Only need DPDP? Three plans. Zero jargon.
All 32 DPDP modules in every plan — Consent (2-D matrix + 22 Indian languages + no-code hosted link + 1-line script embed), DSR + Section 14 Nomination, DPIA, Breach, Section 8(5) Safeguards dashboard, 4th-Party Exposure, Sampling audits, AI Purpose Alignment, Code-repo PII scanner, Deep Website Scan with Reject-All verification, Custom Subdomain DSR portal. Pick your usage tier. 18% GST at checkout.
32 DPDP modules in every plan
Not 5. Not 10. Thirty-two — every DPDP module the Act needs, from consent to Section 8(5) Safeguards, Section 14 Nomination, 4th-party exposure, sampling audits, and AI purpose alignment.
Reject-All actually works
Our Deep Scan v2 launches a real browser and verifies that "Reject All" on your cookie banner actually stops trackers. DPDP Section 6 evidence, not just checkbox theatre.
Branded DSR portal on your domain
Custom Subdomain DSR: point privacy.yourcompany.com at dcomply, keep your customers on your brand throughout the DPDP journey. Included from Pro.
10 DPDP-native upgrades. Shipped.
Every gap the specialists advertise — closed. Every one wired into the app, every one reachable from the sidebar, every one live on app.dcomply.in.
Consent & notices — richer, deeper, universal
Notices in every one of the Eighth Schedule languages — Hindi, Tamil, Bengali, Dogri, Santali, Manipuri, Kashmiri, all 22. Native scripts, not transliteration.
Every purpose classified on two axes — Use type (legitimate use vs business case) × Frequency (one-time vs recurring). Legal-review ready.
Share consent forms via WhatsApp, SMS, email, PDF footer, print QR — zero code integration. One URL, mobile-first, all 22 languages supported.
Paste one <script> tag on any page — WordPress, Shopify, custom sites, whatever. Auto-updates when we ship changes; no re-deploy on your side.
Data-principal rights — first-class Section 14 Nomination
Nominee registration + admin approve/reject + audit-trail evidence. A DPDP-only right that GDPR platforms don't handle. Now surfaced on its own portal card, not buried under DSR types.
Data Principal Portal now shows DSR + Nomination + Withdrawal + Grievance as four equal-weight channels — one operator dashboard, four DPDP-native SLAs.
Governance & audit — regulator-ready evidence
Single evidence surface bundling access control + encryption inventory + vuln posture + log retention + breach history. Traffic-light score. Show it to the Data Protection Board on one screen.
Walks the processor chain end-to-end — who are your vendors' vendors? Tree view, unique-countries-in-chain counter, DPDP Sec 8(2) evidence trail. What enterprise procurement asks first.
Cochran-based sample sizing with finite-population correction — random, stratified, or systematic. Big-4 auditor methodology, reproducible draws, methodology footer in the CSV.
AI-assisted intelligence — closing the last-mile loop
Maps every discovered PII field to a declared consent purpose or published notice. Surfaces orphan data (collected with no stated purpose) and stale purposes (declared but nothing maps to them). Alignment score 0–100.
Scans your source (JS/TS/PHP/Python/Java/HTML) for personal-data collection points — form fields, ORM writes, analytics identifies, request-body accesses. 14 labels × ~25 rules, deterministic, source never leaves your tenant.
Every capability above is included in all three plans — no tier gates, no procurement games.
Platform go-live in three weeks.
Not a sales promise — this is the concrete week-by-week timeline every self-serve customer follows.
This is platform setup + first evidence chain — consent widget deployed, DSR portal live,
policies generated, Sec 8(5) Safeguards populated. Ongoing DPDP maturity (staff training, quarterly audits,
RoPA depth) is continuous work after Day 21.
- Sign up (60 seconds, no card)
- Onboarding wizard picks your industry pack
- Connect 2–3 data sources (S3 / MySQL / Salesforce…)
- PII Discovery + Code-repo scan run
- Gap Assessment report generated
- Deploy consent widget (1-line embed)
- Set up 2-D purpose matrix + 22-language notices
- Configure DSR portal on your subdomain
- Generate policy set (privacy, cookie, DPA)
- DPO Console + Grievance Officer register live
- Section 8(5) Safeguards dashboard populated
- AI Purpose Alignment run — orphan fields fixed
- Sampling audit run for regulator evidence
- SHA-256 EvidenceChain sealed
- You're DPDP-compliant. Board memo generated.
The DPDP Implementation Guidebook
The same step-by-step manual we hand every self-serve customer — now public. Every module dcomply ships, section-by-section DPDP Act mapping, DPDP Rules 2025 requirements, real screenshots, and copy-paste templates in 22 Indian languages.
- Setup guide for each of the 32 DPDP modules
- DPDP Rules 2025 + 10 new Sep-2026 modules covered
- Sample DPIA, DPA, and breach-notification templates
- 22-language consent notice templates
- Section 8(5) Safeguards evidence checklist
"Why not just build this in-house?"
Fair question. Here’s what "building it in-house" actually costs when you add up engineering hours, legal review, and the ongoing update burden as DPDP Rules keep evolving.
Build it in-house
- 2 senior engineers × 6 months ₹ 24–36L
- Legal review by a privacy law firm ₹ 4–8L
- Cloud infra + storage + sending domains ₹ 1–2L/yr
- Ongoing updates as DPDP Rules evolve 1 FTE/qtr
- You still don’t have RBI / SEBI / CERT-In / POSH Missing
Buy dcomply
- DPDP module suite Included
- Policies generated + legally reviewed Included
- India infra + sending + storage Included
- Rules updates auto-shipped to you Included
- RBI, SEBI, CERT-In, POSH, ISO, SOC 2 Same login
DPDP Rules 2025 dropped in Nov 2025. Section 8(5) sub-rules are still being clarified. Every clarification means your in-house code needs a re-review. dcomply absorbs those updates and ships them to you — you never pay again to keep up with the law.
Three plans. Every DPDP module in each.
The only difference between tiers is scale — how many users, DSR requests, and Deep Scans per month.
DPDP Starter
For solo founders and early-stage teams
- All 32 DPDP modules included
- Up to 10 users · 1 website
- Up to 100 DSR requests/month
- 5 Deep Website Scans/month · 50 pages each
- 500 AI credits/month
- Consent, DSR, DPIA, Breach, Policy Gen
- DPO Console + Training + Access Control Reviews
- Grievance Officer register + public API
- Email support · 24-hr SLA
DPDP Pro
For growing companies with real data operations
- All 32 DPDP modules included
- Up to 50 users · 3 websites
- Up to 1,000 DSR requests/month
- 25 Deep Scans/month · 200 pages each
- Custom Subdomain DSR (branded portal)
- Deep Scan v2 with CMP Reject-All verification
- All 22 languages + 2-D Consent Matrix + Hosted Link + 1-line script embed
- Section 8(5) Safeguards + 4th-Party Exposure + Sampling audits
- AI Purpose Alignment + Code-repo PII scanner
- 1,500 AI credits/month
- Email support · 4-hr SLA
DPDP Enterprise
For 100+ users, group companies, cross-border
- All 32 DPDP modules included
- Unlimited users · unlimited websites
- Unlimited DSR requests
- 100 Deep Scans/month · 500 pages each
- Multi-entity + cross-border (DPDP + GDPR + CCPA harmonised)
- 5,000 AI credits/month
- Priority support · 1-hr SLA · dedicated CSM
- Named vDPO on retainer (optional add-on)
Need a Data Protection Officer too?
Bolt on a vDPO — AI-only from ₹2,499/mo, or a named advocate from ₹19,999/mo.
vDPO Basic
AI-only DPO
vDPO Standard
AI + monthly human consult
vDPO Premium
Named advocate as your DPO
vDPO Enterprise
Multi-entity, cross-border
Why dcomply for DPDP?
Comparison based on publicly listed pricing for DPDP-only compliance software in India as of Jul 2026.