← Back to list

I Fact Checked Three Popular DPDP Compliance Template Packs Against the Actual Law.

Manan Patel · 2026-07-09 08:26 · 153 claps · 3.1 min read
#data-privacy #compliance #india #indian #dpdp-act
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity ⚖️ · Law & Justice

I Fact Checked Three Popular DPDP Compliance Template Packs Against the Actual Law. None of Them Passed Clean.

If you run a business in India, you have probably typed some version of "DPDP compliance template" into a search bar in the last few months. What comes back looks reassuring. Polished PDFs, confident language, section numbers scattered through every paragraph like proof of homework done. It all looks official.

Most of it is not what it claims to be.

I spent the last few weeks doing something almost nobody actually does before trusting a compliance template. I opened the real documents, the Digital Personal Data Protection Act 2023 and the Rules notified in November 2025, and checked every citation in three widely circulated template packs line by line. Not skimmed. Checked.

Here is what I found.

Pack one: ComplyDP, the brochure

The first pack came from ComplyDP, a compliance consultancy, and reads like a sales page, because it is one. Twelve templates, breezy explanations, numbers stated with total confidence and zero citations attached. A seven day erasure deadline that does not actually appear anywhere in the Act or Rules. A single flat seventy two hour breach notification window, when the real Rule sets out a two stage process, an immediate initial report followed by a more detailed one within that window. None of it is malicious. It is just written the way marketing gets written, to sound authoritative rather than to survive an audit.

Pack two: ISpectra Technologies, the flat pack furniture

The second pack was a five policy suite from ISpectra Technologies, a technology consultancy. Assemble required, one size fits all. It never drops below Section level, never engages with a single Rule, and reads the same whether you are a two person startup or a bank. Nothing in it is technically wrong exactly, it is just too generic to be load bearing. You could hand this to any company on earth and it would apply equally poorly to all of them.

Pack three: PRICORIS, the carpenter with the mislabeled toolbox

This one surprised me. Nine documents from PRICORIS, a real compliance practice, genuinely well built, genuinely Rule specific, splitting Data Fiduciary and Data Processor obligations the way the law actually requires. Then I checked the citations.

The breach notification register cited Rule 12 for the Board and Data Principal intimation process. Rule 12 is actually the child data exemptions rule. Breach notification lives in Rule 7. Same register also cited Rule 8(3) for the one year log retention requirement. That figure is real, it just sits in Rule 6(1)(e), not Rule 8.

Then the exemptions cheat sheet made a bigger mistake. It listed Section 16 as a surviving obligation when a company invokes the Section 17(1) exemption, and described Section 16 as governing children's data protections. Section 16 is actually the cross border transfer restriction, children's protections live in Section 9, and Section 16 is not a survivor of the exemption at all, the actual text disapplies it completely. That is the kind of error that would tell a reader the opposite of what the law says.

Good craftsmanship, wrong labels on two of the drawers.

Why this matters more than it sounds like it should

A compliance document with a wrong citation is not a typo. If your breach response procedure points your team to the wrong Rule number during an actual incident, someone loses time they do not have. If your exemptions analysis tells you a restriction has been lifted when it has not, you find out the hard way, in front of a regulator, not in a review.

The gap here was not really about writing quality. All three are readable. The gap was about whether anyone actually checked the citations against the primary source before publishing them. None of them did, carefully enough, all the way through.

So here is the actual takeaway, and it is a genuinely useful one. Do not trust a compliance template because it looks official. Trust it because you checked it. Open the Gazette notification yourself, pick three citations at random from whatever pack lands on your desk, and run them down. Twenty minutes, that is all it takes, and it will tell you more than a hundred pages of confident formatting ever could. Your business is going to rely on these documents the day something actually goes wrong. Make sure they can carry the weight before that day arrives.

And this is not where the story ends. There is a fourth pack out there, built completely differently from the three above, one that does not hand every business the same static file but actually generates a different document set depending on who you are, a school, a bank, an offshore vendor, each getting exactly what the law requires them to have and nothing they do not. I ran it through the same line by line check. It held up far better than anything above.

That story is next. Stay tuned.


메타데이터
post_id
e0f3be7745ae
slug
i-fact-checked-three-popular-dpdp-compliance-template-packs-against-the-actual-law-e0f3be7745ae
url
https://medium.com/@manan05.patel/i-fact-checked-three-popular-dpdp-compliance-template-packs-against-the-actual-law-e0f3be7745ae
canonical_url
https://medium.com/@manan05.patel/i-fact-checked-three-popular-dpdp-compliance-template-packs-against-the-actual-law-e0f3be7745ae
author_url
https://medium.com/@manan05.patel
status
ok
fetched_at
2026-07-10 07:28:19