Digital Personal Data Protection Act, 2023

DPDP compliance, handled properly.

Every customer record, unsubscribe, and vendor share is a legal obligation with a deadline. Pramaan finds your exposure, captures the events you route to it, and tells you exactly what to do — with experts making the calls.

Free review · 30 minutes · no obligation

Pramaan — your DPDP compliance on one screen
FIG. 01 — YOUR COMPLIANCE, ON ONE SCREEN
Evidence

Append-only audit log

Every action recorded, nothing overwritten — the trail the Board expects to see.

Clocks

Per-right SLA clocks

Each rights request on its own statutory countdown from the moment it lands.

Consent

Consent withdrawal captured

The instant a principal withdraws, processing stops — and it is on record.

Operated by people

Software tracks. Experts sign.

Every determination the platform surfaces is reviewed by a specialist before it becomes your compliance record.

A compliance team reviewing documents together
§ 8 — SECURITY SAFEGUARDS · MAX PENALTY ₹250 CRORECERT-IN DIR. 20(3) — CYBER INCIDENT 6 HOURSRULE 7(2) — DETAILED BREACH REPORT 72 HOURS§ 6(6) — CONSENT WITHDRAWAL WITHOUT DELAY§§ 11–14 — DATA-PRINCIPAL RIGHTS PER-RIGHT SLA
§§ 5–14 + Rules — what Pramaan operates

What Pramaan runs for you

§ 8

Data-processing register

Every purpose, dataset, and lawful basis recorded — the record of processing DPDP presumes you keep.

Data-processing register
§§ 11–14

Rights & DSAR clocks

Access, correction, and erasure requests logged the moment they arrive, each on its own statutory SLA.

Rights & DSAR clocks
RULE 7 + CERT-IN

Breach incident clocks

A breach starts two clocks at once — 6 hours to CERT-In, the detailed report to the Board. Both tracked.

Breach incident clocks
§§ 5–6

Notices & consent artifacts

The notice you showed and the consent you captured, versioned and retrievable — the proof the Act asks for.

Notices & consent artifacts
§ 8(2)

Processor register

Every vendor you share data with, under contract, with their obligations flowed down and on record.

Processor register
Schedule — penalties · CERT-In · timeline
₹250 crore
Maximum penalty · § 8 Schedule

The ceiling for a security-safeguards failure. One breach, one determination by the Board, and this is the figure in play.

6 hours
CERT-In cyber-incident report
72 hours
Detailed breach report to the DPBI
May 2027
Rules fully in force
Made in India

Built in India, for India’s law.

Built around the DPDP Act, 2023 and its Rules — not retrofitted from a foreign framework.

Gateway of India and the Taj Mahal Palace, Mumbai
Pramaan

See where you stand.

Find out, with no obligation, where your business stands under DPDP, and what it would take to stay compliant. A short call with our team.

  • A plain-language read on your actual exposure
  • The specific obligations that apply to your business
  • No jargon, no pressure, just a clear picture

We reply within one business day

Book your review

We'll get back to you within one business day.

By submitting you agree to be contacted about your review. We don't share your details.