Our approach

From discovery to a governed, audit-ready implementation.

We sit between your company and the technology vendors courting it. We find out what personal data you hold, assess it against the DPDP Act 2023 and Rules 2025, and give you a costed roadmap. Then we select and negotiate the right technology partner for you — and stay on to govern the build.

Five phases, one accountable adviser

Phases 1–4 are delivered entirely by DPDP Impact. In phase 5 a technology partner builds, and we govern.

  1. 01 · Discover

    Find, map and classify your personal data

    AI-accelerated

    Department questionnaires and system-owner interviews, with our AI toolkit reading your policies, forms, schemas and system exports to draft the inventory. Consultants validate every finding with your teams.

    You receive: Data Inventory · Purpose Register · Sensitivity Map

  2. 02 · Assess

    Benchmark every activity, clause by clause

    We compile your Record of Processing Activities and test each activity against the Act and the Rules. Findings are plain enough for a board to act on, detailed enough for an auditor to rely on.

    You receive: RoPA · Board-ready Compliance Scorecard

  3. 03 · Quantify & draft

    Score the risk, close the policy gaps

    Each gap is scored on data sensitivity, threat likelihood and severity, with a mitigation for every risk. Policies are reviewed and drafted to match — business language first, legal reference alongside.

    You receive: DPIA & Risk Register · DPDP-aligned policies and procedures

  4. 04 · Plan & select

    A costed roadmap and the right partner

    Findings are sequenced into a roadmap with phases, owners and costs. We then shortlist, evaluate and negotiate technology partners on your behalf — scored against your scope, not their pitch.

    You receive: Implementation Roadmap & Scope of Work · Vendor Evaluation Report · Negotiated contract

  5. 05 · Govern

    Oversee the build through to go-live

    The technology partner builds; we hold them to your requirements, budget and timelines, test before sign-off, run a breach drill, and certify readiness against the Act and Rules. Quarterly reviews after go-live keep it current.

    You receive: Independent oversight to an audit-ready delivery · one point of escalation

How AI accelerates discovery

Weeks of reading, compressed. Every finding checked by a person.

Discovery is usually the slowest part of a privacy programme. Our AI toolkit does the first pass, so consultants spend their time with your teams on judgement, not spreadsheets.

Your documents stay within the environment you approve.

  1. 01
    Reads

    Policies, sign-up forms, database schemas, system exports, vendor lists and questionnaire responses.

  2. 02
    Drafts

    A first Data Inventory, Purpose Register and Sensitivity Map — flagging personal data, children's data and data with no clear purpose.

  3. 03
    Pre-checks

    Maps each activity to the relevant sections of the Act and Rules, ready for consultant assessment.

  4. 04
    Consultants validate

    Every draft is confirmed in interviews with your system owners before it becomes a deliverable.

Why work with us

Vendor-neutral

Your roadmap is built before any platform is chosen, so you don't pay for capability you don't need.

Board and audit ready

Findings in business language first, with the legal clause alongside — usable by your board and your auditor.

Yours to keep

Every deliverable is a standalone document you own, independent of whichever partner you choose.

Ongoing support

Available on their own or as a retainer after the core engagement. Pricing on request.

Not sure where to start?

Take the 3-minute readiness check and get your score.

Start the readiness check