Taking on DPDP readiness engagements

Himanshu Kumar Singh

DPDP Compliance Consultant

Privacy Engineering for SaaS · Technology + Law

Most privacy advisors read your policy. I also read your code and your architecture diagrams.

I help SaaS teams build India's Digital Personal Data Protection Act, 2023 into the product itself — data maps, consent, access control, retention, and audit evidence. 10+ years of software engineering in Python, APIs, and cloud, plus an LL.B.

10+
Years software engineering
LL.B.
Lloyd Law College
DPDP
Act, 2023 focus
Portrait of Himanshu Kumar Singh
Greater Noida · Remote

Technology + Law

Why a software engineer with a law degree

Lawyers read the Act. Engineers read the code. I read both.

Most DPDP advice stops at a policy document. The hard part is making the product behave the way the policy says — knowing where every piece of personal data lives, who can reach it, and proving it gets deleted.

I spent 10+ years as a software engineer building those systems — APIs, multi-tenant platforms, identity and access control, cloud infrastructure — at companies like UST Global and Idemia, and as an independent consultant. In 2026 I completed an LL.B. at Lloyd Law College to understand the law I was engineering for.

So I can open your repository and your architecture diagrams, trace where personal data really flows, and turn each obligation into a schema change, a consent table, a deletion job, or an audit log — then explain the trade-offs to both your engineers and your counsel.

Who I work with

  • B2B SaaS companies processing their customers' employee or user data
  • HR-tech, fintech-adjacent, and ed-tech products handling personal data at scale
  • Engineering leaders who need a DPDP plan their team can actually build
  • Legal and compliance teams who need a technical partner to implement their policies

10+

Years Software Engineering

LL.B.

Lloyd Law College, 2026

DPDP

Act, 2023 Focus

SaaS

Multi-tenant Specialist

Services

DPDP compliance, built into the product

I review the pull request, not just the privacy policy — from mapping your data to shipping the controls and the evidence that they work.

DPDP Readiness Review

A structured gap assessment of your product, data flows, and processes against DPDP Act obligations — ending in a prioritised remediation plan your developers can pick up directly.

Gap Assessment
Roadmap

Personal Data Inventory & Mapping

Every personal-data field mapped: category, purpose, storage (tables, caches, object storage, logs, backups), access, sharing, and retention — with the Data Fiduciary / Data Processor role assessed per flow.

Data Mapping
Fiduciary vs Processor

Consent & Notice Architecture

Consent records that capture purpose, status, timestamp, notice version, and withdrawal — used where consent is the lawful basis, and kept separate from other grounds such as employment-related legitimate use.

Consent Records
Notices

Access Control & Tenant Isolation

Role- and attribute-based access control per tenant and per role, with isolation enforced in the data layer so no query can cross a customer boundary.

RBAC / ABAC
Multi-tenant SaaS

Retention, Deletion & Rights Requests

Retention periods per data category, real deletion across databases, caches, backups, and logs, and a Data Principal rights workflow — intake, verification, discovery, response, audit trail.

Erasure
Access & Correction

Audit Logs, Breach Response & Vendors

Tamper-evident logs of who touched personal data, a breach runbook from detection to notification, and a register of every processor that receives personal data and why.

Evidence
Incident Response
Software engineering services

Backend & APIs

FastAPI and Django services designed for observability, testability, and growth.

Cloud & DevOps

AWS and GCP infrastructure with Terraform, Docker, and automated CI/CD.

AI & LLM Systems

RAG pipelines and LLM integrations — built with the same data-handling discipline.

Where the Act stands

DPDP commencement is phased

The Act is neither “not yet in force” nor fully in force — obligations arrive in phases. The time to build controls is before the substantive duties apply.

13 Nov 2025

Initial provisions in force

The first phase of the Act commenced — the framework and the Data Protection Board begin to take shape.

13 Nov 2026

Further provisions

The next phase of commencement. A good checkpoint to have your data inventory and ownership mapped.

13 May 2027

Major substantive obligations

Most substantive duties, including most of the DPDP Rules, 2025, apply. Controls and evidence should be live well before this.

Worth knowing

  • Internal-only systems, such as an HRMS a company runs for its own staff, are still covered.
  • Employment-related legitimate use is a ground for processing, not a blanket exemption — marketing needs its own basis.
  • A SaaS vendor can be a Data Processor for one flow and a Data Fiduciary for another.

What my work is not

  • Not a legal opinion or a substitute for advice from a practising advocate — I am not enrolled as one
  • Not a statutory audit or Independent Data Auditor sign-off (a role for notified Significant Data Fiduciaries)
  • No "certified" or "government-approved" claims — just documented, verifiable engineering

Case study

Privacy engineering, feature by feature

A demonstration project showing how I approach DPDP readiness in a real SaaS architecture.

Demonstration project

Employee Management SaaS — DPDP Readiness Case Study

Architecture: Next.js, FastAPI, PostgreSQL, Redis, Object Storage, Email Provider

A demonstration B2B HRMS built so that every feature's personal-data handling is identifiable, documented, and defensible under the DPDP Act, 2023. The employer is treated as Data Fiduciary for its employees' data and the platform as Data Processor — but each flow is assessed on its own, because the platform becomes a Fiduciary for anything it does for its own purposes.

Eight questions for every personal-data field

  1. 1What data is it, and what category?
  2. 2Why is it collected?
  3. 3Who is Fiduciary / Processor for this flow?
  4. 4Where is it stored — including caches, logs, backups?
  5. 5Who can access it?
  6. 6Is it shared with a third party?
  7. 7When and how is it deleted?
  8. 8What evidence proves all of the above?

Controls implemented

  • Personal data inventory kept in sync with schema migrations
  • Consent records with purpose, policy version, and withdrawal — only where consent is the basis
  • Per-tenant RBAC with enforced tenant isolation
  • Retention rules and deletion across caches, backups, and logs, with deletion records
  • Data Principal rights workflow with a full audit trail
  • Tamper-evident audit logs, breach runbook, and vendor/processor register

A demonstration project, not a client engagement. No real client data or audits are represented.

3Automation.com

96× faster workflow execution

Cut a 48-hour processing job to 30 minutes by redesigning the execution engine.

Operations portal

Policy-based authorization

Cross-cloud identity with Auth0 and Amazon Verified Permissions for independently owned services.

Verification platform

Secure credential workflows

Enterprise SSO and automated verification for a workflow built around identity documents.

How an engagement runs

From data map to evidence

Six steps that end with controls running in production and records that show they work.

STEP 01

Discovery Call

Free 30-minute call on your product, data, customers, and where you are with DPDP today.

Scope note
STEP 02

Data Mapping

Walk every system and data flow to build the personal data inventory and assign Fiduciary / Processor roles.

Data inventory
STEP 03

Gap Assessment

Compare what exists against DPDP obligations and rank gaps by risk and effort.

Prioritised roadmap
STEP 04

Implement Controls

Build consent, access control, retention, deletion, and rights workflows — alongside your team or hands-on.

Shipped controls
STEP 05

Evidence Pack

Consent records, notice versions, access logs, and deletion records that show the controls actually run.

Evidence & docs
STEP 06

Handover & Support

Runbooks for rights requests and breaches, team walkthrough, and ongoing support as rules evolve.

Runbooks

Toolkit

Skills & Technologies

Privacy & Compliance Engineering
DPDP Act, 2023
DPDP Rules, 2025
Personal Data Inventory
Data Flow Mapping
Consent Architecture
RBAC / ABAC
Tenant Isolation
Retention & Deletion
Data Principal Rights
Audit Logging
Breach Response
Vendor / Processor Register
Languages & Frameworks
Python
FastAPI
Django
Flask
JavaScript
React.js
Next.js
PHP
Bash
Cloud, Identity & DevOps
AWS (EC2, RDS, ECS, S3, Bedrock, IAM Identity Center)
GCP
Docker
Terraform
Ansible
CircleCI
Auth0
Amazon Verified Permissions
Databases & Messaging
PostgreSQL
MySQL
MongoDB
Neo4j
Redis
RabbitMQ
Pinecone
AI & Machine Learning
LLM
OpenAI
LangChain
RAG
MCP
PyTorch
HuggingFace Transformers

Experience

10+ years of software engineering behind the compliance work

The systems where personal data actually lives — APIs, identity, multi-tenant platforms, and cloud infrastructure.

Independent Consultant
Privacy Engineering & Software Consultant
February 2024 – Present

Credentialing & Verification Platform

Technologies: FastAPI, Next.js, MongoDB, AWS IAM Identity Center, Terraform, CircleCI

Replaced a manual professional-credentialing process with automated verification — a workflow built around sensitive identity documents.

  • Built credential lifecycle APIs and verification orchestration workflows on FastAPI
  • Integrated enterprise SSO with AWS IAM Identity Center for secure client onboarding
  • Developed a Next.js portal for submission, tracking, and compliance views
  • Automated infrastructure and release workflows across environments

Unified Distributed Operations Portal

Technologies: FastAPI, React.js (Microfrontend), GCP Firestore, Pub/Sub, Cloud Functions, AWS, Terraform, Auth0, AVP

A multi-team operations platform where independently owned services plug in without a shared codebase — with access control as a first-class concern.

  • Implemented cross-cloud identity with Auth0 and policy-based authorization using Amazon Verified Permissions
  • Architected a microservices and microfrontend platform for independently onboarded team services
  • Built schema-governed configuration pipelines with Apache Avro and event-driven propagation
  • Provisioned and shipped distributed modules with Terraform and CircleCI pipelines

Enterprise Knowledge Intelligence Platform (RAG)

Technologies: FastAPI, LangChain, OpenAI API, Neo4j, Pinecone, BM25, MMR, MongoDB, Next.js

Helped an enterprise engineering team search GitHub and Confluence in natural language instead of losing hours hunting for answers.

  • Architected a hybrid RAG platform over GitHub and Confluence knowledge
  • Implemented code summarization and Neo4j knowledge-graph relationships to improve retrieval precision
  • Built LangChain pipelines with BM25 + MMR retrieval, query rewriting, and context compression
  • Delivered a Next.js developer portal with CI/CD on GitHub Actions

Hotel Intelligence MCP Server

Technologies: FastAPI, MCP, LangChain, HuggingFace Transformers, Playwright, BeautifulSoup, PostgreSQL

An AI-callable hotel search and pricing tool that travel agents query in plain English.

  • Designed an MCP server exposing hotel search, pricing comparison, and availability as AI-callable tools
  • Engineered a resilient scraping backend with retry logic and rate limiting
  • Integrated transformer-based intent parsing to resolve ambiguous travel queries
UST Global, Pune
Senior Software Engineer II
February 2023 – February 2024

Admin and Tooling Platform

Technologies: FastAPI, GCP, AWS, Terraform, CircleCI, React.js, SQLAlchemy

Internal admin platform and tooling infrastructure spanning GCP and AWS environments.

  • Led architecture design sessions and code reviews for a team of 6 engineers
  • Achieved >80% test coverage across core application modules
  • Provisioned multi-environment GCP infrastructure with Terraform, reducing manual setup time by ~70%
  • Moved from manual releases to fully automated CircleCI pipelines
R System International, Noida
Senior Software Engineer
October 2022 – February 2023

SCREIM (Supply Chain Resilience Evaluation, Integration & Monitoring)

Technologies: Django, AWS, Terraform

Supply chain resilience monitoring — tracking disruption signals across supplier networks.

  • Led architectural design discussions for a multi-tier supplier risk monitoring system
  • Developed core Django modules for disruption signal ingestion and risk scoring
  • Owned sprint planning and deployment workflows across staging and production
Idemia Syscom India Pvt Ltd, Noida
Senior Software Engineer
June 2021 – October 2022

MestaCompact (Road Safety Device)

Technologies: Flask, Python, Matplotlib, OpenCV, FFmpeg, NumPy, React.js

Road safety device platform — real-time video and image processing for European highways.

  • Architected real-time image and video processing pipelines using OpenCV and FFmpeg
  • Led code reviews and drove optimisations that reduced pipeline latency
  • Packaged and deployed the application to embedded road safety hardware
Mall91 / Ongraph Technologies, Noida
Software Engineer → Team Lead
April 2019 – June 2021

3Automation.com (RPA Solution)

Technologies: Flask, Django, AWS, PostgreSQL, Tornado, Ansible, Docker, Redis, RabbitMQ

RPA platform — a bot execution engine that replaced manual business workflows with automated task queues.

  • Led a team of 9 engineers as Team Lead
  • Built the bot engine from scratch across frontend, backend, and execution engine
  • Cut workflow execution time from 48 hours to 30 minutes (96×) by redesigning the engine with multithreading and Pandas pipelines
  • Architected a distributed task queue with Redis and RabbitMQ
Webkul Software Pvt Ltd, Noida
Software Engineer
July 2016 – April 2019

Multi-channel Connector & Prestashop Odoo Bridge

Technologies: Python, Odoo, PHP, JavaScript, jQuery

E-commerce integration modules connecting online storefronts to ERP systems for international retail clients.

  • Built Python/PHP modules connecting Prestashop storefronts to Odoo ERP for 10+ international clients
  • Managed deployment and customisation cycles across varying Odoo versions

Education

Law and computer science

Lloyd Law College
Greater Noida, India

Bachelor of Laws (LL.B.)

Law

2023 – 2026

ABES Engineering College
Ghaziabad, India

Bachelor of Technology

Computer Science Engineering

August 2012 – August 2016

Get in touch

Start with a 30-minute conversation

Tell me about your product and the personal data it handles. I'll tell you honestly where you stand and what to do first.

Why work with me?

  • Legal training and 10+ years of software engineering in one person
  • I read your code and architecture diagrams, not just your privacy policy
  • I implement controls, not just write policies about them
  • Every recommendation maps to a concrete change your team can ship
  • Evidence-first: consent records, access logs, deletion records
  • Honest scope — I tell you when you need a practising advocate
  • Async-friendly, with written updates every week