Why most startups fail the DPDP test
Most Indian startups believe compliance equals privacy policy, cookie banner, consent tool. It does not. The law requires operational evidence: immutable consent logs, processor relationships, breach runbooks, and data-flow diagrams that engineering can defend. Without these, privacy claims are assertions without proof.
Day 1: Data inventory
Map every system that handles personal data: frontend, backend, analytics, CRM, support desk, databases, backups. Capture owner, purpose, data categories, retention, and lawful basis.
Day 2: Classification and lawful basis
Tag datasets by sensitivity: personal, sensitive, non-personal. Assign lawful basis: consent, legitimate interest, legal obligation, contract, vital interest, public task.
Day 3: Third-party processor map
List every sub-processor, processor, and vendor. Confirm DPAs exist, are signed, and match actual data flows.
Day 4: Privacy notices and consent flows
Draft product-facing notices that match your actual processing. Build consent capture, storage, and withdrawal mechanisms.
Day 5: Breach response SOP
Define detection, classification, escalation, notification timelines, and regulator contacts.
Day 6: Evidence pack
Compile one investor-grade folder: data map, ROPA, DPAs, SOPs, consent logs, breach runbook.
Day 7: Validation and version control
Review with cross-functional stakeholders. Lock a change-management process.
What breaks most sprints
Engineering teams often cannot map flows older than three months. Legal stalls because intake is undefined. Vendors delay DPA returns. Founders assign compliance to legal alone.
Speed creates valuation leverage
Investors and acquirers run compliance due diligence before term sheets. An accurate, validated data map protects valuation and negotiating power.
How we help
We run DPDP readiness sprints for startups requiring investor-grade documentation fast. Fixed scope, fixed price, delivered in 10-14 days.
Contact: contact@kramaltus.in