Privacy,orchestrated.
DPOGenie365 turns India's DPDP Act into a daily operating rhythm — consent with cryptographic proof, rights requests on SLA, breach response on two clocks, and evidence a regulator can actually read.
Weighted across consent, rights SLAs, breach readiness, inventory, policy, and processor coverage.
Four gaps. One penalty schedule.
Most Indian teams don't fail DPDPA on intent — they fail on proof. These are the four places the Act looks first.
Consent you can't prove
Permissions collected in forms and lost in databases — no versioned notice, no timestamped record, no proof.
Rights requests in inboxes
Access and erasure requests arriving by email, with no identity check, no deadline tracking, and no closure record.
Breach response by panic
Six hours for CERT-In, seventy-two for the Board — and the runbook lives in one person's head.
Evidence you can't export
Work that happened but can't be shown: screenshots, spreadsheets, and inbox archaeology at audit time.
Enforcement is a schedule, not a rumour.
DPDP Act enacted
India's Digital Personal Data Protection Act, 2023 receives assent. The obligations are law; the machinery follows.
DPDP Rules 2025 notified
Operational detail arrives — consent notice standards, breach reporting formats, the 90-day rights SLA, and children's data verification — with staggered effective dates.
Data Protection Board stands up
The adjudicating body becomes operational and begins receiving complaints from data principals.
The readiness windowYOU ARE HERE
The gap between "notified" and "enforced" is the cheapest compliance you will ever buy.
Full enforcement
Data principal rights, detailed breach reporting, and the bulk of operational obligations become enforceable — with the full penalty schedule behind them.
One flow. Many outcomes.
Discover
Find every record you hold. Agent-based PII discovery files each asset into a living inventory.
Consent
Capture purpose-level permission and route it to every system that relies on it — with proof.
Rights
Verify identity, then route access, correction, and erasure through governed channels on a 90-day SLA.
Policy
Notices and policies drafted from your real records — versioned, published, and acknowledged.
Evidence
Every action leaves the platform as tamper-evident proof, ready for the Board or the board.
Powered by XcellHost
Cloud, security, and AI foundations from XcellHost — India-hosted, enterprise-grade, always on.
Discover
Find every record you hold. Agent-based PII discovery files each asset into a living inventory.
Consent
Capture purpose-level permission and route it with proof.
Rights
Verify identity, route requests, resolve on a 90-day SLA.
Policy
Policies drafted from real records — versioned and acknowledged.
Evidence
Every action becomes tamper-evident proof.
Powered by XcellHost
Cloud, security, and AI foundations — India-hosted.
Fifteen modules. One operating system for DPDPA.
Every obligation in the Act maps to a module. Every module produces its own evidence.
Operational in under an hour.
Assess
A short guided questionnaire maps your exposure and priority actions.
~5 MINUTESMap with AI
Describe your business in plain English — Genie AI drafts purposes, notices, and your starting inventory.
~10 MINUTESEmbed
Two lines of JavaScript put the consent widget live in any of 22 Indian languages.
~10 MINUTESActivate
Publish your rights portal; the SLA engine starts with the first request.
~5 MINUTESThe day it happens.
An erasure request lands
It sits in a shared inbox. Nobody verifies the requester. Day 91 arrives before anyone notices a clock existed.
OTP-verified intake, automatic routing to the owner, a visible countdown, and a sealed closure record on resolution.
A vendor gets breached
You learn from the news. Nobody knows which datasets the vendor touched or whether a DPA was ever signed.
The processor's inventory link scopes the blast radius instantly; both notification clocks start with pre-filled reports.
The regulator writes to you
Three weeks of screenshots, exports, and hope — assembled by people who also have day jobs.
One export: consent proofs, rights case files, incident timelines, and your RoPA — timestamped and tamper-evident.
Priced for every stage of readiness.
Configurable inclusions, no surprise line items. Talk to us for current pricing.
Starter
- Consent Vault + JS SDK
- Rights Portal with SLA engine
- Breach Command (dual clocks)
- Data Inventory & RoPA
- Genie Data Map (core)
- Compliance Dashboard
- Genie AI · 50 msgs/mo
- Up to 3 team members
Growth
- Everything in Starter
- Vendor Risk Intelligence
- Risk Register + board PDF
- Re-consent campaigns
- Breach drill mode
- 7 Indian languages
- Genie AI · 200 msgs/mo
- Up to 10 team members
Business
- Everything in Growth
- Cloud Security Mapping (AWS)
- Children's Data module
- Policy Manager
- 19-control command center
- All 22 languages
- Genie AI · 1,000 msgs/mo
- Up to 25 team members
Enterprise
- Everything in Business
- DPIA & SDF workflows
- White-label rights portal
- Unlimited AWS accounts
- Custom domains & SSO
- Genie AI · 5,000 msgs/mo
- Unlimited team members
- Named success manager
Start before you spend.
Cookie & tracker scannerFREE
Scan your site for trackers firing before consent.
Penalty calculatorFREE
Estimate exposure across the Act's penalty schedule.
Breach cost estimatorFREE
Model the full cost of an incident by sector.
DPDP Act guideFREE
The Act, obligation by obligation, in plain English.
Compliance templatesFREE
RoPA, notices, DPIA, DPA, and retention starters.
Maturity assessmentFREE
20 questions, a scored band, and your top gaps.
PII scannerFREE
Detect 40+ Indian PII types across your data.
DPDPA certificationFREE
Self-paced courses with verifiable certificates.
Expert services, delivered into your tenant
Assessments and audits by empanelled experts — every artefact lands inside your DPOGenie365 workspace, not a PDF graveyard.
- DPDPA gap assessment
- DPDP audit (SDF standard)
- VAPT
- Cloud security review
- ISO 27001 / 27701
- SOC 2
- RBI · SEBI · IRDAI
- Managed SOC
Powered by XcellHost — Cloud | Security | AI
DPOGenie365 runs on XcellHost's India-hosted cloud and security stack. Partners — MSSPs, IT services firms, CAs, and consultancies — earn recurring commission with training, deal protection, and a demo sandbox.
- 15–25% recurring commission
- Deal protection up to 12 months
- Certification programme
- Partner portal