RISKFORTIS
Enforcement092d 01h 44m

Fixed scope · Fixed fee · Eight weeks

DPDP Compliance Implementation

In eight weeks we build the programme itself — notice, consent, rights, retention, transfers, breach response — and hand you the evidence that it works.

Not a policy pack. Working controls, running workflows and a documented, tested response plan, delivered by the people who scoped the work.

08
Weeks to handover
14
Named deliverables
28h
Of your team's time
01
Tested breach drill

What we build

Itemised privacy noticeConsent capture & withdrawalConsent artefact storeConsent Manager integrationRoPA maintenance processData principal rights workflowGrievance redressalRetention schedule & erasure jobsProcessor agreementsTransfer assessmentsRule 6 security safeguardsAccess review & loggingRule 7 breach response planCERT-In reporting runbookDLT notification templatesVerifiable parental consentDPIASDF obligationsDPO or contact appointmentBoard reporting packRole-based training

Scoped to what applies to you. Where an obligation does not reach your processing, we say so in writing rather than billing for it.

The engagement

Four phases, eight weeks, 28 hours of your time.

Every session is booked in advance against named people. If a phase needs more of your team than this, we tell you before it starts.

WEEKS 01–02

Design

Target state and decisions

Lawful basis per processing activity, consent model, retention positions, and the decisions that need a signature before anything is built.

You: privacy lead, legal, product8h across two weeks

WEEKS 03–05

Build

Notices, consent, rights

Notices drafted per journey, consent capture and withdrawal specified for your engineers, rights workflow stood up with owners and SLAs inside the statutory window.

You: engineering, ops, support10h across three weeks

WEEKS 06–07

Harden

Processors, retention, Rule 6

Processor agreements repapered, transfers assessed, retention schedule wired to erasure jobs, access reviewed and logging retained as Rule 6 requires.

You: legal, IT, vendor managers7h across two weeks

WEEK 08

Test & hand over

Drill, evidence, board pack

The breach plan run against a live clock, training delivered to the roles that need it, and the evidence pack handed to your compliance owner.

You: five drill seats, sponsor3h in one week

What you receive

Fourteen documents, each named in the contract.

All in editable form, all yours, whether or not you retain us afterwards.

01

Privacy notice set

Itemised notice per journey, plus the short-form variants for app and SMS.

02

Consent specification

Capture, withdrawal and artefact schema your engineers can build from.

03

Rights request workflow

Intake, verification, fulfilment and refusal grounds, with owners and timers.

04

Grievance redressal procedure

Published route, escalation ladder and response templates.

05

Retention & erasure schedule

Field-level, reconciled against sectoral record-keeping mandates.

06

Processor agreement pack

Master clauses, security schedule and breach notification terms, repapered.

07

Transfer assessments

Per destination and per flow, with the position stated and dated.

08

Rule 6 safeguards baseline

Controls, access model and one-year log retention, with test evidence.

09

Rule 7 breach response plan

Named owners, decision tree, and both clocks on one page.

10

Notification templates

Board, CERT-In and data principal drafts, DLT-registrable where needed.

11

DPIA

For the high-risk processing identified, completed rather than templated.

12

Updated RoPA and maintenance process

Plus the change trigger that keeps it current after we leave.

13

Drill report and attestation

Evidence that the response plan was tested, signed and dated.

14

Board reporting pack

Programme status, residual risks and the quarterly cadence to keep it.

Fit

Who this is for

  • Organisations that have completed a gap assessment — ours or someone else's — and know what needs building.
  • Between 25 and 200 processing activities, one or two entities, a functioning IT team.
  • An executive sponsor who can settle a lawful-basis decision in the room.
  • Anyone who needs to be defensible before enforcement powers activate, not by May 2027.

Who it is not for

  • Organisations that have not mapped their processing yet — start with the DPDP Gap Assessment instead.
  • Anyone who wants a document pack to file and forget. We build controls, and controls need owners.
  • Groups with more than four entities or a shared processor estate across them — that is a longer, differently priced programme.
  • Teams that cannot release 28 hours across eight weeks. The engagement stalls, and we would rather say so now.

The fee

Published, banded, and fixed on signature.

Banded by the size of your processing estate and the number of entities. Half your gap assessment fee comes off the first invoice if you continue within sixty days.

Get a scoped quote
Single entity25–75 PROCESSING ACTIVITIES
₹12,00,000
Large estate or SDF75–200 ACTIVITIES · SDF DUTIES
₹18,00,000
Multi-entity groupSCOPED PER ENTITY
On request
Post-handover supportOPTIONAL · PER MONTH
₹85,000

Questions

We specify, you build in your own systems — we do not write production code, deploy infrastructure, or procure tooling. Consent Manager platform licences, DLT registration fees and security tooling are yours. Everything else in the scope document is ours to deliver.

Eight weeks from signature, you can evidence it.

Talk to DPDP experts

Free consultation · 45 min · scope and fee in writing within two working days.