We test your DPDP Act duties before the Board asks
India’s Digital Personal Data Protection Act 2023 makes almost every organisation handling Indian personal data a Data Fiduciary. SIS assesses your notice, consent, retention, breach intimation and grievance processes against what your systems and contracts really do.
- !A customer contract now carries DPDP clauses and an audit right, and nobody has tested whether you would pass.
- !You have been notified, or expect to be notified, as a Significant Data Fiduciary and must appoint an independent data auditor.
- !Consent for marketing was collected years ago through a checkbox nobody can now produce evidence for.
- !Personal data flows to call centres, business correspondents or franchise partners with no data processing contract in place.
- !A breach happened and nobody was clear who intimates the Data Protection Board or the affected individuals.
- !You process children’s data and have no mechanism for verifiable parental consent or the advertising restrictions.
Indian legislation governing digital personal data. It defines Data Fiduciaries and Data Processors, requires itemised notice and valid consent, limits retention, mandates security safeguards, breach intimation and a grievance redress route.
Nobody certifies DPDP compliance; it is law, not a certification scheme. SIS conducts an independent third-party audit against the Act and issues an assessment report and statement of conformity.
The report reflects the scope and date of assessment. Reassess annually, after material system changes, and as the phased obligations come into force.
Any organisation processing digital personal data of individuals in India: banks, telecom operators, hotels, hospitals, edtech, SaaS providers and government programmes.
Industries that require ISO 22000 Certification
DPDP Act is applicable across 8 of the 25 industries SIS covers. The pages below set out the specific reason it comes up in each one.
What DPDP Act Actually Requires
An organisation must understand the requirements for ISO 22000 certification to implement it effectively.
Establish where you act as Data Fiduciary and where as Data Processor, which entities and systems are in scope, and whether Significant Data Fiduciary duties apply.
Itemised notice in plain language, available in English or a language in the Eighth Schedule, with consent that is specific, withdrawable, and evidenced per individual.
Personal data used only for the notified purpose, and erased when consent is withdrawn or the purpose is served, unless a law requires it to be kept.
A published route for access, correction, erasure and nomination requests, a responsive grievance mechanism, and records showing requests answered within the stated period.
Reasonable security safeguards proportionate to the data held, plus a tested procedure to intimate the Data Protection Board and every affected Data Principal.
Processing by vendors, agents and franchise partners only under a valid contract, with oversight that checks what they actually do with the data.
How DPDP Act Compliance Assessment Works
A clear, step-by-step process from your first call to a completed engagement.
Scoping & Role Mapping
We identify the entities, systems and processing activities in scope, whether you act as Fiduciary or Processor for each, and whether Significant Data Fiduciary duties are in play.
3–5 daysData Discovery & Gap Assessment
A marketing team swears the database is consented; discovery finds the same numbers in a call-recording archive nobody owns. Each duty in the Act is then measured against what exists.
2–4 weeksIndependent Compliance Audit
Evidence testing on site and remotely: notice and consent artefacts, retention and deletion records, grievance logs, breach drills, safeguard configuration and the contracts covering every processor.
2–5 audit daysAssessment Report & Statement
The report is scored duty by duty against the Act, so a customer exercising an audit right reads the same document your board does. Closing the non-conformities remains your work.
Report in 10 working daysIndustries That Need DPDP Act
Commonly taken alongside
Not Sure Which Certification You Need?
Three questions. The selector reads the same industry-to-standard mapping this whole site is built on, then shortlists what applies to you.
Which sector best describes your organisation?
Scope the DPDP audit before the Board notice arrives
The work is decided by how many systems hold personal data and how many vendors touch it, not by headcount. Those two numbers give you a duration and a fee.
Get My Free Quote →What DPDP Act Changes for Your Business
More than a certificate — a testimony that you have raised the bar and built customer confidence.
Audit rights you can meet
Customer and partner contracts carrying DPDP obligations and audit rights get answered with an independent report rather than a self-assessment questionnaire filled in by your own team.
Penalties adjudicated on evidence
The Act’s schedule sets financial penalties up to ₹250 crore for failing to take reasonable security safeguards. Demonstrated diligence is what the Board weighs when it adjudicates.
Data you forgot about
Most organisations discover personal data in places nobody listed: old CRM exports, WiFi capture logs, call recordings, and spreadsheets on the desktops of departed employees.
Vendor risk closed off
Call centres, recovery agents, franchise operators and technology vendors are where most gaps sit. The assessment forces the contracts and the oversight into existence.
Breach response that works
Intimation duties to the Board and to every affected individual are unforgiving of confusion. A tested procedure with named owners is the difference between hours and days.
A base for other regimes
Data mapping, retention schedules and processor contracts built for DPDP carry over directly into GDPR work and into ISO/IEC 27701 certification.
Frequently Asked Questions
Straight answers to what buyers ask before they commit to DPDP Act.
Is there such a thing as a DPDP certificate?
Does the Act apply to us if we are outside India?
Are we allowed to transfer personal data outside India?
What are the penalties?
We already hold ISO/IEC 27001. How much of DPDP is covered?
Who has to appoint an independent data auditor?
DPDP Act certification across Canada
Pick your region to see the industries concentrated there and the standards their buyers and regulators ask for most.
Book an independent DPDP compliance audit
An independent audit against the Act itself, not a maturity score borrowed from another regime, so the gaps you are shown are the ones that matter when the Board asks.
Get My Free Quote → WhatsApp Us