For SMEs

A defensible DPDP baseline, without a privacy team.

Binary AIQ walks a founder or operating lead through the exact records the DPDP Act asks for, then keeps them current as the business changes.

For SMEs with 20 to 500 employees, no full-time DPO, and no existing privacy programme.

01
Business risk

DPDP applies from day one. Penalties scale with the incident, not the company.

The Digital Personal Data Protection Act, 2023 imposes obligations from the first byte of personal data processed. The Schedule to the Act lists financial penalties for failures around breach notification, children's data and reasonable security safeguards.

"A monetary penalty which may extend to two hundred and fifty crore rupees" — DPDP Act 2023, Schedule.
02
Operational challenge

Founders are running compliance from email threads and shared drives.

The people signing DPAs, publishing notices and answering data-principal requests are the same people running the business. Without a system, evidence lives in memory.

  • No inventory of systems that process personal data.
  • Notice drafted once, then forgotten across product changes.
  • Consent captured in a form, never reconciled with what's being done with the data.
  • Vendor DPAs signed and filed, never renewed or reviewed.
03
Binary AIQ workflow

A guided wizard produces the baseline in one working week.

The SME setup path builds the minimum defensible record: what data is held, why, on what basis, with whom it is shared, and how a data principal can act on their rights.

  1. 01
    Setup wizard
    Founder answers a short questionnaire; Binary AIQ scaffolds systems, applications and vendors from the answers.
  2. 02
    Processing record
    One Record of Processing Activity per business function, linked to lawful basis under DPDP §6.
  3. 03
    Notice generator
    A single-page notice is generated from the processing record — never drafted freehand.
  4. 04
    Consent capture
    Consent Center wires into the website and product; withdrawal is a first-class action, not an email.
  5. 05
    DSR intake
    A public rights portal accepts access, correction and erasure requests with SLA tracking against §13.
  6. 06
    Vendor register
    Third-party processors listed with DPA status and renewal reminders.
04
Proof / evidence

Every action leaves an attested record the founder can show a lawyer.

Binary AIQ replaces "we did that, I'll find the email" with a lineage-tracked record. Every publish, withdrawal, DSR and vendor change is versioned and time-stamped.

Artifacts generated
  • Signed Record of Processing Activities (PDF)
  • Published privacy notice with version history
  • Consent receipts with capture timestamp and purpose
  • DSR case files with SLA clock and closure evidence
  • Vendor register with DPA status per counterparty
  • Audit log showing who changed what and when
05
Outcome

A baseline programme the board and auditor can rely on.

In a matter of weeks, an SME moves from "we handle privacy carefully" to a documented programme with owners, evidence and review cadence.

Setup time
1–2 wks
Records produced
8+
Founder hours
< 6