Services

Data Protection Advisory, Scoped to Where You Are in the DPDP Journey

From first gap assessment to Board reporting after go-live, Mehta & Mehta advises on the DPDP Act, 2023 as a governance obligation, not a one-off IT project. Engage a single service or the full compliance lifecycle.

Find Your Starting Point

Which Service Fits Where You Are Today?

Most organisations enter at one of four points. Every path can be engaged on its own or carried through to the 13 May 2027 deadline and beyond.

Stage 01

"We haven't assessed our exposure yet"

Start with Readiness & Gap Assessment to establish whether you're a Fiduciary, Processor or both, and where the gaps sit.

View this service →
Stage 02

"We know the gaps, we need the paperwork and workflows built"

Move to Policy, Notice & Consent Architecture to convert findings into an audit-ready documentation suite.

View this service →
Stage 03

"We expect to be notified as a Significant Data Fiduciary"

Rule 13 brings added obligations — DPIA, independent audit and a Data Protection Officer. Plan for it early.

View this service →
Stage 04

"We're compliant — now it has to hold up"

Ongoing Compliance Retainership keeps notices, vendors and Board reporting current as processing evolves.

View this service →
Service types used on this page: Assessment Implementation Advisory Retainer
What We Do

Our Service Lines

Five services, each independently engageable. Every deliverable is prepared to withstand review by an Independent Data Auditor or the Board.

Service Line 01 Assessment

Readiness & Gap Assessment

A diagnostic review of current data-handling practice against the DPDP Act and the Rules, resulting in a risk-rated, Board-ready roadmap rather than a generic checklist.

  • Applicability & entity scoping (Fiduciary / Processor / SDF exposure)
  • Gap assessment mapped clause-by-clause to the Act and Rules
  • Risk-rated findings report with remediation priority
  • Board-approved roadmap with realistic sequencing to May 2027
Service Line 02 Implementation

Policy, Notice & Consent Architecture

Converts assessment findings into the actual notices, policies and consent flows your organisation runs on — drafted to be usable by product, legal and customer-facing teams alike.

  • Data mapping — personal data discovery and processing inventory, including the baseline RoPA
  • Data Principal-facing notices, in plain and itemised form
  • Consent architecture, including Consent Manager readiness
  • Internal data protection policy and standard operating procedures
  • Data Processor and vendor contract clauses (Section 8(2) alignment)
  • Rights-fulfilment and grievance-redressal workflow design
  • Personal data breach response playbook
Service Line 03 Advisory

Significant Data Fiduciary (SDF) Advisory

Rule 13 obligations for entities notified as Significant Data Fiduciaries under Section 10, including the annual assessments the Rules require.

  • Rule 13 obligation mapping and readiness review
  • Annual Data Protection Impact Assessment (DPIA)
  • Independent Data Auditor coordination and audit facilitation
  • Data Protection Officer (DPO) advisory and function set-up
  • Algorithmic and cross-border data-transfer risk review
  • Periodic compliance certification support
Service Line 04 Retainer

Ongoing Compliance Retainership

Compliance is a state to be sustained, not a project to be closed. A retainership keeps the programme current as products, vendors and guidance evolve.

  • Quarterly Board and Committee compliance reporting
  • Regulatory watch — Rules, MeitY guidance and Board circulars
  • Breach-readiness drills and incident response support
  • Annual compliance health check and re-assessment
  • Employee training and awareness programmes
  • On-call advisory for new products, features and vendors
Service Line 05 Advisory

Regulatory Overlay Advisory

For regulated entities, DPDP obligations rarely sit in isolation. We map them against existing sectoral requirements so controls don't conflict or duplicate.

  • DPDP mapping against RBI data-localisation and outsourcing norms
  • DPDP mapping against SEBI cybersecurity and data-governance circulars
  • DPDP mapping against IRDAI data protection guidelines
  • Single consolidated control matrix for internal and Board use
Capabilities

What Our Team Builds, Reviews and Runs

Practical capabilities that sit underneath each service line above. Every item is tagged with the service type it's delivered under.

Implementation

Data Mapping

Structured inventory of personal data across systems, vendors and business functions, including the Record of Processing Activities (RoPA) that sits under it.

Assessment

Clause-Wise Gap Analysis

Line-by-line comparison of current practice against the Act and Rules, rated by regulatory and reputational risk.

Implementation

Notice & Consent Drafting

Plain-language and itemised notices, and consent flows designed to be genuinely free, specific and informed.

Implementation

Vendor & Processor Contracts

Section 8(2)-aligned clauses for Data Processor agreements, since liability stays with the Fiduciary regardless of contract terms.

Implementation

Rights & Grievance Workflows

Operational design for access, correction, erasure and grievance requests, with defined turnaround times.

Implementation

Breach Response Playbooks

Escalation paths, notification templates and Board-reporting triggers for personal data breach events.

Advisory

DPIA Facilitation

Structured Data Protection Impact Assessments for Significant Data Fiduciaries and high-risk processing activities.

Advisory

Independent Audit Coordination

Preparing evidence trails and liaising with Independent Data Auditors ahead of Rule 13 audit cycles.

Advisory

Sectoral Overlay Mapping

Reconciling DPDP obligations with RBI, SEBI and IRDAI requirements into one control matrix.

Retainer

Board & Committee Reporting

Periodic compliance status reporting in the form Boards and Audit Committees expect to see.

Retainer

Regulatory Watch

Ongoing tracking of Rules, MeitY guidance and Data Protection Board orders, translated into action items.

Retainer

Training & Awareness

Role-based training for product, engineering, HR and customer-facing teams on data-handling obligations.

Why Mehta & Mehta

How These Services Are Delivered

Governance-first

Every service is framed as a Board obligation, consistent with our practice as Company Secretaries and Chartered Accountants.

Senior Partner-led

One Senior Partner owns each engagement end to end, backed by a team of 150-plus professionals.

Audit-ready by default

Deliverables are built to withstand review by an Independent Data Auditor or the Board — not just to pass internally.

Modular engagement

Take a single service line or the full lifecycle. Nothing here requires committing to more than you need today.

Not Sure Which Service Line Applies to You?

Most engagements begin with a short conversation, not a proposal. Tell us where you are and we'll point to the right starting service.