Service 03 — Privacy

Privacy programmes that stand up to scrutiny.

DPDPA and GDPR alignment, DPIAs, data mapping, records of processing and ISO 27701 — turning privacy obligations into working processes, controls and evidence.

Techno-legal implementation, backed by counselWe interpret and implement DPDPA, GDPR and other privacy obligations technically — turning them into working programmes, controls and evidence. Formal legal opinions and regulatory representation are signed off by a licensed advocate or law firm, so technical depth and legal accountability stay clearly separated.
Capabilities

From obligations to operating controls.

01

DPDPA 2023 & GDPR alignment

Gap assessment against India's Digital Personal Data Protection Act and the EU GDPR, with a prioritized implementation roadmap.

02

ISO/IEC 27701 PIMS

Privacy Information Management System implementation, integrated with your ISO 27001 ISMS.

03

DPIA & privacy impact assessments

Data protection impact assessments for new products, processing activities and AI use cases.

04

Privacy by Design

Privacy requirements and privacy engineering patterns embedded into product design and SDLC.

05

Data mapping & records of processing

Data inventories, data-flow maps and records of processing activities that stay current.

06

Vendor & third-party privacy assessments

Due diligence and ongoing assessment of processors and sub-processors.

What we deliver

A privacy programme, not a policy binder.

01

Privacy governance

Roles, responsibilities, policies and a privacy operating model with clear ownership.

02

Consent & notice

Notice and consent flows aligned to DPDPA and GDPR requirements, including rights-request handling.

03

Data subject rights

Processes and tooling to handle access, correction, erasure and grievance requests within required timelines.

04

Breach readiness

Personal-data breach response procedures, playbooks and tabletop exercises.

05

Sector alignment

Alignment with CCPA and HIPAA requirements where you operate in those markets.

06

Privacy-awareness training

DPDPA / GDPR awareness programmes for product, engineering and support teams, informed by IAPP and DSCI curricula.

DPDPA · GDPR
CORE PRIVACY REGULATIONS
ISO/IEC 27701
PRIVACY INFORMATION MANAGEMENT SYSTEM
CCPA · HIPAA
MARKET-SPECIFIC ALIGNMENT

Proof pointOur privacy practice is informed by IAPP and DSCI frameworks, alongside our team's privacy certifications. Privacy-awareness training is delivered jointly with VVNT Foundation.

Related

Pairs naturally with ISO and security.

Ready to discuss your privacy programme?

Tell us where personal data flows through your business and which regulations apply — we'll come back with an assessment and implementation plan.