Data privacy — DPDPA, GDPR & cross-border

Build a data protection programme that stands up under the EU/UK GDPR, India’s DPDP Act and other regional privacy laws.

Companies operating across regions have to satisfy several privacy regimes at once — the EU and UK GDPR, India’s Digital Personal Data Protection Act, and sectoral or state laws elsewhere. The underlying obligations overlap enough to run as one programme.

This engagement builds that programme: knowing what personal data you hold, why, where it goes, and how individuals exercise their rights.

What the engagement covers

Data mapping

Map personal data flows across products, systems and vendors, and build the records of processing that most regimes require.

Lawful basis and notices

Review the legal basis for each processing activity and align privacy notices and consent mechanisms.

Rights and requests

Design workflows for access, correction, deletion and other data subject / data principal requests within statutory timelines.

Impact assessments

Establish a DPIA process and complete assessments for higher-risk processing.

Cross-border transfers

Select and document transfer mechanisms (adequacy, standard contractual clauses, transfer impact assessments) for the regions you operate in.

Common questions

Talk through Data privacy for your team

A short call to confirm scope, timeline and a firm price — before you commit to anything.