DPDP Compliance Consultant
Privacy Engineering for SaaS · Technology + Law
Most privacy advisors read your policy. I also read your code and your architecture diagrams.
I help SaaS teams build India's Digital Personal Data Protection Act, 2023 into the product itself — data maps, consent, access control, retention, and audit evidence. 10+ years of software engineering in Python, APIs, and cloud, plus an LL.B.
Technology + Law
Lawyers read the Act. Engineers read the code. I read both.
Most DPDP advice stops at a policy document. The hard part is making the product behave the way the policy says — knowing where every piece of personal data lives, who can reach it, and proving it gets deleted.
I spent 10+ years as a software engineer building those systems — APIs, multi-tenant platforms, identity and access control, cloud infrastructure — at companies like UST Global and Idemia, and as an independent consultant. In 2026 I completed an LL.B. at Lloyd Law College to understand the law I was engineering for.
So I can open your repository and your architecture diagrams, trace where personal data really flows, and turn each obligation into a schema change, a consent table, a deletion job, or an audit log — then explain the trade-offs to both your engineers and your counsel.
Years Software Engineering
Lloyd Law College, 2026
Act, 2023 Focus
Multi-tenant Specialist
Services
I review the pull request, not just the privacy policy — from mapping your data to shipping the controls and the evidence that they work.
A structured gap assessment of your product, data flows, and processes against DPDP Act obligations — ending in a prioritised remediation plan your developers can pick up directly.
Every personal-data field mapped: category, purpose, storage (tables, caches, object storage, logs, backups), access, sharing, and retention — with the Data Fiduciary / Data Processor role assessed per flow.
Consent records that capture purpose, status, timestamp, notice version, and withdrawal — used where consent is the lawful basis, and kept separate from other grounds such as employment-related legitimate use.
Role- and attribute-based access control per tenant and per role, with isolation enforced in the data layer so no query can cross a customer boundary.
Retention periods per data category, real deletion across databases, caches, backups, and logs, and a Data Principal rights workflow — intake, verification, discovery, response, audit trail.
Tamper-evident logs of who touched personal data, a breach runbook from detection to notification, and a register of every processor that receives personal data and why.
FastAPI and Django services designed for observability, testability, and growth.
AWS and GCP infrastructure with Terraform, Docker, and automated CI/CD.
RAG pipelines and LLM integrations — built with the same data-handling discipline.
Where the Act stands
The Act is neither “not yet in force” nor fully in force — obligations arrive in phases. The time to build controls is before the substantive duties apply.
The first phase of the Act commenced — the framework and the Data Protection Board begin to take shape.
The next phase of commencement. A good checkpoint to have your data inventory and ownership mapped.
Most substantive duties, including most of the DPDP Rules, 2025, apply. Controls and evidence should be live well before this.
Case study
A demonstration project showing how I approach DPDP readiness in a real SaaS architecture.
Architecture: Next.js, FastAPI, PostgreSQL, Redis, Object Storage, Email Provider
A demonstration B2B HRMS built so that every feature's personal-data handling is identifiable, documented, and defensible under the DPDP Act, 2023. The employer is treated as Data Fiduciary for its employees' data and the platform as Data Processor — but each flow is assessed on its own, because the platform becomes a Fiduciary for anything it does for its own purposes.
A demonstration project, not a client engagement. No real client data or audits are represented.
Cut a 48-hour processing job to 30 minutes by redesigning the execution engine.
Cross-cloud identity with Auth0 and Amazon Verified Permissions for independently owned services.
Enterprise SSO and automated verification for a workflow built around identity documents.
How an engagement runs
Six steps that end with controls running in production and records that show they work.
Free 30-minute call on your product, data, customers, and where you are with DPDP today.
Scope noteWalk every system and data flow to build the personal data inventory and assign Fiduciary / Processor roles.
Data inventoryCompare what exists against DPDP obligations and rank gaps by risk and effort.
Prioritised roadmapBuild consent, access control, retention, deletion, and rights workflows — alongside your team or hands-on.
Shipped controlsConsent records, notice versions, access logs, and deletion records that show the controls actually run.
Evidence & docsRunbooks for rights requests and breaches, team walkthrough, and ongoing support as rules evolve.
RunbooksToolkit
Experience
The systems where personal data actually lives — APIs, identity, multi-tenant platforms, and cloud infrastructure.
Technologies: FastAPI, Next.js, MongoDB, AWS IAM Identity Center, Terraform, CircleCI
Replaced a manual professional-credentialing process with automated verification — a workflow built around sensitive identity documents.
Technologies: FastAPI, React.js (Microfrontend), GCP Firestore, Pub/Sub, Cloud Functions, AWS, Terraform, Auth0, AVP
A multi-team operations platform where independently owned services plug in without a shared codebase — with access control as a first-class concern.
Technologies: FastAPI, LangChain, OpenAI API, Neo4j, Pinecone, BM25, MMR, MongoDB, Next.js
Helped an enterprise engineering team search GitHub and Confluence in natural language instead of losing hours hunting for answers.
Technologies: FastAPI, MCP, LangChain, HuggingFace Transformers, Playwright, BeautifulSoup, PostgreSQL
An AI-callable hotel search and pricing tool that travel agents query in plain English.
Technologies: FastAPI, GCP, AWS, Terraform, CircleCI, React.js, SQLAlchemy
Internal admin platform and tooling infrastructure spanning GCP and AWS environments.
Technologies: Django, AWS, Terraform
Supply chain resilience monitoring — tracking disruption signals across supplier networks.
Technologies: Flask, Python, Matplotlib, OpenCV, FFmpeg, NumPy, React.js
Road safety device platform — real-time video and image processing for European highways.
Technologies: Flask, Django, AWS, PostgreSQL, Tornado, Ansible, Docker, Redis, RabbitMQ
RPA platform — a bot execution engine that replaced manual business workflows with automated task queues.
Technologies: Python, Odoo, PHP, JavaScript, jQuery
E-commerce integration modules connecting online storefronts to ERP systems for international retail clients.
Education
Bachelor of Laws (LL.B.)
Law
2023 – 2026
Bachelor of Technology
Computer Science Engineering
August 2012 – August 2016
Get in touch
Tell me about your product and the personal data it handles. I'll tell you honestly where you stand and what to do first.