Skip to content
DPDP Act, 2023 • the operative obligations commence 13 May 2027

Govern. Control. Prove.

Operationalise India's DPDP compliance from obligation to audit-ready evidence. Replace scattered spreadsheets with continuous regulatory governance.

End-to-end traceability

Regulatory Source
Obligation
Control
Evidence
Audit
app.dpdpniti.com/controls

Controls

Every obligation that applies to you, its control, its owner, its evidence

Append-only audit trail
DPDP Act provisionControlOwnerEvidenceStatus
Section 5(1) — NoticeNotice content standardPrivacy Office

3 of 3 current

Implemented
Section 6(4)–(6) — WithdrawalWithdrawal handling procedurePrivacy Office

1 of 2 current

In progress
Section 8(5) — Security safeguardsAccess control baselineIT Security

4 of 4 current

Implemented
Section 8(6) — Breach noticeIncident response procedureIT Security

0 of 2 current · 1 undetermined

Not started
Section 11(1) — Right to accessRights request workflowCustomer Operations

2 of 2 current

Implemented
Illustration of the DPDPNiti model using a synthetic organisation. Evidence is counted, never scored — a coverage figure shows its own denominator, and anything undetermined is counted beside the others rather than folded into either side. No percentage appears here, in the product, or anywhere it could quietly mislead.

What the platform does

One operating model, from the statute to the evidence

Six capabilities that are built and running today, and one that is on the roadmap and labelled as such.

Applicability and readiness

Answer a structured assessment and get a versioned readiness result you can defend: which provisions reach your organisation, where you fall short, and which gaps cap the rating regardless of the arithmetic.

Controls, owners and evidence

Adopt controls against the obligations that apply, give each one an accountable owner, attach the evidence that proves it, and route that evidence through a review queue with an expiry that is derived, never stale.

Registers of your data reality

A data inventory with processing activities and flows, a vendor and processor register with the contracts behind it, and notices and policies that version, approve and publish.

Rights requests and incidents

Intake, identity verification, classification and closure for Data Principal requests, and the same discipline for personal data breaches — each transition recorded, none of them a free-text status field.

Risk, remediation and acceptance

Findings become risks with inherent and residual scoring against measured control effectiveness, remediation tasks that track effort, and a risk acceptance that is a recorded decision with a name against it.

Executive view and audit trail

Seven tiles that count honestly, each carrying the basis it was calculated on, over an append-only audit trail recording who did what, when, and what changed.

Consent and multilingual noticesComing· Phase 2

Consent capture, withdrawal and a notice lifecycle across English and the 22 languages of the Eighth Schedule — the option the Act itself gives the Data Principal. Not built yet; on the roadmap and scoped.

How it works

From obligation to evidence

Four steps that put compliance work where it belongs — in a system of record rather than a spreadsheet nobody owns.

  1. 01

    Find what applies

    Answer a scoped assessment. Applicability rules decide which provisions reach your organisation, and say so — including the ones that need a human decision.

  2. 02

    Assign controls and owners

    Adopt a control against each obligation, name the accountable owner, and set the review cadence the control actually needs.

  3. 03

    Collect and review evidence

    Contributors attach evidence to the requirement it satisfies; a reviewer approves or rejects it; expiry is derived from the evidence itself, so cover lapses visibly instead of silently.

  4. 04

    Report and prove

    A dashboard of honest counts, a readiness result with its decomposition, and an append-only record of every action behind them — exportable when someone asks you to show your work.

How it is built

The guarantees a privacy team will ask us about

Stated at the level they are actually enforced — and where something is not built yet, it says so.

Tenant isolation in the database

Every tenant-owned table carries PostgreSQL row-level security, and the application connects with a role that cannot bypass it. Isolation is a property of the database, not a filter the application remembers to add.

Append-only audit trail

Important actions are recorded with actor, tenant, timestamp and before-and-after state. Neither application role holds an UPDATE or DELETE grant on the audit table, and a trigger refuses the write if anything reaches it another way.

Roles, permissions and MFA

Authorisation is enforced on the server for every route: identity, tenant, role, permission, resource, action. Accounts enrol a TOTP second factor, and the interface never stands in for the check.

Enterprise SSO and SCIMComing

Single sign-on against your identity provider, and directory-driven provisioning. On the roadmap for the Enterprise tier; not available today.

We publish what we have not done as carefully as what we have. The security page names our current certifications — there are none yet — alongside the controls that are in place.

See it against your own obligations

A walkthrough of the real product — the assessment, the controls, the evidence and the audit trail — with the roadmap shown as the roadmap.