Credibility and resources
Trusted by India's
leading institutions.
Built at IIT Guwahati, incubated at its Technology Incubation Centre, and recognised by the ministry that wrote the DPDPA.

Institutional backing
Three institutions.
One standard.

Founded at
Indian Institute of Technology
Guwahati
IIT GuwahatiVerified
Kensara AI was born at IIT Guwahati, an Institute of National Importance, bringing first principles thinking to India's data privacy challenge.

Incubated at
Technology Incubation
Centre, IIT Guwahati
TIC, IITGVerified
An officially incubated startup at IITG's flagship Technology Incubation Centre, with access to world class research, mentorship, and infrastructure.
Recognised by
Govt. of India
Government Backed
MeitY, Govt. of IndiaVerified
Recognised by the Ministry of Electronics and Information Technology, the very ministry that enacted the DPDPA, giving us unique insight into India's regulatory direction.
Questions
Everything a buyer
asks us first.
Grouped by what you are trying to work out.
DPDPA and Regulation
What is the Digital Personal Data Protection Act (DPDPA) 2023?
India's first comprehensive data protection law, governing how organisations collect, store, process, and share personal data. The DPDP Rules 2025 were notified on 13 November 2025, and full compliance is mandatory from 13 May 2027.
Who does the DPDPA apply to?
Any entity, Indian or foreign, processing the personal data of Indian residents. There is no size threshold: a 10-person startup faces the same core obligations as a listed enterprise, covering e-commerce, SaaS, fintech, healthcare, edtech, and HR systems alike.
What are the key DPDPA compliance obligations my business must meet?
By May 2027, all Data Fiduciaries must secure lawful consent, publish a plain-language privacy notice, fulfil data-principal rights, and report breaches within 72 hours. You must also minimise and delete data once its purpose ends, obtain verifiable parental consent for under-18s, and restrict cross-border transfers to whitelisted countries.
What are the penalties for DPDPA non-compliance?
Fines are cumulative, each violation is separate. Weak security safeguards attract up to ₹250 crore; missed breach notifications and children's-data failures up to ₹200 crore; SDF breaches up to ₹150 crore; and general violations up to ₹50 crore each. The Data Protection Board can also suspend operations entirely.
What is a Significant Data Fiduciary (SDF) and does my company qualify?
An SDF is a Data Fiduciary notified by the Government based on data volume, sensitivity, and risk, with provisions expected to activate on 13 May 2027. SDFs must appoint an Indian-resident DPO, run annual DPIAs, and undergo independent audits. Building SDF-ready infrastructure now avoids a later scramble.
What is a Consent Manager under the DPDPA?
A registered intermediary, unique to India, that lets individuals grant, review, and withdraw consent from one platform. Registration opens 13 November 2026 and is limited to India-incorporated entities with a minimum net worth of ₹2 crore, so foreign platforms cannot serve as registered Consent Managers.
How does DPDPA compare to GDPR? Do they conflict?
Both centre on consent, data minimisation, breach notification, and individual rights. Key differences: DPDPA treats all personal data equally (no separate 'sensitive' category), prescribes no imprisonment, and uses a government whitelist for transfers instead of adequacy decisions. GDPR compliance is a strong foundation, but India-specific gaps still need closing, our platform maps both at once.
Are startups and MSMEs exempt from DPDPA obligations?
The Government may notify exemptions from specific obligations (like appointing a DPO), but none are confirmed yet. Basic consent, security safeguards, and grievance mechanisms remain mandatory for every entity regardless of size, so waiting on exemptions is a high-risk strategy.
Our Platform
What exactly does Kensara AI do?
We're an expert-led, AI-powered GRC platform that takes you from regulatory chaos to audit-ready confidence. Certified DPOs, privacy lawyers, and techno-legal consultants work alongside automation covering gap assessment, consent, data mapping, DPIAs, policy drafting, DPO-as-a-Service, training, and real-time monitoring across 51+ frameworks.
How many regulatory frameworks does the platform cover?
51+, monitored and enforced in real-time, including DPDPA, DPDP Rules 2025, RBI, SEBI, and IRDAI for India; GDPR and the EU AI Act; CCPA/CPRA and HIPAA; PDPL; and ISO 27001 and SOC 2, plus 40+ more jurisdictions. Coverage auto-updates as regulations evolve, with no re-engagement needed.
What is DPO-as-a-Service and do I need it?
A fully outsourced Data Protection Officer function: our certified DPOs handle board reporting, regulator communications, and breach notifications without a full-time senior hire. It's mandatory for Significant Data Fiduciaries (who need an Indian-resident DPO) and strongly recommended for any fintech, healthtech, edtech, or e-commerce processing personal data at scale.
What credentials and certifications does your team hold?
Certified DPOs across GDPR and DPDPA, CIPP/E (IAPP), and 5+ years of operational privacy experience across fintech, healthcare, and social media. Kensara AI is incubated at IIT Guwahati's TIC and recognised under MeitY's GENESIS EIR 2.0 programme, the ministry that enacted the DPDPA.
What does your 100% audit success rate mean in practice?
Zero clients we've supported have experienced a compliance failure in an audit. Continuous monitoring, real-time evidence generation, and automated mandate mapping keep you perpetually audit-ready, living documentation that evolves with your data, not a report that's outdated the day it's printed.
Compliance Process
How long does it take to become DPDPA-compliant with Kensara AI?
Most clients reach full compliance in 2 to 6 weeks, versus the 6 to 12 months typical of traditional consulting, a ~70% reduction. Our platform runs data mapping, evidence generation, consent deployment, and policy drafting in parallel. You'll get an accurate estimate for your size and systems on the discovery call.
What does the onboarding process look like step by step?
Four phases. Day 1, discovery call. Week 1 to 2, gap assessment with a prioritised roadmap. Week 2 to 4, platform deployment (consent, DPIAs, data mapping, rights requests, policies) with zero IT disruption. Ongoing, continuous monitoring, auto-updates, and expert support.
What is a Data Protection Impact Assessment (DPIA) and when do I need one?
A structured assessment run before any high-risk processing, covering its purpose, necessity, and safeguards. DPIAs are mandatory annually for Significant Data Fiduciaries and best practice for high-risk activities like profiling or large-scale sensitive data. We automate the workflow so it's continuous, not a one-time exercise.
Do I need to appoint a Data Protection Officer (DPO)?
It's mandatory for Significant Data Fiduciaries, whose DPO must be an Indian resident (SDF provisions activate 13 May 2027). For everyone else it's strongly recommended, appointing one, or using our DPO-as-a-Service, signals accountability to regulators and cuts risk if you process data at scale.
What happens if I am not compliant by May 2027?
13 May 2027 is a hard cutoff with no grace period. Enforcement is complaint-driven from Day 1, and non-compliant businesses face fines up to ₹250 crore per violation, cumulative penalties, mandatory breach notifications, and possible suspension. Starting now, while runway remains, is the only risk-managed approach.
How does Kensara AI handle cross-border data transfer compliance?
DPDPA limits transfers to government-whitelisted countries, and no contract overrides that. We map every cross-border flow, cloud, SaaS, analytics, CDNs, flag what needs remediation, and alert you when whitelists change. For global businesses we address GDPR and CCPA transfer rules under one governance framework.
Pricing and Terms
How does Kensara AI's pricing compare to traditional compliance consultants?
Traditional enterprise DPDPA programmes cost ₹50 lakh to ₹2 crore, take 6 to 12 months, and require re-engagement whenever rules change. We deliver the same outcome at roughly 60% lower cost in 2 to 6 weeks, on one subscription covering assessment, implementation, and ongoing enforcement, no per-framework add-ons.
What does your 14-day money-back guarantee cover?
If you're not satisfied within 14 days of onboarding, we offer a full refund, no questions asked. See our Terms of Service for the precise conditions.
Are there hidden costs or add-on fees I should know about?
No. Your subscription covers gap assessment, deployment, policy drafting, monitoring, and regulatory auto-updates, with no per-framework or re-engagement fees. Optional extras, like expanded DPO-as-a-Service or bespoke training, are quoted separately, only if you choose them.
Technical and Integration
Will implementing Kensara AI disrupt my existing IT systems or operations?
No, zero IT disruption is a core design principle. We integrate with your existing cloud, databases, SaaS tools, and warehouses with no overhaul or downtime. Your engineers are involved only briefly, mainly for API connectors and access, usually hours, not weeks, while our analysis runs in the background.
How does your platform handle real-time regulatory monitoring?
We continuously monitor 51+ frameworks across India, the EU, USA, Saudi Arabia, and 40+ more jurisdictions. When a rule changes, an amendment, a new whitelist, a penalty change, the system updates your posture and flags any action needed, all as part of your subscription rather than a fresh engagement each time.
How does your consent management system work for websites and apps?
Our consent layer deploys across websites, apps, portals, and APIs, handling collection, granular withdrawal, and preferences in a DPDPA- and GDPR-compliant format from day one. Valid consent must be free, specific, informed, and affirmative, no pre-ticked or bundled boxes, and we store all consent records for the required minimum of 7 years.
What is a Record of Processing Activities (RoPA) and can your platform generate one?
A RoPA is an internal register of every processing activity: what data, why, how long, who has access, which processors, and any cross-border transfers. Our data-mapping module discovers your flows, maps them to your obligations, and maintains the RoPA continuously as a living document, not a one-time deliverable.
How does Kensara AI help with data breach response?
Every breach must be reported to the Data Protection Board and affected individuals within 72 hours, with no minimum threshold. We provide a ready-to-activate workflow, detection alerts, incident templates, regulator drafts, and user communications, and our DPO team can manage the whole response for you under DPO-as-a-Service.
Resources
Documents worth
keeping open.
The source texts and the working documents we hand clients.
Next step
Still have
a question?
Ask a certified DPO directly. Thirty minutes, no obligation.