7Unit

DPDP Exposure Analysis

Powered by Alligri

Check your DPDP exposure

7UNIT / DPDP · EXPOSURE ANALYSIS

For Indian operators, CTOs and compliance owners — not a free PDF quiz

Can you prove one person’s data trail — or only hope you are safe?

In client calls and readiness reviews, leadership often feels covered by ISO, SOC, a privacy policy, or counsel notes. Then we ask for consent evidence, system maps, vendor paths and erasure proof. That is where exposure shows up.

Paid executive session from 7Unit · powered by Alligri · technical and operational readiness, not a legal opinion

₹15,000 adjustable advance · credited to your first implementation invoice · keeps research traffic out

01 / WHAT YOU LEAVE WITH

Clarity you can take to leadership — before you fund the wrong programme

The paid analysis is deliberately bounded. You get an exposure profile and a prioritised plan — not a certificate and not a full implementation.

01

Exposure profile

Where your organisation is operationally weak — not a fake compliance percentage.

02

Evidence gaps

Consent, access, vendors, retention and erasure paths that cannot currently be proved.

03

Priority list

What to fix first if enforcement pressure, a rights request, or a board question arrives.

04

30 / 60 / 90 roadmap

A practical next-step plan before you fund a larger implementation programme.

02 / FALSE SAFETY

Feeling safe is not the same as being able to prove it

Patterns from readiness conversations and executive reviews — anonymised, recurring, and usually expensive to discover late.

Common misconception

ISO 27001 or SOC 2 ≠ DPDP readiness

Security certifications strengthen controls. DPDP still asks whether you can evidence purpose, notice, consent or permitted use, access, vendors, retention, withdrawal and erasure for personal data — including children’s data where relevant. Teams that collapse “certified” into “compliant” often walk into the session confident and leave with a gap list.

Pattern we see

“We are ISO / SOC certified, so DPDP is covered.”

ISO 27001 and SOC 2 are valuable security and control frameworks. They are not a DPDP readiness programme. They do not by themselves prove consent notice versions, purpose limitation, children’s-data safeguards, rights fulfilment across CRM + WhatsApp + payroll, or vendor processing under Indian law.

Pattern we see

“Our privacy policy and cookie banner are live.”

Policy text is not operational evidence. In executive sessions we often find notices that do not match the form actually shown, consent that cannot be retrieved by person or timestamp, and withdrawals that never reach downstream tools.

Pattern we see

“Legal said we are fine — until we asked for one person’s trail.”

Leadership felt safe until we asked a simple question: can you locate one individual’s data across every system, prove why it is there, and stop or erase it with evidence? That is where confidence usually breaks.

Pattern we see

“Vendors handle it for us.”

Processors reduce work; they do not remove accountability. Teams that cannot list who receives personal data, for what purpose, and how erasure propagates discover exposure only when a request or incident forces the map.

03 / THE OPERATIONAL TEST

Five questions that separate policy from operations

DPDP obligations are being brought into force in phases. Organisations should treat readiness as an operational programme, not a last-minute checkbox.

Run the readiness check →

Q.01

Can you prove when and how consent was obtained?

Q.02

Can you locate every system where an individual’s data exists?

Q.03

Do you know every employee and vendor with access?

Q.04

Can you stop processing or fulfil an erasure request across all systems?

Q.05

Can you produce evidence of these actions?

04 / THE PAID ANALYSIS

What the Executive Exposure Analysis includes

Useful enough to brief a board. Bounded enough that it is not sold as “full compliance done.”

Includes

  • Current exposure profile
  • Data-source and workflow review
  • Consent and notice traceability review
  • Access and vendor visibility review
  • Rights-request and erasure workflow review
  • High-priority gap list
  • Practical 30/60/90-day roadmap
  • Indicative implementation effort and scope

Does not include

  • Statutory certification
  • Legal representation
  • Exhaustive legal opinion
  • Full technical penetration test
  • Complete implementation unless separately scoped

05 / DATA JOURNEY

Where personal data actually moves

Exposure appears between systems — not only in the privacy policy.

01

Collection

Website form · WhatsApp

02

Consent or permitted use

Notice version · purpose

03

Storage

CRM · spreadsheet · cloud drive

04

Internal access

Payroll · support desk

05

Processor / vendor sharing

External vendor · API

06

Retention

Purpose-linked periods

07

Rights request

Correction · withdrawal

08

Erasure or cessation

Primary + downstream

06 / HIGH-RISK USE CASES

Where operational gaps concentrate

AGE < 18

Children’s data

Do you process personal data of individuals below 18? Assess parental consent, notice design, tracking or behavioural monitoring restrictions, access, retention, sharing and erasure workflows.

HR / PAYROLL

Employee and payroll data

HRMS, payroll processors, attendance, and benefits systems often hold persistent personal data with broad internal access.

TALENT

Recruitment and candidate data

Portals, agencies, and spreadsheets create fragmented candidate records that are hard to locate, retain lawfully, or erase.

HEALTH

Health and patient data

Clinical, wellness, and insurance workflows demand stronger operational controls across systems and vendors.

GROWTH

Customer and lead data

Marketing, CRM, WhatsApp, and support tools multiply collection points and consent contexts.

VENDORS

Third-party processor / vendor data

If you cannot list who receives personal data and why, rights fulfilment and incident response stall.

07 / WHY 7UNIT

Evidence-led, engineering-led

01

Compliance-heavy delivery

Engineering experience in fintech and healthcare environments where evidence and access controls are not optional.

02

Real system inspection

We inspect workflows, systems, APIs, databases and vendor movement — not only policy documents.

03

Build after assess

Technical plus operational implementation capability after the executive session, when you choose to proceed.

04

Structured by Alligri

Alligri provides structured evidence, checks and action tracking for the engagement.

08 / ADJUSTABLE ADVANCE

Why the session is paid

₹15,000 is not a product SKU for a certificate. It is an executive advance that reserves senior time, filters Meta research traffic, and converts into implementation credit when you proceed.

  • Cheaper than discovering the gap mid-implementation or after a rights request lands.
  • Credited against your first scoped 7Unit DPDP implementation invoice within 30 days.
  • Keeps the funnel for operators ready to act — not free-form tire kickers.
  • If you attend the full executive session and it was not useful for your organisation, request a refund within 48 hours. We would rather return the advance than leave you with an empty readout.

PAID EXECUTIVE ADVANCE

DPDP Exposure Analysis

₹15,000 + applicable taxes

Usefulness guarantee

If you attend the full executive session and it was not useful for your organisation, request a refund within 48 hours. We would rather return the advance than leave you with an empty readout.

  • 60–90 minute executive session
  • Pre-session assessment review
  • Exposure summary for leadership
  • Prioritised next-step roadmap
Start the readiness check →

The ₹15,000 fee is an adjustable advance — credited against your first 7Unit DPDP implementation invoice if you proceed within 30 days. It is not a cash refund.

Usefulness guarantee. Cash refund is available only when you (1) completed the readiness check beforehand, (2) attended the full scheduled session, (3) brought or attempted the prep checklist, and (4) request a refund in writing within 48 hours of the session with a short reason. One refund per organisation. A cash refund and implementation credit are mutually exclusive — if we refund, no adjustable-advance credit applies. No-shows and late cancellations follow the cancellation / no-show policy and are not refundable under this guarantee.

Fees are quoted exclusive of applicable GST. GST is added at checkout where required.

The adjustable advance remains valid for 30 days from payment toward a scoped 7Unit DPDP implementation engagement.

You may reschedule once with at least 24 hours’ notice. Later changes are at 7Unit’s discretion.

Cancellations with at least 48 hours’ notice may be credited as an adjustable advance toward a future 7Unit DPDP engagement within the validity window. This is not a cash refund unless required by applicable law.

Missed sessions without prior notice forfeit the session slot. The fee remains an adjustable advance under the same validity terms. No-shows are not eligible for the usefulness refund.

09 / NEXT STEP

Test the assumption that you are safe.Then decide what to fund.

Start the DPDP readiness check →

Free readiness check first · paid executive analysis ₹15,000 only if you choose to reserve it

How your data moves here

Browser → encrypted application endpoint → Alligri assessment database → authorised 7Unit team → payment provider / calendar only when you choose to proceed

The DPDP Act provides for significant penalties for specified contraventions — readiness is about operational evidence, not panic. This assessment is a technical and operational readiness service, not a legal opinion or statutory certification. It does not constitute legal advice or representation. Patterns described above are composite from readiness conversations; they are not attributions to named clients.