Pick what you need. Run them together for full coverage. Each module anchors to the specific section of the Act it implements.
DPDP §6 · §7 · Rule 4
The full consent lifecycle: capture, store, refresh, withdraw. ProtectComply ships three surfaces — a hosted preference centre, a cookie banner, and an embeddable widget.js — all wired into the same audit trail. Per-purpose granular consent is enforced; bundled consent flags are rejected at write time. Returning-principal recognition uses a per-tenant cookie plus SHA-256 fingerprint, so an Indian user who already granted consent on the same device doesn't see the banner again. Withdrawal is OTP-gated so it's as easy as granting — the explicit Rule-4 mandate. Every record carries provenance: capture IP, user-agent, fingerprint, and principal cookie. Auto-translates notice text into all 22 official Indian languages via Bedrock.
Try Consent Management →Highlights
DPDP §5(3) · 8(1)
A 30-policy bank — Privacy Notice, Cookie Policy, Data Retention, Breach Response Plan, Vendor Agreement, Children's Notice, and 24 more — drafted by AI from your organisation profile and the live DPDP spec. Every clause is grounded in a specific section, so when the Act is amended (and it will be), regeneration is one click. Policies are version-controlled, signed-off by named roles, and exportable as PDF. Public publication via a hosted URL means your principals get the latest notice without you redeploying anything. Built-in AI gap analysis flags clauses that are missing or contradict the Act. Regulator response drafter pre-writes replies to common Board queries.
Try AI Policy Generator →Highlights
DPDP §8 obligations
A two-tier assessment engine — Protect Pro (self-serve) and Protect Max (DeepDive) — with 350+ questions tuned per industry and per data-fiduciary role. Healthcare and BFSI ship with their own specialised banks; the Max tier surfaces separate Fiduciary vs Processor content depending on which role your tenant operates in. Every question accepts evidence upload; AI vision validation reads documents and screenshots to confirm what's claimed actually matches what's attached. Per-question and per-module legal references point to the exact §s being tested. Module-level assignments push individual sections to named team members with deadlines.
Try Readiness Assessment →Highlights
DPDP §11 · Rules 12 & 13
Honours the five DPDP §11 data-principal rights — Access, Correction, Erasure, Nominee, and Grievance — with a public principal-facing portal at /rights/[org]. OTP-verified intake, auto-routing rules push requests to the right team based on category and data type, an AI response-letter drafter pre-fills a regulator-grade reply, and an SLA timer with escalation makes sure nothing rots in a queue. Rule 12 (refusal must state reasons) is enforced at the contract layer — you can't close a request marked refused without filling the legal justification. Every artefact exports as PDF for the principal and as a signed audit trail for the Board.
Try Rights Manager (DSR) →Highlights
DPDP §13 · Rule 13
Section 13 says every Fiduciary must publish a grievance officer and resolve complaints within a defined period. ProtectComply gives you a principal-facing form at /grievance/[org], a per-org DPO inbox, category-based routing, and a 90-day SLA timer with two automatic escalations. The audit-event trail captures every state transition — submitted, acknowledged, in-review, refused-with-reason, resolved — so the Board's grievance register is always one export away. Refusal logic enforces Rule 13: you cannot close-refused without recording the legal basis in writing. Principal satisfaction is captured post-resolution for trend reporting.
Try Grievance Management →Highlights
DPDP §8(6)
§8(6) requires a Data Fiduciary to notify the Board and affected principals on becoming aware of a breach. ProtectComply's breach lifecycle gives you the 72-hour detection clock, the 24-hour Board-notification clock, and a structured workflow for containment, root cause, and corrective action. Each breach record has reportable / contained / RCA / corrective-action status, attached evidence, regulator-notification record with reference number, and a principal-notification campaign. A standing breach register satisfies the audit obligation; report generation produces both the Board form and the principal-facing notice in any of the 22 supported languages.
Try Breach Management →Highlights
DPDP §8(7) · 8(8)
Records of Processing Activities (Article 30-equivalent), data-flow diagrams, vendor / processor catalog, and a cross-module risks aggregator. RoPA entries link to the consent purposes they're collected under and the retention policy they're disposed against — so if anyone changes one, the others light up red. The vendor catalog covers due-diligence questionnaires, DPA tracking, and sub-processor disclosures (the §8(8) 'reasonable security safeguards' obligation extends down your supply chain). Risk aggregator rolls everything up into one heatmap for the DPO's weekly review.
Try Data Map, RoPA & TPRM →Highlights
DPDP §5 · §6 · §13
Point the scanner at a URL — your site or a vendor's — and it runs 60+ DPDP-specific checks across 10 weighted domains: Notice & Banner, Consent Mechanics, Withdrawal & Rights, Cookies & Trackers, Children's Data, Forms & Inputs, Security Headers, Vendor Sharing, Retention Notices, and Grievance Disclosure. Each finding is severity-tagged and section-anchored. The output is a scored report ranging from 0 to 100, with deltas across re-runs so you can prove improvement over time. Hub at /dashboard/scanner.
Try Website Scanner →Highlights
Every plan includes the same audit trail, so you can add modules later without re-onboarding.