GRC software tracks your data. DRMLAW carries your liability.
A GRC platform generates a checkmark. It cannot speak for the organisation when a breach happens, an AI pipeline leaks data, or the Data Protection Board of India sends a notice under Section 27. DRMLAW does not sell GRC platforms or security software — we assess the business, recommend and coordinate the right technology partners, govern AI usage, train staff, and represent the client before regulators when enforcement arrives.
The statutory penalty cap under the DPDPA, 2023 is ₹250 crore per instance for failure of reasonable security safeguards. Software helps; it does not answer that question alone.
- DPDPA Compliance Service Pack — Fixed-scope, fixed-timeline, fixed-fee: data mapping & RoPA, gap analysis, privacy notices & consent workflows, breach response SOP, staff training.
- Service Pack + DPO-as-a-Service — Adds a Section 10 statutory DPO with board-level reporting, DPIAs, CERT-In 6-hour breach notification management, and DPB representation.
- Platinum · Full Programme — Adds programme management, AI governance, Virtual CISO coordination, PETs guidance and certification readiness (NIST Privacy Framework, ISO/IEC 31700, ISO 27701).
FAQ
Do we need to buy any software or GRC platform from DRMLAW?
No. DRMLAW does not sell, license or resell any software or GRC platform. If your programme needs a consent management platform, a data discovery tool or a DSAR workflow engine, we evaluate vendors on fit and you contract with them directly.
Why do we need DRMLAW if we already use GRC software?
Because a GRC platform produces a checkmark — not a defence. It does not tell you whether the underlying processing activity was lawful, whether a privacy notice would survive a DPB inquiry, or whether an AI model needs an algorithmic impact assessment. DRMLAW supplies that legal judgement and accountability.
We don't have a DPO. Do we legally need one?
Under Section 10 of the DPDPA, only organisations designated as Significant Data Fiduciaries (SDFs) are legally required to appoint a DPO. For any organisation processing personal data at scale, appointing a DPO before formal designation signals governance maturity to clients, auditors and regulators.
What are the penalties for non-compliance?
The Schedule to the Act provides for monetary penalties up to ₹250 crore per instance of certain violations (failure to take reasonable security safeguards), with lesser amounts for breach of other duties. Penalties are determined by the Data Protection Board after inquiry.
How long does a Tier 1 engagement take?
Typically 10–16 weeks from kickoff to attestation pack, depending on the complexity of your data estate and vendor footprint. The plan is fixed-scope, fixed-timeline and fixed-fee.
Continue to the full page at https://www.drmlaw.in/technolegal/dpdpa