A defensible DPDP baseline, without a privacy team.
Binary AIQ walks a founder or operating lead through the exact records the DPDP Act asks for, then keeps them current as the business changes.
For SMEs with 20 to 500 employees, no full-time DPO, and no existing privacy programme.
DPDP applies from day one. Penalties scale with the incident, not the company.
The Digital Personal Data Protection Act, 2023 imposes obligations from the first byte of personal data processed. The Schedule to the Act lists financial penalties for failures around breach notification, children's data and reasonable security safeguards.
"A monetary penalty which may extend to two hundred and fifty crore rupees" — DPDP Act 2023, Schedule.
Founders are running compliance from email threads and shared drives.
The people signing DPAs, publishing notices and answering data-principal requests are the same people running the business. Without a system, evidence lives in memory.
- No inventory of systems that process personal data.
- Notice drafted once, then forgotten across product changes.
- Consent captured in a form, never reconciled with what's being done with the data.
- Vendor DPAs signed and filed, never renewed or reviewed.
A guided wizard produces the baseline in one working week.
The SME setup path builds the minimum defensible record: what data is held, why, on what basis, with whom it is shared, and how a data principal can act on their rights.
- 01Setup wizardFounder answers a short questionnaire; Binary AIQ scaffolds systems, applications and vendors from the answers.
- 02Processing recordOne Record of Processing Activity per business function, linked to lawful basis under DPDP §6.
- 03Notice generatorA single-page notice is generated from the processing record — never drafted freehand.
- 04Consent captureConsent Center wires into the website and product; withdrawal is a first-class action, not an email.
- 05DSR intakeA public rights portal accepts access, correction and erasure requests with SLA tracking against §13.
- 06Vendor registerThird-party processors listed with DPA status and renewal reminders.
Every action leaves an attested record the founder can show a lawyer.
Binary AIQ replaces "we did that, I'll find the email" with a lineage-tracked record. Every publish, withdrawal, DSR and vendor change is versioned and time-stamped.
- Signed Record of Processing Activities (PDF)
- Published privacy notice with version history
- Consent receipts with capture timestamp and purpose
- DSR case files with SLA clock and closure evidence
- Vendor register with DPA status per counterparty
- Audit log showing who changed what and when
A baseline programme the board and auditor can rely on.
In a matter of weeks, an SME moves from "we handle privacy carefully" to a documented programme with owners, evidence and review cadence.
- Setup time
- 1–2 wks
- Records produced
- 8+
- Founder hours
- < 6
