Data privacy — DPDPA, GDPR & cross-border
Build a data protection programme that stands up under the EU/UK GDPR, India’s DPDP Act and other regional privacy laws.
Companies operating across regions have to satisfy several privacy regimes at once — the EU and UK GDPR, India’s Digital Personal Data Protection Act, and sectoral or state laws elsewhere. The underlying obligations overlap enough to run as one programme.
This engagement builds that programme: knowing what personal data you hold, why, where it goes, and how individuals exercise their rights.
What the engagement covers
Data mapping
Map personal data flows across products, systems and vendors, and build the records of processing that most regimes require.
Lawful basis and notices
Review the legal basis for each processing activity and align privacy notices and consent mechanisms.
Rights and requests
Design workflows for access, correction, deletion and other data subject / data principal requests within statutory timelines.
Impact assessments
Establish a DPIA process and complete assessments for higher-risk processing.
Cross-border transfers
Select and document transfer mechanisms (adequacy, standard contractual clauses, transfer impact assessments) for the regions you operate in.
Common questions
Talk through Data privacy for your team
A short call to confirm scope, timeline and a firm price — before you commit to anything.
