The DPDP Rules are phasing in through 2026 and 2027. Most organisations are working towards full operational compliance by May 2027.

What this means for you

Home / Trust centre

We ask clients to document how they handle data. Here is ours.

A data protection practice that cannot show its own position has no business assessing yours. Everything we publish about our own handling of information sits on this page.

Straight answer

What we do not claim.

We are a new practice. We hold no ISO certification, we have not been through an external security audit, and we are not going to display badges we have not earned. Several firms in this market do, and a buyer cannot easily tell the difference between a certificate and a logo on a page.

What we offer instead is specific and checkable. We publish our commitments with times attached, we publish exactly what we do with access to your systems, and we publish completion criteria for every document we produce. You can hold us to all three, and you can ask for any of it in writing before you engage us.

If your procurement process requires a certified supplier, say so on the first call. We will tell you honestly whether we clear your bar, and if we do not, we would rather say so than waste a month of your time.

Published commitmentsYes
Data handling policyYes
Completion criteriaYes
Confidentiality by defaultYes
Vendor referral feesNone accepted
ISO certificationNot held
External security auditNot yet
Client names publishedOnly with consent