Three weeks to know whether you can actually delete a user.
A fixed-fee engagement for Indian companies holding consumer data. We map it, trace it, and hand your counsel evidence they can defend.
- November 2026 — the Data Protection Board gains penalty powers
- May 2027 — notice, consent, safeguards, breach reporting and data-principal rights all live
- Up to 250 crore — the ceiling for failing to take reasonable security safeguards
The problem
Ask your engineering lead to completely delete one real user, today, and count how long the silence lasts.
You have a privacy policy your lawyer drafted, a consent banner someone bolted on, and a database nobody has audited. That silence is the whole problem.
Personal data does not sit in one place. It is in your primary database, your analytics warehouse, last night’s backup, a support tool, three vendor dashboards, an object store of uploaded documents, and a spreadsheet on somebody’s laptop. A policy document reaches none of it.
What you walk away with
- A field-level data map: every place personal data lands, down to the column, across your primary database, warehouse, object storage, logs, analytics, support tools and vendor systems.
- The erasure trace: we take one real user identifier and follow it to full deletion across every system on that map, including backups and third-party processors, and show you exactly where the path breaks.
- A consent ledger schema deployed to your staging environment: append-only, versioned, hash-chained, row-level isolated. Consent stored as a boolean proves nothing.
- Notice and preference-centre copy in English and Hindi, versioned so an old consent stays attributable to the text the user actually saw.
- A 72-hour breach runbook with a named owner per step, pre-drafted Board intimation and user notification templates, dry-run once before handover.
- A processor register and ranked gap list: every vendor touching personal data, which ones you hold no contract with, ordered by exposure against effort.
How it runs
- Week one — kickoff, read-only access, automated scan for Indian identifiers, draft data map
- Week two — erasure trace end to end, consent ledger to staging, notice copy drafted, findings shown raw
- Week three — breach runbook dry-run, processor register closed, gap list ranked, handover to your team and your counsel
Investment
Readiness Sprint · three weeks
Rs 1,85,000 plus GST- +All six deliverables
- +Consent ledger to staging
- +Ranked gap list your team executes
- +Handover session with your counsel
Sprint plus Build · six weeks
Rs 3,60,000 plus GST- +Everything in the Sprint
- +Consent ledger shipped to production
- +Access, correction and erasure endpoints
- +Retention jobs and audit logging wired in
- +The gap list closed by us, not by you
Optional afterwards: a watch retainer at Rs 30,000 a month. We re-run the erasure trace quarterly, keep the processor register current as you add vendors, and re-version your notice when the rules move. Founding cohort, first five clients: Rs 1,50,000 for the Sprint, in exchange for a monthly feedback call, use of your logo, and a case study you can have blinded. The trade goes in the contract rather than being implied.
Is this you?
This is for you if
- +You are an Indian company of roughly 15 to 150 people
- +You hold consumer personal data at real volume
- +You run Postgres, Supabase or something comparable
- +You have no privacy engineer in house
- +A board member or an investor has already asked the question
Honestly, not if
- ×You are pre-revenue and pre-users
- ×You have been notified as a Significant Data Fiduciary and need a registered auditor
- ×You are a bank or an insurer, where sectoral rules sit on top of this
- ×You want a PDF to show your board and nothing underneath it
What this is not
- Not legal advice. We are engineers. Your counsel owns the legal position and signs the documents.
- Not a certification. No DPDP certification body exists. Anyone selling you a certificate is selling you nothing.
- Not a Consent Manager. That is a separately registered intermediary requiring two crore in net worth and Board registration.
- Not a dashboard subscription. You get artefacts you own, in your repo, that outlive the engagement.
- Not a guarantee against penalty. Nobody can offer that. We reduce exposure and leave a defensible record.
Start with the erasure question
Forty-five minutes, no charge. Bring your engineering lead. We walk your schema and tell you on the call whether a complete user deletion is currently possible. If it is, you probably do not need us yet, and we will say so.
References: the Digital Personal Data Protection Act, 2023 (penalties under the Schedule to section 33) and the Digital Personal Data Protection Rules, 2025, notified 13 November 2025 with phased application at twelve and eighteen months. Dates and obligations described here reflect the position as at August 2026 and may change as the Data Protection Board is constituted and further notifications issue. This page is commercial information about an engineering service. It is not legal advice and creates no advocate-client relationship.