We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Hyderabad · DPDP

DPDP Compliance Services in Hyderabad

DPDP Act readiness for Hyderabad pharma, life sciences and global capability centres — data mapping, notice and consent design, breach readiness and gap assessment ahead of the May 2027 framework.

Why Hyderabad's exposure is different

Hyderabad's economy concentrates two kinds of organisation that the DPDP Act treats seriously. The first is life sciences — pharmaceutical manufacturers, CROs and diagnostics groups whose datasets include health information about identifiable individuals. The second is the global capability centre: captive technology and operations arms processing personal data on behalf of a foreign parent.

Both raise the same uncomfortable question early. A GCC processing employee or customer data for a parent in the US or EU has to establish whether it is acting as a data fiduciary in its own right or processing on another's instructions, because the Act's duties attach very differently. That determination is a legal and architectural exercise, and it is much cheaper to do now than to retro-fit once the substantive framework commences.

The dates that actually govern you

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 as G.S.R. 843(E). Commencement is phased, and conflating the phases is the most common planning error we see:

  • 13 November 2025 — the provisions constituting and empowering the Data Protection Board, the definitions and the procedural rules took effect on notification.
  • November 2026 — verifiable parental consent under section 6(9) and the publication duty under section 27(1)(d) commence one year from notification.
  • May 2027 — the substantive framework: notice and consent standards, data fiduciary duties, children's data and data-principal rights. Published analyses differ on whether the exact day is 12 or 13 May; confirm it with counsel before you put it in a board paper.

The Schedule to the Act caps penalties at up to ₹250 crore per instance for the highest tier — failure to take reasonable security safeguards to prevent a personal data breach — with lower tiers at ₹200, ₹150 and ₹50 crore. For a diagnostics group or a GCC holding health data at volume, that is not a theoretical number.

Breach reporting is the duty that catches teams out

Under Rule 7, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware of it, follow with a detailed report within 72 hours (extendable by the Board), and notify each affected data principal. Two clocks, two audiences, and one of them starts the moment somebody in your SOC realises what they are looking at.

If you already report to CERT-In under the April 2022 Directions, note that these are separate obligations with separate deadlines. Meeting one does not discharge the other, and the fastest way to fail both is to have a single undocumented escalation path.

What a readiness engagement covers

Personal-data inventory and flow mapping first — you cannot design notice, consent, retention or erasure for data you have not located. Then fiduciary/processor determination, notice and consent design against the section 5 contents requirement, data-principal rights workflows including withdrawal and grievance redressal, retention and deletion schedules, processor contracts, and breach runbooks tested against the Rule 7 clocks.

How we cover Hyderabad

We do not keep an office in Hyderabad. This work is delivered from our Bengaluru office, which means on-site phases — data-flow walkthroughs, interviews, evidence review — are scheduled rather than ad hoc. We would rather say that plainly than list a coworking address and imply a local team. Most of a DPDP or PCI engagement is document and system review that runs remotely in any case; the parts that genuinely need a room with your people in it, we plan and travel for.

Related

DPDP compliance services · DPDP compliance checklist · DPDP gap assessment · DPDP Act explained

Free tool
DPDP Readiness Checker
Check your readiness for India’s DPDP Act and see your priority gaps — free.
Try it free →
PCI SSC Qualified Security Assessor — CYBERSIGMA CONSULTING SERVICES LLP

QSA Authorised
CEMEA · Asia Pacific · USA

Ready to discuss your Hyderabad DPDP Compliance requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.

Talk to an expert →Request a scope review

Delivering from Noida · Mumbai · Bengaluru · Pune · Dubai · Cairo · Melbourne see all locations & addresses →