Book a demo
DPDP Rules 2025 ready Data hosted in India 22 Indian languages Powered by XcellHost

Privacy,orchestrated.

DPOGenie365 turns India's DPDP Act into a daily operating rhythm — consent with cryptographic proof, rights requests on SLA, breach response on two clocks, and evidence a regulator can actually read.

Scroll to orchestrate
Built for regulated and fast-moving Indian teams
FintechSaaSHealthtech EdTechBFSID2C & Commerce IT ServicesProfessional services
The exposure

Four gaps. One penalty schedule.

Most Indian teams don't fail DPDPA on intent — they fail on proof. These are the four places the Act looks first.

₹250 CrS.5 · S.6

Consent you can't prove

Permissions collected in forms and lost in databases — no versioned notice, no timestamped record, no proof.

₹50 CrS.11–14

Rights requests in inboxes

Access and erasure requests arriving by email, with no identity check, no deadline tracking, and no closure record.

₹200 CrS.8(6) · Rule 7

Breach response by panic

Six hours for CERT-In, seventy-two for the Board — and the runbook lives in one person's head.

₹150 CrS.8 · S.10

Evidence you can't export

Work that happened but can't be shown: screenshots, spreadsheets, and inbox archaeology at audit time.

The clock

Enforcement is a schedule, not a rumour.

Aug 2023

DPDP Act enacted

India's Digital Personal Data Protection Act, 2023 receives assent. The obligations are law; the machinery follows.

Nov 2025

DPDP Rules 2025 notified

Operational detail arrives — consent notice standards, breach reporting formats, the 90-day rights SLA, and children's data verification — with staggered effective dates.

2026

Data Protection Board stands up

The adjudicating body becomes operational and begins receiving complaints from data principals.

Today

The readiness windowYOU ARE HERE

The gap between "notified" and "enforced" is the cheapest compliance you will ever buy.

May 2027

Full enforcement

Data principal rights, detailed breach reporting, and the bulk of operational obligations become enforceable — with the full penalty schedule behind them.

01 / 06

One flow. Many outcomes.

01

Discover

Find every record you hold. Agent-based PII discovery files each asset into a living inventory.

Scan → classify → shelve
02

Consent

Capture purpose-level permission and route it to every system that relies on it — with proof.

Notice → capture → prove
03

Rights

Verify identity, then route access, correction, and erasure through governed channels on a 90-day SLA.

Verify → route → resolve
04

Policy

Notices and policies drafted from your real records — versioned, published, and acknowledged.

Draft → publish → acknowledge
05

Evidence

Every action leaves the platform as tamper-evident proof, ready for the Board or the board.

Capture → seal → report
06

Powered by XcellHost

Cloud, security, and AI foundations from XcellHost — India-hosted, enterprise-grade, always on.

Cloud | Security | AI
01

Discover

Find every record you hold. Agent-based PII discovery files each asset into a living inventory.

Glass hexagon vault with shelves of data records
02

Consent

Capture purpose-level permission and route it with proof.

Glass gateway routing consent to four glowing pads
03

Rights

Verify identity, route requests, resolve on a 90-day SLA.

Rights gateway with three transparent channels
04

Policy

Policies drafted from real records — versioned and acknowledged.

Glass hexagon holding a policy scroll
05

Evidence

Every action becomes tamper-evident proof.

Evidence ribbon flowing through a glass hexagon
06

Powered by XcellHost

Cloud, security, and AI foundations — India-hosted.

XcellHost and DPOGenie365 puzzle pieces joined
The platform

Fifteen modules. One operating system for DPDPA.

Every obligation in the Act maps to a module. Every module produces its own evidence.

Onboarding

Operational in under an hour.

01

Assess

A short guided questionnaire maps your exposure and priority actions.

~5 MINUTES
02

Map with AI

Describe your business in plain English — Genie AI drafts purposes, notices, and your starting inventory.

~10 MINUTES
03

Embed

Two lines of JavaScript put the consent widget live in any of 22 Indian languages.

~10 MINUTES
04

Activate

Publish your rights portal; the SLA engine starts with the first request.

~5 MINUTES
Real situations

The day it happens.

An erasure request lands

Without DPOGenie365

It sits in a shared inbox. Nobody verifies the requester. Day 91 arrives before anyone notices a clock existed.

With DPOGenie365

OTP-verified intake, automatic routing to the owner, a visible countdown, and a sealed closure record on resolution.

A vendor gets breached

Without DPOGenie365

You learn from the news. Nobody knows which datasets the vendor touched or whether a DPA was ever signed.

With DPOGenie365

The processor's inventory link scopes the blast radius instantly; both notification clocks start with pre-filled reports.

The regulator writes to you

Without DPOGenie365

Three weeks of screenshots, exports, and hope — assembled by people who also have day jobs.

With DPOGenie365

One export: consent proofs, rights case files, incident timelines, and your RoPA — timestamped and tamper-evident.

Plans

Priced for every stage of readiness.

Configurable inclusions, no surprise line items. Talk to us for current pricing.

Starter

Early-stage startups getting compliant fast.
  • Consent Vault + JS SDK
  • Rights Portal with SLA engine
  • Breach Command (dual clocks)
  • Data Inventory & RoPA
  • Genie Data Map (core)
  • Compliance Dashboard
  • Genie AI · 50 msgs/mo
  • Up to 3 team members
Book a demo
MOST POPULAR

Growth

Funded startups scaling their privacy program.
  • Everything in Starter
  • Vendor Risk Intelligence
  • Risk Register + board PDF
  • Re-consent campaigns
  • Breach drill mode
  • 7 Indian languages
  • Genie AI · 200 msgs/mo
  • Up to 10 team members
Book a demo

Business

Regulated sectors — fintech, health, education.
  • Everything in Growth
  • Cloud Security Mapping (AWS)
  • Children's Data module
  • Policy Manager
  • 19-control command center
  • All 22 languages
  • Genie AI · 1,000 msgs/mo
  • Up to 25 team members
Book a demo

Enterprise

Significant Data Fiduciaries and large estates.
  • Everything in Business
  • DPIA & SDF workflows
  • White-label rights portal
  • Unlimited AWS accounts
  • Custom domains & SSO
  • Genie AI · 5,000 msgs/mo
  • Unlimited team members
  • Named success manager
Book a demo
Data resident in IndiaWORM evidence vaultSHA-256 proof recordsImmutable audit logsDPDP Rules 2025 alignedMulti-tenant isolation

Expert services, delivered into your tenant

Assessments and audits by empanelled experts — every artefact lands inside your DPOGenie365 workspace, not a PDF graveyard.

  • DPDPA gap assessment
  • DPDP audit (SDF standard)
  • VAPT
  • Cloud security review
  • ISO 27001 / 27701
  • SOC 2
  • RBI · SEBI · IRDAI
  • Managed SOC
Scope a project

Powered by XcellHost — Cloud | Security | AI

DPOGenie365 runs on XcellHost's India-hosted cloud and security stack. Partners — MSSPs, IT services firms, CAs, and consultancies — earn recurring commission with training, deal protection, and a demo sandbox.

  • 15–25% recurring commission
  • Deal protection up to 12 months
  • Certification programme
  • Partner portal
XcellHost and DPOGenie365 logos on interlocking puzzle pieces
Straight answers

DPDPA, answered directly.

What is the DPDP Act and who must comply?
India's Digital Personal Data Protection Act, 2023 applies to any organisation processing digital personal data of individuals in India — there is no small-business carve-out by default. If you collect emails, phone numbers, or any personal data digitally, you are a Data Fiduciary with obligations under the Act.
How fast must a breach be reported?
Two clocks run in India. CERT-In directions require intimation of certain cyber incidents within 6 hours. DPDP Rules 2025 require notifying the Data Protection Board and affected individuals, with detailed reporting inside 72 hours. DPOGenie365 tracks both clocks on a single incident record.
How long do we have to answer a rights request?
DPDP Rules 2025 give Data Fiduciaries 90 days to respond to access, correction, and erasure requests. DPOGenie365 runs a live countdown on every case with escalating alerts well before the deadline.
What is a Significant Data Fiduciary?
An SDF is designated by the Central Government based on data volume, sensitivity, and risk — with no published threshold. Designation brings an India-based DPO, periodic DPIAs, audits, and extra records. Because it can arrive without warning, Enterprise-grade readiness is the hedge.
Do cookies need consent under DPDPA?
Tracking identifiers that can identify a person are personal data, so firing analytics or marketing scripts before consent is processing without notice. Our CMP holds categorised scripts out of the page until that category is granted.
What are the penalties?
The schedule allows up to ₹250 crore per violation: ₹250 Cr for security-safeguard failures, ₹200 Cr for breach-notification failures and children's-data violations, and ₹50 Cr for other defaults including rights-handling failures.

Orchestrate privacy.
Deliver trust.

DPOGenie365 helps your team stay ahead, every day.

Book a demo
15Modules covering every DPDPA obligation
< 60 minFrom signup to operational compliance
22Indian languages for consent capture
2 clocksCERT-In 6-hour + DPDPA 72-hour, tracked together