🇮🇳 Built in India · AI-Powered · DPDP Act 2023 + Rules 2025
India's #1 DPDP Compliance Platform.
DPDPSaathi by Privaxa is your AI compliance co-pilot for the Digital Personal Data Protection Act 2023. DPIA assessment, consent management, breach response, website compliance scanner, privacy policy analyzer, cookie scanner, grievance redressal, vendor management — in Hindi, Telugu, Tamil & English.
DPDP Compliance Tool - DPIA Services - Data Protection Impact Assessment - DPDP Services India - Privacy Compliance Automation
5+
Countries CA · DE · AU · IN · US
4
Languages HI·TE·TA·EN
72hr
Breach response engine
24/7
AI Co-Pilot support
Your AI compliance co-pilot for DPDP Act 2023.
DPDPSaathi automates everything — from data audits and consent management to breach response and penalty calculation. Works in Hindi, Telugu, Tamil and English. Built by Indians, for Indian businesses.
🛡 DPDP Act 2023 native
🇮🇳 India-first
🤖 AI-powered
🌐 4 languages
⚡ 15-min setup
🛡 Platform Features
Everything you need for DPDP compliance.
From AI-powered audits to breach response in 4 languages — DPDPSaathi covers every section of the DPDP Act 2023 and Rules 2025.
🤖
AI Co-Pilot
Ask anything about DPDP compliance in Hindi, Telugu, Tamil or English. Get instant answers with legal citations and actionable next steps.
Trained on DPDP Act 2023 + Rules 2025
4 Indian languages supported
Legal citations with every answer
Generate documents instantly
🗺️
Data Audit
AI scans your databases, APIs and cloud storage to discover personal data. Auto-generates RoPA and maps data flows to processors.
Auto data discovery across all sources
RoPA generator (Record of Processing)
Data flow mapping with risk scoring
Children's data (§9) detection
✅
Consent Manager
Manage all consent purposes under DPDP Act §3-7. 7-year immutable ledger, multi-language notices, and real-time withdrawal tracking.
DPDP §3-7 compliant consent flows
7-year immutable audit trail
Multi-language consent notices
Real-time withdrawal tracking
🚨
Breach Response
72-hour DPB notification engine. AI drafts breach notifications, tracks deadlines, and guides you step-by-step through the response process.
72-hour countdown timer
AI-drafted DPB notifications
Step-by-step response checklist
Penalty calculator per violation
🏪
Vendor Management
Track every third-party data processor. Auto-generate DPAs, monitor cross-border transfers, and audit vendor compliance continuously.
Data processor registry
Auto-generated DPA templates
Cross-border transfer tracking (§16)
Vendor risk scoring & audit trail
📱
WhatsApp Bot
Get compliance alerts, breach notifications and AI Q&A directly on WhatsApp — in Hindi, Telugu, Tamil and English.
Breach alerts + 72hr countdown
AI Q&A in 4 languages
Deadline reminders
Score change notifications
⚡ How It Works
DPDP compliance in 5 simple steps.
DPDPSaathi takes your business from zero to fully compliant — no legal team required.
🔍
Step 1: Scan Your Website
Enter your website URL. DPDPSaathi checks your privacy policy, cookies, consent banners, trackers, and security headers — gives you a DPDP compliance score in seconds.
📝
Step 2: Analyze Your Privacy Policy
Upload your privacy policy or enter its URL. The system checks it against all 12 DPDP Act requirements and tells you exactly what's missing with fix recommendations.
🛡️
Step 3: Run a DPIA
Answer a simple 7-module questionnaire about your data processing. DPDPSaathi calculates your risk score and determines if a full Data Protection Impact Assessment is required.
✅
Step 4: Set Up Compliance
Manage consent, register vendors, set retention policies, appoint a grievance officer, and prepare breach response plans — all from one dashboard.
📊
Step 5: Monitor & Maintain
Track your compliance score in real-time, get deadline reminders, maintain a 7-year audit trail, and re-scan periodically to stay ahead of regulators.
📄
Auto-Generate Documents
One-click generation of DPDP-compliant privacy policy, DPAs, breach notices, grievance officer letters, consent notices, and retention schedules.
🏢 About DPDPSaathi
Born in India. Built for DPDP compliance.
DPDPSaathi was built because Indian businesses deserve an AI-native compliance tool that speaks their language and understands Indian regulation.
Our story
Privaxa Technologies was founded in 2026 by a team of engineers, security researchers, and compliance experts who had spent the better part of a decade watching Indian businesses struggle with two unfair choices: buy expensive Western tools that don't understand DPDP, RBI, or Hindi — or cobble together open-source and pray nothing breaks.
We started with DPDPSaathi — India's most comprehensive DPDP compliance automation platform. Today, we serve clients across Canada, Germany, Australia, India and the USA, helping enterprises navigate data protection regulations with confidence and ease.
One product, one mission: make DPDP compliance simple, affordable, and automated for every Indian business. From website scanning to DPIA assessments, from consent management to breach response — DPDPSaathi covers it all.
Our values
🛡Trust by defaultSecurity and compliance baked in from line one — never bolted on later.
🇮🇳India-first contextBuilt for Hindi, Telugu, Tamil, INR pricing, Indian regulators, Indian devices.
⚡Ship weeklySmall batches, fast feedback, no quarterly waterfall theatre.
🤝Customer firstDirect access to our team. Reach us at info@privaxa.in or +91 7997700218.
Our mission
Engineer the trust infrastructure for India's next 100 million businesses going digital.
Our vision
A world where trust is verifiable, not assumed — for every human, every agent, every transaction.
📊 Privaxa Technologies by the numbers
2026
Founded
1
Product: DPDPSaathi
5+
Countries served
2
Founders
AK
Akshay KumarFounder & CEO
Worked with MeitY drafting DPDP policies. Expertise in DPDP Act compliance, ISO 27001, ISO 27701, SOC operations, dark web monitoring, threat intelligence, and VAPT — building Privaxa to protect every Indian enterprise.
AK
AkheelCo-founder & CTO
Technology strategist specialising in networking, AI/ML, and cloud platforms powering Privaxa's product suite — architecting India's most advanced cyber defence infrastructure.
💼 Careers
Join Privaxa Technologies
We're not actively hiring at the moment, but we're always looking for talented people who are passionate about data privacy and cybersecurity.
📬
If you want to know about any current or upcoming openings, reach out to us at:
Completed 3 days ago · Available in Hindi and Telugu
Done
Section-wise Score
Consent Management (§3-7)85%
Principal Rights (§11-14)78%
Data Security (§8)62%
Breach Notification (§8, Rule)40%
Data Retention (§8(7))55%
Compliance Timeline
✓
Aug 2023
Act passed
✓
Nov 2025
Rules notified
⚡
Now
Board active
!
May 2027
Full penalties
🔴 Live Compliance Feed
Real-time activity across Indian businesses
Live
BharatPay just completed a full audit · score 88
12s ago
Vyapar Cloud generated DPB breach notification
47s ago
Krishi Connect upgraded to Pro plan
2m ago
Namma EduTech onboarded 240 consent records
4m ago
Desi Mart resolved 3 principal rights requests
7m ago
🧠 AI PREDICTION · BETA
Next 30-day Breach Risk Forecast
Customers table SQL injection
78%
3rd-party processor leak (Mailchimp)
54%
Unauthorised admin access
32%
Lost device · employee laptop
15%
Trained on 12,400 incidents across Indian businesses
Conversations
📋
DPDP Compliance Help
What are my critical gaps?
Now
🚨
Breach Response Guide
Step-by-step DPB filing
2h
✅
Consent Notice Review
Is my privacy policy OK?
1d
⚖️
Penalty Assessment
What's my max fine?
2d
🤖
Saathi — Your DPDP AI Co-Pilot
Online · Trained on DPDP Act 2023 + Rules 2025
Hindi ✓Telugu ✓Tamil ✓
🤖
नमस्ते! I'm Saathi, your DPDP compliance expert. 🙏Trained on DPDP Act 2023, Rules 2025, and sector regulations (RBI, IRDAI, SEBI). Ask me in Hindi, Telugu, Tamil, or English.
Your company Your Company has score 70/100 with 3 critical gaps.
⚡ Top 3 Critical Gaps
🔴
No Breach Response Plan — 72-hr DPB notification mandatory
🔴
Unencrypted PII — 12,400 customer records
🔴
No Grievance Officer — Section 13 requires one
What's my penalty exposure?How to fix encryption gap?मेरी कंपनी को क्या करना है?Generate Grievance Officer letter
Saathi · Just now
Enter to send · Shift+Enter newline
📊 Live Company Context
Score—
Critical tasks—
Vendors—
Open grievances—
Rights requests—
Active breachYes ⚠️
📄 Generate Documents
⚡ Quick Ask
📚 Legal References
📋
§3-7 — Consent & Notice
Grounds, manner, withdrawal
📋
§8 — Security & Breach
Safeguards, 72hr notification
📋
§9 — Children's Data
Parental consent, no profiling
📋
§11-14 — Principal Rights
Access, correct, erase, nominate
📋
§15 — SDF Obligations
DPO, DPIA, audits
📋
§16 — Cross-Border
Notified countries, SCCs
📋
§17 — Exemptions
Govt, security, research
📋
Schedule — Penalties
₹10 Cr to ₹250 Cr
🗺️ Data Audit
AI Data Discovery
AI scanned 3 connected data sources. Last scan: 2 hours ago.
⚠️
3
High-risk categories
📊
47,230
Personal data records
🤝
6
Third-party processors
🌍
2
Cross-border transfers
Personal Data Inventory
💳
Financial Data
Bank accounts · PAN · Transactions
8,430High Risk
🪪
Identity Data
Aadhaar · Mobile · Email
12,100High Risk
👤
Contact & Profile Data
Names · Addresses · DOB
26,700Medium
📊
Behavioral Data
Page views · Purchase history
~890KLow Risk
🧒
Children's Data (§9)
Age under 18 · Parental consent required
340Special
Data Flow Map
🏢 Your Company
Primary Data Fiduciary
↓ shares data with ↓
💳 Razorpay
Payment processing
DPA ✓
📧 Mailchimp
Email marketing
DPA Missing
☎️ Freshdesk
Customer support
DPA ✓
📊 Google Analytics
Web analytics
No Consent
✅ Consent
Consent Management
Manage all consent purposes under DPDP Act §3-7. 7-year immutable ledger enforced.
✅
▲ 8%
44,108
Active consents
🔄
2,841
Pending re-consent
✗
281
Withdrawn this month
🌐
4
Languages active
Consent Purposes
Purpose of ProcessingData CategoryStatusLanguagesRecordsActive
Account Registration
§4 — Creating accounts
Identity✓ CompliantHI·TE·EN12,430
Payment Processing
§4 — Transactions
Financial✓ CompliantHI·EN8,430
Marketing Emails
§6 — Promotional
Contact⚠️ Needs UpdateEN only26,700
Analytics (Google)
§4 — Web tracking
Behavioral✗ Non-CompliantEN only—
🚨 Breach
Breach Response Center
Active breach detected. 72-hour DPB notification window is running now.
ACTIVE BREACH — DPB Notification Deadline
47:22:08remaining
DPDP Rules 2025 — ALL breaches must be reported
Records affected
3,240
Data types
Names, Email, Phone
Financial data?
No ✓
Aadhaar data?
No ✓
AI Response Checklist
✓
Breach Detected & Contained
Today 09:14 AM · Database access blocked
Done
2
Identify Scope of Breach
AI scanning · 3,240 records identified
In Progress
3
Draft DPB Notification
AI will generate DPDP-compliant notice
4
Notify Affected Data Principals
3,240 users via email + WhatsApp
Pending
5
Submit to DPB Portal
File before 72-hour deadline
Pending
6
Post-Incident Review
DPDP §8 — maintain incident records
Pending
Penalty if Not Reported
Breach notification failure (§8)Up to ₹200 Cr
Failure to notify data principalsUp to ₹200 Cr
If all steps completed on time₹0
✓ Completing all 6 steps within 72 hours = full compliance, zero penalty risk
👤 Rights
Data Principal Rights
Manage rights requests under DPDP Act §11-14 — access, correction, erasure, nomination.
⏳
8
Pending requests
✅
34
Completed (30d)
⏱️
18h
Avg response time
⚠️
1
Overdue (72h SLA)
Rights Requests Queue
Data Principal
Request Type
Submitted
Status
Action
Priya Sharma
priya.sharma@gmail.com
§12 — Erasure
3 days (OVERDUE)
⚠️ Overdue
Rahul Mehta
§11 — Access
1 day ago
In Review
Ananya Krishnan
§12 — Correction
2 days ago
Pending
⚖️ Penalty
Penalty Risk Calculator
Know your exact DPDP financial exposure. Mapped to Schedule penalties up to ₹250 Crore.
Assess Your Risk
Estimated Maximum Penalty Exposure
₹85 Crore
Complete all critical tasks to reduce this to ₹0
DPDP Schedule — Penalty Map
Violation
Section
Max Penalty
Your Status
Breach notification failure
§8, Rule 7
₹200 Cr
Active ⚠️
Security safeguard failure
§8
₹250 Cr
Risk
Consent notice violation
§5-7
₹50 Cr
Risk
Rights request failure
§11-13
₹10 Cr
1 Overdue
Children's data violation
§9
₹200 Cr
Risk
📄 Documents
AI Document Generator
Generate DPDP-compliant legal documents in seconds. All updated for DPDP Rules 2025.
🔐
Privacy Policy (DPDP)
Comprehensive policy in 22 Indian languages. Covers all DPDP Act requirements.
HI·TE·TA+19
🤝
Data Processing Agreement
DPA template for all third-party processors with DPDP obligations.
English · Hindi
👤
Grievance Officer Appointment
Section 13 compliant appointment letter and website disclosure template.
English · Hindi
🚨
Breach Notification (DPB)
AI-drafted breach notification in DPB-required format. All mandatory fields.
English (Official)
📊
RoPA — Processing Register
Record of Processing Activities auto-generated from your data audit.
PDF · Excel · JSON
🏢
Board Compliance Report
Executive-level report for Board meetings. Score, risks, roadmap.
English
📈 Reports
Compliance Reports
Download, schedule and share reports for auditors, investors and board meetings.
Available Reports
📊
DPDP Compliance Score Report — March 2026
Full assessment · Score: 70/100 · 3 critical gaps
Amber
🚨
Breach Incident Report — Active Breach #2026-001
3,240 records · DPB notification draft · Timeline documentation
Urgent
🗺️
Data Inventory & RoPA — Q1 2026
47,230 records · 6 processors · 2 cross-border transfers
Ready
✅
Consent Compliance Report — February 2026
44,108 active consents · 281 withdrawals · 98.7% compliant
Complete
💰 Investor
Investor Dashboard
Live metrics, traction and competitive moat for investor pitches. Confidential.
Investor View · Confidential
DPDPSaathi — Investment Overview
India's only AI-native DPDP compliance platform. ₹18,000 Crore TAM · 63M SMBs · May 2027 enforcement creates non-negotiable buying urgency.
Stage
Pre-Seed
Raising
₹2.5 Crore
Valuation
₹15 Crore
Deadline Catalyst
May 13, 2027 🔥
Monthly Recurring Revenue
₹4.8L
▲ 34% MoM
Target: ₹50L MRR by Dec 2026
Paying Customers
142
▲ 28 this month
Avg ₹3,380/month per customer
Churn Rate
1.8%
Industry avg: 8–12%
Best-in-class for SMB SaaS
Gross Margin
84%
AI-native = high margin
No human consultants needed
Customer Acq. Cost
₹1,200
↓ via CA channel
CA firms bring 20 clients each
LTV / CAC Ratio
14x
World-class ratio
LTV: ₹16,800 · CAC: ₹1,200
Net Revenue Retention
118%
▲ Expansion revenue
Upsell as DPDP evolves
Runway (Post-Raise)
24 mo
Series A: Q3 2027
Burn: ₹8L/mo post-raise
Market Opportunity
TAM — Total Addressable Market
₹18,000 Crore
All 63M Indian businesses handling personal data
SAM — Serviceable Market
₹2,400 Crore
SMBs with digital operations (8M businesses)
SOM — 3-Year Target
₹120 Crore
100,000 SMBs at ₹999+/month
Competitive Moat
🇮🇳
India-First + Vernacular
Only DPDP tool in Hindi, Telugu, Tamil — competitors are English-only
🤖
AI trained on Indian law
Fine-tuned on DPDP Act + RBI/IRDAI/SEBI — data moat no one can replicate fast
📱
WhatsApp-native distribution
500M WhatsApp users in India — we go where SMBs already are
🏢
CA firm channel (unfair advantage)
18 CA firms → 360 built-in customers. Zero cold calls.
⏰
Deadline-driven urgency
May 2027 enforcement = non-negotiable buying deadline. Unique market catalyst.
Investment Roadmap
MVP Live + 142 Paying Customers
AI chat, breach response, consent manager, WhatsApp bot
Estimate penalty savings, time saved and total return on investment.
Your Business Inputs
Estimated 1-year savings
₹0
vs DPDPSaathi Pro at ₹11,988 / year
Penalty avoided
₹0
Lawyer fees saved
₹0
ROI multiplier
0×
Payback period
0 days
💡 Calculations assume 65% reduction in compliance hours, 90% reduction in breach incidents, and average DPDP penalty of ₹85 Cr per breach (Source: MeitY 2025 estimates).
🏆 Leaderboard
India DPDP Compliance Leaderboard
Top performers across sectors — updated daily. Climb the ranks and earn investor-ready badges.
🏆
#42
Your rank (Fintech)
📈
+8
Climbed this week
🎯
12
Points to top 30
🥇
320
Companies competing
Top Performers · Fintech Sector
1
BP
BharatPay
Mumbai · Series B
98
2
VC
Vyapar Cloud
Bangalore · Series A
95
3
PB
PaisaBazaar
Delhi · Public
93
4
FM
FinMantra
Pune · Seed
91
5
QR
QuickRemit
Hyderabad · Series A
89
42
RT
Your Company (You)
India
70
⚔️ Comparison
Why DPDPSaathi vs the rest?
India-first features that global compliance tools simply don't offer.
Feature
DPDPSaathi
OneTrust
TrustArc
In-house
DPDP Act 2023 + Rules 2025 native
✓
✕
✕
✕
Hindi / Telugu / Tamil AI
✓
✕
✕
✕
Data hosted in India (Mumbai)
✓
✕
✕
Maybe
RBI / IRDAI / SEBI overlays
✓
✕
✕
✕
WhatsApp compliance bot
✓
✕
✕
✕
72-hour breach response engine
✓
✓
✓
✕
CA firm white-label portal
✓
✕
✕
✕
Starting price (per month)
Contact us
$2,500+
$1,800+
₹50,000+
Setup time
15 minutes
3-6 months
2-4 months
6-12 months
🏪 Vendor Management
Data Processor Vendors
Track every third-party that handles Your Company personal data · DPA, risk, audits · Admin Panel
🏪
14 active
14
Total vendors
📝
▲ 79%
11/14
DPAs signed
⚠️
Action needed
2
Critical-risk vendors
🌐
§16 DPDP
4
Cross-border processors
Vendor Registry
All data processors with access to Your Company personal data
Vendor
Category
Data Shared
Region
DPA
Risk
Last Audit
Actions
Razorpay
Payments
UPI ID, name, phone
India
✓ Signed
Low
12 days ago
Mailchimp
Email marketing
Email, name
US (cross-border)
✗ Missing
Critical
Never
AWS Mumbai
Cloud hosting
All PII (encrypted)
India
✓ Signed
Low
4 days ago
Twilio
SMS / OTP
Phone
US (cross-border)
⚠ Expired
High
92 days ago
Google Analytics 4
Analytics
Device IDs, IP
US (cross-border)
⚠ Pending
Medium
31 days ago
Freshdesk
Support tickets
Email, name, ticket body
India
✓ Signed
Low
18 days ago
WhatsApp Business
Customer comms
Phone, name
India
✓ Signed
Low
9 days ago
Zoho CRM
CRM
Name, email, phone
India
✓ Signed
Low
22 days ago
Segment
Customer data platform
Email, events
US (cross-border)
✓ Signed
Medium
27 days ago
Karix SMS
Transactional SMS
Phone
India
✓ Signed
Medium
40 days ago
Risk Distribution
14 vendors
Critical2
High1
Medium3
Low8
Admin Quick Actions
Admin · Your Company
Admin
Recent Vendor Activity
🔴 Mailchimp — DPA missing flagged by audit · 2h ago
🟠 Twilio — DPA expired, renewal request sent · 1d ago
🟢 Razorpay — Quarterly audit passed · 12d ago
🟢 AWS Mumbai — Encryption verified · 4d ago
🧒 Children's Data
Children's Data Management (§9)
DPDP Act §9 prohibits tracking, profiling and targeted advertising for children under 18. Verifiable parental consent is mandatory.
🧒
Special
340
Children's records found
✅
218
Parental consent verified
⏳
87
Pending parental consent
🚫
35
Non-compliant (no consent)
§9 Compliance Checklist
All obligations for processing children's data
4/7 Done
✓
Age verification mechanism deployed
Date-of-birth gate on registration form · under 18 flagged automatically
GA4 and analytics cookies disabled for under-18 users
Done
✓
No targeted ads to children
Ad network pixel removed for flagged accounts
Done
!
Collect parental consent for 87 pending records
§9(1) — Verifiable parental consent mandatory before processing
Critical
!
Delete 35 non-compliant records
§9 — Cannot process without parental consent. Must delete or obtain consent.
Critical
~
Document children's data handling policy
Internal policy for staff on how children's data is treated differently
Medium
Children's Records by Source
🗄️
MySQL — users table
DOB field indicates age < 18
284High Risk
☎️
Freshdesk — support tickets
AI detected minor-related tickets
38Medium
📧
Mailchimp — email subscribers
No age verification on signup
18No Consent
§9 Key Rules:
• No profiling or behavioural monitoring of children
• No targeted advertising directed at children
• Verifiable parental consent before ANY processing
• Higher penalties: up to ₹200 Crore for violations
• Exemptions: educational institutions (with safeguards)
📬 Grievance Portal
Grievance Redressal Portal (§13)
DPDP Act §13 requires a published Grievance Officer. All grievances must be acknowledged within 48 hours and resolved within 30 days.
📬
Open
4
Open grievances
✅
▲ 6 this month
28
Resolved (all time)
⏱️
4.2d
Avg resolution time
📊
0%
SLA Breach %
Grievance Queue
SLA: 48h acknowledgement · 30d resolution
ID
Data Principal
Category
Filed
SLA Status
Status
Action
#G-031
Vikram Desai
vikram.d@gmail.com
Data Erasure
26 days ago
⚠️ 4d left
In Progress
#G-030
Meena Iyer
meena.i@yahoo.com
Data Access
5 days ago
On Track
In Progress
#G-029
Amit Patel
amit.p@hotmail.com
Correction
3 days ago
On Track
Acknowledged
#G-028
Sunita Rao
sunita.rao@gmail.com
Consent Withdrawal
1 day ago
On Track
New
Grievance Officer Details
AP
Your Grievance Officer — Grievance Officer
info@privaxa.in · +91 7997700218
Published on: Website footer, Privacy Policy, App settings Hours: Mon–Fri, 9 AM – 6 PM IST Response SLA: 48h acknowledgement, 30d resolution Escalation: If unresolved → Data Protection Board appeal
Resolution Stats
Data Erasure Requests92% resolved <30d
Data Access Requests100% resolved <30d
Correction Requests96% resolved <30d
Consent Withdrawal88% resolved <30d
🗑️ Retention
Data Retention Management
DPDP §8(7) — Personal data must be erased when consent is withdrawn or purpose is fulfilled. Auto-delete schedules enforced.
📋
6
Retention policies active
✅
▲ 2,400
12.4K
Records auto-deleted (YTD)
⏳
3,200
Due for deletion (30d)
⚠️
840
Overdue deletions
Retention Policies
Data Category
Retention Period
Legal Basis
Auto-Delete
Records
Next Purge
Status
Transaction Records
7 years
§8(7) + IT Act
8,430
Jan 2032
Compliant
Marketing Consent
Until withdrawn
§6 — Consent based
26,700
On withdrawal
Compliant
Support Tickets
2 years
§8(7) — Purpose fulfilled
4,100
Apr 2028
Compliant
Inactive User Profiles
1 year post-inactivity
§8(7) — Purpose ceased
840
Overdue
⚠️ Action
Analytics Data
6 months
§4 — Aggregated only
~890K
Jun 2026
Compliant
Consent Proof Ledger
7 years (immutable)
§7 — Proof of consent
44,108
Never (audit trail)
Protected
🌍 Cross-Border
Cross-Border Data Transfers (§16)
DPDP §16 — Transfer of personal data outside India only to countries/territories notified by Central Government. Standard Contractual Clauses required.
🌍
4
Cross-border processors
📝
2
SCCs signed
⚠️
2
SCCs missing
🏛️
1
Restricted jurisdiction
International Data Transfer Registry
All vendors processing Your Company data outside India
Vendor
Country
Data Shared
Transfer Mechanism
SCC
Risk
Action
Mailchimp
🇺🇸 USA
Email, name
Standard Contractual Clauses
✗ Missing
Critical
Twilio
🇺🇸 USA
Phone numbers
Standard Contractual Clauses
⚠ Expired
High
Google Analytics 4
🇺🇸 USA
Device IDs, IP
DPA + Model Clauses
✓ Signed
Medium
Segment
🇺🇸 USA
Email, events
Standard Contractual Clauses
✓ Signed
Medium
§16 Transfer Impact Assessment
DPDP §16 Rules:
• Transfer only to countries/territories notified by Central Government
• Standard Contractual Clauses (SCCs) mandatory for each transfer
• Data localization: certain categories must stay in India (per sector rules)
• RBI data: payment data must be stored in India (RBI circular 2018)
• IRDAI data: policyholder data Indian servers preferred
• Penalty for non-compliance: up to ₹250 Crore
🏛️ SDF Toolkit
Significant Data Fiduciary Toolkit (§15)
If your entity is classified as SDF by Central Government, additional obligations apply — DPO appointment, DPIA, periodic audits, and transparency reports.
🏛️
SDF
Classification status
👤
✓
DPO appointed
📋
1
DPIA pending
📊
Due
Annual audit
SDF Compliance Obligations
§15 — Additional duties for Significant Data Fiduciaries
5/8 Done
✓
Appoint Data Protection Officer (DPO)
§15(2) — DPO must be India-based, senior management, Board-reported
Done
✓
DPO registered with Data Protection Board
DPO details submitted to DPB portal
Done
✓
Published DPO contact on website
Privacy Policy, website footer, and app settings updated
Done
✓
Data protection framework document
Comprehensive internal data protection policy adopted
§15(3) — DPIA mandatory for high-risk processing activities
Critical
!
Commission independent annual audit
§15(4) — Periodic audit by independent data auditor, report to DPB
Critical
~
Publish annual transparency report
Public report on data requests, breaches, and compliance measures
In Progress
DPO Profile
RK
Your DPO — Data Protection Officer
info@privaxa.in · Reports to Board of Directors
Registered with DPB: Yes (Reg #DPO-2026-04821) India-based: Hyderabad, Telangana Board reporting: Quarterly DPO report to Board
SDF Criteria (§15)
You may be classified as SDF if:
• Volume/sensitivity of personal data processed is high
• Risk to rights of data principals is significant
• Impact on sovereignty, security, or public order
• Revenue exceeds thresholds set by Central Government
⚠️ Note: Central Government has not yet published final SDF criteria. Monitor DPB notifications.
📋 DPIA
Data Protection Impact Assessment
§15(3) — SDFs must conduct DPIA before high-risk processing. AI-assisted assessment with risk scoring and mitigation tracking.
✅
2
DPIAs completed
📋
1
DPIA in progress
⚠️
1
DPIA overdue
📊
14
Risks identified
Impact Assessments
Assessment
Processing Activity
Risk Level
Risks Found
Mitigated
Status
Date
DPIA-001
Customer onboarding (KYC + Aadhaar)
High
6
6/6
✓ Complete
Jan 2026
DPIA-002
Marketing email automation
Medium
4
4/4
✓ Complete
Feb 2026
DPIA-003
AI-based fraud detection model
High
3
1/3
In Progress
Mar 2026
DPIA-004
Cross-border analytics (GA4 + Segment)
High
—
—
⚠️ Overdue
Due: Apr 2026
🔍 Website Scanner
Website DPDP Compliance Scanner
Enter any URL to scan for DPDP compliance — checks privacy policy, cookie consent, third-party trackers, data collection, security headers, and cross-border transfers.
Scan a Website
Scanning website...
🎯
—
Overall DPDP Score
⚠️
0
Critical Issues
🔔
0
Warnings
✅
0
Passed Checks
Category Scores
Scan Summary
Detailed Findings
Category
Check
Status
Severity
Details
DPDP Section
Cookies Detected
Name
Category
Secure
HttpOnly
SameSite
Third-Party Trackers
Tracker
Category
Purpose
Scan History
URL
Score
Critical
Warnings
Date
Status
Action
📝 Policy Analyzer
Privacy Policy Compliance Analyzer
Upload a privacy policy (.docx) or enter a URL to check against DPDP Act requirements. Identifies missing sections with actionable recommendations.
Upload Privacy Policy
Analyze from URL
Analyzing privacy policy...
0
Overall Compliance Score
Analysis History
File / URL
Score
Sections Present
Sections Missing
Date
Action
🍪 Cookie Scanner
Cookie Compliance Scanner
Scan any website to discover cookies, categorize them, and check if proper consent mechanisms are in place under DPDP Act.
Scan Website Cookies
🍪
0
Total Cookies
🔒
0
Necessary
📊
0
Analytics
📢
0
Marketing
Cookie Consent Status
Cookie Categories Breakdown
All Cookies Found
Cookie Name
Domain
Category
Secure
HttpOnly
SameSite
Expires
🛡️ DPIA Advanced
DPIA Assessment (Multi-Module)
Comprehensive Data Protection Impact Assessment with guided questionnaire. Covers scale, children's data, AI/profiling, cross-border, sensitive data, security, and consent.
DPIA Dashboard
ID
Title
Created At
DPIA Required
Status
Actions
📋
7
Total Modules
✅
0
Completed
⚠️
0
Risk Score
🎯
—
Risk Level
🔐 Admin
Client Approval Management
New client registrations require admin approval before they can access the platform.
⏳
0
Pending Approval
✅
0
Approved Clients
❌
0
Rejected
Pending Registrations
These clients are waiting for your approval to access DPDPSaathi
Company
Name
Email
Phone
Industry
Registered
Actions
All Clients
Complete list of registered companies
Company
Name
Email
Phone
Status
Registered
Approved On
🏦 DPB
Data Protection Board Filings
Manage all interactions with the Data Protection Board of India — registrations, breach notifications, annual reports, and appeals.
🏦
✓
DPB registered
🚨
1
Active breach filing
📋
3
Filings submitted
✅
0
Penalties received
Filing History
All DPB submissions and responses
Filing ID
Type
Submitted
DPB Response
Status
Action
DPB-2026-003
Breach Notification
Today
Pending review
In Review
DPB-2026-002
DPO Registration
Feb 2026
Acknowledged — Reg #DPO-2026-04821
✓ Accepted
DPB-2026-001
Entity Registration
Jan 2026
Registered as Data Fiduciary
✓ Accepted
DPB Appeal Process
If you receive a DPB penalty order:
1. Appeal to TDSAT (Telecom Disputes Settlement & Appellate Tribunal) within 60 days
2. Appeal fee: As prescribed by TDSAT rules
3. Stay orders: TDSAT may grant interim stay on penalty
4. Further appeal: Supreme Court of India on questions of law
✅ Your Company has ZERO penalty orders. Keep compliance score above 85 to maintain clean record.
🏛️ Exemptions
Government Exemptions Tracker (§17)
DPDP §17 grants exemptions to certain government instrumentalities and for specified purposes. Track which exemptions apply to your data processing.
Applicable Exemptions
✓
§17(2)(a) — National Security
Central Govt may exempt processing in interest of sovereignty, integrity, security of State
Not Applicable
✓
§17(2)(b) — Public Order
Processing necessary for maintaining public order
Not Applicable
~
§17(2)(c) — Prevention of Offences
Fraud prevention data shared with law enforcement
Partial — 2 LE requests
✓
§17(3) — Research & Statistics
Anonymized/aggregated data for research purposes
Applied — Analytics
✓
§17(4) — Startups
Certain obligations relaxed for DPIIT-recognized startups (as notified)
DPIIT Recognized
~
§17(5) — Legal Proceedings
Processing for legal claims, seeking legal advice, or compliance
Active — 1 legal matter
Law Enforcement Requests
Total LE requests (YTD)2
Complied with2
Rejected (insufficient basis)0
Data principals notified0 (exempted)
📅 Calendar
Compliance Calendar & Deadlines
Never miss a DPDP deadline. Auto-tracked milestones, audit dates, renewal schedules and enforcement timelines.
Upcoming Deadlines
Sorted by urgency
🔴
Active Breach — DPB Filing Deadline
72-hour window · Must file before deadline
47 hours left
🔴
Priya Sharma Erasure Request — SLA Breach
Grievance #G-031 · 30-day SLA exceeded
4 days left
🟠
DPIA-004 — Cross-border Analytics Assessment
Overdue since Apr 2026 · Required before GA4 renewal
Overdue
🟡
Twilio DPA Renewal
Cross-border SCC expired · Must renew before continued data transfer
May 2026
🔵
Q2 2026 Compliance Report
Board presentation scheduled · DPO quarterly report due