, Data Fiduciary identity, and rights of Data Principals?
PII Discovery Coverage (Section 8), has a PII scan been run to identify where personal data is being processed and stored across the organisation's digital assets?
Grievance Officer Designation (Section 13), is a Grievance Officer named in the privacy notice with a working contact channel for Data Principal complaints?
Consent Withdrawal Mechanism (Section 6(6)), can Data Principals withdraw consent as easily as they gave it? Is there a functioning withdrawal flow?
Data Retention Compliance (Section 8(7)), is there a documented retention policy and is data being erased after the stated retention period?
FAQ

Frequently Asked Questions

dcomply generates a unique, cryptographically secure token URL for each client or subsidiary. When you share this link, the recipient sees the compliance dashboard instantly, no account creation, no password, no login screen. The token is tied to a specific client record and can be configured with an expiry date and optional IP address restriction. Tokens can be revoked instantly if the access relationship changes. This frictionless access is specifically designed for board members and audit committees who cannot be expected to manage yet another set of login credentials.

Yes, this is the core value of the portal. Every metric shown is live: obligation scores update within minutes of a new scan or assessment; DSR counts reflect the current open and overdue queue; the alert feed shows events from the last few hours, not the last report cycle. When you resolve a gap, the score changes in the portal. When a DSR SLA is breached, an alert appears. When a consent banner scan flags a missing banner, that specific alert appears in the live feed. Board members who open the portal the morning of a meeting see the exact current compliance picture, not a snapshot from the last reporting cycle.

Yes, and this is one of the primary use cases. You can generate a token with a specific expiry (for example, 7 days during an audit engagement) and optionally restrict it to the IP range of the auditor's network. The external auditor sees the live obligation scores, the alert feed, and can download the evidence package (consent audit log, DSR records, gap assessment, scan history) directly from the portal, without requiring any access to your dcomply account, your operational data, or any other system. When the engagement ends, revoke the token. The portal is designed to be the single compliance documentation interface for external audit engagements.

The evidence package is a ZIP file containing four documents: (1) Consent Audit Log, a PDF record of every consent obtained, modified, or withdrawn, with timestamps and data subject identifiers (for DPDP Section 6 evidence); (2) DSR Response Records, a complete record of all Data Subject Requests received, the type of request, date received, date responded, and outcome (for DPDP Sections 11–14 evidence); (3) Gap Assessment Report, the current obligation-by-obligation compliance status with any identified gaps and remediation actions taken (for DPDP Act obligations generally); and (4) Website Scan History, all scanner results showing when scans were run, what was found, and what the current status is. This package is designed to answer "show me your DPDP compliance evidence" in one download.

Yes. On the Professional and Enterprise plans, the client portal can be white-labeled with your firm's logo, brand colors, and a custom domain. Clients who open their portal link see your firm's name and branding throughout, not dcomply's. This is designed specifically for CAs and compliance consultancies who want to deliver a professional, branded compliance experience to their corporate clients. The master dashboard (your consolidated view of all client scores) is also white-labeled, so your team operates within a branded compliance management environment.

Yes. The portal shows the current count of open DSRs, the count of overdue DSRs (where the 30-day DPDP response window has been exceeded), and the live alert feed flags each SLA breach with the specific DSR number and the date it became overdue. The DSR readiness score in the obligation breakdown reflects both the presence of a functioning DSR submission channel and the current SLA performance, a consistently overdue DSR queue will show in the obligation score as Amber or Red, not just in the alert feed. This gives boards and HQ teams an honest picture of DSR operational performance, not just whether a DSR button exists on the website.

Give Your Board, Subsidiaries & Clients a Live DPDP Compliance View

DPDP obligation scores, live alert feed, DSR submission portal, auditor-ready evidence package, all in a token-secured portal that takes 3 minutes to enable.

View All Features