Publishing door. Subscribers + GDPR + editorial.

Subscriber data, done right.

DPDP for subscriber lists, newsletter consent and one-click unsubscribe, GDPR for EU readers, editorial source protection. Every publisher obligation, one workspace. dcomply handles the re-consent workflow for lists imported from multiple tools, produces a DSAR portal that works for both DPDP and GDPR requests, and gives your editorial team a sensitive-source workflow with access controls and audit trail. Every email send stays on the right side of DPDP and the IT Rules 2021 grievance officer obligation.

Newsletter consent built-in One-click unsubscribe everywhere No credit card to start
Live Subscriber Compliance Snapshot
The Daily Acme · 142K subscribers
Compliance Score: 87/100 GREEN
───────────────────────────────
DPDP Act 2023 ............... 92%
Newsletter consent .......... 96%
Unsubscribe SLA ............. 100%
GDPR (EU readers) ........... 78%
Vendor DPA (analytics, ESP) . 88%
───────────────────────────────
Last send to 141,884 opt-ins · withdrawals this week: 412
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences we hear on first calls. If two or three of them ring true, dcomply is the workspace you have been trying to build in a spreadsheet.

Your subscriber list has been imported from three different tools and consent status is a mystery.

Your newsletter unsubscribe link works but you have no audit trail.

You have EU readers and no DSAR process.

Editorial source data lives in reporter inboxes with no formal protection policy.

Your privacy policy hasn't been updated for DPDP.

If you sell reader subscriptions internationally, the SaaS door covers ISO 27001 + SOC 2 for enterprise-media buyers.

Your regulator stack

Here's what sits above the foundation.

Digital publishers, newsrooms, and newsletter platforms live under Indian regulators plus (for EU/US readers) foreign laws too. dcomply ships modules for each layer.

Editorial source protection (case law)
Sensitive-source workflow, access controls, time-boxed reads, audit trail.
CAN-SPAM (US subscribers)
Unsubscribe-in-every-message, physical address disclosure, no deceptive subject lines.
GDPR (EU readers)
DSAR portal, EU representative, cross-border transfer records, cookie consent.
IT Rules 2021 (online news)
Grievance officer publication, 15-day resolution SLA, monthly compliance report for significant publishers.
DPDP Act 2023
The foundation. Subscriber consent, one-click unsubscribe, DSR portal, retention schedule for reader data.
100%
Explicit consent required
1 click
Unsubscribe expectation
€20M
GDPR max for EU readers
₹250 Cr
Max DPDP penalty
Why Publisher Compliance Is About to Get Loud

Four Pressures on Every Subscriber List

Newsletter Consent

Pre-DPDP lists with implicit opt-ins. Every send carries risk until consent is re-confirmed.

Withdrawal Anywhere

DPDP requires the same ease for unsubscribe as subscribe. One-click everywhere.

Editorial Source Protection

Journalist source confidentiality vs lawful access requests. Audit trail matters.

Ad & Analytics Vendors

GA, programmatic ad networks, ESP, CDN, every one needs a signed DPA and sub-processor entry.

In Your Tenant On Day One

Every Publishing Module. Pre-Wired

DPDP
Newsletter Consent Capture

Double-opt-in form generator, version history, retention rules per list.

DPDP
Consent Withdrawal

One-click unsubscribe link + WhatsApp + portal + email. SLA enforced.

DPDP
DSR Portal

Reader right-to-access, correct, delete. Subscriber portal with token access.

DPDP
Cross-Border Tracker

ESP servers, CDN locations, analytics tools outside India. DPDPB approvals.

GDPR
GDPR for EU Readers

Article 28 DPA generator, lawful basis log per send, EU representative tracker.

DPDP
Children Data

Age verification gate for any subscriber under 18. Parental consent for under-18 newsletters.

Vendor
Vendor DPA Chain

Auto-tracked DPAs for ESP, analytics, ad networks, CDN. Sub-processor register.

Vendor
Sub-Processor Disclosure

Reader-facing page listing every current sub-processor with locations.

Editorial
Source Confidentiality Log

Encrypted source register, lawful access request log, retention overrides.

Audit
Send Audit Trail

Per-send proof of consent, timestamp, send list hash, GDPR lawful basis.

Security
Phishing + Awareness

Editorial staff training tracking for ISO 27001 and SOC 2 if needed.

Audit
Evidence Locker

One vault: privacy policy, T&C versions, consent receipts, vendor DPAs, training records.

Coverage By Regulator

What dcomply Replaces

Regulator / FrameworkWhy It Appliesdcomply Module
DPDP Act 2023Subscriber + reader personal data Data Privacy pack
GDPREU readers / subscribers GDPR Compliance module
CCPACalifornia readers (50K+) CCPA module
CERT-InCyber incident reporting CERT-In 6-hour intake
Press CouncilEditorial standards (where applicable) Custom regulatory alignment
POSH10+ employees POSH IC + annual return
vDPO Addon

Newsletter Lists Are Personal Data. Get a Virtual DPO.

Publishers with large opt-in lists hit Section 10 SDF criteria fast. DPDP Section 10 makes appointing a DPO mandatory.

dcomply vDPO bolts on from ₹2,499/mo. Standard tier adds a monthly human checkpoint. Premium gives you a dedicated advocate-DPO for editorial legal questions and DPB liaison.

See vDPO tiers
vDPO Standard₹7,999/mo

AI for the daily work + monthly human checkpoint.

  • Q&A with DPDP + GDPR citations
  • Monthly DPO PDF report
  • DSR auto-draft for subscribers
  • Vendor DPA assistant (ESP, analytics)
  • 30-min monthly consultation
Built for publishing & media

Subscriber data + sources + ad tech. We map the lot.

CMS DB, S3 image library, Razorpay subscriber payments, ESP, source register. dcomply finds PII everywhere DPDP touches.

MySQL
CMS / subscriber DB
MongoDB
Article / asset DB
AWS S3
Image / video library
Google Sheets
Ad ops + reports
Razorpay
Subscriber payments
Tally
Accounts & royalties
Publisher compliance FAQs

Questions editorial and digital heads actually ask.

Digital publishers process reader personal data through subscriptions, comments, newsletter sign-ups, analytics, ad targeting and personalisation. Every one is subject to DPDP. Publishers additionally face Press Council rules on journalistic accuracy, IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 for news content, and CERT-In 6-hour breach reporting.

The DPDP Act has a research/journalism exemption but it is narrow. It exempts only the processing needed for a specific journalistic story, not the general data-collection infrastructure of a publisher (subscription, analytics, ad platform, comment system). dcomply keeps journalism and platform-side data separate in the processing register.

Every third-party pixel, SSP or DMP tag on a publisher's site is a joint-controller relationship under DPDP. Requires: disclosure in the notice, purpose-specific consent (usually "advertising and measurement"), preference-centre control per vendor, and a data-processing addendum with each vendor. dcomply's consent widget supports IAB TCF v2.2 signal generation.

The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 require digital news publishers to appoint a Grievance Officer (India-resident), publish a monthly compliance report if a significant publisher, honour 15-day grievance resolution timelines, and self-regulate content under the Press Council of India / NBSA code.

Reader data used for AI-generated news or personalisation must be covered by explicit purpose-scoped consent. "Improving our service" is not specific enough. Also: DPDP Rule 12 mandates a DPIA before deploying AI systems that process personal data at scale. dcomply auto-triggers the DPIA workflow when an AI purpose is added.

DSR requests from readers must be honoured within 90 days. For publishers this means: erase newsletter subscription, remove/anonymise reader comments per journalistic archive policy, fan out to CDPs and email platforms, and produce an export bundle. dcomply's DSR portal plus connector layer handles all of this via the /api/v1 endpoint.

Yes, under DPDP. Existing lists need re-consent or a documented legitimate basis. dcomply's Consent Manager handles the re-consent workflow.

Anonymous readers don't need consent management. The moment you have identifiable data (email, phone, account) DPDP applies.

Yes. The Grievance module publishes the required officer details and logs the workflow.

Sensitive-source workflow with access controls, audit trail, and time-boxed access. Designed with editorial teams to preserve source confidentiality.

dcomply is a processor for the personal data you upload. A DPA is in place at signup.
Real teams, real programmes

"Handled in one screen."

"We had subscriber data across five tools with no consistent consent record. Six weeks later, one register, one DSAR portal, one purge schedule. The EU DSAR that showed up in month two was handled in one screen."
Head of Digital, a national news publication.

Start Free. Scale When You're Ready.

Pay-per-module from ₹1,499. Sector pack from ₹4,999. vDPO from ₹2,499.