A five-stage service to get your programmes compliant with India’s Digital Personal Data Protection (DPDP) Act, with Anumati.
Every organisation handling Indians’ personal data is now a Data Fiduciary, legally responsible for it. Nonprofits included, any size.

Consent has to work here: shared phones, low literacy, 22 languages.
The Board, definitions, and rule-making powers are active now. It can already act.
Registration requirements take effect. The track Anumati is built for.
Notice, consent, fiduciary duties, children’s data, and transfer limits are all in force.
Some obligations apply only above a size threshold, as a Significant Data Fiduciary. Any one of these can put you there:
Several million people’s data, across all programmes
Health, financial, or biometric data at scale
Turnover past the significant-fiduciary threshold
Five stages, from a mindset shift to an audit by an independent agency.
Collect only what you can justify. Culture first, technical second.
Reviews every collection. Can overrule any programme team.
New data follows the rules from day one. Old data gets stripped or encrypted.
Residency, consent arrangements, written policy, MIS reviews.
An outside agency certifies. A certificate for your board.
Yes. Any organisation handling Indians’ personal data is a Data Fiduciary under the Act, whatever its size or legal form. There is no nonprofit exemption.
A certificate from an independent agency, a data inventory, a constituted data-protection team, written policies and notices, India-resident storage confirmed in writing, and provable consent.
There are two adoption pathways. New data follows the rules from day one; existing data is stripped back to what you can justify, or encrypted.
Where organisations get stuck, and how we handle it.
A higher bar: verifiable guardian consent, no tracking, nothing that could cause harm.
From the audit at the end, for your board and your donors.
The most collection points and the most old data. Where this work is hardest.
One API call: OTP-verified, 22 languages, tamper-evident trail.
Six things you can put in front of your board.
Issued by an outside agency, for your board and your donors.
What personal data you hold, where it sits, and why.
Constituted, with the authority to stop a collection.
Including notices your beneficiaries can actually read.
Every record stays in India, with vendor confirmation in writing. The Act only restricts transfers to countries the government names; we hold our own engagements to that stricter bar.
Running through Anumati, with a tamper-evident trail.
The difference between us and a generic compliance consultancy.
Shared phones, low literacy, 22 languages. The only kind of consent we’ve had to design for since 2015.
Grounded in the DPDP Act 2023 and the Rules 2025, not a generic checklist.
The certificate comes from an outside agency, not from us. We prepare you for it.
And aligned with DPDP and GDPR ourselves. We ask nothing we haven’t already done.
The phases, what each one involves, and what the audit at the end covers, on our dedicated DPDP site.
Provable consent is the requirement organisations get stuck on, so we built a product for it. Anumati is plug-and-play consent infrastructure: one API call from your MIS, a notice in any of 22 languages, OTP or signed-upload verification, and a tamper-evident trail you can produce on demand.