Case study · Compliance platform
DPDPNow
India-focused DPDP privacy assessment platform.
- Industry
- Data protection and compliance
- Current status
- Beta — In private beta
- Focus areas
- Compliance & Privacy, AI Platforms, Product Strategy
- External links
- Not yet public
01 · Executive summary
In brief
DPDPNow turns India's Digital Personal Data Protection Act from a legal memo into assignable work. An assessment establishes which obligations apply, each becomes tracked work with an owner and evidence requirement, and an audit-ready pack can be produced in a single action.
02 · Business context
The business and its environment
Organisations subject to the DPDP Act hold legal interpretation in one place and operational reality in another. Counsel produces advice; operations keeps spreadsheets. Neither side can answer, on a given day, whether the organisation is ready.
03 · The challenge
The problem that existed
Organisations facing India's Digital Personal Data Protection Act had no practical way to assess exposure or evidence readiness. Obligations sat in legal memos while the work sat in spreadsheets, with no link between them.
04 · Product vision
Why the product was created
The product exists because compliance fails at the handover between legal interpretation and operational execution. Closing that gap — one register, one owner per obligation, evidence attached — is worth more than any maturity score.
05 · Solution
The platform and the approach
A structured assessment that produces an obligation register: each requirement becomes tracked work with an owner, evidence requirement and deadline, and leadership gets a current view of status and gaps.
06 · Architecture overview
Structural decisions
The decisions that were expensive to change later, and were therefore made first.
- Obligation model versioned separately from client data so regulatory updates propagate safely
- Assessment engine mapping answers to applicable obligations and required evidence
- Evidence store with immutable timestamps and reviewer attribution
- Tenant isolation enforced at the database policy level, not in application code alone
- Export pipeline producing an audit-ready pack in a single action
Architecture diagram to follow
07 · Key features
What the platform actually does
Listed as capabilities that change how work happens, not as a feature inventory.
Structured DPDP assessment
A guided assessment establishes which statutory obligations actually apply, rather than presenting the whole Act to every organisation.
Obligation register
Each applicable obligation becomes tracked work with an owner, an evidence requirement and a deadline.
Evidence store
Policies, notices and records are held with immutable timestamps and reviewer attribution, so evidence stands up when questioned.
Readiness view for leadership
A current position by obligation category, so leadership can see exposure without commissioning a report.
Versioned regulatory reference data
Obligations are versioned independently of client records, so a legal update propagates without a data migration.
One-action audit pack
Export produces the pack a regulator or auditor asks for, replacing weeks of manual assembly.
08 · Technology stack
What it runs on
Conventional choices, selected so a team other than the one that built it can run and extend it.
- Application
- TypeScript
- React
- Server-side rendering
- Data
- PostgreSQL
- Row-level security
- Versioned reference data
- Platform
- Managed Postgres, auth and storage
- AI
- Document classification and gap explanation via hosted models
09 · AI usage
Where AI adds value, and where it does not
Uploaded policies and notices are classified against obligations to propose which requirements they may satisfy, and gaps are explained in plain language. Every proposal requires human confirmation before it counts as evidence.
10 · Security and compliance
What was decided before the build
Included because these decisions are difficult and expensive to retrofit.
- Tenant isolation enforced by database row-level security, not application logic alone
- Evidence records are append-only, with reviewer attribution and immutable timestamps
- Data residency and retention decisions taken before build, given the subject matter
- Access to client evidence is logged and reviewable, including administrative access
11 · Current status
Where it stands today
Beta
In private beta with early organisations. The target measure is time from assessment start to a defensible evidence pack, replacing multi-week manual preparation.
12 · Lessons learned
What the work taught
Strategic rather than technical: the judgements that carry into the next engagement.
- Regulatory reference data must be versioned independently of client records, or every legal update becomes a migration.
- Compliance software is adopted when it reduces audit preparation, not when it scores maturity.
- AI is useful for triaging evidence and useless for asserting it; the confirmation step is the product.
Interface
Product views
Reserved for published screenshots. Alt text and captions are in place so the section is meaningful once images are added.
Image to follow
Image to follow
15 · Next evolution
What comes next, and why
Sequenced against business value rather than technical interest.
- Consent and notice lifecycle tracking, extending readiness into ongoing operation
- Data principal request handling with service levels and evidence of response
- Support for adjacent regimes so multi-jurisdiction organisations work from one register
The best products begin with the right questions.
Send the business context and the constraint you are working against. I will reply with a direct read on the approach I would take, and whether I am the right person for it.