This post is for informational purposes only and does not constitute legal advice. The DPDP Act 2023 and its implementing Rules 2025 are relatively new — requirements may evolve through further notifications or guidance. Verify the current position with a qualified data protection lawyer before making compliance decisions.
Your company just received this email:
"I would like to know all personal data your organisation holds about me. This is a formal request under the DPDP Act."
It lands in a shared [email protected] inbox. Someone reads it. Forwards it to legal. Legal forwards it to engineering. Engineering says they need to check three databases. Nobody notes the date it arrived. Three weeks pass. When someone finally circles back, there are nine days left on the 30-day window the DPDP Rules require. Not enough time to locate the data, get legal sign-off, draft a response in the right language, and send it.
On day 32, you're in violation.
That scenario is the default for most Indian companies right now. Not because they're careless — but because nobody built the infrastructure for it.
I built DPDP Copilot to close that gap: a self-hosted operator tool that accepts public data requests, classifies them with Claude, drafts compliant multilingual replies, tracks every action as immutable evidence, and monitors SLA status in real time.
But before the tool, you need to understand what you're actually dealing with. Let's start with the law.
Built by Swapnanil Saha — swapnanilsaha.com
SOCIAL SHARE CARD GENERATOR