9+ years securing regulated
35% Reduction in time to compliance
100% Compliance Success

DPDPA Compliance ,

Driven by Forensics-Led Security

Rex is a forensics-led security firm. We've investigated real breaches in India — so we build your DPDPA programme around what regulators and enterprise buyers actually test, not a template.

2-4 Weeks

to a full readiness assessment

9+ yrs

securing regulated Indian businesses

Every obligation

assessed, not sampled

Fixed fee

for the assessment — no open-ended billing
Why Rex
Most consultants prepare you for the checklist.
We prepare you for the incident.
Rex runs digital forensics and incident response for Indian companies after real breaches. That casework decides what we build first in your DPDPA programme — because we've seen which controls hold and which ones only existed on paper.
From the field
We've seen what fails under pressure
The moment that tests your privacy programme isn't an audit — it's the week you discover data has moved somewhere it shouldn't. We build for that week.
Evidence discipline
Forensic-grade records
Chain-of-custody thinking applied to consent logs, access records and processing activity — so when someone asks for proof, retrieval takes hours, not weeks.
Beyond the report
Breach response you can actually run
DPDPA requires you to notify the Data Protection Board and affected individuals. Our incident response practice writes that plan — and has run it for real.
"You cannot notify a breach you never detected, and you cannot prove consent you never logged. Both problems are built years before the incident."
Field note
The most common privacy failure we find isn't a missing policy — it's a missing map. Companies genuinely don't know every place personal data lives: the analytics tool, the support inbox, the exported spreadsheet, the vendor's sandbox. Every DPDPA obligation — notice, erasure, breach notification — assumes you know where the data is. That's why data discovery is week one, not week six.
What We Do
What We Actually DO
Five workstreams, run with your team rather than handed to you as a document set. Most clients have no privacy function when we start.
Data discovery and mapping
We interview your teams and trace the data itself — products, vendors, analytics, support inboxes, exports — then map each flow to a purpose and a lawful basis. This is week one, because everything else depends on it.
Notice, consent and rights
We rewrite your notice, rebuild consent capture so it is specific and withdrawable, and stand up a request process with an owner and a clock — so an erasure request is handled, not just acknowledged.
Processor and vendor controls
We build your processor register, assess what each vendor actually does with your data, and get contracts in place — including the awkward ones signed years before the Act existed.
Security safeguards and breach readiness
Safeguards that hold, detection that would actually catch a breach, and a notification playbook naming who decides, who signs and what gets sent — written by the team that runs real incident response.
Customer and auditor evidence pack
The artefact your buyer actually wants: one current pack you send when the next questionnaire arrives, kept up to date as you change — plus us on the call when their security team pushes back.
Two ways to start
Which one do You need?
Most companies start with the Health Check because it turns an unanswerable question into a scoped problem. If a deal or an inquiry is already on the clock, go straight to the full programme.
Track 1 — Compliance Health Check
Find out where you actually stand
2 – 4 weeks  ·  fixed scope
What you get
Data discovery across your key systems and vendors
Obligation-by-obligation gap assessment
Risk-ranked remediation roadmap with owners and dates
An executive summary you can send to the customer who asked
Best for

Teams who've been asked a hard question and need a credible, defensible answer fast — without committing to a full programme before they know the size of the problem.

₹1,50,000 fixed
Fixed scope, fixed fee — no surprises.
Fill : Price
Track 2 — Full readiness programme
Close the gaps and build the evidence
Typically months  ·  scoped after the Health Check
What Type II proves
Notice, consent and rights workflows implemented
Processor agreements and vendor assessments completed
Security safeguards and breach notification playbook
Evidence pack maintained for customers and regulators
Best For

Companies with a deal, renewal or inquiry on the clock — or anyone who wants privacy to stop being a recurring sales blocker. Duration depends on how much data you hold and how many systems and vendors touch it.

₹2L - 4L
Scoped after the Health Check, because pricing it earlier is guesswork.
Fill : Range
Straight answer on timelines: the Health Check is genuinely 2–4 weeks. Full readiness is measured in months, not days — anyone promising DPDPA compliance in 30 days is selling you documents, not compliance. We scope your real timeline in the first call.
Most people get this wrong
There is no DPDPA certificate. Nobody can certify you compliant — not us, not anyone. Unlike ISO 27001, DPDPA has no certification scheme and no badge to put in your footer. What you actually hand a customer is your own evidence: your data map, your consent records, your processor agreements, your breach playbook. That's why the deliverable that matters is an evidence pack, not a certificate — and why any vendor offering you "DPDPA certification" is describing something that doesn't exist.
Book a DPDPA readiness call with Rex.
Your options
Four ways to do this. Rex is only one of them.
An honest read on each, including where we're the wrong choice. If you can already answer your customer's questionnaire, you don't need us — and we'd rather you knew that now than three calls in.
Build it in-house
Template or tooling vendor
 Large consulting firm
Rex
What you get
Full control, and whatever your team has time to build
Policy set, consent tooling, a dashboard
Deep bench, broad methodology, formal deliverables
Discovery, remediation and an evidence pack, built with your team
Best when
You have privacy counsel and an engineer who owns this
You need documents fast for one questionnaire
You're large, multi-jurisdiction, and audit-heavy
Personal data is core to the business, but nobody owns privacy yet
Watch out for
It slips every quarter behind product work
Documents that describe a company you aren't
Cost and pace scaled for much larger clients
We scope tightly — we won't take work we can't do well
Typical timeline
Open-ended
Days for documents; the gaps stay
Months, with a longer start-up
2–4 weeks to assessment, months to full readiness
When we'd tell you not to hire us
Three situations where we'll say so on the first call rather than sell you a programme:
You already have a current data map, working consent records and processor agreements — you need an auditor or counsel, not a readiness programme.
You need a policy pack to answer one questionnaire this week and nothing more. A tooling vendor is cheaper, and we'll name one.
Your real problem is a live incident, not compliance. Then you need our forensics team, not this page — and that's a different, faster conversation
FAQ

DPDPA, Questions answered

Everything founders ask us before starting their DPDPA journey, from readiness and scope to audit support and next steps.

Still Have Questions?
01
Does DPDPA apply to us?
02
How long does DPDPA readiness take?
03
We already did ISO 27001 / SOC 2. Aren't we covered?
04
What does it cost?
05
What does "forensics-led" actually mean here?
06
Do you work alongside our existing counsel or auditor?
07
Nobody has asked us yet. Should we start now?
Get Started
Not ready to talk? Take the answer key.
The Vendor Questionnaire Pack: the questions Indian enterprise buyers are actually sending vendors right now — and what a defensible answer to each one looks like. The same document we give clients in week one. Free, in your inbox.
Built for teams without a dedicated compliance function.