Skip to content

Stratgik — technology strategy and business systems engineering.
Delivery across the USA, UK, UAE and India.

Talk about a problem

DPDP Act 2023Rules notified 13 November 2025

Get DPDP-ready before the penalties start. From ₹14,999.

India's Digital Personal Data Protection Act applies to every business that collects a name, phone number or email. We map your data, fix your notices and consent, and set it up inside your website and systems, at a price built for Indian businesses, not multinationals.

  • Fixed prices in ₹, GST invoice
  • Implemented in your systems, not just a PDF
  • Notices in English and Hindi

No size limit. It applies to

  • D2C & ecommerce
  • Clinics & diagnostics
  • Schools & edtech
  • Fintech & NBFCs
  • Real estate
  • SaaS & IT services
  • HR & staffing
  • Travel & hospitality

What is at stake

The penalties are written into the Act

The Data Protection Board decides the amount based on how serious the failure was, how long it went on and what you did to fix it. These are the upper limits in the Schedule to the Act.

The largest one is not about paperwork. It is for failing to take reasonable security measures that would have prevented a breach.

  1. ₹250 crore

    Failing to take reasonable security safeguards to prevent a personal data breach

  2. ₹200 crore

    Failing to inform the Board and affected people about a breach

  3. ₹200 crore

    Failing the additional obligations for children's data

  4. ₹150 crore

    Failing the additional obligations of a Significant Data Fiduciary

  5. ₹50 crore

    Any other breach of the Act or Rules, such as notice, consent or rights requests

What the law asks, in plain words

Eight things your business has to get right

Most businesses already do some of these. The gaps are usually in consent records, breach readiness and deletion.

  • A clear notice

    Tell people, item by item and in plain language, what you collect and why. English or any of the 22 languages in the Constitution's Eighth Schedule.

  • Real consent

    Free, specific and unambiguous, for a stated purpose. Withdrawing it must be as easy as giving it. Pre-ticked boxes do not count.

  • Security safeguards

    Encryption or masking, access control, and logs kept for at least one year so misuse can be detected and investigated.

  • Breach reporting

    Tell affected people without delay, and send a detailed report to the Data Protection Board within 72 hours.

  • Children's data

    Verifiable parental consent for anyone under 18. No tracking, behavioural monitoring or targeted advertising aimed at children.

  • People's rights

    Let people access, correct and erase their data, and raise a grievance. Publish how, and respond within 90 days.

  • Deletion on time

    Erase data once its purpose is over. Large ecommerce, social media and gaming platforms must erase after 3 years of inactivity, with 48 hours' notice.

  • Vendors under contract

    You stay responsible for data your CRM, payment, cloud and marketing vendors process for you. Your contracts must say so.

Free self-check

How DPDP-ready is your business?

Ten questions, two minutes. Answer honestly; nothing is sent anywhere unless you ask for the report.

0/ 100

Answer the questions to see your score

0 of 10 answered

  1. 1Do you have a written list of every place you store customer or employee personal data?
  2. 2Does your privacy notice say, item by item, what you collect and why, in plain language?
  3. 3Do your website and app forms take clear consent, with an unticked box and a stated purpose?
  4. 4Can a customer withdraw consent as easily as they gave it?
  5. 5Do you keep a record of who consented, when, and to what?
  6. 6Is personal data encrypted or masked, with access limited to people who need it?
  7. 7Do you keep access logs for at least one year?
  8. 8If you had a data breach tonight, do you know who reports it to the Data Protection Board within 72 hours?
  9. 9Do you delete personal data once its purpose is over?
  10. 10Do your vendors (CRM, payment, marketing, cloud) have contracts that bind them to protect your data?

How we get you compliant

Four steps, done with your team, not handed to them

A typical small or mid-sized business with one website and a handful of systems takes three to five weeks.

  1. 1

    Discover

    Find every copy of personal data

    Website forms, app, CRM, WhatsApp Business, Excel sheets, email, payroll, vendors. This is usually where forgotten copies turn up.

  2. 2

    Decide

    Rank the gaps by risk

    Each gap is scored against the penalty it attracts and the effort to fix it, so the ₹250 crore risks get fixed before the cosmetic ones.

  3. 3

    Implement

    Fix it in your systems

    Notices, consent capture and logs, a rights request page, access controls, retention rules, vendor clauses. Working on WordPress, Shopify, custom apps and common CRMs.

  4. 4

    Hand over

    Train your people, rehearse a breach

    A live session for the staff who handle data, a breach playbook with named owners, and a practice run of the 72-hour report.

Pricing

Fixed prices. No surprises on the invoice.

For businesses with one website or app and up to 5 systems holding personal data. Larger scope is quoted in writing before you pay anything.

Readiness Audit

Know exactly where you stand and what to fix first.

14,999one-time
+ GST

Report in 7 working days

Choose Readiness Audit
  • Discovery call with an engineer (up to 2 hours)
  • Map of where personal data lives: website, app, CRM, WhatsApp, spreadsheets (up to 5 systems)
  • Gap report against the Act and the 2025 Rules
  • Each gap ranked by penalty exposure
  • 90-day action plan your team can follow

Recommended

Compliance Setup

We do the work, in your website and systems, not just on paper.

49,999one-time
+ GST

Typically 3 to 5 weeks

Choose Compliance Setup
  • Everything in Readiness Audit
  • Privacy notice in English and Hindi
  • Consent banner and consent on every website form
  • Consent log with 1-year retention
  • Data rights and grievance request page
  • Retention and deletion schedule
  • Breach response playbook with 72-hour report template
  • Vendor data processing agreement template
  • One live online training session for your staff

DPDP Care

Stay compliant as your business, vendors and the rules change.

7,999per month
+ GST

Cancel any month

Choose DPDP Care
  • Handling of access, correction and erasure requests
  • Quarterly re-check of consent, logs and new systems
  • Breach support on call during business hours
  • Notice and process updates when rules or guidance change
  • Annual staff refresher session

Enterprise & Significant Data Fiduciaries

Data protection impact assessments, independent audit preparation, DPO support, consent integration across apps and multiple systems, cross-border transfer review.

Get a custom quote

Your options

Why not just download a template?

A template gives you a privacy policy. It does not put consent on your forms, keep a log, or tell anyone what to do at 2 a.m. when a breach happens.

FeatureFree templatesLarge consultancyStratgik
Price Free Priced for large enterprises From ₹14,999
Written for your actual dataNoYesYes
Consent and logs built into your websiteNo Often extra Yes
Breach playbook with named ownersNoYesYes
Hindi notice includedNo Often extra Yes
Monthly support without a big retainerNoNoYes

Free readiness call

Talk to an engineer, not a salesperson

Tell us a little about your business. We will reply within one working day with a time for a free 20-minute call and a fixed quote.

  1. 1
    You send the formTwo minutes. Your self-check score is attached if you took it.
  2. 2
    We call you20 minutes on where your data lives and your biggest risks.
  3. 3
    You get a fixed quoteIn writing, in rupees. Nothing is billed until you approve it.

Book your free DPDP readiness call

Interested in

This form follows the consent practice we set up for clients. See our privacy policy.

Questions

DPDP questions Indian businesses ask us

Have a question about your situation? Ask on WhatsApp and an engineer will answer.

Ask on WhatsApp
Does the DPDP Act apply to small businesses?

Yes. The Act has no turnover or size threshold. If you collect digital personal data of people in India, such as a name, phone number or email through a website, app or WhatsApp, it applies. The government can exempt some classes of businesses, such as notified startups, from certain provisions, but no business should assume it qualifies without checking.

When do we have to be compliant?

The DPDP Rules were notified on 13 November 2025. Consent Manager registration starts on 13 November 2026, and the main obligations on notice, consent, security, breach reporting, retention and rights requests become enforceable on 13 May 2027, when the Data Protection Board can impose penalties.

We already follow GDPR. Is that enough?

It is a strong start, but not the same law. DPDP has its own notice format, consent rules, 72-hour breach reporting to the Indian Board, parental consent for everyone under 18, and specific retention and erasure rules. A readiness audit usually finds a short list of India-specific gaps.

Do we need to appoint a Data Protection Officer?

Only Significant Data Fiduciaries, a category the government notifies based on volume and sensitivity of data, must appoint a DPO based in India. Every other business must publish the contact details of a person who can answer questions about its processing of personal data.

Is this legal advice?

No. Stratgik is a technology firm. We map your data, write plain-language notices and processes based on the Act and Rules, and implement consent, logging, security and rights handling in your systems. If you need a legal opinion, we work alongside your lawyer.

Which platforms can you work with?

Websites on WordPress, Shopify, Wix and custom code, mobile apps, and common CRMs and tools such as Zoho, HubSpot, Salesforce, Google Workspace and WhatsApp Business. If a system cannot support something, we tell you and propose a workaround.

Are the prices final? Is GST extra?

The prices are fixed for businesses with one website or app and up to five systems holding personal data. GST at 18% is added to the invoice. For larger scope we send a written quote before any work starts.

What happens if the rules change?

Clients on DPDP Care get their notices and processes updated when the rules or official guidance change. Audit and Setup clients get a note from us when a change affects them, with a quote if work is needed.

Start now. Fixing it in April 2027 will cost more.

A readiness audit takes 7 working days. Every month you wait leaves less time to fix what it finds.

The Stratgik model

Strategy first. Technology that follows through.

Four stages, in order. Most businesses need them one at a time.