Case study: how a SaaS vendor passed a client DPDP review

DPDP compliance
Case study: how a SaaS vendor passed a client DPDP review
Shortlist Stage · Case Study

Case study: how a SaaS vendor passed a client DPDP review

A 120-person HRMS provider in Pune faced losing an ₹80L healthcare contract renewal over DPDP compliance. Here is what they did in 6 weeks — and what was genuinely hard.

Note: This is a fictionalised composite case study. The company, individuals, and specific figures are illustrative — based on the type of engagements we run, but not depicting any specific named client. Details are representative of real outcomes, not a verbatim account.
Quick Answer: A 120-person HRMS provider in Pune went from zero data inventory and no privacy notice to a passed enterprise DPDP review in 6 weeks. The work: 3-week gap assessment, privacy policy rewrite, 12 vendor DPAs, consent flow rebuild, and 2-hour team training. Hardest part: getting the engineering team to prioritise consent changes during a product sprint. Outcome: ₹80L contract renewed.

Background

The company — call them "PulseHR" — is a 120-person HRMS software provider based in Pune, founded in 2017. Their product handles payroll, leave management, and employee self-service for mid-market Indian companies. Their client base skews toward manufacturing, retail, and healthcare companies with 200–2,000 employees.

In January 2026, their largest client — a 1,400-person multi-specialty hospital group based in Mumbai — sent them a vendor compliance questionnaire as part of their annual contract renewal process. The questionnaire included 23 questions about DPDP compliance: consent mechanisms, data processor agreements, breach notification capability, employee training records, and Grievance Officer designation.

The contract value was approximately ₹80L annually. It represented 12% of PulseHR's total ARR. The renewal decision was due in 10 weeks.

Starting state

0
Data inventory entries
0
Vendor DPAs in place
38
DPDP readiness score (out of 100)
2017
Year privacy notice was last updated

PulseHR's privacy notice, last updated in 2017, was three paragraphs long and referenced the IT Act 2000. It did not mention any of the four data principal rights, had no Grievance Officer contact, and described data usage as "to provide services and improve our platform." Their consent mechanism was a single checkbox bundled with terms acceptance.

They had 34 active SaaS vendors — including AWS, Razorpay, Mixpanel, Intercom, and Zoho — none of whom had a DPDP-compliant Data Processing Agreement. They had no formal data inventory, though individual engineers had tribal knowledge of where data lived. They had never run a DPDP training session for their team.

When we completed the initial gap assessment, their readiness score was 38/100. The hospital client's procurement team had made clear that a score of 70 or above was the minimum threshold for continued vendor approval.

What was done — week by week

W1

Gap assessment and data inventory

Document review of all existing policies, contracts, and system architecture. Interviews with the engineering lead, Head of Customer Success, and Finance. Technical check of database access logs, encryption configuration, and consent flows. Output: gap analysis report with 31 findings across 8 domains, severity-rated. Simultaneously: data inventory built for all 12 processing activities (payroll, leave, attendance, performance, recruitment, expense, helpdesk, analytics, email, support chat, mobile app, integrations).

W2

Policy documentation package

New privacy notice (3,200 words, plain language, 10/10 on DPDP rubric). Separate employee privacy notice for internal HR data. Cookie policy. Grievance Officer designated (Head of Legal at PulseHR, with new email grievance@pulsehr.com and 48-hour SLA). Privacy Rights section added to product dashboard with request intake form. Internal data processing policy drafted for board approval.

W3

Vendor DPA execution

Prioritised 12 vendors processing the largest volumes of personal data (AWS, Razorpay, Mixpanel, Intercom, Zoho CRM, Zoho Desk, Twilio, Freshdesk, Google Workspace, Slack, GitHub, HubSpot). DPA template sent with covering email explaining the DPDP requirement. 9 of 12 vendors signed standard DPAs within the week. 3 required follow-up (Intercom needed a custom schedule; HubSpot's standard DPA needed a 6-hour breach notification addendum; GitHub's DPA excluded sub-processor notification — accepted with documented risk note).

W4

Consent flow rebuild — the hard part

The engineering team had a product sprint in Week 4 with three committed client feature deliveries. Getting consent flow changes prioritised was the single most difficult part of the engagement. The resolution: consent changes were scoped as a two-day engineering task (not a sprint) and the product manager agreed to treat it as a compliance-critical hotfix. The new consent flow went live on Day 26 of the engagement.

W5

Team training and incident response planning

Two-hour DPDP awareness session for the full team (85 attended of 120 — engineering, sales, customer success, HR, finance). Session covered: what DPDP requires, what a data breach looks like, what to do if a data principal contacts you directly, and what not to say. Incident response procedure documented, including the 6-hour DPB notification workflow. Breach notification template prepared for the hospital client specifically.

W6

Evidence package and client response

All 23 questionnaire items answered with supporting evidence: privacy notice URL, consent flow screenshots with timestamps, signed DPA summary (vendor name, signing date, key obligations), training attendance record, Grievance Officer contact, incident response procedure excerpt, and post-remediation readiness score (79/100). Evidence package submitted to hospital client's legal team on Day 40 of engagement.

The outcome

The hospital client's legal team reviewed the evidence package over four business days. They came back with three follow-up questions: whether the Grievance Officer would be reachable during weekends (yes, with a 24-hour callback SLA), whether the data inventory included patient data processed through the HR system (it did not — patient data was out of scope for the payroll integration), and whether PulseHR's AWS DPA covered the Mumbai region specifically (it did).

The contract was renewed on Day 47 of the engagement. The hospital's Head of Legal sent an email noting that PulseHR's evidence package was "among the more thorough DPDP compliance submissions we have received from a software vendor." The contract value was ₹80L for the year.

Three months after the engagement, PulseHR included their post-remediation DPDP readiness score in responses to two additional enterprise RFPs. They won one (a 900-person manufacturing company) citing compliance readiness as a differentiation factor in the vendor selection. The second is still under negotiation.

What was genuinely hard

Honest about the hard parts:
  • Engineering prioritisation: Consent flow changes competed with committed sprint deliverables. This required founder-level escalation to resolve. Compliance work always competes with product work — plan for it.
  • Vendor DPA follow-up: Three vendors required 2–4 follow-up emails before signing. One vendor (a legacy HR integration partner) still has not responded after six weeks. This is common — not every vendor will cooperate quickly.
  • Employee awareness gap: The training session revealed that 60% of customer-facing staff did not know what to do if a client asked about data deletion. This is a cultural gap, not a documentation gap, and it takes more than one session to close.
  • Evidence formatting: The first version of the evidence package was rejected by the client's legal team as "insufficiently structured." Reformatting to match their questionnaire template added three days to the timeline.

To understand how the readiness score used in this engagement is calculated, see our post on how DPDP readiness scoring works. For an overview of what a gap analysis report looks like, see our sample gap analysis report post. For pricing context on this type of engagement, see our post on DPDP compliance pricing in India. If you're still evaluating whether to engage a consultant, see our guide on how to choose a DPDP compliance consultant.

Facing a client DPDP review? Start with a free 30-min call.

Tell us your timeline, your client's requirements, and your current compliance state. We'll give you an honest assessment of what's achievable and what it will take — before you commit to anything.

Book a Free 30-Min Call →

Frequently Asked Questions

Is 6 weeks a realistic timeline for a SaaS vendor of this size to reach compliance?

Six weeks is achievable for a company of 100–200 people with a single product and a manageable vendor list (under 40 processors). It requires a dedicated internal point of contact, engineering availability for consent flow changes, and fast vendor DPA turnaround. It is not a comfortable timeline — it is a compressed one driven by client deadline pressure. For a more measured compliance programme without a hard deadline, 10–12 weeks is more realistic and produces higher-quality outcomes.

What if an enterprise client wants to audit us directly, not just review a questionnaire?

Direct audits are increasingly common for enterprise clients with large contract values (typically ₹50L+ annually). A client-side audit typically involves a 2–3 hour session with your legal, engineering, and security leads, plus a request for specific evidence (database access logs, encryption configuration screenshots, training attendance records, DPA copies). The best preparation is ensuring your internal point of contact can answer questions about actual systems — not just documentation.

Can smaller companies (10–30 people) also pass enterprise DPDP reviews?

Yes — and in some ways it is easier. Smaller companies have simpler data flows, fewer processors, and faster internal decision-making. The gap assessment takes less time, the data inventory is smaller, and training can be done in a single session. The constraint is usually time: founders of 10–30 person companies often cannot dedicate the internal bandwidth that a focused compliance push requires. Engaging an external compliance partner to run the process is often more efficient than trying to do it in parallel with normal business operations.

Previous Post Next Post

Get Free DPDP Checklist