Legal door. Your firm and your clients, one login.

DPDP built the way a law firm actually works.

Your firm is a Data Fiduciary the moment you run payroll. And half your partners are already fielding calls from clients asking, "will you be our DPO?" dcomply covers both jobs from a single tenant — the firm's own DPDP, POSH, BCI, LLP and CERT-In stack on one side, and a partner console for the client DPO work on the other.

Want your associates trained first? Free DPDP course for law firm associates Certificate on completion. Four hours. Written by practising counsel.

Privilege-aware DSR workflow Per-client partner tenants POSH IC + annual return
Live Law Firm Compliance Snapshot
Sharma & Co. Advocates LLP
DPDP Readiness: 82/100 AMBER
───────────────────────────────
Firm HR + BD consent .......... Compliant
POSH IC constituted ........... Yes, term valid
CERT-In DMS incident register . 180d retained
LLP Form 11 (30 May) .......... Due in 42 days
Client vDPO tenants ........... 6 active
───────────────────────────────
Client DSRs: 2 (privilege review pending) · POSH awareness: Q2 done
Powered by dcomply
Two hats, one tenant

A law firm's DPDP life runs on two tracks.

One track is your own firm. The other is the DPO work you deliver for clients. Both live in dcomply, side by side, in the same login.

Track 1

Your firm as Data Fiduciary

Everything you touch that is not a case file falls here. Payroll, associates, interns, BD lists, the mail server, the DMS, the vendor invoices. Case papers are carved out by Section 17(1)(c); the rest of the firm is inside DPDP scope.

  • HR: joining, appraisals, exits, background checks.
  • Client intake and conflict-check data.
  • Newsletter and event lists, alumni CRM.
  • DMS, VDR, mail server, vendor contracts.
  • POSH IC register and annual return.
Track 2

Your firm as advocate-DPO for clients

Section 10(2)(a) wants an India-based DPO who reports to the client's board. An advocate on retainer fits that description exactly. The Partner tier turns that from a Word-doc deliverable into a real operating platform behind your retainer.

  • One dashboard, per-client workspaces.
  • White-labelled DSR portal on your client's subdomain.
  • Per-client breach workflow and DPB liaison log.
  • DPIA templates you can rebrand and deliver.
  • Consolidated billing. Your engagement letter stays yours.

Looking for the in-house counsel view? See For Legal & GC. Building a DPO practice? See For DPOs. Just want the DPDP fundamentals? Start with DPDP compliance.

Sound familiar?

If any of these land, you're in the right place.

Real sentences we hear on first calls with managing partners and privacy heads. Two or three of them are usually enough.

A client asked you to be their DPO last week and you're quoting a retainer without a real delivery platform behind it.

Your firm's HR data lives on a shared drive and someone forwarded a candidate resume on WhatsApp on Monday.

Your POSH IC term ran out six months ago and nobody has scheduled the reconstitution.

Your DMS ransomware plan is a slide deck from 2023 and the partners think insurance covers everything.

You are advising three different clients on DPIA and each one is a separate Word file with an associate's initials.

Your regulator stack

Every Indian law firm lives under all of these.

DPDP sits at the base because the firm processes personal data every working day. BCI shapes how you speak to the outside world. POSH is triggered the moment you cross ten employees. LLP filings apply if that is your entity. CERT-In catches whatever hits the DMS. Each layer maps to a dcomply module.

CERT-In Directions 2022
Six-hour incident report on DMS or VDR breach, mail-server takeover, ransomware. 180-day log retention.
LLP Act 2008 / Companies Act
Form 11 by 30 May, Form 8 by 30 October, statutory audit at ₹40L turnover. MSME-1 half-yearly if applicable.
POSH Act 2013
Mandatory IC once you cross ten employees. Annual return to the District Officer by 31 January. Quarterly awareness.
Advocates Act 1961 + BCI Rules
Rule 36 on advertising and solicitation. Professional-conduct exposure runs alongside DPDP fines, not instead of them.
DPDP Act 2023 + Rules 2025
The base. Firm as Data Fiduciary for staff, BD and admin data. Section 17(1)(c) carves out court files, and only court files.
₹250 Cr
Max DPDP penalty per security failure
6 hours
CERT-In incident window for DMS breach
31 Jan
POSH annual return deadline
10+ staff
Triggers mandatory POSH IC
Where firms usually get caught

Four things that keep tripping up Indian law firms

The partners bill hard on client DPDP work. The firm's own compliance rarely gets the same attention. These four are where the actual audits land.

Privilege vs DSR

A client asks for their own data. You still have to redact work product, honour privilege, and reply in the statutory window. Guesswork does not scale.

DMS ransomware

Legal DMS is a top ransomware target in India right now. CERT-In wants a report inside six hours. DPDP wants notice on top. Your IR plan is a Word doc from 2023.

POSH lapses

Expired IC term, missed annual return, no quarterly awareness. All three carry statutory penalties, and it looks awful for a firm that advises clients on POSH.

Multi-client DPO

Six clients on retainer means six DSR portals, six evidence lockers, six DPB liaison logs. Spreadsheets have never survived past client number four.

In your tenant on day one

The modules a law firm actually uses

These are live modules in the platform, not marketing categories. Each card links to the module page. Everything below is included in the Professional plan or the Partner tier.

Coverage by regulator

What dcomply replaces

Regulator / FrameworkWhy it appliesdcomply module
DPDP Act 2023Firm processes staff, BD and admin PII Consent, DSR, Retention
DPDP Rules 2025Consent format, breach format, DPO obligations Breach notifications
POSH Act 2013Any firm with 10+ employees POSH IC & annual return
Advocates Act / BCIRule 36 on advertising, professional conduct BCI review workflow (built-in)
LLP Act 2008Firms operating as LLP MCA / LLP filings
CERT-In 2022DMS, VDR, mail-server incidents CERT-In reporting
DPDP Sec. 10 (SDF)Clients you take on as advocate-DPO DPO-as-a-Service + SDF Determination
GST + E-invoicingFirm turnover ≥ ₹5 crore GST tracker (add-on)
Partner Programme

Turn the DPO retainer into a real product line.

Every mid-market SDF is looking for an India-based, board-facing DPO. Advocates already satisfy Section 10(2)(a). What most firms are missing is the platform behind the retainer.

Partner tier gives you multi-client tenants, per-client evidence isolation, a co-branded DSR portal at your firm's subdomain, and one consolidated invoice. Price the retainer wherever your market bears — most firms land between ₹40k and ₹75k / mo per client and use dcomply as the delivery platform underneath.

See how the DPO delivery works
Partner tier for law firmsFrom ₹24,999/mo

Firm-level Professional plan plus per-client tenants.

  • Firm-level Professional plan (every module above)
  • Up to 10 client tenants on the partner console
  • Co-branded DSR portal per client
  • Per-client evidence isolation and DPB liaison log
  • Consolidated billing, single invoice from dcomply
  • Board-report pack generator with your firm masthead
Law-firm DPDP FAQs

Questions managing partners actually ask.

Yes, and it applies from the first payroll entry. The moment you hold personal data of employees, associates, prospective clients, vendors or newsletter subscribers, you are a Data Fiduciary. Even sole practitioners are covered. Case files are the only real carve-out, and even that is narrower than most partners think.

It only exempts what you process to enforce a legal right or claim, and what is processed by courts themselves for judicial functions. Case papers, pleadings, evidence, witness statements — those are fine. Your HR spreadsheet, associate onboarding folder, prospective-client intake form, the CRM you built in a weekend, the mailing list you export into Mailchimp, and last quarter's vendor invoices are all outside the carve-out. That is where DPDP hits your firm.

The client can ask. You can still redact work product and privileged material before you release. Section 12(4) lets you withhold where disclosure would harm a third party, and privilege under BSA 129/132 sits above discovery in any event. What matters is that you have a workflow to spot the matter-linked records before you send anything. Our DSR portal flags those records automatically so a partner reviews them before the response goes out.

Yes, and a lot of Indian firms are already turning this into a recurring line. Section 10(2)(a) wants an India-based DPO reporting to the client's board. An advocate on retainer ticks both boxes. The hard part is delivery — running six or ten client DPO practices out of shared drives and emails burns your associates out fast. The Partner tier gives you one console and one login for all of them.

Rule 36 was liberalised in 2008. You can run a website. You can publish articles. You can list your practice areas and contact details. What you cannot do is solicit — no cold outreach, no comparative marketing, no client testimonials that read like endorsements. Anything the firm sends outbound goes through our BCI review flag before it leaves the outbox. Nothing here forces you to police your associates' LinkedIn, but the marketing pipeline stays clean.

Yes. The POSH Act applies to any workplace with 10 or more employees, and that includes partnerships, LLPs and chambers. You need a constituted Internal Committee with a woman Presiding Officer and an external member, an annual return to the District Officer by 31 January, and quarterly awareness sessions on the record. A firm that advises corporates on POSH but has its own IC term lapsed is a bad look, and District Officers do notice.

The April 2022 Direction applies to any entity running ICT infrastructure that suffers a reportable incident. Ransomware on your DMS, an unauthorised access to your VDR, or a compromised mail server — all in scope. Six-hour report window, 180-day log retention, named CISO. Legal DMS platforms are already inside CERT-In's attention radius after the 2023 wave of law-firm ransomware.

The biggest number is ₹250 crore for a security-safeguards failure under Section 8(5). Add up to ₹200 crore for missing the breach notification under Section 8(6). And the fine on your firm does not extinguish the parallel BCI professional-misconduct route, nor does it protect the client whose data leaked.

Two annual filings under the LLP Act 2008. Form 11 by 30 May, Form 8 by 30 October. Statutory audit if turnover crosses ₹40 lakh or partner contribution crosses ₹25 lakh. If you receive supplies from MSME vendors, add the MSME-1 half-yearly. Corporate Compliance tracks all of them in the same calendar as your DPDP items.

Yes. The Partner tier gives you co-branded tenants at yourfirm.dcomply.in with your masthead, per-client evidence isolation, and consolidated billing. The client sees your firm brand. Their engagement letter with you is still the DPA. We're the platform underneath.

It does not. Privilege is a rule of evidence — it stops compelled testimony in court. It is not a gag on statutory disclosure obligations. The Rules 2025 template limits what goes to the DPB to breach facts and mitigation steps, not the content of any privileged matter. The privileged root-cause analysis your firm produces internally sits in a separate vault from the notice itself.

Advocates practice tends to hold matter files for around seven years for professional-defence reasons. That is fine — retain them, but tag them as archival-retention. When the archival period expires, DPDP purpose-limitation kicks back in and the Retention module flags the file for review or deletion. It is a two-phase policy, not a fight between the two frameworks.
Real firms, real practice programmes

"We stopped rebuilding DPO delivery from scratch every time."

"We had three clients on advocate-DPO retainer and each set of deliverables was a fresh Word doc. Six months in we would have burned a junior. The partner console gave us one platform. Now we bill six clients on the same infra, and the deliverables are audit-ready without anyone spending a week per quarter reformatting."
Partner, privacy practice — a mid-tier corporate law firm in Bengaluru.

Start free. Add client tenants as you sign them.

Pay-per-module from ₹1,499. Professional plan from ₹11,999. Partner tier from ₹24,999.