Turn India's new privacy law
into your most recurring revenue line
A Chartered Accountant, Company Secretary and lawyer's guide to the DPDP Act 2023 and the DPDP Rules 2025: compliance, sectors, and building a privacy practice. Almost every digital business in India is now a Data Fiduciary with real obligations, the substantive duties become enforceable on 13 May 2027, and the practitioner who builds compliance in the window before then captures the stickiest, most defensible, most recurring work in practice.
From the team behind 500+ Indian startup incorporations since 2015. The timing is once-in-a-career: a brand-new privacy law, a fixed 13 May 2027 enforcement date, and almost every digital business now a Data Fiduciary. Every covered business must build compliance in the window before then, and the practitioner who leads that build captures the most recurring work in practice.

What You'll Learn
“Bought this because a couple of my clients started asking about the new data protection law and I did not want to keep saying I will check. It is clearly written and current, walks you through who is covered and what they have to do, and there is a genuinely useful section on how to price this as a service. Ended up scoping a small compliance engagement for a client within a few weeks of reading it. For the price it is easily worth it.”
CA Meera K · Chennai
Verified purchase
Take a Sneak Peek
The data-protection practice this book builds
Data protection is the highest-opportunity new work a practice can take on, and building it well means becoming fluent across four connected stages. They are connected because a single client moves through all of them: the law creates the obligation (the new privacy era), the Act sets out the duties (the framework and core concepts), some clients carry heightened duties (the special regimes and enforcement), and the whole must be delivered by a practice that prices it as recurring revenue (the compliance programme and the practice itself). This book is organised around these four.
01
The new privacy era and why it is the opportunity.
Why data protection is the practitioner's biggest new revenue line, the shift from the IT Act and SPDI Rules to the DPDP Act, and the global context that shapes it. Almost every digital business in India is now a Data Fiduciary. Covered in Part I.
02
The Act's architecture and core concepts.
The framework and the seven principles, lawful processing, consent and the legitimate uses, the notice and consent-manager architecture, and the obligations of the Data Fiduciary. The concepts every engagement rests on. Covered in Part II.
03
The special regimes, rights, and enforcement.
Children's and disabled persons' data, Significant Data Fiduciaries with their DPO, DPIA and audit duties, cross-border transfers, exemptions and the startup and MSME position, Data Principal rights, the Data Protection Board, appeals to the TDSAT, and breach response. Covered in Parts III and IV.
04
Applicability, the programme, and the practice itself.
Who is caught across fintech, healthtech, edtech, e-commerce, SaaS, gaming, adtech, AI and HR, the build-year roadmap and the documentation set, and the service lines, pricing, and recurring revenue that turn data protection into the stickiest line a firm runs. Covered in Parts V to VII.
A data-protection engagement is the rare compliance work that does not end when the project ends. An audit repeats, a DPO seat stays filled, a breach line stays staffed, a retainer renews. What begins as a one-time build becomes annual recurring revenue on the stickiest relationship a firm can hold. That recurring practice is exactly what this book builds.
Common signs you're leaving the data-protection opportunity on the table
From referring it out to owning the recurring work
Data protection is the most valuable new work a practice can add. It carries a fixed deadline, a board-level penalty exposure, and, uniquely, it recurs: an audit repeats, a DPO seat stays filled, a breach line stays staffed, a retainer renews. What separates the practitioner who owns this line from the one who refers it out is method, and method can be learned.
Meeting the new law without a method
Building the practice with the DPDP playbook
The fee math, before you even read the book
From Appendix H: indicative 2026 fee ranges for the principal data-protection engagements a covered Indian business generates in the build-year window and beyond. Several of these are recurring revenue, billed month after month. These are working ranges observed across the ecosystem; they vary by city, practice tier, and company complexity.
The handbook is ₹2,999. One DPIA, or a single month of a DPO-as-a-Service retainer, pays it back many times over, and the retainers keep paying every month after. It pays for itself on the first engagement it helps you win.
4.8 / 5(9 reviews)
Rated by Indian CA / CS practitioners
“The section on pricing and retainers was worth the whole book for me. Finally clear on what this work is actually worth.”
CA Rohit A · Pune
Verified purchase
“Well structured and easy to follow. The checklists and document list save a lot of time when you actually start a client.”
CS Pranav J · Pune
Verified purchase
“Solid overview and very current. Would have liked a couple more worked examples, but for the price I am not complaining.”
Aarti S · Bengaluru
Verified purchase
Built on real engagements
The team behind Finjour has been incorporating and advising Indian startups since 2015, with 500+ to date, and 100+ of them going on to raise ₹100 crore+ in angel, VC, or debt funding. We have drafted the agreements, run the valuations, signed the audits, and built the data, consent, and vendor relationships that the DPDP Act now regulates, which is exactly why we can see where the compliance work, and the fees, sit.
Every obligation in this book is grounded in the DPDP Act 2023 and the DPDP Rules 2025, mapped to the earlier IT Act and SPDI Rules it replaces, and tested against how Indian digital businesses actually process data, not borrowed from a GDPR textbook or generated by AI.
The CA, CS, CMA, and advocate practitioners we work alongside told us, repeatedly, what they wished existed for the moment a client asks whether the new privacy law applies to them. This is that book.
10+
Years operating
since 2015
500+
Indian startups
incorporated
100+
Funded rounds
angel · VC · debt
₹100Cr+
Capital raised
by startups we advised
Sectorsfintech · healthtech · edtech · e-commerce · SaaS · gaming · adtech · AI · HR
The mistakes that cost the client and the practitioner
Data-protection work is high-value and high-exposure in equal measure. These are the errors that leave revenue on the table or leave a client exposed, and where the book addresses each.
Assuming the new privacy law does not apply to a client's business
Almost every digital business is a Data Fiduciary: place it on the Sector-Applicability Matrix and scope the work
Treating data protection as a one-time project
Design the DPO, breach, and compliance retainers so the work recurs every month
Missing the children's-data and consent duties
The verifiable-consent and no-tracking rules, and the ₹200 crore exposure for breaching them
Overlooking a client's Significant Data Fiduciary status
The DPO, DPIA, and audit duties that follow designation, and the ₹150 crore exposure
Ignoring the breach-notification obligation
The breach playbook and the ₹200 crore penalty for failing to notify
Waiting past the build-year window to start
The obligations become enforceable on 13 May 2027: lead the build now
₹250Cr
the maximum penalty under the Act's Schedule for a security-safeguards failure
13 May 2027
the date the substantive DPDP obligations become enforceable
Recurring
revenue from DPO, breach-response, and compliance retainers, month after month
9
sectors deep-dived, from fintech to HR, so any client can be placed
“Good timing and good content. The deadline framing genuinely helps you have the conversation with clients.”
— CS Ramesh V · Hyderabad
What You'll Walk Away With
Answer the applicability question with confidence
When a client asks whether the new privacy law applies to them, you will know exactly how to place them: Data Fiduciary, Processor, or Significant Data Fiduciary, caught or exempt, and which duties bite. The judgement that opens the engagement.
Lead the build-year window
The substantive obligations become enforceable on 13 May 2027. You will know the roadmap, the milestones, and the sequence to lead a client's build from gap assessment to a live compliance programme before the clock runs out.
Build the documentation set that makes compliance real
The privacy notice, the consent architecture, the vendor DPAs, the RoPA, and the breach playbook, the documents that turn advice into a defensible posture, with a checklist library to work from.
Price the work as recurring revenue
The DPO-as-a-Service, breach-response, and ongoing compliance retainers billed month after month, and the fee schedule to price each to the value protected and the ₹250 crore exposure carried.
Advise any sector on its specific duties
The Sector-Applicability Matrix and the deep-dives across fintech, healthtech, edtech, e-commerce, SaaS, gaming, adtech, AI, and HR, so you can tell any client exactly where their data-protection work sits.
“Clear, current, and to the point. Answers the applicability question fast, which is what I needed.”
— CA Nidhi A · Ahmedabad
22 Chapters of Actionable Content
68 pages of structured, India-specific reference material.
Why a new law with a fixed deadline creates a rare, recurring, defensible line of work. Almost every digital business in India is now a Data Fiduciary, and the practitioner who builds compliance in the window before 13 May 2027 captures the stickiest client relationships in practice.
“Practical and well organised. Landed a new practice line from it within a month. Worth it.”
— CA Deepak B · Kochi
Referring it out vs owning the DPDP practice
Common Questions
No. It is a practitioner's working guide to building a data-protection practice around the DPDP Act 2023 and the DPDP Rules 2025, from the applicability question through the build-year programme, the documentation set, and the recurring service lines. It is not a substitute for the bare Act and the current Rules, and it is honest about where specialist legal counsel should be engaged.
The build-year window is open. Be the practice that leads it.
Join the practitioners who meet the new privacy law with a plan, lead the build-year work before the deadline, and turn a one-time project into recurring revenue on the stickiest client relationship in practice.

