





.png)
.png)
.png)
.png)
.png)
Teams who've been asked a hard question and need a credible, defensible answer fast — without committing to a full programme before they know the size of the problem.

.png)
.png)
.png)
.png)
Companies with a deal, renewal or inquiry on the clock — or anyone who wants privacy to stop being a recurring sales blocker. Duration depends on how much data you hold and how many systems and vendors touch it.
.png)
.png)



























.png)
.png)
.png)
Everything founders ask us before starting their DPDPA journey, from readiness and scope to audit support and next steps.
If you process digital personal data in India, it very likely applies — and it also reaches processing outside India where you're offering goods or services to people in India. Size doesn't exempt you; a 20-person SaaS company handling customer data is a Data Fiduciary the same as a large enterprise.
The Health Check is 2–4 weeks. Full readiness is measured in months and depends on your data footprint — how many systems hold personal data, how many vendors touch it, and how much of your consent and rights tooling has to be rebuilt rather than adjusted. We scope your real timeline after discovery rather than quoting a number upfront.
Partly. Those frameworks give you security controls, which DPDPA also expects — but DPDPA adds privacy-specific obligations they don't cover: itemised notice, lawful consent and withdrawal, data principal rights, purpose limitation and erasure. In practice, existing certifications shorten the security workstream and leave the privacy workstream largely ahead of you.
Two components: the Health Check (fixed scope, fixed fee) and the remediation programme (scoped after the assessment, because pricing it before we know your data footprint would be guesswork). Tell us your size and stack on the call and we'll give you a range the same week.
Rex investigates real breaches. That casework shows us how data actually escapes, which records are missing exactly when you need them, and which written processes turn out to be fiction under pressure. Those patterns decide what we fix first in your DPDPA programme.
Yes, routinely. We handle the technical and operational side — data discovery, controls, evidence, breach readiness — and work to your counsel's legal positions rather than around them. If you don't have privacy counsel and need one, we'll say so rather than pretend the work is ours to do.
If personal data is core to your product and you sell to enterprise, someone will ask — usually at the worst possible moment, mid-renewal or mid-diligence. Starting before that happens is materially cheaper, because you set the pace instead of a customer's deadline setting it. If you're early, the Health Check alone is often enough for a year: you'll know your gaps, have a dated plan, and be able to answer the question the day it arrives.
.png)
.png)