A privacy programme is only as good as its records when an inquiry lands. IrisInfosec builds the GDPR and DPDPA foundations that stand up to scrutiny: a current RoPA, DPIAs where they are required, a working data subject request process, valid transfer mechanisms, and a DPO who can answer for it all. One control set, several regimes.
Modern privacy law runs on accountability: you have to demonstrate compliance, not assert it. That means knowing what data you hold, why, and on what basis, and being able to produce the records on request. We build that foundation and keep it current.
The same work answers several regimes at once. A programme designed to GDPR covers much of India’s DPDPA and US state laws, with the differences handled deliberately rather than hoped over.
A privacy and data protection programme
is the records, processes and oversight that let you process personal data lawfully and prove it: a RoPA, DPIAs, data subject request handling, valid transfers and a Data Protection Officer.
What we build
Each of these is something a regulator can ask to see. We make sure the answer exists
and is current.
A living record of what data you process, why, on what basis, and where it flows, kept current as your business changes.
Data Protection and Transfer Impact Assessments for high-risk processing and cross-border flows, documented to stand up.
A workflow that finds the data, applies exemptions correctly, and meets the deadline without disrupting your teams.
Standard Contractual Clauses, Binding Corporate Rules and the transfer impact assessments that make them defensible.
An outsourced Data Protection Officer, or support to your in-house DPO, across the EU and India.
A tested process to assess, contain and notify within the timelines GDPR and the DPDPA set, before the clock matters.
Common question
If you operate across the EU and India, you need both. Here is where they line up and
where they part.
| GDPR (EU) | DPDPA (India) | |
|---|---|---|
| Lawful bases | Six, including legitimate interests | Consent-centric, with limited legitimate uses |
| Key terms | Controller and processor | Data fiduciary and data processor |
| Individual | Data subject | Data principal |
| Transfers | Adequacy, SCCs, BCRs | Government-notified country model |
| One programme | A GDPR foundation covers much of the DPDPA; we map the gaps deliberately so one programme serves both | |
How we work
A measured approach that starts with knowing your data and ends with oversight you can sustain.
Find the personal data you hold and build the RoPA that everything else depends on.
Run DPIAs and transfer impact assessments where the law and the risk require them.
Lawful bases, notices, retention, transfer mechanisms and security measures, documented.
Stand up the request, breach and vendor processes your teams will use day to day.
DPO oversight, training and review, so the programme stays current as you change.
What you receive
The documents a supervisory authority can ask to see, built so your teams can keep them
current.
A current record of processing and a data map you can actually maintain, not a one-off spreadsheet.
Completed assessments, clauses and the supporting analysis for your high-risk processing and transfers.
Privacy notices, internal policies and the request and breach playbooks your teams follow.
Ready for the inquiry before it comes
Tell us the markets you operate in and where personal data flows. We will assess the gaps and send a prioritised plan.
Questions, answered
Related services