7Unit TRACE

DPDP Exposure Analysis

Where controls become evidence.

Run the free readiness check

7UNIT / TRACE · SURFACE

Where controls become evidence.

For Indian operators, CTOs and compliance owners — not a free PDF quiz

Can you prove one person’s data trail — or only hope you are safe?

In client calls and readiness reviews, leadership often feels covered by ISO, SOC, a privacy policy, or counsel notes. Then we ask for consent evidence, system maps, vendor paths and erasure proof. That is where exposure shows up.

Free readiness check first · TRACE Surface · technical and operational readiness, not a legal opinion

About 3 minutes · structured operational assessment · no credit card · your category-level exposure signal, then you decide what to fund.

01 / WHAT YOU LEAVE WITH

Clarity you can take to leadership — before you fund the wrong programme

The paid analysis is deliberately bounded. You get an exposure profile and a prioritised plan — not a certificate and not a full implementation.

01

Exposure profile

Where your organisation is operationally weak — not a fake compliance percentage.

02

Evidence gaps

Consent, access, vendors, retention and erasure paths that cannot currently be proved.

03

Priority list

What to fix first if enforcement pressure, a rights request, or a board question arrives.

04

30 / 60 / 90 roadmap

A practical next-step plan before you fund a larger implementation programme.

02 / FALSE SAFETY

Feeling safe is not the same as being able to prove it

Patterns from readiness conversations and executive reviews — anonymised, recurring, and usually expensive to discover late.

Common misconception

ISO 27001 or SOC 2 ≠ DPDP readiness

Security certifications strengthen controls. DPDP still asks whether you can evidence purpose, notice, consent or permitted use, access, vendors, retention, withdrawal and erasure for personal data — including children’s data where relevant. Teams that collapse “certified” into “compliant” often walk into the session confident and leave with a gap list.

Pattern we see

“We are ISO / SOC certified, so DPDP is covered.”

ISO 27001 and SOC 2 are valuable security and control frameworks. They are not a DPDP readiness programme. They do not by themselves prove consent notice versions, purpose limitation, children’s-data safeguards, rights fulfilment across CRM + WhatsApp + payroll, or vendor processing under Indian law.

Pattern we see

“Our privacy policy and cookie banner are live.”

Policy text is not operational evidence. In executive sessions we often find notices that do not match the form actually shown, consent that cannot be retrieved by person or timestamp, and withdrawals that never reach downstream tools.

Pattern we see

“Legal said we are fine — until we asked for one person’s trail.”

Leadership felt safe until we asked a simple question: can you locate one individual’s data across every system, prove why it is there, and stop or erase it with evidence? That is where confidence usually breaks.

Pattern we see

“Vendors handle it for us.”

Processors reduce work; they do not remove accountability. Teams that cannot list who receives personal data, for what purpose, and how erasure propagates discover exposure only when a request or incident forces the map.

03 / THE OPERATIONAL TEST

Five questions that separate policy from operations

DPDP obligations are being brought into force in phases. Organisations should treat readiness as an operational programme, not a last-minute checkbox.

Run the free readiness check →

Q.01

Can you prove when and how consent was obtained?

Q.02

Can you locate every system where an individual’s data exists?

Q.03

Do you know every employee and vendor with access?

Q.04

Can you stop processing or fulfil an erasure request across all systems?

Q.05

Can you produce evidence of these actions?

05 / DATA JOURNEY

Where personal data actually moves

Exposure appears between systems — not only in the privacy policy.

01

Collection

Website form · WhatsApp

02

Consent or permitted use

Notice version · purpose

03

Storage

CRM · spreadsheet · cloud drive

04

Internal access

Payroll · support desk

05

Processor / vendor sharing

External vendor · API

06

Retention

Purpose-linked periods

07

Rights request

Correction · withdrawal

08

Erasure or cessation

Primary + downstream

06 / HIGH-RISK USE CASES

Where operational gaps concentrate

AGE < 18

Children’s data

Do you process personal data of individuals below 18? Assess parental consent, notice design, tracking or behavioural monitoring restrictions, access, retention, sharing and erasure workflows.

HR / PAYROLL

Employee and payroll data

HRMS, payroll processors, attendance, and benefits systems often hold persistent personal data with broad internal access.

TALENT

Recruitment and candidate data

Portals, agencies, and spreadsheets create fragmented candidate records that are hard to locate, retain lawfully, or erase.

HEALTH

Health and patient data

Clinical, wellness, and insurance workflows demand stronger operational controls across systems and vendors.

GROWTH

Customer and lead data

Marketing, CRM, WhatsApp, and support tools multiply collection points and consent contexts.

VENDORS

Third-party processor / vendor data

If you cannot list who receives personal data and why, rights fulfilment and incident response stall.

07 / WHY 7UNIT

Evidence-led, engineering-led

01

Compliance-heavy delivery

Engineering experience in fintech and healthcare environments where evidence and access controls are not optional.

02

Real system inspection

We inspect workflows, systems, APIs, databases and vendor movement — not only policy documents.

03

Build after assess

Technical plus operational implementation capability after the executive session, when you choose to proceed.

04

Built on TRACE Surface

TRACE Surface maps what your public estate can actually prove — structured evidence, checks and action tracking. Built by the 7Unit engineering team.

08 / WHO RUNS THE SESSION

Who runs the session

Dipin Krishnan

Founder & CEO, 7Unit Softwares Pvt. Ltd.

Leads the executive session. Engineering and delivery background in compliance-heavy environments where evidence, access control and auditability are contractual, not optional.

LinkedIn →

Harish Venkat

CTO & Co-founder

Reviews every exposure summary before it reaches you. Owns the TRACE Surface evidence and assessment architecture.

Current engagements include DPDP readiness work with organisations operating HR platforms with 1M+ end users, K-12 education systems, and RBI-regulated financial entities.

09 / NEXT STEP

Test the assumption that you are safe.Then decide what to fund.

Start the free readiness check →

Free readiness check first · paid executive analysis ₹15,000 only if you choose to reserve it

How your data moves here

Browser → encrypted application endpoint → TRACE assessment database → authorised 7Unit team → payment provider / calendar only when you choose to proceed → analytics / ad measurement tools only when you grant optional cookie consent

The DPDP Act provides for significant penalties for specified contraventions — readiness is about operational evidence, not panic. This assessment is a technical and operational readiness product built by the 7Unit engineering team, not a legal opinion or statutory certification. It does not constitute legal advice or representation. Patterns described above are composite from readiness conversations; they are not attributions to named clients.