Service
Data Protection & Privacy
Compliance programmes, privacy documentation and incident response for the DPDP era.
Privacy compliance is now an operational question, not a policy document you publish and forget. We start from what your systems actually do with personal data, then build documentation that matches reality.
The work covers data mapping, notices and consent flows, processor agreements, retention practice, breach response, and preparing for the questions a regulator or an enterprise customer will ask.
What’s included
- Data inventory and processing map
- Privacy notices and consent mechanics
- Data processing agreements with vendors
- Retention and deletion schedules
- Breach response plan and notification drafting
- Readiness review for customer security assessments
How it runs
Map the data
What you collect, where it goes, who can see it, and how long you keep it.
Close the gaps
A prioritised remediation list separating legal obligations from good practice.
Document it properly
Notices, agreements and internal records that reflect what actually happens.
Prepare for incidents
A response plan rehearsed before you need it, not drafted during a breach.
Common questions
We are a small company. Does this really apply to us?
If you handle personal data, obligations apply regardless of size, though what is proportionate differs a great deal. A scoping conversation is the cheapest way to find out where you stand.
Can you help with a breach that has already happened?
Yes, and this is time-critical work. Contact us immediately; notification obligations run on short clocks.
Do you work alongside our engineering team?
Usually, yes. Privacy documentation written without reference to the actual system architecture tends to be worse than useless, because it creates a written record of commitments you are not keeping.
Ready to talk about Data Protection & Privacy?
A 30-minute consultation is usually enough to establish where you stand and what it will take.