Skip to main content

DPDP-ready before 2027.

A five-stage service to get your programmes compliant with India’s Digital Personal Data Protection (DPDP) Act, with Anumati.

Solutions/DPDP Act Readiness

What the Act asks of you

Every organisation handling Indians’ personal data is now a Data Fiduciary, legally responsible for it. Nonprofits included, any size.

₹250 crMax penalty, security lapse
₹200 crPenalty, unreported breach
A mobile health unit collecting beneficiary data in the field

Consent has to work here: shared phones, low literacy, 22 languages.

Where the Act stands

273 days to full enforcement
13 Nov 2025
12 Nov 2026
13 May 2027
Today
13 Nov 2025

Immediate effect

The Board, definitions, and rule-making powers are active now. It can already act.

12 Nov 2026

Consent Manager registration

Registration requirements take effect. The track Anumati is built for.

13 May 2027

Full enforcement

Notice, consent, fiduciary duties, children’s data, and transfer limits are all in force.

Some obligations apply only above a size threshold, as a Significant Data Fiduciary. Any one of these can put you there:

Several million people’s data, across all programmes

Health, financial, or biometric data at scale

Turnover past the significant-fiduciary threshold

How we take you through it

Five stages, from a mindset shift to an audit by an independent agency.

01
02
03
04
05

Change the mindset

Collect only what you can justify. Culture first, technical second.

A data-protection team

Reviews every collection. Can overrule any programme team.

Two adoption pathways

New data follows the rules from day one. Old data gets stripped or encrypted.

Prepare for adoption

Residency, consent arrangements, written policy, MIS reviews.

Audit and certify

An outside agency certifies. A certificate for your board.

Common questions

Does this apply to us if we are a nonprofit?

Yes. Any organisation handling Indians’ personal data is a Data Fiduciary under the Act, whatever its size or legal form. There is no nonprofit exemption.

What do we have at the end of it?

A certificate from an independent agency, a data inventory, a constituted data-protection team, written policies and notices, India-resident storage confirmed in writing, and provable consent.

What happens to the data we already hold?

There are two adoption pathways. New data follows the rules from day one; existing data is stripped back to what you can justify, or encrypted.

Depth for the hard cases

Where organisations get stuck, and how we handle it.

Children and persons with disabilities

A higher bar: verifiable guardian consent, no tracking, nothing that could cause harm.

An independent certificate

From the audit at the end, for your board and your donors.

Built for multi-site organisations

The most collection points and the most old data. Where this work is hardest.

Anumati for the consent part

One API call: OTP-verified, 22 languages, tamper-evident trail.

See Anumati, our consent manager

What you get

Six things you can put in front of your board.

An independent certificate

Issued by an outside agency, for your board and your donors.

A data inventory

What personal data you hold, where it sits, and why.

A data-protection team

Constituted, with the authority to stop a collection.

Written policies and notices

Including notices your beneficiaries can actually read.

India-resident storage

Every record stays in India, with vendor confirmation in writing. The Act only restricts transfers to countries the government names; we hold our own engagements to that stricter bar.

Provable consent

Running through Anumati, with a tamper-evident trail.

Why Dhwani

The difference between us and a generic compliance consultancy.

We know field data

Shared phones, low literacy, 22 languages. The only kind of consent we’ve had to design for since 2015.

Guidance from the Act itself

Grounded in the DPDP Act 2023 and the Rules 2025, not a generic checklist.

The audit is independent

The certificate comes from an outside agency, not from us. We prepare you for it.

ISO 27001 certified

And aligned with DPDP and GDPR ourselves. We ask nothing we haven’t already done.

See our full DPDP approach

The phases, what each one involves, and what the audit at the end covers, on our dedicated DPDP site.

Visit dpdp.dhwaniris.com

The consent part is Anumati

Provable consent is the requirement organisations get stuck on, so we built a product for it. Anumati is plug-and-play consent infrastructure: one API call from your MIS, a notice in any of 22 languages, OTP or signed-upload verification, and a tamper-evident trail you can produce on demand.

Handling beneficiary data? Get DPDP-ready.

Book a call