Most of the DPDP Act is a question about your code.

Notice, erasure, purpose limitation and security safeguards are all statements about what your software does. No amount of policy drafting answers any of them.

01 · The split

What the code can answer, and what it cannot.

Being honest about the second column is the point. A tool that claims to make you DPDP compliant is lying; a tool that tells you which obligations it can evidence, and evidences them, is useful.

DPDP §5evidenced from code
Notice, in a language they read
Notice must be available in English and the Eighth Schedule languages. That is a property of your banner, not of your policy PDF.
DPDP §6evidenced from code
Consent that is specific and revocable
Free, specific, informed and unconditional, with withdrawal as easy as giving. Provable only from the record you kept at the time.
DPDP §8(1)evidenced from code
Accuracy and completeness
You are responsible for what your processors do with the data too, which means knowing which processors receive it.
DPDP §8(5)evidenced from code
Reasonable security safeguards
The clause behind most findings we raise: personal data in logs, unencrypted at rest, reachable by more of the system than needs it.
DPDP §8(7)evidenced from code
Erasure on withdrawal
When consent is withdrawn, the data goes. This is the obligation almost nobody can evidence, because it requires code that deletes.
DPDP §10organisational
Significant Data Fiduciary duties
DPIAs, audits and an appointed DPO. Organisational, not code, though the data map is the input every DPIA needs.
02 · The one nobody can evidence§8(7)

Withdrawal means deletion. Can your code do it?

Every organisation says it honours withdrawal. Very few have checked whether a delete path exists for every field they hold. Scrutora looks for the code that would delete or export each one and tells you which fields have none, before someone asks.

On a real scan of a public banking platform, no delete or export path existed for a third of the personal-data fields it stored. That is not an unusual result.

scrutora
Erasure coverage across classified fields, with covered and not-covered marked per field.
03 · Notice§5

Eighth Schedule languages, without a translation project.

The banner auto-translates to the visitor’s browser language. Hindi, Marathi, Gujarati, Tamil, Kannada, Telugu, Bengali, Malayalam and Punjabi ship pre-translated, and you can override any wording per language when your counsel wants their own phrasing.

scrutora
Banner language configuration with Indian languages, per-language banner text, and the purpose list.
Purposes carry a required or functional flag, and publishing a notice version keeps the record of what each person was actually shown.
04 · Safeguards

Where §8(5) actually breaks.

IN THE LOGS

An identifier written in the clear for debugging. The most common finding we raise, and the easiest to fix.

AT REST

A store holding personal data with no encryption asserted, or a backup whose access control was widened and never narrowed.

ON THE WAY OUT

A processor receiving more than it needs, or one nobody recorded as a recipient at all.

05 · Rule 6, control by control

Seven safeguards. Each one has a page, and each one has a check.

The Rules are due by May 2027. Rule 6(1) lists the minimum technical controls a Data Fiduciary must show. For each one: what the clause asks for, what the code can evidence, and what it cannot.

DPDP consent managementIndia data residency in IaCConsent, verified against code