DPDP Shield
DPDP Act, 2023 · Indian healthcare

Patient data, guarded like patients.

One operating system for hospital privacy — continuous software, senior DPO judgment, and a dedicated Shield Manager working in concert.

01

Self-hosted hospital AI

02

22 patient languages

03

Human approval built in

Zero data egress22 Indian languages₹250 Cr at stake72-hour breach windowABDM-nativeAadhaar · PAN · ABHA · UHIDHuman-in-the-loopAudit-ready evidence
The stakes

The Act is generous with obligations — and unforgiving with deadlines.

Hospitals hold the most sensitive personal data there is. The Digital Personal Data Protection Act treats it that way: statutory windows measured in hours and days, penalties measured in hundreds of crores, and consent that must speak every patient’s language. Meeting that standard by hand isn’t a staffing plan — it’s a gamble.

250 Cr

Maximum penalty per breach under the DPDP Act, 2023

72 hrs

Statutory window to notify the Data Protection Board

30 days

Deadline to answer every patient data request

22

Indian languages every consent notice must speak

How it works

Audit. Fix. Maintain. Repeat — automatically.

the flywheel
  1. 01

    Audit

    The scanner maps every system, every table, every file share — and scores all ten statutory obligations.

  2. 02

    Fix

    Flagged items become tasks. Consent gaps close, DPAs get signed, DPIAs get drafted and approved.

  3. 03

    Maintain

    Continuous rescans, quarterly drills and a human Shield Manager keep the score green — permanently.

Module 01

Compliance Software

The backbone that never sleeps.

Scans every hospital system, builds a living data map, manages consent, automates DPIAs, handles DSARs, watches for breaches, tracks vendor risk and generates audit-ready evidence — continuously.

  • Explainable, weighted compliance score across all 10 statutory obligations
  • Four-layer PII detection tuned for Indian healthcare data
  • Zero data egress — findings leave, patient data never does
  • One-click, DPO-attested evidence packs for regulators
Explore the module
Module 02

DPO as a Service

Senior counsel, fractional cost.

Every hospital gets a named Data Protection Officer — a real, board-reporting relationship at a fraction of the cost of hiring full-time.

  • DPO signs off on DPIAs, breach notices and consent escalations
  • Grievance handling, vendor DPA legal review and board reporting
  • Dedicated console inside the DPDP Shield control plane
  • Fractional retainer from ₹5L/yr vs ₹20–50L full-time
Explore the module
Module 03

Dedicated Shield Manager

A human watching the machine.

A named operator assigned to your hospital who triages the dashboard daily, closes flagged items, runs your breach drills and escalates to the DPO only when real judgment is needed.

  • Daily scan review, DSAR triage and consent monitoring
  • Urgency-ranked task queue from P0 critical to P3 routine
  • One-click escalation paths to DPO or engineering
  • Quarterly tabletop breach drills, documented as evidence
Explore the module
Module 04

AI Consent Module

Consent at the speed of admission.

Admission starts a verifiable consent journey — guardian consent for minors, self-consent for adults and OTP or staff attestation. Self-hosted AI can draft notice text, but only a DPO-approved version is ever presented.

  • Purpose-by-purpose toggles, never a blanket checkbox
  • Situation-aware escalation: SMS, call, then human follow-up
  • Schema-validated AI drafts with deterministic fallback and provenance
  • Human guardian verification with opaque evidence references
Explore the module
Explainable, not a black box

One score your board can actually interrogate.

0Compliance score
<70 70–85 85+
  1. 01Consent validity15%
  2. 02Security safeguards15%
  3. 03Data minimisation10%
  4. 04Purpose limitation10%
  5. 05Breach readiness10%
  6. 06DPO & grievance handling10%
  7. 07Retention compliance10%
  8. 08Children & guardian consent10%
  9. 09Cross-border transfer5%
  10. 10Vendor compliance5%

Ten statutory obligations, individually scored and weighted — so when the number moves, you know exactly which obligation moved it.

Humans in the loop

Software flags. People decide.

The DPO

“Are we legally compliant with how we handle personal data?”

Your named Data Protection Officer signs off on every DPIA and breach notification, handles consent escalations, and reports to your board — a real, substantive relationship, not a name on paper.

The Shield Manager

“Is anything slipping today?”

A dedicated operator who triages your dashboard every morning, keeps every DSAR inside its deadline, runs your quarterly breach drills, and escalates to the DPO only when real judgment is needed.

Senior DPO coverage plus a dedicated Shield Manager at 50–70% below the cost of hiring a full-time DPO — because each expert serves a carefully-tiered portfolio of hospitals, never a thin spread of names.

Zero data egress

Findings leave. Patient data never does.

The scanner transmits type labels, counts, sensitivity tiers and change-detection hashes — never raw records. Sampled rows are processed locally, used only to generate findings, and discarded from memory. Nothing patient-identifiable ever reaches the cloud.

Begin the audit

Ready when you are. The Act already is.

A 30-minute walkthrough with our team — your systems, your tier, your gaps, and exactly what week one looks like.