Ahmedabad's economy runs on pharmaceuticals, textiles, chemicals and a dense layer of family-owned manufacturing groups. Many of these businesses are decades older than any privacy function, and their personal data sits in ERP systems, dealer records and HR files that have never been inventoried.
Family-run groups often operate several legal entities sharing systems, staff and customer lists. Under the Act each entity determining its own purposes is a separate Data Fiduciary, so the first task is usually establishing who is accountable for which data.
Pharmaceutical businesses carry the additional complication of clinical, pharmacovigilance and patient-support data, which is governed by its own regimes alongside DPDP.
ProtectComply is built by Exuverse, whose team sits in Noida. We work with organisations across India — remotely for most of a programme, in person when discovery or a workshop genuinely needs it.
Each entity that determines the purpose and means of processing is its own Data Fiduciary. Sharing customer or employee data between sister companies is a transfer requiring a basis and a record, not an internal movement.
Inventory. Personal data in these businesses is typically spread across ERP, dealer records, warranty and service histories and plant HR files that no one has mapped.
Priya Gupta — Priya writes on compliance operations at ProtectComply, including data principal rights, grievance handling and sector-specific programmes.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →