Privacy Programmes That Hold
Up To A Regulator’s Questions

A privacy programme is only as good as its records when an inquiry lands. IrisInfosec builds the GDPR and DPDPA foundations that stand up to scrutiny: a current RoPA, DPIAs where they are required, a working data subject request process, valid transfer mechanisms, and a DPO who can answer for it all. One control set, several regimes.

1

Programme satisfying GDPR, DPDPA and CCPA together.

1 Month

The GDPR window we build your DSAR process to meet.

DPO

Outsourced or supporting your in-house officer.

Transfers

SCCs, BCRs and transfer impact assessments handled.

What this covers

Accountability You Can Show, Not Just Claim

Modern privacy law runs on accountability: you have to demonstrate compliance, not assert it. That means knowing what data you hold, why, and on what basis, and being able to produce the records on request. We build that foundation and keep it current.

The same work answers several regimes at once. A programme designed to GDPR covers much of India’s DPDPA and US state laws, with the differences handled deliberately rather than hoped over.

In one line

A privacy and data protection programme

is the records, processes and oversight that let you process personal data lawfully and prove it: a RoPA, DPIAs, data subject request handling, valid transfers and a Data Protection Officer.

What we build

The Parts Of A Programme That Get Tested

Each of these is something a regulator can ask to see. We make sure the answer exists
and is current.

Records Of Processing (RoPA)

A living record of what data you process, why, on what basis, and where it flows, kept current as your business changes.

DPIAs & TIAs

Data Protection and Transfer Impact Assessments for high-risk processing and cross-border flows, documented to stand up.

Data Subject Requests

A workflow that finds the data, applies exemptions correctly, and meets the deadline without disrupting your teams.

Cross-Border Transfers

Standard Contractual Clauses, Binding Corporate Rules and the transfer impact assessments that make them defensible.

DPO-As-A-Service

An outsourced Data Protection Officer, or support to your in-house DPO, across the EU and India.

Breach Response

A tested process to assess, contain and notify within the timelines GDPR and the DPDPA set, before the clock matters.

Common question

GDPR Vs DPDPA

If you operate across the EU and India, you need both. Here is where they line up and
where they part.

GDPR (EU) DPDPA (India)
Lawful bases Six, including legitimate interests Consent-centric, with limited legitimate uses
Key terms Controller and processor Data fiduciary and data processor
Individual Data subject Data principal
Transfers Adequacy, SCCs, BCRs Government-notified country model
One programme A GDPR foundation covers much of the DPDPA; we map the gaps deliberately so one programme serves both

How we work

From Data Map To A Running Programme

A measured approach that starts with knowing your data and ends with oversight you can sustain.

01

Discover & Map

Find the personal data you hold and build the RoPA that everything else depends on.

02

Assess The Risk

Run DPIAs and transfer impact assessments where the law and the risk require them.

03

Put Controls In Place

Lawful bases, notices, retention, transfer mechanisms and security measures, documented.

04

Operationalise

Stand up the request, breach and vendor processes your teams will use day to day.

05

Govern & Sustain

DPO oversight, training and review, so the programme stays current as you change.

What you receive

The Records An Inquiry Asks For

The documents a supervisory authority can ask to see, built so your teams can keep them
current.

RoPA & Data Map

A current record of processing and a data map you can actually maintain, not a one-off spreadsheet.

DPIA & Transfer Pack

Completed assessments, clauses and the supporting analysis for your high-risk processing and transfers.

Policies, Notices & Playbooks

Privacy notices, internal policies and the request and breach playbooks your teams follow.

Ready for the inquiry before it comes

See Where Your Privacy Programme Would Hold

Tell us the markets you operate in and where personal data flows. We will assess the gaps and send a prioritised plan.

Questions, answered

Privacy Programme FAQ

Both protect personal data, but they differ in important ways. The DPDPA is consent-centric with a narrower set of lawful bases, uses its own terms such as data fiduciary and data principal, and has distinct rules on cross-border transfers and breach notification. A GDPR programme covers much of the DPDPA, but the gaps need deliberate handling, which we map rather than assume.

A Data Protection Impact Assessment is a structured review of how a project or system processes personal data, the risks to individuals, and the measures that reduce them. GDPR requires a DPIA where processing is likely to result in high risk, for example large-scale profiling or new technologies, and a documented DPIA is part of accountability.

Standard Contractual Clauses are EU-approved contract terms used to transfer personal data outside the EEA, often paired with a transfer impact assessment. Binding Corporate Rules are internal data protection rules approved by a regulator for transfers within a corporate group. SCCs suit most transfers; BCRs suit large multinationals moving data internally at scale.

DPO-as-a-Service provides an outsourced Data Protection Officer, or support to your in-house DPO, covering RoPA, DPIAs, data subject requests, transfer mechanisms, training and regulator engagement. It suits organisations that need DPO expertise without a full-time hire, across the EU and India.

Under GDPR you must respond to a data subject request without undue delay and within one month, extendable by two further months for complex requests. We build a workflow that finds the data, applies exemptions correctly and meets the deadline without disrupting your teams.

Related services

Privacy You Can Demonstrate, Not Just Declare

Book a call with a privacy advisor who works from the regulation itself.
We assess your gaps and send a prioritised plan, no obligation.