DPDP Shield
The platform

Every obligation, engineered.

Four modules that work as one: software that watches continuously, legal expertise that decides, a Shield Manager who operates, and a consent engine that moves at the speed of admission.

Zero data egress22 Indian languages₹250 Cr at stake72-hour breach windowABDM-nativeAadhaar · PAN · ABHA · UHIDHuman-in-the-loopAudit-ready evidence
Module 01 · Compliance Software

The backbone that never sleeps.

1.1

Dashboard & Scoring

Are we compliant right now? One screen answers.

Ten statutory DPDP obligations, each scored 0–100 and combined into a weighted overall score — explainable, never a black box. Red below 70, amber to 85, green above. Role-based views for administrators, DPOs and the board, with continuous rescoring and AI-predicted score trajectory.

  • Weighted scoring across 10 statutory obligations
  • Role-based views: admin, DPO, Shield Manager, board
  • Continuous rescoring on every module’s latest state
  • Predictive AI flags a falling score before it turns red
1.2

Discovery & Living Data Map

Every place patient data lives, found and mapped.

A four-layer detection pipeline — regex, Presidio NER, India-specific NER for Hindi and Marathi, and LLM post-processing — discovers and classifies PII across every hospital system. Ready-made connectors for SoftClinic and Healthray, generic PostgreSQL support, and a living RoPA that keeps itself current with daily full scans and six-hourly incremental rescans.

  • Recognises Aadhaar, PAN, ABHA, UHID, UPI and more — with checksum validation
  • Four-tier sensitivity model, from mental health data to anonymised aggregates
  • Zero data egress: only findings transmit, never raw records
  • Auto-generated RoPA, exportable as PDF or Excel
1.4

DPIA Automation

AI drafts. Your DPO decides.

New vendor, new data category, new AI tool — each auto-opens a DPIA from healthcare-specific templates. The AI drafts the risk assessment from scan results, vendor records and data flows; a human DPO reviews, edits and signs. Every draft tracks its edit distance as an honest accuracy metric. The AI never auto-approves.

  • Auto-triggered by vendor, scanner and connector events
  • Templates for AI diagnostics, telemedicine, labs, research and ABDM
  • Draft-then-review workflow with recorded DPO sign-off
  • Draft-to-edit distance tracked on every assessment
1.5

Patient Rights & DSAR

Every request answered inside the 30-day window.

Access, correction, erasure and nomination requests flow from portal, email or phone into an OTP-verified, countdown-tracked pipeline. Automated search runs across every connected system via the living data map; escalation fires at day 25 and day 28 so nothing slips. Deceased-patient nomination and guardian access follow their own verified paths.

  • OTP identity verification on intake
  • Automated cross-system search via the data map
  • Auto-escalation at day 25 (Shield Manager) and day 28 (DPO)
  • Legally-grounded denial path where clinical retention is mandated
1.6

Breach Response

72 hours is enough — when the clock starts pre-armed.

Continuous anomaly detection over access logs and connector telemetry. On detection, the on-call Shield Manager is paged, affected data is auto-classified from the living map, and Board and patient notifications are drafted in plain multilingual language — queued for mandatory DPO approval before anything sends. Five pre-built hospital playbooks, rehearsed in quarterly tabletop drills.

  • Statistical anomaly detection over access patterns
  • Auto-classification of affected patients and categories
  • Drafted Board and patient notices with the 72-hour countdown
  • Playbooks for exfiltration, ransomware, lost devices and insiders
1.7

Vendor & Third-Party Risk

Labs, TPAs, insurers, AI vendors — scored and current.

Vendors are auto-discovered from actual data flows rather than self-reported lists. Category-specific DPA templates cover diagnostic labs, TPAs, billing SaaS and AI/ML vendors — including model-training exclusions and hallucination liability. Quarterly reassessment prompts keep every DPA and risk score current, feeding directly into the compliance score.

  • Auto-discovery of vendors from observed data flows
  • DPA templates by category, including AI-specific clauses
  • 90-day reassessment cycles with expiry alerts
  • Vendor posture feeds the compliance score directly
1.8

ABHA / ABDM Consent Layer

Two consent systems, properly linked — never conflated.

DPDP consent and ABDM consent artifacts are kept distinct and can be linked to the same patient. The current product implements M1 ABHA verification and patient linkage; M2/M3 HIE-CM exchange remains subject to NHA sandbox certification and provider onboarding.

  • M1 ABHA verification and durable patient linkage
  • DPDP and ABDM consent records kept distinct
  • M2/M3 exchange tracked as an external certification gate
  • Human-assisted ABDM onboarding
1.9

Evidence Packs

Audit-ready in one click, attested by humans.

One click assembles live data from every module — score and trend, RoPA, consent records, signed DPIAs, DSAR response times, breach timeline, vendor DPAs, ABDM status — sealed with a hash-chain verification and carrying the DPO’s attestation. PDF for the regulator, Excel for analysis, JSON for machines.

  • Live data pulled from all nine sub-modules
  • DPO attestation — stronger than a software-only trail
  • Hash-chain audit verification included
  • PDF, Excel and JSON exports
Module 02 · DPO as a Service

Senior counsel, fractional cost.

A named Data Protection Officer — real, board-reporting, and working through a dedicated console inside the platform — who owns DPIAs, breach notifications, consent escalations and grievance handling under the DPDP Act.

The DPO owns
  • Legal point of contact for the Data Protection Board
  • DPIA review, edits and recorded sign-off
  • Approval of every breach notification before it sends
  • Consent escalations needing legal judgment
  • Grievance oversight, vendor DPA legal review and board reporting
Hospital tierDPO engagementShield Manager
Small clinic (<50k records)Monthly reviewShared across 5–8 clinics
Mid-size private (50k–200k)Bi-weekly reviewShared across 2–4 hospitals
Large private / SDF (200k+)Weekly reviewDedicated, or across 1–2

A full-time DPO runs ₹20–50L a year. DPDP Shield bundles the DPO, the Shield Manager and the software at a fraction of the cost of hiring a DPO directly.

Module 03 · Dedicated Shield Manager

Every minute your DPO spends on triage is a minute lost to judgment.

The Shield Manager absorbs the operational load — daily scan reviews, DSAR triage, consent monitoring — and escalates only what needs real legal judgment. One console shows every hospital in their care as a single, urgency-ranked queue.

P0CriticalDSAR at day 28+, active breach, consent escalation beyond six hours
P1HighDSAR at day 25–27, consent past two hours, vendor DPA expired
P2MediumScan results to review, DPIA draft pending, vendor reassessment due
P3LowRoutine dashboard check, weekly status report

Escalate to DPO

Disputed guardian consent, deceased-patient DSARs, DPIA sign-off, breach notification approval.

Escalate to Engineering

A silently failing connector, scan results that don’t match reality, OTPs not sending.

One click carries the reason, urgency and notes with the task — whoever picks it up has full context immediately.

Begin the audit

Ready when you are. The Act already is.

A 30-minute walkthrough with our team — your systems, your tier, your gaps, and exactly what week one looks like.