DPO role, done for you.
The DPDP Act requires a named DPO for Significant Data Fiduciaries. We give you one on retainer from ₹2,499 a month, with the same training and accountability as a full-time hire.
DPDP, SOC 2, ISO 27001, VAPT, POSH, CERT-In, RBI and SEBI compliance — delivered by named CAs, CSs and DPOs on the dcomply platform. Fixed-price retainers, not surprise invoices.
The Digital Personal Data Protection Act 2023 made India one of the most consequential privacy jurisdictions in the world. Penalties go up to ₹250 crore per violation. The compliance window closes in May 2027. Most Indian businesses — including businesses that think they are not touching personal data — fall under scope the moment they take an email address or a phone number.
Enterprise buyers, meanwhile, are refusing to sign without SOC 2 Type II or ISO 27001. Banks demand DPDP certificates before releasing credit lines. RBI and SEBI are tightening master directions every quarter. The CERT-In 6-hour breach-reporting window is not a suggestion.
Running this in-house means a Chief Compliance Officer, a Data Protection Officer, two or three analysts, a security engineer, auditor fees and a lot of overtime. For most companies under ₹500 crore in revenue, that is three to five times what the problem is worth.
Cosmoura runs compliance as a retainer. A named lead — CA, CS or DPO depending on the framework — owns your account. Our in-house SaaS platform dcomply.in automates evidence collection, policy versioning and buyer-questionnaire response. Our sister concern Decipher Consultancy Services builds the AI tooling that handles the repetitive bits. You get regulator-grade compliance without a regulator-grade cost base.
DPDP deadline: The Act is in force. Rules are being notified in phases. Significant Data Fiduciary classification is coming. Prepare now; retrofit later costs 4–6× more.
What we handle
DPDP is where most clients start. Add SOC 2, ISO 27001 and sector-specific packs as your buyers and regulators demand them.
Featured · Deadline May 2027
Done-for-you Digital Personal Data Protection Act compliance in 15–30 days. Gap assessment, personal-data mapping, consent architecture, vendor review and DPAs, policies, employee training. Live on dcomply platform for ongoing rights-request handling.
Ongoing
A named Data Protection Officer on retainer. Rights-request handling (access, correction, deletion), breach response within statutory windows, monthly compliance reporting, regulator liaison. The DPO role, without the full-time hire.
Audit-ready
SOC 2 Type I and Type II preparation. Policy drafting (TSC-aligned), evidence collection via dcomply, control mapping, auditor coordination. We take you from zero to audit-ready in 90 days, then run the Type II observation window with you.
Certification
ISMS build-out, Statement of Applicability, risk register, internal audit, management review, and certification body coordination. ISO 27701 (privacy extension) layered on top where DPDP + GDPR scope demands it.
Security
Web, mobile, infrastructure and API penetration testing by CERT-In empanelled partners. OWASP + CIS benchmarked. Fix-verify cycles included. Report in the format your buyer or regulator actually wants.
Industry-regulated
Sector-specific compliance for NBFCs, PA-PGs, PPIs, Account Aggregators, AMCs, brokers and insurers. Master directions mapped to controls. Monthly / quarterly returns filed. Scrutiny and inspection response support.
Workplace
Internal Complaints Committee setup, external member appointment, mandatory POSH training (English + Hindi + regional), annual report filing. Shops & Establishment, Factories Act, and state-specific labour returns.
Incident
Breach notification setup within 6-hour statutory window. Log retention policy (180 days), incident response playbooks, tabletop exercises, VAPT scheduling. On-call coordination when something actually fires.
How we deliver
The schedule compresses for DPDP-only engagements (4–6 weeks) and extends for multi-framework engagements (16–20 weeks).
Week 1
We walk your current state against the framework you need to comply with — DPDP Act, SOC 2, ISO 27001, or sector-specific regulation. Interviews with engineering, HR, finance, legal and vendor management. Written gap report with risk-prioritised action list.
Week 2–4
Scope statement locked. 12-week deliverable calendar signed off. Policy library drafted (DPDP: ~15 policies; SOC 2: ~40 policies; ISO 27001: ~45 policies + SoA). Risk register populated. Control-to-evidence mapping started.
Week 4–12
Controls implemented across engineering, HR, vendor and infrastructure. Evidence collected into dcomply platform (automated where possible). Employee training rolled out. Vendor DPAs renegotiated. Breach response tabletop run.
Week 12+
External auditor engaged (for SOC 2 / ISO 27001) or regulator coordination (for DPDP / sector-specific). After certification, retainer continues at a reduced rate — rights-request handling, continuous monitoring, annual re-certification prep.
How we compare
Honest comparison on cost, speed, coverage and the parts most consultants quietly skip.
| In-house team | Traditional consultant | Cosmoura retainer | |
|---|---|---|---|
| DPO role | ₹25–40L/yr full-time hire | Not offered | Named DPO from ₹2,499/mo |
| Multi-framework (SOC 2 + ISO + DPDP) | 18+ months typical | Sequential — 24 months | Parallel tracks — 6–9 months |
| Evidence collection | Manual spreadsheets | Shared drive upload | Automated via dcomply platform |
| Breach response SLA | Depends on team | Business hours only | 6-hour window, on-call 24×7 |
| Buyer questionnaire response | 2–3 days per questionnaire | Case-by-case | Answer library · 24h turnaround |
| Cost (SOC 2 + ISO + DPDP) | ₹60L+/yr fully loaded | ₹35–50L one-time + hourly | ₹25–35L one-time + ₹5L/yr retainer |
| Regulator liaison | Legal team handles | Added fee | Included — DPO is your face |
Why Cosmoura
The DPDP Act requires a named DPO for Significant Data Fiduciaries. We give you one on retainer from ₹2,499 a month, with the same training and accountability as a full-time hire.
SOC 2, ISO 27001 and DPDP share roughly 60% of their controls. We map them once and run three parallel audit tracks. Cuts your total compliance effort by ~40%.
Evidence collection runs on dcomply.in — our in-house compliance platform. Automated collection, auditor-ready exports, buyer questionnaire answer library. You do not maintain a spreadsheet.
What's included
Industry packs
DPDP + factory + labour + CCTV + biometric consent
DPDP children's data + POSH + CBSE compliance + fee-app review
DPDP patient data + HIPAA-adjacent + lab vendor DPAs + CDSCO
RBI master directions + SOC 2 + ISO 27001 + CERT-In + DPDP
DPDP + consumer protection + shipping vendor DPAs + returns
SOC 2 + ISO 27001 + DPDP + GDPR + buyer questionnaires
FAQ
Our back-office runs on Decipher AI and the dcomply platform. That means we deliver the same quality a traditional CA/CS firm does, at 3–4× the throughput and 60–80% lower cost per deliverable. You still get senior human signoffs on everything.
Yes — this is the most common engagement. We map overlapping controls once and run parallel audit tracks, which cuts your overall effort by roughly 40% versus sequential projects. Typical multi-framework engagement runs 6–9 months end to end.
We prepare you fully and coordinate with external auditors / regulators of your choice. For SOC 2 and ISO 27001 we have preferred audit partners we can introduce; for RBI/SEBI/CERT-In we work with your appointed authorities.
Most clients move onto a monthly retainer (Virtual DPO + ongoing compliance management) starting from ₹25,000/month. This handles rights requests, policy updates when regulations change, quarterly reviews and audit renewals.
Yes — our delivery is fully online across India. On-site training and workshops are available in NCR, Mumbai, Bangalore and Hyderabad on request.
No. We provide compliance implementation and documentation services. For specific legal disputes or interpretations, consult your appointed legal counsel.
An SDF is a data processor classified by the Data Protection Board as significant based on volume, sensitivity, risk and critical infrastructure impact. SDFs must appoint a DPO (not a Virtual DPO), conduct annual data protection impact assessments, and submit to annual audits. We prepare clients ahead of SDF notification.
Yes. We maintain an on-call rota, run quarterly tabletop exercises, and coordinate CERT-In reporting within the 6-hour statutory window. Breach retainer is included in Growth tier and above.
Deadline is 2027
Free 30-minute compliance audit. We benchmark your current posture against DPDP, SOC 2 and your sector regulator, then come back with a sequenced plan.