Rules Notified, Board Live
The DPDP Rules, 2025 were notified 13 November 2025, and the Data Protection Board of India is already established and operational.
India’s Digital Personal Data Protection regime is now law. The DPDP Rules, 2025 were notified on 13 November 2025, and every business that handles the personal data of people in India has to comply. GoTrust provides the privacy automation platform. Flentas implements it and builds the data and security foundation underneath, so you reach compliance and stay there.
The law is operational and the Data Protection Board of India is already established, so complaints can be filed. The rollout is phased over roughly 18 months — preparation time, not a reason to wait.
The DPDP Rules, 2025 were notified 13 November 2025, and the Data Protection Board of India is already established and operational.
Penalties reach up to ₹250 crore per violation and can stack across violations — the Board can already receive complaints.
Personal data scattered across applications, cloud accounts, warehouses, and spreadsheets makes minimization and breach scoping guesswork without discovery and mapping.
Access, correction, erasure, grievance redressal, and breach notification all have deadlines that manual, email-and-spreadsheet processes cannot meet at scale.
We work backward from the compliance deadline and sequence by risk, so the highest-exposure gaps close first. You prove readiness in stages rather than in one rush at the end.
We run data discovery across your estate, map processing activities, and measure the gap against the DPDP Act and Rules. You get a prioritized roadmap with owners and a path to the deadline.
We deploy the GoTrust modules you need, integrate consent, notice, and rights workflows into your applications and cloud, and put the data governance and security safeguards in place.
We run consent, rights, and breach workflows with you, keep evidence audit-ready, and adapt as the Data Protection Board issues further guidance.
Universal Consent Management, cookie consent, and policy/notice management for clear, itemized, versioned notices.
Automated scanning and classification of personal data, data security posture management, and records of processing.
Workflow-driven access, correction, erasure, and consent-withdrawal requests, with grievance redressal tracked against deadlines.
Data protection impact assessments, risk register, compliance scoring, and shared-ownership policy management.
Vendor and third-party risk management, and incident management to identify, assess, and notify breaches in time.
GoTrust also supports GDPR, UAE PDPL, and other global privacy regimes from the same platform.
Applies regardless of sector, and to many businesses outside India that handle Indian users’ personal data.
Regulated sectors need sector templates and pre-built mappings that keep pace with both DPDP and existing sector obligations.
Businesses already managing GDPR or UAE PDPL can extend the same platform to DPDP rather than standing up a parallel program.
Personal data scattered across cloud accounts and shadow IT needs automated discovery that keeps pace with change.
HPE needed to see and evidence what happens across its estate for breach readiness. Flentas built a security data fabric across roughly 2,500 accounts with full audit logging and central governance.
Cashew Payments needed a governed copy of data with a clear audit trail for minimization and accountability. Flentas built a governed lake fed by change-data-capture.
GHFL could not protect or map personal data it could not see. Flentas unified more than 20 applications and environments into a single monitoring and analytics view on AWS.
“We genuinely did not know how many places customer data lived — three CRMs, two data warehouses, and a folder of vendor spreadsheets nobody owned. The GoTrust rollout with Flentas found all of it, and the consent and rights workflows were live before our board even asked about DPDP. We stopped worrying about the deadline the day the roadmap had owners on it.”
Chief Compliance OfficerRegulated Enterprise, India
A DPDP readiness assessment maps your data, measures the gap against the DPDP Act and Rules, and hands you a prioritized roadmap to the May 2027 deadline.