Data mapped, leaks stopped, paperwork written. Audit-ready in about 30 days.
How a Navi Mumbai insurer went from unable to find a customer’s consent record, to a full findings document in under four weeks. Story below.
DPDP Compliance Package at a glance
Why this is now a board-level deadline, not a legal nicety.
- What it is
- A managed engagement that maps your data, stops the leaks, and writes the paperwork a regulator or auditor will ask to see.
- Why teams pick it
- The DPDP Act allows penalties up to Rs 250 crore for a single failure to protect personal data. Most firms assume IT has it covered. Usually nobody does.
- The three stages
- Find your data, stop the leaks with DLP controls, then write the consent notices, processing record, and breach plan.
- Who needs it first
- Any business holding names, phone numbers, Aadhaar details, or health records of Indian citizens. BFSI, pharma, manufacturing, and logistics see the most exposure.
- India pricing
- Rs 40,000 a month for Essentials (25-100 users), rising to a custom quote for BFSI or pharma at Enterprise scale. Plus applicable GST.
- Sirius Star role
- We run the gap review, deploy the tooling, and hand you a written findings document you can show a regulator on day one.
The DPDP Compliance Package tiers Sirius Star runs
Priced per month. Pricing covers tooling, deployment, and a named consultant.
Essentials
25 to 100 users getting started.
- Data inventory and risk score
- DLP controls deployed
- Consent notices and privacy policy
Growth
100 to 500 users, multi-site.
- Multi-site data mapping
- Breach response plan
- Quarterly policy refresh
Enterprise
BFSI, pharma, 500+ users.
- BFSI/IRDAI/RBI overlap mapping
- Dedicated named consultant
- One-time data mapping billed separately
The package vs building it yourself
You have three real options. Each fits a different size of business.
| Option | Where it wins | Best fit |
|---|---|---|
| Build it in-house | Full control, if you already have someone who has run a DPDP project before. | Larger firms with a dedicated privacy hire and a year to spend. |
| Pure software (GTB, Safetica, Bitdefender, Purview) | Strong point tools for the DLP layer. | Teams who already have someone to map data and write policy, and just need the controls. |
| DPDP Compliance Package (Sirius Star) | The people and the platform bundled, run by a named consultant in Navi Mumbai. | Most Indian mid-size businesses who want to be audit-ready in weeks, not a year. |
How the package gets you audit-ready
Three clear stages. Each one ends with something you can show a regulator.
Find your data
We map where personal data sits across laptops, servers, email, and cloud apps.
Stop the leaks
DLP controls block USB copy, unapproved uploads, and risky email attachments.
Write the paperwork
Consent notices, processing record, breach plan, and a policy your legal team can sign.
Audit-ready handover
A written findings document and logs you can hand to a regulator on day one.
The DPDP field guide for Indian teams
The five duties the Act actually requires, and the proof file a regulator accepts.
- The five duties: know, consent, protect, respond, report
- The three-stage rollout timeline
- The proof file a DPDP auditor accepts
DPDP Compliance Package FAQ
Common questions Indian compliance teams ask.
How long does it take to get compliant?
A mid-size firm reaches a defensible position in about 30 days. Larger BFSI or pharma estates take longer because the data is messier and the scrutiny is higher.Who counts as a data fiduciary?
If your business decides why and how personal data gets used, you are a data fiduciary under the Act. That covers almost every company with customers or staff.Do we need new tools or just policies?
Both. Policies tell people what to do. Tools stop the data from leaving when people forget. We deploy the controls and write the policies in one project so they actually match.What proof will we have for an audit?
A data inventory, a processing record, consent notices, a breach plan, and logs from the Secure Data Guard controls.Is this only for large companies?
No. The Essentials tier is built for firms with 25 to 100 users. The law applies the moment you hold one Indian citizen’s personal data.Get your free DPDP gap review
Tell us what you hold and where it sits. We come back with a plan and a fixed quote within 24 working hours.
Pair this with your device and cloud stack
What Sirius Star clients typically bundle with this on one PO.
Read more before you decide
Related guides from the Sirius Star team.
