Digital Personal Data Protection Act, 2023

Get your infrastructure
DPDPA compliant.

Consent, notices, data principal rights and breach reporting, layered onto the systems you already run. Built with your in-house team, not around it.

Your systems

WebsiteMobile appCRMHRMSPaymentsSupport deskWarehouse

Kensara layer

ConsentNoticeRightsRetentionBreachEvidence

Enforcement 13 May 2027

Founded at IIT GuwahatiIncubated at TIC, IIT GuwahatiBacked by MeitY, Govt. of IndiaFounded at IIT GuwahatiIncubated at TIC, IIT GuwahatiBacked by MeitY, Govt. of IndiaFounded at IIT GuwahatiIncubated at TIC, IIT GuwahatiBacked by MeitY, Govt. of IndiaFounded at IIT GuwahatiIncubated at TIC, IIT GuwahatiBacked by MeitY, Govt. of IndiaFounded at IIT GuwahatiIncubated at TIC, IIT GuwahatiBacked by MeitY, Govt. of India

The law

What the DPDPA
asks of you.

Six obligations decide whether you pass an audit. All of them apply from 13 May 2027.

Sec. 5 and 6

Lawful purpose and consent

A specific purpose, explicit consent, no bundling.

Sec. 11 to 14

Data principal rights

Access, correction and erasure, answered inside the statutory window.

Sec. 8(6)

Breach notification

The Board and affected users, told within 72 hours.

Sec. 9

Children's data

Verifiable parental consent. No behavioural targeting under 18.

Sec. 16

Cross-border transfers

Only to countries the government permits.

Sec. 10

Significant Data Fiduciaries

Appoint a DPO, run DPIAs, submit to audit.

The cost of getting it wrong

Penalties add up.
There is no size exemption.

A 200 person company carries the same core obligations as a listed enterprise. Each violation is assessed separately.

The Board can also order you to stop processing, which for a digital business means switching the product off.

₹250 Cr

Weak security safeguards

₹200 Cr

Unreported breach, or children's data

₹150 Cr

Missed SDF obligations

₹50 Cr

Every other violation

India's law follows a playbook regulators have already used.

  • MetaUnlawful data transfers€1.2 B2023
  • AmazonImproper processing€746 M2021
  • WhatsAppTransparency failures€225 M2021
Track Indian enforcement

The platform

One platform for
every obligation.

Each module covers a duty under the Act and produces its own audit evidence, month after month.

See it in a live demo

kensara console

DPDPA readiness

evidence: live

Consent managementActive
Notices and policies22 languages
Data principal rights4 open, on SLA
Breach managementArmed, 72h

Audit evidence

Rebuilt nightly, ready for the Board on request.

Consent management

Purpose bound consent with one click withdrawal.

Notices and policies

Versioned notices in all 22 scheduled languages.

Data principal rights

A request portal with identity checks and SLA timers.

Data discovery and RoPA

What you hold, where it sits, why you hold it.

Breach management

A 72 hour workflow with drafts ready to send.

Retention and erasure

Deletion clocks tied to the purpose you declared.

Children's data

Age assurance and verifiable parental consent.

Processor governance

Every vendor touching personal data, on record.

Built for

FintechNBFCsInsuranceBankingHealthcareSaaSE-commerceEdTech

How we compare

Why teams pick us over
the global platforms.

Criteria

Kensara AI

Global platforms

Consultants

Built for
The DPDP Act and Rules
A GDPR core with DPDPA added on
Re-read every engagement
Time to live
2 to 6 weeks
3 to 6 months
6 to 12 months
Commercials
INR, Indian mid-market
USD enterprise contracts
₹10L to ₹1 Cr per project
Data residency
India
Varies by region
Not applicable
Audit evidence
Generated nightly
Manual export
One point in time
Who runs it
A named DPO and our engineers
You, or an implementation partner
A consultant, until they leave
When the law changes
Tracked from MeitY, pushed to you
Global release cycle
A new engagement

Comparison reflects typical market offerings as positioned publicly by each category. Product names are trademarks of their respective owners.

Who builds this

Built in-house.
Run by privacy veterans.

Our own engineers build the platform. Certified privacy professionals who have already carried companies through GDPR enforcement operate it.

5+

Years in privacy operations

100%

Audit success rate

4

Jurisdictions served

01

In-house engineering

The platform is designed and built by our own team, not assembled from third-party modules.

02

Certified DPOs

A named DPO owns your programme. Not a ticket queue.

03

GDPR before DPDPA

Our leads ran GDPR programmes under live European enforcement.

04

CIPP certified

IAPP recognised certifications behind every control we sign off.

AlsoWorking across borders?The same team covers GDPR, CCPA, the EU AI Act and 47 more frameworks, mapped onto one control set.GDPR · CCPA · EU AI Act · PDPL · HIPAA · ISO 27001 · SOC 2See global coverage

Next step

The deadline will not move.
Your readiness can.

Find out where you stand in five minutes, or talk to a DPO about what it takes.

No hidden costsZero IT disruptionNamed DPOIndian data residency