Security visibility for your organization —every dimension, one picture.

Helping organizations manage cyber risk, compliance, cloud, data, and operational resilience—before risk becomes business impact.

Ensure Compliance. Accelerate Growth.

Connect

Unify people, process, and technology across your security program.

Secure

See risk and control posture across every dimension of the organization.

Advance

Move from reactive compliance to continuous, leadership-ready GRC.

PrivyCore · Data privacy

India DPDP compliance platform for data privacy & governance

Consent · Data governance · RoPA · DSAR · DPIA · Breach readiness

PrivyCore helps Indian enterprises operationalize the Digital Personal Data Protection Act with one privacy command center — from consent and data mapping to grievance redressal, breach notification, and auditor-ready evidence.

India DPDP implementation roadmap

Three phases. Clear deadlines. One compliance journey.

The Digital Personal Data Protection Rules 2025 roll out in phases — not a single switch.PrivyCore helps you track each milestone and stay audit-ready before enforcement bites.

13 Nov 2025

Foundation phase

Completed

Act & Rules in force · Data Protection Board operational

Rules 1, 2, 17–21

  • Data Protection Board of India established
  • Definitions, enforcement machinery, and grievance redressal live
  • Breach-ready documentation and DPB escalation paths
  • Begin RoPA, governance charter, and gap assessment

PrivyCore focus

Program charter, DPDP gap assessment, and readiness baseline in PrivyCore.

You are here

13 Nov 2026

Consent infrastructure

In progress

Consent Managers registered · verifiable consent traceability

Rule 4 · Sec 6(9) · Sec 27(1)(d)

  • DPB-registered Consent Managers operational
  • Consent withdrawal parity — as easy as giving consent
  • Notice and consent logs ready for verification
  • Data mapping, RoPA reconciliation, and processor DPAs

PrivyCore focus

Consent center, notices, Auto-Discovery, and RoPA workflows in PrivyCore.

13 May 2027

Full compliance

Upcoming

Substantive obligations · penalty regime enforcement

Rules 3, 5–16, 22–23 · Sec 3–17

  • Lawful notice and verifiable consent at scale
  • Security safeguards, breach notification, and retention/erasure
  • Data principal rights — access, correction, erasure, grievance
  • SDF obligations: DPIA, independent audit, DPO accountability

PrivyCore focus

DSAR, grievance, breach, DPIA, and audit-ready evidence briefcase.

Based on the Digital Personal Data Protection Act, 2023 and DPDP Rules 2025 (GSR 843–845(E)), notified 13 November 2025. Timelines reflect MeitY's phased enforcement schedule — plan now; the runway to May 2027 closes faster than most teams expect.

DPDP affects every sector

Mandatory data privacy obligations across industries

Whether you process customer, employee, or vendor data, India DPDP requires lawful processing, clear notice, consent where applicable, data principal rights, and accountability — with significant penalties for non-compliance.

BFSI

Banks, NBFCs, fintech, and insurance — KYC, transactions, and customer records.

Healthcare & pharma

Hospitals, diagnostics, and healthtech — patient records, trials, and prescriptions.

Retail & e-commerce

Marketplaces and retail chains — customer profiles, orders, and loyalty data.

SaaS & technology

Product analytics, cloud apps, and multi-tenant personal data processing.

Why teams choose PrivyCore

Manage data privacy and governance in one place — with automation that reduces manual compliance work and keeps programs audit-ready.

Built for India DPDP

Capability centers mapped to the Digital Personal Data Protection Act — not generic GDPR checklists repackaged.

Always-on privacy operations

Move beyond annual spreadsheet exercises with continuous RoPA, discovery, and evidence.

Demonstrate compliance with confidence

Gap assessments, control catalogs, and audit-ready exports for regulators and leadership.

Integrated where it matters

Privacy program depth in PrivyCore; vendor risk on ComplAI TPRM; security GRC on ComplAI.

Our solutions

Five solutions. One security & privacy stack.

Propel Ready Solutions delivers ComplAI for GRC, PrivyCore for privacy, TPRM for third-party risk, ASM for attack surface management, and VAPT as a managed penetration testing service — integrated where it matters.

ComplAI

AI-powered GRC & compliance platform

Unified workspace for SOC 2, ISO 27001, multi-framework controls, policies, evidence, risk, intelligence, and leadership dashboards.

  • Multi-framework control catalog (SOC 2, ISO 27001, GDPR, DPDP, CSCRF)
  • Attack Surface Management — 20 modules, deep scan & 800+ exposure rules
  • Policy & ISMS templates with approval workflows
  • Evidence briefcase and auditor-ready exports

PrivyCore

India DPDP & data privacy platform

Dedicated privacy operations for consent, RoPA, discovery, DSAR, grievance, breach, and DPIA — mapped to India DPDP, GDPR, and ISO 27701.

  • India DPDP — consent, notices, grievance & breach workflows
  • RoPA, Auto-Discovery & data mapping across your stack
  • DSAR & data principal rights — request intake to fulfillment
  • DPDP readiness, gap assessment & DPIA automation

TPRM

Third-party risk on ComplAI

Continuous vendor risk — 0–950 ratings, live instant reports, industry baselines, framework questionnaires, remediation, and executive exports.

  • Vendor portfolio with tiering and 0–950 security ratings
  • Instant risk reports from live external scans
  • Industry baseline & sector percentile benchmarks
  • Framework questionnaires with AI autofill

ASM

Attack surface management on ComplAI

Outside-in ASM with 20 capability modules — eight core workspaces plus twelve solution modules for attack paths, threat exposure, compliance risk, and deep discovery scanning.

  • 20 modules — 8 core + 12 solution workspaces
  • Light scan (~2 min) and deep scan discovery campaigns
  • 800+ ASM rules with CVE/EPSS prioritization
  • Attack paths, threat exposure, secret & credential intel

VAPT

Managed penetration testing on ComplAI

Managed VAPT with seven-phase engagement workflow — client-side VA, manual pentest, live findings tracker, GRC-mapped reports, and retest close-out inside ComplAI Assurance.

  • Seven-phase workflow — scope through retest
  • Client-side VA at your network edge
  • Manual pentest — Burp Suite, Kali, business-logic testing
  • Live findings tracker with Jira / ServiceNow push

See the full DPDP roadmap above, or compare all five Propel Ready platforms below.

Ready to Strengthen Your Security Program?

Propel Ready Solutions combines cybersecurity expertise with GRC technology to help you secure your business, simplify compliance, and build resilience—at every stage of your growth.