Skip to content
FaceOff Technologies

Buyer's guide

How to evaluate a DPDP compliance platform

Fifteen questions to put to any vendor, including us. Each one maps to an obligation under the Act, and each has an answer that sounds good in a demo and an answer that survives an inquiry.

Questions
15 across 4 areas
Deadline
13 May 2027
Programme
9–12 months typical
Max penalty
₹250 Cr, per instance

Why this is a checklist, not a scorecard

Vendor comparison tables age badly and tend to be written by whoever wins them. These are the questions that separate a platform that enforces from one that records — put them to every vendor on your list, including FaceOff, and compare the answers you get rather than the columns someone else filled in.

01

Consent that actually holds

Sec. 6(1)

Does a downstream system have to check consent before it processes, or is consent only recorded?

Consent that no system queries is a record, not a control. If the CRM can process regardless, the lawful basis fails at the point it matters.

A demo answer sounds like
A consent log, with enforcement described as a roadmap item or an integration you build.
A real answer sounds like
A real-time API downstream systems call at query time, and an acknowledgement returned from each consumer.
FaceOff’s answer
Every consumer queries the ledger before processing and returns an ack that lands in the audit trail. Consent Management

Sec. 6(4)

Is withdrawal exactly as easy as consent, and can you prove the click parity?

Sec. 6(4) requires parity. A two-click grant with a five-step withdrawal is a defect a regulator can verify from outside your perimeter.

A demo answer sounds like
Withdrawal via a support ticket, an email address, or a preference centre three levels deep.
A real answer sounds like
Withdrawal on the same surface as the grant, with the flows measured against each other.
FaceOff’s answer
One-click withdrawal with parity enforced against the give-flow, and cessation tracked to an SLA. Consent Management

Sec. 5

Can it serve notice in the Eighth Schedule languages, and replay the exact notice a person saw?

Sec. 5 entitles a Principal to notice in any of 22 languages besides English. Proving consent means producing the notice version displayed at the time.

A demo answer sounds like
One English notice, with a link to a policy page that has since changed.
A real answer sounds like
Versioned notice per purpose, localised, with the served version bound to the consent record.
FaceOff’s answer
22 scheduled languages plus English, every notice stored and replayable against the Principal who saw it. Consent Management

Sec. 6(1)

Do non-essential tags stay dormant until opt-in, on single-page apps and authenticated journeys?

A tag that fires pre-consent is unlawful processing from the first pageview. It is also the easiest defect for anyone to verify with browser dev tools.

A demo answer sounds like
A banner that appears while analytics has already loaded, or scanning that only covers public marketing pages.
A real answer sounds like
Default-deny prior blocking, with scans that reach SPAs, subdomains and logged-in journeys.
FaceOff’s answer
Prior blocking with scheduled crawls across SPAs and authenticated journeys, and drift alerts on new cookies. Cookie Management

02

Knowing where the data is

Sec. 8(6), 8(7), 11

Can it answer “where is this person's data?” as a query, across unstructured sources?

Erasure, access and breach notification all depend on a complete store list. Structured-only discovery misses the file shares and mailboxes where the exposure usually sits.

A demo answer sounds like
A spreadsheet inventory refreshed quarterly, or scanning limited to databases.
A real answer sounds like
Continuous scanning of structured, semi-structured and unstructured sources with identity resolution across systems.
FaceOff’s answer
Scheduled and event-triggered rescans with drift detection, feeding DSAR, redaction and erasure directly. Intelligent Data Mapper

Sec. 10(2)(c)(iii)

Is the classifier explainable, and can you audit a false positive?

Sec. 10(2)(c)(iii) requires due diligence of algorithmic software. A classifier you cannot interrogate is itself an unassessed algorithm.

A demo answer sounds like
A confidence score with no visibility into what produced it.
A real answer sounds like
The detection chain per finding, showing which layers agreed and which dismissed it.
FaceOff’s answer
Per-finding detection chain, provenance tiers and layer-level consensus, with false-positive auditing built in. Intelligent Data Mapper

Sec. 5

Does discovery reconcile what you collect against what your notice declares?

Notice must itemise what is actually collected. Undeclared collection is a Sec. 5 defect that no consent flow can cure.

A demo answer sounds like
Notice maintained by hand in legal, discovery maintained separately in security, with no reconciliation.
A real answer sounds like
A reconciliation that surfaces collection no notice covers.
FaceOff’s answer
Discovery compares declared against present data and surfaces the delta. Intelligent Data Mapper

03

Proving it under inquiry

Sec. 28

Is the audit trail produced by operating the controls, or assembled when an auditor asks?

Under a Sec. 28 inquiry the Board weighs mitigating action taken promptly. Evidence reconstructed after the fact is worth less than evidence generated at the time.

A demo answer sounds like
Reporting built from exports at quarter end.
A real answer sounds like
An append-only trail written as a by-product of running the platform.
FaceOff’s answer
Immutable timestamped trail across all products, with Board-facing packages assembled from the same records. Audit & Evidence

Sec. 10(2)(b)

Can an external auditor be given evidence without being given the estate?

An SDF must appoint an independent data auditor. Granting broad access to satisfy an audit creates the exposure the audit is meant to test.

A demo answer sounds like
Auditor access via shared credentials or bulk data exports.
A real answer sounds like
A scoped workspace serving masked evidence, with sampling that needs no raw export.
FaceOff’s answer
Scoped auditor workspace, evidence masked by default, findings tracked to remediation. Audit & Evidence

Sec. 8(6)

When an incident is scoped to systems, how long to turn that into a list of affected Principals?

Sec. 8(6) requires intimation to the Board and to each affected Principal. This step is where the window is usually lost.

A demo answer sounds like
A manual investigation across system owners, measured in weeks.
A real answer sounds like
A catalogue query that converts system scope into an individual list.
FaceOff’s answer
Incident scope resolves through the catalogue into the exact list, with intimations generated and evidenced from it. Data Breach Management

04

Architecture and longevity

Sec. 8(4)

Do the modules share one catalogue and one consent record, or integrate with each other?

Products that integrate reconcile; products that share a fabric do not need to. Reconciliation is where evidence chains break.

A demo answer sounds like
A suite assembled by acquisition, with connectors between modules and a separate data model each.
A real answer sounds like
One catalogue, one consent record of truth, one policy engine, one trail beneath every module.
FaceOff’s answer
Eight products on one fabric — a rights request, an audit and a breach all resolve against the same records. Privacy Program Governance

Is a new regulation configuration over existing controls, or another purchase?

DPDP will not be the last. What you buy for DPDP should still work when the next regime lands.

A demo answer sounds like
A DPDP module priced separately from the GDPR module, with controls duplicated between them.
A real answer sounds like
One control library that each regime maps onto.
FaceOff’s answer
DPDP, GDPR, CCPA/CPRA, LGPD and PIPEDA run against one library; a new regime is a mapping. Privacy Program Governance

Sec. 16

Can it run on-premise or in-country, and does inference store biometric templates?

Sec. 16 permits transfer except to restricted territories, and data residency is frequently a sectoral requirement independent of the Act.

A demo answer sounds like
Single-tenant cloud in one region, with residency described as available on request.
A real answer sounds like
On-premise or in-country deployment, with a clear statement of what is retained.
FaceOff’s answer
On-premise, in-country or edge deployment. Inference is stateless and no biometric templates are stored. Federated FaceOff

Sec. 6(7)–(9)

Are the consent artefacts interoperable enough for a registered Consent Manager?

Consent Manager registration is expected to open around November 2026. Interoperability designed in later is a rebuild.

A demo answer sounds like
A proprietary consent schema with export to CSV.
A real answer sounds like
Consent artefacts emitted in an interoperable format with Consent Manager-ready APIs.
FaceOff’s answer
Interoperable artefacts and Consent Manager-ready APIs, so registration is configuration rather than a rebuild. Consent Management

Sec. 10(2)(c)(iii)

Does the vendor carry its own algorithmic due diligence?

If a vendor's AI touches your Principals' data, its models fall inside your Sec. 10 duty, not just its own.

A demo answer sounds like
AI capability marketed heavily, with no model inventory or bias testing offered for review.
A real answer sounds like
A model register, documented training-data provenance, bias testing and human oversight you can inspect.
FaceOff’s answer
Algorithmic due diligence runs as a dedicated assessment type on our models and yours. AI Governance

Questions

Common questions from evaluations

How do I compare DPDP compliance platforms?
Compare on enforcement rather than features. Ask whether downstream systems must check consent before processing, whether discovery reaches unstructured sources, whether the audit trail is generated by running the controls or assembled on request, and whether the modules share one catalogue or integrate with each other. A feature checklist will not separate vendors; those four questions will.
What is the difference between a Consent Manager and a Consent Management Platform?
A Consent Manager is an entity registered with the Data Protection Board that gives a Data Principal one interoperable place to manage consent across many Data Fiduciaries, and carries a minimum net-worth requirement. A Consent Management Platform is the software an organisation runs internally to capture, enforce and evidence consent on its own channels. You deploy a CMP; you register as, or integrate with, a Consent Manager.
Do we need a separate tool for cookies and for consent?
No, and separating them is usually the cause of the defect. Cookie consent is one capture channel for the same purpose-scoped consent object. When the banner keeps its own store, the preference a visitor sets there never reaches the systems that process their data.
How long does a DPDP compliance programme take?
Typically nine to twelve months from gap assessment to audit readiness for an enterprise. The sequence matters more than the duration: discovery first, because every other obligation is undeliverable without a catalogue, then masking and breach detection because they carry the largest penalty exposure, then consent, then rights and audit.

Put these questions to us.

Bring the checklist to a walkthrough. We will answer every one against your estate rather than a demo environment, and tell you where we are not the right fit.