Pricoris

How to Choose a DPDP Consultant in India: Ten Questions to Ask Before You Sign

There is no licence, empanelment or accreditation for DPDP consultants in India, so the title proves nothing and the proposal proves almost everything. Choose the firm whose proposal ties every piece of work to a provision of the Digital Personal Data Protection Act, 2023 or the DPDP Rules, 2025, puts most of its effort where the Act places its heaviest penalties, names the people who will actually do the work, leaves you owning and able to run what it builds, and does not end with the same firm certifying its own work. The ten questions below test each of those things, and a competent consultant will answer all of them without hesitation.

Since the Rules were notified on 13 November 2025, the number of firms offering DPDP consulting has grown faster than the number that have actually implemented it. Buyers looking for help find ranked lists of the top ten consultants, most of them published by one of the ten. They receive quotes that differ tenfold for what looks like the same scope. And nobody can point them to an official register, because none exists.

A poor choice is expensive in either direction. Buy too much and you pay for a European compliance apparatus the Indian statute never asked for. Buy too little and you receive a folder of policies describing a programme your organisation does not run. On the day the proposal is signed, the two failures look identical. They look very different on the day a data principal complains or a breach has to be reported.

Part One: What you are actually buying

Before assessing anyone, be clear about the job. The DPDP Act is a deliberately lean statute. It has no category of sensitive personal data, no equivalent of the GDPR’s Record of Processing Activities, and no general duty to appoint a Data Protection Officer. Cross border transfer is permitted unless the Government restricts a destination. The heaviest obligations apply only to Significant Data Fiduciaries: the Data Protection Impact Assessment, the periodic audit and the India based DPO. An organisation becomes a Significant Data Fiduciary only when the Central Government notifies it under Section 10(1).

What the Act does care about is visible in its Schedule of penalties.

FailureMaximum penalty
Reasonable security safeguardsINR 250 crore
Notifying a personal data breachINR 200 crore
Obligations concerning childrenINR 200 crore
Significant Data Fiduciary obligationsINR 150 crore
Everything else, including defective notice and consentINR 50 crore (residual head)

That weighting is the first test of any proposal. If most of the effort goes into documents while security safeguards and breach readiness get a line each, the proposal is upside down.

The work itself falls into three kinds:

  • Legal drafting: notices, processor contracts and the lawful basis analysis.
  • Operational build: consent records, the rights procedure, retention decisions and the breach procedure.
  • Technical assurance: mapping your existing controls to Rule 6 and closing the gaps.

Few firms are equally strong in all three. Work out which one your organisation needs most, and buy that strength.

Part Two: Ten questions to ask before you sign

1. Which provision of the Act or Rules does each line item answer?

This single question removes more waste than any other. Every deliverable in a DPDP proposal should trace to a section or a rule. Notices trace to Section 5 and Rule 3, security to Section 8(5) and Rule 6, breach reporting to Section 8(6) and Rule 7, and so on down the list. A consultant who has done this work will answer line by line. One who is reselling a GDPR template will talk about best practice. Best practice may be worth buying, but you should know when you are buying it, and what it costs.

2. Have you established whether we are a Data Fiduciary, a Data Processor, or both?

A fiduciary decides why and how personal data is processed. A processor acts on someone else’s instructions. The substantive obligations sit with the fiduciary. For a B2B software company, most of the product estate is processor territory. It is governed by the contract required under Section 8(2), not by notices and consent. A consultant who quotes before asking this question is quoting a template, and the template is usually the more expensive option.

3. Which of our processing does not need consent at all?

Section 7 sets out legitimate uses that need no consent, including processing for the purposes of employment. A consultant who proposes consent capture for employee data is creating a withdrawal right you do not want in an employment relationship. A good answer to this question often shortens the consent build considerably.

4. What exactly will you do about security safeguards and breach reporting?

These two carry the largest penalties, so this should be the most specific part of the proposal. Rule 6 expects measures such as:

  • encryption, masking or tokenisation;
  • access control;
  • logs retained for at least a year, with monitoring;
  • continuity arrangements.

Rule 7 expects intimation to affected individuals without delay, plus a two stage report to the Board, with the detailed report due within 72 hours. Organisations within CERT-In’s remit must also reconcile this with its six hour window for reporting cyber incidents.

A good answer maps what you already run against these requirements and rehearses the breach procedure at least once. A weak answer proposes a new security stack. A worse one comes from a team with no security capability at all.

5. Who will actually do the work?

Ask for names, not a team slide. Ask which people from the pitch will attend your workshops, and roughly how many days of senior time the fee buys. Relevant credentials include:

  • ISO/IEC 27701 lead implementer or lead auditor, the standard behind a privacy information management system;
  • ISO/IEC 27001 competence for the Rule 6 work;
  • legal qualification for contract and notice drafting.

Credentials are necessary but not sufficient. Ask as well for two engagements of similar size and sector that the named people delivered themselves.

6. What will we own at the end, and can we run it without you?

Your own people operate a DPDP programme every day. That means the team answering rights requests, the owner deciding retention, and the incident lead making the breach call. The deliverables should be in your formats, editable, and handed over with training. Be wary of artefacts that live only inside the consultant’s platform. Be equally wary of any design that quietly assumes a permanent retainer to keep working.

7. Does your recommendation depend on a product you sell or resell?

Many firms in this market sell or resell consent management platforms and rights tools. That is not wrong in itself, and at high consumer volume a platform earns its cost. What matters is whether the programme works without the product.

Treat any claim that you must integrate with a registered Consent Manager with particular caution. Rule 4 governs entities that wish to register as Consent Managers. It does not oblige a Data Fiduciary to use one.

For transparency: our sister company, Pricoris Technologies, builds DPDP software. No Pricoris consulting proposal requires it, and we will tell you when you do not need a tool at all.

8. Will you also assess or certify the programme you build?

The answer should be no. There is no official DPDP certification in India, and a compliance letter is only as credible as the independence of whoever signs it. If the team that built the programme then attests to it, your customer learns nothing from the letter that it could not have heard from you directly. More on what a credible letter contains is in our piece on whether an official DPDP certification exists.

9. Which deadline are you planning against?

The substantive obligations on notice, consent, security, breach reporting, rights and retention commence on 13 May 2027. The Consent Manager provisions in Rule 4 take effect earlier, on 13 November 2026. In January 2026, MeitY also put to industry a proposal to shorten the eighteen month runway to twelve months, at least for Significant Data Fiduciaries. That proposal has not been notified, so May 2027 remains the operative date.

Even so, a careful consultant puts breach readiness and rights handling in place early, because those are what a complaint or an incident tests first. A plan that leaves everything for the final quarter is a plan with no margin.

10. How will you deal with our other regulators?

For a regulated entity, another statute has often done much of the DPDP work already. In financial services, the RBI directions, the PMLA record keeping requirements, and SEBI and IRDAI rules fix most retention periods, and Section 8(7) gives way to retention that law requires. A consultant who knows your sector will adopt those periods rather than invent new ones. They will also fold DPDP into the controls your auditors already test.

Where the law is silent, retention is a business decision for whoever owns the record. An adviser should tell you the statutory minimum, and should tell you plainly when a practice cannot be defended. The adviser should not set the period for you.

Part Three: Reading the proposal

The line items below appear regularly in DPDP proposals. None is always wrong. Each should be justified by your facts rather than assumed.

Line item in the proposalThe question to askWhen it is justified
Record of Processing ActivitiesWhich provision requires it?Never as a legal requirement. A record of collection points serves the Section 8(1) duty to demonstrate compliance at a fraction of the effort
Appointment of a Data Protection OfficerHave we been notified as a Significant Data Fiduciary?Only after notification under Section 10. Otherwise, publish a contact person under Rule 9
DPIA and annual data auditSame questionOnly for Significant Data Fiduciaries under Rule 13, or as a voluntary exercise you have chosen
Integration with a registered Consent ManagerWhich rule obliges us?Never obligatory. It is a commercial choice
Consent management platform licenceWhat collection volume justifies it?High volume consumer collection. Rarely justified in year one for B2B
Rights request softwareWhat monthly request volume do you expect?When volume outgrows a register and a named owner
Standalone breach platformWhy not extend our incident response process?Rarely justified
Transfer clauses on the GDPR modelWhich transfer restriction applies to us?Only where a notified restriction applies
Classifying data as “sensitive”Which category in the Act is this?The Act has none. It may still help a security programme

Part Four: What a DPDP consultant should cost

Fees vary with your footprint far more than with the name on the proposal. Our guide to DPDP compliance on a startup budget puts external advisory cost for most startups between INR 1 lakh and INR 8 lakh, depending on sector, with B2B software at the lower end. For larger organisations the fee should be scoped after an assessment, because it turns on the number of entities, collection points, processors and regulators involved rather than on headcount alone. Be cautious of any firm that quotes a fixed enterprise price before it has seen your estate.

Price is a weak signal in both directions. A very low fixed fee usually buys a template set with your name on it. A very high one usually includes apparatus the Act does not require. Ask for the fee broken into phases, each with named deliverables, so that you can stop after the gap assessment if the findings do not justify the rest. That is how we structure our own DPDP engagements.

A case from our practice

A travel and tourism company came to us after its first DPDP engagement with a large multinational advisory firm. The proposal it had signed was for full implementation. What it received was a gap assessment, and a high level one at that: gaps were listed, but not examined function by function. There was no action plan, no remediation plan, and no guidance on how any of the gaps was to be closed. The company had paid for a programme and been handed a diagnosis. It then appointed us to do the work it had already bought once.

Nothing in that account requires bad faith to explain it. It requires only a proposal that describes the engagement as an outcome, “DPDP implementation”, rather than as a set of deliverables. Ask for each phase to name what you will hold at the end of it: a gap register by business function, a remediation plan with owners and dates, closure guidance for each gap, and the implemented artefacts themselves. Better still, ask to see a redacted sample of each from a previous engagement. A firm that has delivered them before will have no difficulty showing you one.

Part Five: Consultant, law firm, large advisory firm or platform vendor?

Each has its place.

  • Law firm. The right choice for processor contracts under negotiation, for notices where the drafting risk is high, and for anything that may end up before the Data Protection Board. Its advice is also privileged. It is rarely the most economical way to build operations.
  • Large advisory firm. Brings capacity for programmes spanning several entities or countries, at a price that reflects its staffing model.
  • Specialist privacy consultancy. Usually strongest on the operational build. Check its legal depth.
  • Platform vendor with bundled consulting. Quick if you have already chosen the tool, but its advice will tend to lead back to the product.

Many mid sized organisations end up with two advisers: a specialist to build and run the programme, and counsel on call for contracts and disputes.

Part Six: How we answer these questions

We publish these questions knowing that buyers will put them to us. Our proposals map each deliverable to the provision it answers, our position on software is stated under question 7, and every engagement ends with a handover that your own team can run. The firm’s approach is set out on our DPDP consulting page.

Closing

The right DPDP consultant will usually make your programme smaller than you feared, and more demanding in the two places the statute cares about most. If a proposal does the opposite, ask which provision each item answers, and keep asking until you get a section number.

Frequently asked questions

Does a DPDP consultant need a licence or government empanelment in India?

No. Neither the DPDP Act, 2023 nor the DPDP Rules, 2025 creates a licence, register or empanelment for consultants. Anyone may use the title, so the proposal and the people behind it are the only real evidence of competence.

What qualifications should a DPDP consultant have?

No qualification is prescribed. Useful signals are ISO/IEC 27701 lead implementer or lead auditor credentials, ISO/IEC 27001 competence for the Rule 6 work, legal qualification for contracts and notices, and engagements in your sector delivered by the people named in the proposal.

How much does a DPDP consultant cost in India?

For most startups, external advisory cost falls between INR 1 lakh and INR 8 lakh, depending on sector. For larger organisations the fee should be scoped after an assessment, because it rises with the number of entities, collection points, processors and regulators involved, not with the size of the consulting firm.

Should the consultant who implements our programme also certify it?

No. There is no official DPDP certification, and an attestation from the team that built the programme carries little weight with customers or auditors. Use a separate assessor.

Do we need a consultant to act as our Data Protection Officer?

Only Significant Data Fiduciaries must appoint a DPO, who must be based in India and responsible to the board under Section 10(2). Every other Data Fiduciary must publish the contact details of a person who can answer questions about its processing, under Section 8(9) and Rule 9. A consultant can support that function, but doing so is not a DPO appointment.

Is a consent management platform mandatory under DPDP?

No. Where consent is the basis for processing, the Act requires it to be valid and requires withdrawal to be as easy as giving consent. Neither the Act nor the Rules requires a particular platform or a registered Consent Manager. A platform becomes worthwhile at high consumer volume.


Sandhya Khamesra is Founder and CEO of Pricoris LLP, a Noida-based data privacy and governance consultancy that itself provides DPDP consulting; readers should weigh this guide with that interest in mind. She is a Chartered Accountant with more than 35 years across information security, privacy and risk management. This article is general commentary on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as in force on 22 September 2026. It is not legal advice. Last reviewed 22 September 2026.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top