Privacy compliance is now a condition of doing business
Data-protection law has moved from a legal footnote to an operating requirement. The EU/UK GDPR set the template with serious enforcement; India's Digital Personal Data Protection Act 2023 brought the world's largest population under a modern privacy regime; and dozens of jurisdictions have followed. If you handle personal data of people in these regions — customers, users, employees — compliance isn't optional, and "we're a small company" is not a defence regulators accept.
The practical challenge is that privacy compliance is cross-cutting: it touches your product, your marketing, your contracts, your vendors and your security. We approach it as an operational programme, not a policy document — because a privacy notice on your website means nothing if the data flows underneath it tell a different story. Privacy and security are two sides of one coin, which is why our compliance and security teams work the problem together.
GDPR and DPDP — same spirit, different detail
Both laws share core principles: process personal data lawfully, collect only what you need, be transparent, keep it secure, respect individuals' rights, and be accountable. But the details differ in ways that matter:
| EU / UK GDPR | India DPDP Act 2023 | |
|---|---|---|
| Scope | Personal data of people in the EU/UK, extraterritorial | Digital personal data processed in India (and some processing abroad) |
| Lawful bases | Six bases incl. legitimate interests | Consent-centric, with defined "legitimate uses" |
| Key roles | Controller / processor; DPO where required | Data Fiduciary / Data Processor; Consent Manager; DPO for Significant Fiduciaries |
| Rights | Access, rectification, erasure, portability, objection… | Access, correction, erasure, grievance redressal, nomination |
| Cross-border | Transfer mechanisms (SCCs, adequacy) | Government-notified restriction model |
For organisations operating across both — increasingly the norm — we design one programme that satisfies the stricter requirement on each dimension, with jurisdiction-specific overlays where they genuinely diverge. That's cheaper and more coherent than running parallel compliance efforts.
What we do
Data mapping & inventory
A record of what personal data you hold, where it flows, why, on what legal basis and for how long — the foundation every other obligation rests on.
Privacy notices & policies
Transparent, accurate privacy notices and internal policies that match your actual data practices — not aspirational fiction.
Consent & lawful basis
Consent mechanisms that meet the standard (freely given, specific, informed) and a defensible lawful basis for every processing activity.
DPIAs & risk assessment
Data Protection Impact Assessments for high-risk processing, documented to withstand regulator scrutiny.
Rights & request handling
Processes to handle access, correction, erasure and other requests within statutory deadlines — before the first request forces improvisation.
Breach response
Breach assessment and notification procedures aligned to each law's timelines, integrated with our incident response.
Data mapping: you can't comply with what you can't see
Almost every privacy failure traces back to an incomplete picture of where personal data actually lives. Marketing has a tool nobody registered; a legacy database holds records no one remembers; a vendor processes data under an agreement that predates the current law. We build a genuine data inventory and flow map — categories of data, sources, purposes, legal bases, recipients, cross-border transfers and retention — because it's the artifact that makes every downstream obligation (rights requests, breach assessment, DPIAs, vendor management) tractable rather than guesswork. It's also the first thing a regulator asks to see.
Handling individual rights requests
Both regimes grant individuals rights over their data, and both set deadlines for responding. The organisations that struggle are the ones that build the process after the first request arrives — scrambling to locate one person's data across systems that were never designed to find it. We help you stand up the capability in advance: a defined intake channel, identity verification, a repeatable way to locate and act on an individual's data across your systems, and response templates. Handled well, rights requests are routine; handled reactively, they're a compliance incident waiting to happen.
Our process
Scoping & applicability
Which laws apply to you and where, based on who your data subjects are and where you operate — so effort goes where the obligation actually bites.
Data mapping
The personal-data inventory and flow map — the foundation. Most engagements surface data flows the client didn't know existed.
Gap assessment
Current practices measured against the applicable laws; gaps prioritised by risk and regulatory exposure.
Remediation
Notices, consent flows, policies, DPIAs, rights-handling and vendor agreements put in place — with product and engineering changes where the data flows demand them.
Operationalise & maintain
Training, a rhythm for keeping the data map current, and readiness for requests and breaches — because privacy compliance decays without upkeep.
Frequently Asked Questions
Does GDPR apply to us if we're not in Europe?
Potentially yes — GDPR is extraterritorial. If you offer goods or services to, or monitor the behaviour of, people in the EU/UK, it applies regardless of where your company sits. Many non-European businesses are surprised to learn they're in scope. We assess applicability precisely so you neither ignore a real obligation nor over-comply with one that doesn't apply.
What is the DPDP Act and who does it affect?
India's Digital Personal Data Protection Act 2023 is the country's comprehensive data-protection law, bringing a very large population under a modern, consent-centric privacy regime. It affects any organisation processing the digital personal data of individuals in India — domestic and, in defined cases, foreign. If you have Indian users or customers, it likely applies to you.
Can one programme cover both GDPR and DPDP?
Largely yes, and that's the efficient approach. The two share core principles, so we build a unified programme that meets the stricter requirement on each dimension, with jurisdiction-specific overlays where they genuinely differ (consent specifics, cross-border rules, role definitions). Running entirely separate efforts wastes money and creates inconsistency.
What is a DPIA and when do we need one?
A Data Protection Impact Assessment is a documented evaluation of privacy risks for processing likely to be high-risk — large-scale profiling, sensitive data, new tracking technologies. GDPR requires it for such processing, and it's good practice generally. A proper DPIA both reduces risk and demonstrates the accountability regulators expect. We produce ones that hold up under scrutiny.
Do we need to appoint a Data Protection Officer?
It depends. GDPR mandates a DPO for public authorities and organisations whose core activities involve large-scale monitoring or sensitive-data processing; DPDP requires one for "Significant Data Fiduciaries". Many organisations aren't strictly required to appoint one but benefit from designated privacy ownership. We advise on your obligation and can support a DPO or fractional-DPO arrangement.
How do we handle a data subject request?
With a process built in advance: a defined intake channel, identity verification, a reliable way to locate the individual's data across your systems, and action within the statutory deadline. The failure mode is improvising when the first request lands. We help you stand up the capability so requests are routine, not emergencies.
What are the penalties for non-compliance?
Both regimes carry substantial financial penalties, and beyond fines there's reputational damage and lost business — enterprise customers increasingly require privacy compliance contractually. The exact figures differ by law and are set by the respective authorities. The point isn't the headline number; it's that non-compliance is now a real commercial and legal risk, not a theoretical one.
Is this legal advice?
No. We provide practical privacy compliance consulting — data mapping, controls, processes and documentation — and we work alongside your legal counsel where formal legal interpretation is needed. For definitive legal positions on your obligations, qualified data-protection lawyers should be involved, and we're happy to collaborate with them.
The GDPR is EU/UK legislation; the DPDP Act 2023 is Indian legislation. This page is informational and is not legal advice; consult qualified counsel for legal interpretation of your obligations.