Questions to ask a DPDP consultant before you hire
Not all DPDP consultants are equal. These 10 questions will separate the firms that deliver real compliance from the ones that deliver a polished slide deck.
The DPDP compliance consulting market in India is growing fast — and so is the variation in quality. You will find firms that have been advising on privacy law for a decade sitting alongside general-purpose legal consultancies that added "DPDP" to their brochure six months ago. The stakes are real: penalties under DPDP can reach ₹250 crore per instance, and the quality of your compliance programme depends heavily on who helps you build it.
The good news is that a 30-minute intake call is enough to separate genuine specialists from generalists, if you ask the right questions. Below are the 10 questions we recommend, along with what a strong answer looks like and what should give you pause.
For context on what DPDP compliance actually involves before you start these conversations, see our earlier post on understanding DPDP obligations for your business.
Question 1: What does your gap assessment methodology cover?
What a good answer looks like: The consultant describes a structured methodology — typically a combination of a questionnaire, document review, and process walkthrough — that maps your current data processing activities against each DPDP obligation: consent, notice, Data Principal rights, breach notification, Grievance Officer, cross-border transfers, and retention. They should name the specific sections of the Act and draft Rules they assess against.
Red flag: A vague answer like "we review your privacy policy and data practices" without specifying which obligations are assessed or how evidence is collected.
Question 2: What deliverables do I actually receive?
What a good answer looks like: A written gap assessment report with a findings register (each gap mapped to a specific DPDP provision), a prioritised remediation roadmap with timelines, and template documents for the gaps identified — consent notice templates, Grievance Officer policy, breach notification procedure. Ask for a sample table of contents.
Red flag: Deliverables described in vague terms ("a comprehensive compliance report") without specifics on format, length, or what the remediation roadmap contains. If they cannot show you a sample, walk away.
Question 3: How do you handle sub-processor and vendor chains?
What a good answer looks like: Under DPDP, a Data Fiduciary remains responsible for the data processing activities of its Data Processors. A strong consultant will assess your vendor contracts, identify where Data Processing Agreements need to be introduced or updated, and help you build a vendor due diligence questionnaire for ongoing management.
Red flag: The consultant focuses only on your internal data practices and treats vendor risk as out of scope. This is a critical gap — many Indian companies have dozens of SaaS vendors processing employee or customer data on their behalf.
Question 4: What is your approach to consent notice drafting?
What a good answer looks like: DPDP mandates consent notices in plain language, with an itemised list of purposes, the identity of the Data Fiduciary, and a mechanism to withdraw consent as easily as it was given. A good consultant drafts notices that are legally compliant and actually readable — not boilerplate legalese. Ask them to describe a specific drafting decision they made for a client.
Red flag: The consultant plans to adapt your existing GDPR privacy notice rather than building a DPDP-specific notice. The two instruments have different requirements and different language standards.
Question 5: How do you stay current with the DPDP Rules?
What a good answer looks like: The DPDP Rules are not yet finalised. The consultant should be tracking MeitY consultation documents, industry body submissions, and regulatory guidance as it emerges. Ask which sources they monitor and whether your deliverables are updated when the Rules change.
Red flag: The consultant treats the Act alone as the complete compliance framework. The Rules will determine the practical obligations — timelines, formats, SDF criteria — and a consultant who is not tracking them will deliver work that may be out of date on day one.
Question 6: What happens after the report?
What a good answer looks like: Good DPDP consultants offer implementation support, not just assessment. This means helping you draft policies, review updated vendor contracts, train staff, and set up the Grievance Officer process. Ask whether post-report support is included or billed separately, and whether they offer a follow-on verification review to check remediation progress.
Red flag: The engagement ends when the report is delivered. A gap assessment without implementation support is a document, not compliance.
Question 7: Have you worked with companies in our sector?
What a good answer looks like: Sector experience matters because DPDP obligations are applied differently across HRMS, healthcare, fintech, and e-commerce. A consultant who has worked in your sector will know which processing activities are common, which consent flows are practical, and which vendor relationships are typical. Ask for anonymised case examples, not just a list of sector names.
Red flag: The consultant claims expertise across every sector without being able to describe a specific challenge they solved in yours.
Question 8: How do you handle the Grievance Officer appointment?
What a good answer looks like: The Grievance Officer is a named, contactable individual responsible for resolving Data Principal complaints. The consultant should help you define the role, draft the internal policy covering complaint intake, escalation, and resolution timelines, and ensure the Officer is published and reachable as required. They should also flag whether your company may be notified as a Significant Data Fiduciary, which triggers additional obligations.
Red flag: The consultant treats the Grievance Officer as a simple form-filling exercise rather than an operational process with training, escalation, and logging requirements.
Question 9: What is your view on Data Principal rights fulfilment?
What a good answer looks like: DPDP grants Data Principals rights to access their data, correct inaccuracies, erase data in certain circumstances, and raise grievances. The consultant should assess whether your current systems can operationalise these rights within prescribed timelines — and propose a fulfilment workflow if they cannot. Ask whether they review your CRM, HRMS, or database structure as part of this assessment.
Red flag: The consultant covers Data Principal rights only at a policy level without assessing the technical feasibility of fulfilment. A policy that says "we will respond in 30 days" is worthless if your systems cannot actually locate and export a specific individual's data.
Question 10: What is your fee structure and what drives it up?
What a good answer looks like: Fixed-price engagements with clearly scoped deliverables are preferable to open-ended time-and-materials retainers for a defined compliance project. The consultant should be transparent about what is included, what triggers additional fees (e.g., more than a set number of vendor DPAs, additional legal entity assessments), and what the payment schedule looks like.
Red flag: A purely hourly or per-day rate with no clear scope. DPDP compliance has a defined set of obligations — a structured engagement should have a defined price. Vague scope leads to scope creep and budget overruns.
Also see how to scope a DPDP programme for your company size and what DPDP compliance costs for mid-market companies. For a deeper look at what post-assessment implementation involves, check our DPDP implementation timeline guide.
Know where you stand before you call a consultant
Run our free DPDP Readiness Score to understand your current compliance gaps. It takes five minutes and gives you a structured starting point for any consultant conversation.
Get Your Free Readiness ScoreFrequently asked questions
How long should a proper DPDP gap assessment take?
For a mid-sized company with a single legal entity and straightforward data flows, a thorough gap assessment typically takes two to four weeks from kickoff to report delivery. That timeline includes a data mapping exercise, policy and document review, process walkthroughs with relevant teams, and a written findings report with remediation roadmap. Faster timelines are possible but usually indicate that the scope is narrower — either fewer obligations are being assessed or the data mapping has been abbreviated. Ask your consultant for a week-by-week project plan before signing.
Should we hire a law firm or a specialist compliance consultancy?
Both can do good work, and the right choice depends on your situation. Law firms are well-suited when DPDP compliance intersects with complex legal questions — cross-border structuring, regulatory negotiations, or litigation risk. Specialist compliance consultancies often deliver faster, more operational output: policies, procedures, training, and vendor management frameworks built to be used by your team, not just read by lawyers. For most mid-market companies, a compliance-focused engagement is more practical. If you have specific legal exposure, keep a law firm in the loop for advice while using a consultancy for operational delivery.
Can a single consultant cover both DPDP and ISO 27001 or SOC 2?
There is meaningful overlap between DPDP and information security frameworks — both require data mapping, vendor risk management, breach response procedures, and access controls. Some consultancies handle both, which can reduce duplication. However, be cautious about consultancies that treat DPDP as a checkbox within a broader ISO or SOC 2 engagement. DPDP has specific legal requirements — consent architecture, Grievance Officer appointment, Data Principal rights — that are not fully addressed by security frameworks. Ensure whoever handles DPDP has specific expertise in the Act, not just in information security standards.