Turn India's new privacy law
into your most recurring revenue line

A Chartered Accountant, Company Secretary and lawyer's guide to the DPDP Act 2023 and the DPDP Rules 2025: compliance, sectors, and building a privacy practice. Almost every digital business in India is now a Data Fiduciary with real obligations, the substantive duties become enforceable on 13 May 2027, and the practitioner who builds compliance in the window before then captures the stickiest, most defensible, most recurring work in practice.

(4.8)
Loved by 9+ Indian practitioners
A new law with a fixed 2027 deadlineAlmost every digital business is a Data FiduciaryRecurring revenue, not one-time projectsSector deep-dives and a full fee schedule

From the team behind 500+ Indian startup incorporations since 2015. The timing is once-in-a-career: a brand-new privacy law, a fixed 13 May 2027 enforcement date, and almost every digital business now a Data Fiduciary. Every covered business must build compliance in the window before then, and the practitioner who leads that build captures the most recurring work in practice.

Read sample chapters
The Data Protection Compliance Handbook

What You'll Learn

How to place any business under the Act: Data Fiduciary, Processor, or Significant Data Fiduciary, caught or exempt
How the seven principles, lawful processing, and the consent-manager architecture actually work in practice
How to run the build-year roadmap and hit the milestones before the 13 May 2027 enforcement date
How to build the documentation set: notices, consent, DPAs, RoPA, and the breach playbook
How the heightened duties apply: children's data, Significant Data Fiduciaries, DPO, DPIA, audit, and cross-border transfers
How the Data Protection Board, its penalties up to ₹250 crore, and appeals to the TDSAT operate
How data protection applies across fintech, healthtech, edtech, e-commerce, SaaS, gaming, adtech, AI, and HR
How to price the service lines and design retainers that turn a one-time build into recurring revenue

Bought this because a couple of my clients started asking about the new data protection law and I did not want to keep saying I will check. It is clearly written and current, walks you through who is covered and what they have to do, and there is a genuinely useful section on how to price this as a service. Ended up scoping a small compliance engagement for a client within a few weeks of reading it. For the price it is easily worth it.

CA Meera K · Chennai

Verified purchase

Take a Sneak Peek

Loading preview…

The data-protection practice this book builds

Data protection is the highest-opportunity new work a practice can take on, and building it well means becoming fluent across four connected stages. They are connected because a single client moves through all of them: the law creates the obligation (the new privacy era), the Act sets out the duties (the framework and core concepts), some clients carry heightened duties (the special regimes and enforcement), and the whole must be delivered by a practice that prices it as recurring revenue (the compliance programme and the practice itself). This book is organised around these four.

01

The new privacy era and why it is the opportunity.

Why data protection is the practitioner's biggest new revenue line, the shift from the IT Act and SPDI Rules to the DPDP Act, and the global context that shapes it. Almost every digital business in India is now a Data Fiduciary. Covered in Part I.

02

The Act's architecture and core concepts.

The framework and the seven principles, lawful processing, consent and the legitimate uses, the notice and consent-manager architecture, and the obligations of the Data Fiduciary. The concepts every engagement rests on. Covered in Part II.

03

The special regimes, rights, and enforcement.

Children's and disabled persons' data, Significant Data Fiduciaries with their DPO, DPIA and audit duties, cross-border transfers, exemptions and the startup and MSME position, Data Principal rights, the Data Protection Board, appeals to the TDSAT, and breach response. Covered in Parts III and IV.

04

Applicability, the programme, and the practice itself.

Who is caught across fintech, healthtech, edtech, e-commerce, SaaS, gaming, adtech, AI and HR, the build-year roadmap and the documentation set, and the service lines, pricing, and recurring revenue that turn data protection into the stickiest line a firm runs. Covered in Parts V to VII.

A data-protection engagement is the rare compliance work that does not end when the project ends. An audit repeats, a DPO seat stays filled, a breach line stays staffed, a retainer renews. What begins as a one-time build becomes annual recurring revenue on the stickiest relationship a firm can hold. That recurring practice is exactly what this book builds.

Common signs you're leaving the data-protection opportunity on the table

A client asks whether the new privacy law applies to them and you are not sure how to answer
You treat data protection as a legal matter to refer out, not a compliance line to own
You cannot say whether a given business is a Data Fiduciary, a Processor, or a Significant Data Fiduciary
You have never scoped a DPIA, a RoPA, or a breach playbook for a client
You are pricing privacy advice as a one-time note, not as a recurring retainer
You have no view on the 13 May 2027 clock or what a client must build before it

From referring it out to owning the recurring work

Data protection is the most valuable new work a practice can add. It carries a fixed deadline, a board-level penalty exposure, and, uniquely, it recurs: an audit repeats, a DPO seat stays filled, a breach line stays staffed, a retainer renews. What separates the practitioner who owns this line from the one who refers it out is method, and method can be learned.

Meeting the new law without a method

Freezing when a client asks whether the privacy law applies to them
Referring the whole matter out and keeping none of the recurring revenue
Guessing whether a business is caught, exempt, or a Significant Data Fiduciary
Delivering a one-time note instead of a build-year programme
Pricing privacy advice like a compliance filing
Missing the 13 May 2027 window while competitors build

Building the practice with the DPDP playbook

Placing any business on the matrix and scoping the gap assessment with confidence
Owning the build, the documentation set, and the retainers that follow
Knowing exactly which duties bite: consent, DPIA, DPO, breach, cross-border
Leading the build-year roadmap to a live, defensible compliance posture
Pricing to the value and the exposure, using the Appendix H fee schedule
Winning the build-year work before the enforcement date, then keeping it on retainer

The fee math, before you even read the book

From Appendix H: indicative 2026 fee ranges for the principal data-protection engagements a covered Indian business generates in the build-year window and beyond. Several of these are recurring revenue, billed month after month. These are working ranges observed across the ecosystem; they vary by city, practice tier, and company complexity.

Readiness & gap assessment (one-time)₹75,000 – 5,00,000+
Notice, consent & policy suite (one-time)₹50,000 – 2,50,000
DPA review & remediation (per vendor)₹40,000 – 2,00,000+
Data Protection Impact Assessment / DPIA (per new processing)₹1,00,000 – 5,00,000
DPO-as-a-Service (monthly retainer, recurring revenue)₹40,000 – 2,50,000 / month
Independent data audit, Significant Data Fiduciary (annual, recurring)₹3,00,000 – 15,00,000+
Breach-response retainer (monthly, recurring revenue)₹25,000 – 1,00,000 / month
Ongoing compliance retainer (monthly, recurring revenue)₹30,000 – 2,00,000 / month

The handbook is ₹2,999. One DPIA, or a single month of a DPO-as-a-Service retainer, pays it back many times over, and the retainers keep paying every month after. It pays for itself on the first engagement it helps you win.

4.8 / 5(9 reviews)

Rated by Indian CA / CS practitioners

The section on pricing and retainers was worth the whole book for me. Finally clear on what this work is actually worth.

C

CA Rohit A · Pune

Verified purchase

Well structured and easy to follow. The checklists and document list save a lot of time when you actually start a client.

C

CS Pranav J · Pune

Verified purchase

Solid overview and very current. Would have liked a couple more worked examples, but for the price I am not complaining.

A

Aarti S · Bengaluru

Verified purchase

Built on real engagements

The team behind Finjour has been incorporating and advising Indian startups since 2015, with 500+ to date, and 100+ of them going on to raise ₹100 crore+ in angel, VC, or debt funding. We have drafted the agreements, run the valuations, signed the audits, and built the data, consent, and vendor relationships that the DPDP Act now regulates, which is exactly why we can see where the compliance work, and the fees, sit.

Every obligation in this book is grounded in the DPDP Act 2023 and the DPDP Rules 2025, mapped to the earlier IT Act and SPDI Rules it replaces, and tested against how Indian digital businesses actually process data, not borrowed from a GDPR textbook or generated by AI.

The CA, CS, CMA, and advocate practitioners we work alongside told us, repeatedly, what they wished existed for the moment a client asks whether the new privacy law applies to them. This is that book.

10+

Years operating

since 2015

500+

Indian startups

incorporated

100+

Funded rounds

angel · VC · debt

₹100Cr+

Capital raised

by startups we advised

Sectorsfintech · healthtech · edtech · e-commerce · SaaS · gaming · adtech · AI · HR

The mistakes that cost the client and the practitioner

Data-protection work is high-value and high-exposure in equal measure. These are the errors that leave revenue on the table or leave a client exposed, and where the book addresses each.

Assuming the new privacy law does not apply to a client's business

Almost every digital business is a Data Fiduciary: place it on the Sector-Applicability Matrix and scope the work

Chapter 15

Treating data protection as a one-time project

Design the DPO, breach, and compliance retainers so the work recurs every month

Chapter 21

Missing the children's-data and consent duties

The verifiable-consent and no-tracking rules, and the ₹200 crore exposure for breaching them

Chapter 8

Overlooking a client's Significant Data Fiduciary status

The DPO, DPIA, and audit duties that follow designation, and the ₹150 crore exposure

Chapter 9

Ignoring the breach-notification obligation

The breach playbook and the ₹200 crore penalty for failing to notify

Chapter 14

Waiting past the build-year window to start

The obligations become enforceable on 13 May 2027: lead the build now

Chapter 18

₹250Cr

the maximum penalty under the Act's Schedule for a security-safeguards failure

13 May 2027

the date the substantive DPDP obligations become enforceable

Recurring

revenue from DPO, breach-response, and compliance retainers, month after month

9

sectors deep-dived, from fintech to HR, so any client can be placed

Good timing and good content. The deadline framing genuinely helps you have the conversation with clients.

CS Ramesh V · Hyderabad

What You'll Walk Away With

Answer the applicability question with confidence

When a client asks whether the new privacy law applies to them, you will know exactly how to place them: Data Fiduciary, Processor, or Significant Data Fiduciary, caught or exempt, and which duties bite. The judgement that opens the engagement.

Lead the build-year window

The substantive obligations become enforceable on 13 May 2027. You will know the roadmap, the milestones, and the sequence to lead a client's build from gap assessment to a live compliance programme before the clock runs out.

Build the documentation set that makes compliance real

The privacy notice, the consent architecture, the vendor DPAs, the RoPA, and the breach playbook, the documents that turn advice into a defensible posture, with a checklist library to work from.

Price the work as recurring revenue

The DPO-as-a-Service, breach-response, and ongoing compliance retainers billed month after month, and the fee schedule to price each to the value protected and the ₹250 crore exposure carried.

Advise any sector on its specific duties

The Sector-Applicability Matrix and the deep-dives across fintech, healthtech, edtech, e-commerce, SaaS, gaming, adtech, AI, and HR, so you can tell any client exactly where their data-protection work sits.

Clear, current, and to the point. Answers the applicability question fast, which is what I needed.

CA Nidhi A · Ahmedabad

22 Chapters of Actionable Content

68 pages of structured, India-specific reference material.

PDF with checklist library, fee schedule and document index inside3-4 hours read
Get Instant Access

Why a new law with a fixed deadline creates a rare, recurring, defensible line of work. Almost every digital business in India is now a Data Fiduciary, and the practitioner who builds compliance in the window before 13 May 2027 captures the stickiest client relationships in practice.

Practical and well organised. Landed a new practice line from it within a month. Worth it.

CA Deepak B · Kochi

Referring it out vs owning the DPDP practice

Referring it out
This guide
A client asks if it applies
Unsure, or refers it out
Places them on the matrix and scopes the gap assessment
The engagement shape
A one-time note
A build-year programme, then monthly retainers
The duties
Vague on which apply
Consent, DPIA, DPO, breach, cross-border mapped to the client
The exposure
Not raised
The ₹250 crore Schedule made real to the board
The fee
Priced like a filing
Priced to value and exposure, with the Appendix H fee schedule

Common Questions

No. It is a practitioner's working guide to building a data-protection practice around the DPDP Act 2023 and the DPDP Rules 2025, from the applicability question through the build-year programme, the documentation set, and the recurring service lines. It is not a substitute for the bare Act and the current Rules, and it is honest about where specialist legal counsel should be engaged.

The build-year window is open. Be the practice that leads it.

Join the practitioners who meet the new privacy law with a plan, lead the build-year work before the deadline, and turn a one-time project into recurring revenue on the stickiest client relationship in practice.

2999799963% OFF