Compliance support

DPDP Act readiness, the infrastructure half

In short: A large part of DPDP readiness is not legal drafting, it is being able to answer where personal data actually sits, who can reach it, and what would happen if it leaked. Those are infrastructure questions. We do that half: data-path mapping, access control, segmentation and logging. We do not provide legal advice on the Act.

The split that matters

DPDP readiness projects tend to be presented as a documentation exercise, and a meaningful part of one genuinely is: notices, consent, grievance handling, contracts with processors. That work belongs with your legal advisers and we do not do it.

But underneath the paperwork are questions that only the infrastructure can answer. Which systems hold personal data. Who can reach those systems, from where, and with what authentication. Whether you would know if data left. Whether an access log exists to show anyone. Those are engineering questions, and they are usually where the real gap is.

What we actually do

We are not a law firm and do not give legal advice. We do not draft privacy notices, interpret the Act's obligations for your business, or tell you whether you qualify as a Significant Data Fiduciary. Anyone selling you DPDP compliance as a single package that includes legal opinion is overreaching. Work with your legal advisers on the obligations; bring us in for the part that runs on hardware.

A realistic sequence

If you are starting from nothing, the order that produces the most defensible position for the least disruption is fairly consistent.

None of this requires a compliance product, and all of it survives whatever the final enforcement posture turns out to be.

What we will tell you not to buy

We would rather say this plainly than have you find out later. A data-discovery platform is rarely worth it at mid-market scale; the map can be built by talking to people who use the systems. A SIEM at this size generates alerts nobody has time to read, which is worse than no alerts because it manufactures a sense of coverage. And a consultancy engagement that bundles legal opinion with technical work is usually weak at both.

An honest position on timing

There is a lot of urgency being sold around this. Our view is more measured: the technical work worth doing for DPDP is almost entirely work that was worth doing anyway. Knowing where your data is, controlling who reaches it, and keeping logs are good engineering regardless of any statute.

So we would not recommend a DPDP-branded project at a premium. We would recommend an assessment, which answers most of the same questions, and then the remediation it surfaces. If that also happens to put you in a defensible position under the Act, so much the better.

Further reading

We have written at more length on what to actually do in 2026. For advisories relevant to Indian infrastructure, CERT-In is the authoritative source, and the CIS Critical Security Controls cover the same technical ground in a vendor-neutral way.

Frequently asked questions

Does NexusSec provide DPDP legal advice?

No. We do the infrastructure half: mapping where personal data sits, controlling who can reach it, segmentation, access control and logging. Notices, consent and legal interpretation belong with your legal advisers.

Is DPDP readiness mostly paperwork?

Part of it is, and that part is not ours. But the questions of where personal data actually sits, who can reach it, and whether you could evidence access are infrastructure questions, and that is usually where the real gap is.

Should we run a DPDP-specific project?

Usually not at a premium. Most of the technical work is work worth doing regardless. An assessment answers most of the same questions and the remediation it surfaces improves your position under the Act as a side effect.

What is the fastest technical improvement?

Multi-factor authentication on remote access and email, followed by separating the systems that hold personal data from the general office network. Those two change the most for the least disruption.

Working out which half of DPDP is yours?

A short call will separate the engineering work from the legal work, so you are not paying anyone twice.

Book a free consultation