Case study · Compliance platform

DPDPNow

India-focused DPDP privacy assessment platform.

Industry
Data protection and compliance
Current status
Beta — In private beta
Focus areas
Compliance & Privacy, AI Platforms, Product Strategy
External links
Not yet public

01 · Executive summary

In brief

DPDPNow turns India's Digital Personal Data Protection Act from a legal memo into assignable work. An assessment establishes which obligations apply, each becomes tracked work with an owner and evidence requirement, and an audit-ready pack can be produced in a single action.

02 · Business context

The business and its environment

Organisations subject to the DPDP Act hold legal interpretation in one place and operational reality in another. Counsel produces advice; operations keeps spreadsheets. Neither side can answer, on a given day, whether the organisation is ready.

03 · The challenge

The problem that existed

Organisations facing India's Digital Personal Data Protection Act had no practical way to assess exposure or evidence readiness. Obligations sat in legal memos while the work sat in spreadsheets, with no link between them.

04 · Product vision

Why the product was created

The product exists because compliance fails at the handover between legal interpretation and operational execution. Closing that gap — one register, one owner per obligation, evidence attached — is worth more than any maturity score.

05 · Solution

The platform and the approach

A structured assessment that produces an obligation register: each requirement becomes tracked work with an owner, evidence requirement and deadline, and leadership gets a current view of status and gaps.

06 · Architecture overview

Structural decisions

The decisions that were expensive to change later, and were therefore made first.

  • Obligation model versioned separately from client data so regulatory updates propagate safely
  • Assessment engine mapping answers to applicable obligations and required evidence
  • Evidence store with immutable timestamps and reviewer attribution
  • Tenant isolation enforced at the database policy level, not in application code alone
  • Export pipeline producing an audit-ready pack in a single action
Architecture diagram reserved. It shows the obligation model versioned away from client data, the assessment engine that maps answers to obligations, and the evidence store feeding the export pipeline.

07 · Key features

What the platform actually does

Listed as capabilities that change how work happens, not as a feature inventory.

Structured DPDP assessment

A guided assessment establishes which statutory obligations actually apply, rather than presenting the whole Act to every organisation.

Obligation register

Each applicable obligation becomes tracked work with an owner, an evidence requirement and a deadline.

Evidence store

Policies, notices and records are held with immutable timestamps and reviewer attribution, so evidence stands up when questioned.

Readiness view for leadership

A current position by obligation category, so leadership can see exposure without commissioning a report.

Versioned regulatory reference data

Obligations are versioned independently of client records, so a legal update propagates without a data migration.

One-action audit pack

Export produces the pack a regulator or auditor asks for, replacing weeks of manual assembly.

08 · Technology stack

What it runs on

Conventional choices, selected so a team other than the one that built it can run and extend it.

Application
  • TypeScript
  • React
  • Server-side rendering
Data
  • PostgreSQL
  • Row-level security
  • Versioned reference data
Platform
  • Managed Postgres, auth and storage
AI
  • Document classification and gap explanation via hosted models

09 · AI usage

Where AI adds value, and where it does not

Uploaded policies and notices are classified against obligations to propose which requirements they may satisfy, and gaps are explained in plain language. Every proposal requires human confirmation before it counts as evidence.

10 · Security and compliance

What was decided before the build

Included because these decisions are difficult and expensive to retrofit.

  • Tenant isolation enforced by database row-level security, not application logic alone
  • Evidence records are append-only, with reviewer attribution and immutable timestamps
  • Data residency and retention decisions taken before build, given the subject matter
  • Access to client evidence is logged and reviewable, including administrative access

11 · Current status

Where it stands today

Beta

In private beta with early organisations. The target measure is time from assessment start to a defensible evidence pack, replacing multi-week manual preparation.

12 · Lessons learned

What the work taught

Strategic rather than technical: the judgements that carry into the next engagement.

  • Regulatory reference data must be versioned independently of client records, or every legal update becomes a migration.
  • Compliance software is adopted when it reduces audit preparation, not when it scores maturity.
  • AI is useful for triaging evidence and useless for asserting it; the confirmation step is the product.

Interface

Product views

Reserved for published screenshots. Alt text and captions are in place so the section is meaningful once images are added.

Obligation register: owner, evidence status and deadline per requirement.
Readiness summary with open gaps grouped by obligation category.

15 · Next evolution

What comes next, and why

Sequenced against business value rather than technical interest.

  1. Consent and notice lifecycle tracking, extending readiness into ongoing operation
  2. Data principal request handling with service levels and evidence of response
  3. Support for adjacent regimes so multi-jurisdiction organisations work from one register

The best products begin with the right questions.

Send the business context and the constraint you are working against. I will reply with a direct read on the approach I would take, and whether I am the right person for it.