Chapter 25 — The DPDP Solution Landscape
1. Why the market is not the map
When an enterprise announces a DPDP programme, the market arrives at its door within weeks. Consulting firms offer readiness assessments; platforms offer compliance suites; cloud providers point at their India regions; open-source projects present themselves as the sovereign alternative. Every one of these arrives with a claim, and most of the claims use the same word: “DPDP-compliant.”
It is at exactly this moment — when the options are most numerous and the vocabulary most confident — that an enterprise needs something the market will not volunteer: a disciplined way to tell claims apart. That is what this chapter supplies, and its central idea is a deliberate reframing of what a “solution landscape” is:
The idea. A DPDP solution landscape is not a list of vendors that say they are DPDP-compliant. It is an evidence ledger: a catalogue of sources, each graded for provenance (who wrote it and why should we believe them), and each flag-tested for DPDP-specificity (does it actually address DPDP provisions, or generic privacy with an Indian label on it?). The landscape exists so that the enterprise’s build-versus-buy decisions can be made on evidence rather than brand — and so that the legal position is never confused with the vendor position.
The legal position is derived from retained primary instruments and their applicability analysis, with the Chapter 2 register as the book’s organised lookup. A vendor’s page is evidence that the vendor makes a claim. Even detailed documentation is not observation that the feature works in the buyer’s environment. A product can be technically useful while its legal explanation is stale; a DPDP-branded page can be legally topical while its connectors remain untested.
2. What the landscape actually contains
The current source workbook contains the “Solution Landscape” data sheet and a separate “Q08 usage” explanation sheet. The data sheet has seven columns: evidence file, vendor/provider, product URL, SHA-256, DPDP-specific claim, evidence grade and title. Q05 reread the workbook and verified its 38 source-file hashes; there are two A-grade, 35 B-grade and one F-grade rows. out/remediation/Q05/landscape-workbook-checks.json records that check. This establishes the local artifact’s contents and identity, not market completeness.
It contains no per-entry price, integration-effort estimate or low/medium/high integration-debt score. A blank or missing field is not zero cost or low risk. The companion inception research reviews 18 brands, not verified contracting legal entities, and explicitly limits itself to a bounded, non-ranking scan (research/solutions/SOLUTIONS_LANDSCAPE.md:3–9). Those boundaries should govern how the reader uses it.
Categories are navigation aids rather than mutually exclusive supplier classes. A service firm may provide a product; a security supplier may claim privacy workflows; a repository scanner is not therefore an end-to-end runtime privacy suite. The later chapters examine named firms and products in detail. At this entry point, three inspected examples show why module-level classification changes the questions:
| Retained first-party material | What it documents as a vendor claim | What it does not establish in this review | Useful next test |
|---|---|---|---|
| Privado Quick Start | Repository scan with local .privado/privado.json output and optional cloud-dashboard synchronisation | Complete runtime consent/rights operations or measured scan coverage | Known-flow repository fixture plus inspection of exported report fields and sync boundary |
| Seqrite Data Privacy | Consent/preferences, rights cases, assessments, breach functions and modular cloud/on-premise/hybrid claims | Tested target connectors, contract terms, deployment location or lawful request semantics | Purpose-specific withdrawal and scoped rights case across the proposed deployment |
| Amazon Macie user guide | Sensitive-data discovery and security visibility for the S3 data estate | Whole-enterprise consent/rights orchestration or coverage of every non-S3 system | Seeded supported S3 objects, excluded types and findings integration |
The first row is grounded in V18:25–41, the second in V23:73–109,189–215 and the third in V35:89–100.[5][6][7] These are not product demonstrations. In particular, Seqrite should not be reduced to a security-only slice, while the retained Privado quick start should not be expanded into proof of a full privacy suite. “Not established here” is not “not offered”.
3. Integration hypotheses, not proven market gaps
Two useful PoV questions are downstream purpose enforcement and identifiable-derived-copy reach. The inception sources do not establish that these capabilities are universally absent or that only custom engineering can supply them. Ask whether the proposed deployment checks current purpose-specific authority at every relevant processing route, and whether retention/disposal instructions reach the declared data copies. The answer depends on connector, configuration, customer code and supplier responsibilities, not a category label.
For the Company’s SYS-005, training and serving need separate decisions. For SYS-003, withdrawal acceptance and later marketing denial must be distinguished from lawful restricted retention and missing processor evidence. A vendor claiming “consent management” should be asked to demonstrate those semantics on the intended path. The test is not whether the screen uses DPDP vocabulary. A familiar “DSAR” label is not evidence of wrong behaviour, just as a “Data Principal” label is not evidence of correct behaviour.
4. Separate source inventory from the decision matrix
Freshness. Retained vendor pages were accessed in September 2026; that does not establish what they said in November 2025. Legal instrument date, publication date, retrieval date, page update text and product version are separate fields. This chapter withdraws the unsupported 12 April 2026 Schedule-amendment example. No such notification is relied on. Before a purchase, retrieve the relevant body/version again and inspect changed claims. HTTP 200 and a digest alone do not rule out a login page, soft 404 or unrelated content.
Pricing. The source inventory does not contain the former per-record ₹0.02 price. Actual products may meter seats, modules, requests, objects, inspected data or storage. For example, the retained Macie pricing page describes buckets evaluated, objects monitored and quantity of data inspected, and notes additional S3 request charges (V36:85–99).[8] That is a documented meter structure, not a retained India-region quote or the complete cost of the Company’s deployment. Do not normalise every product into “per GB” and hide dimensions that drive cost. Model each quoted meter, minimum, overage, environment, tax and exit term separately; compare total cost only for equivalent scope.
Integration effort. An integration-debt rating needs a scope and a reason. Count target connectors and ownership, identity joins, policy event semantics, retry/ordering, retention classes, observability, upgrade work and exit conversion. Estimate person-hours with ranges after a bounded spike. A product with fewer APIs may be easier or harder depending on the estate; the inception scan does not prove that a monolithic API automatically has higher integration debt.
The decision matrix therefore has its own fields: processing scope, product/module/version, supported claim with source and date, deployment assumptions, unknowns, test contract, mandatory gate, pricing meters, effort range, owner and decision status. A-grade legal sources are never bidder alternatives that can be outranked by B-grade suppliers. Provenance and capability evaluation are different dimensions. The populated out/remediation/Q05/landscape-decisions.json records shortlist hypotheses and open tests, not scores or invented prices.
5. Brand recognition versus applicable evidence
The tension this chapter holds is the one every procurement team lives with: the best-known names in the landscape are also the ones whose material is most polished, and polish is easily mistaken for substance.
The brand pull. A familiar supplier can make internal procurement easier, but familiarity is not evidence for a particular connector, data boundary or legal-control mapping.
The evidence pull. Evaluate the specific module and proposed operating scope. DPDP-specific material is useful for identifying claimed mappings; generic technical documentation may be stronger evidence for an underlying mechanism. Neither should be excluded merely because it uses a different jurisdiction’s terminology. Require primary-law mapping from the buyer’s legal process and actual testable behaviour from the proposed solution.
The failure modes sit on either pole:
- Buy-the-brand. Procuring from a famous firm or platform on reputation, without asking whether the specific capability discharges a specific obligation. The enterprise pays enterprise prices for generic privacy and discovers, at the first control test, that the Section 6 evidence chain or the Section 8(7)(b) processor erasure was never actually in scope.
- Anti-brand cynicism. Rejecting all vendor material can waste useful documented components and force unnecessary maintenance onto the buyer. Public documentation is a reason to investigate, not a reason to assume measured superiority.
Grade sources for provenance and evaluate capabilities against a separate scoped test contract. A strong source supports only the claim it actually documents. Failed retrievals remain labelled invalid evidence; they do not establish that the product or provider has disappeared. A supplier’s claim can be included in the shortlist hypothesis without being accepted as a completed control.
6. How to use the landscape in practice
First, separate statutory mapping from mechanism evidence. Use the retained Act/Rules and applicable instruments for the obligation; use product documentation for claimed APIs, scope and deployment. DPDP-specificity is a useful tag, not a hard filter that excludes a technically suitable generic component.
Second, name the proposed deliverable and its owner. A consent UI, policy service, connector, outsourced rights team and statutory Consent Manager are different purchases. Software does not establish Board registration or an agency relationship for the Data Principal; the Act’s definition and Section 6(9) concern a registered person (ACT:65–67,258–268).[1] Do not promise that a software vendor holds that role unless independently verified.
Third, verify evidence identity and applicability. Retain exact URL, retrieval date, body hash, product version when known, claim-bearing passage and unresolved questions. A new hash only says the body differs; review the difference before changing a score. A stale legal page may coexist with current technical capability, so preserve the distinction rather than discard or accept everything by brand.
Fourth, define the PoV before seeing the demo. Supply expected permitted and denied branches, target systems and data minimisation requirements. Include failed or late processor action, lawful restricted retention and changed authority. A vendor that completes a narrow test has demonstrated that narrow test; the buyer still owns applicability, integration coverage and operation. Keep mandatory failures separate from optional quality/price comparisons.
Chapters 26–30 develop named advisory approaches, provider/module evidence, cloud and open-source choices, and acceptance scoring. This chapter supplies the entry discipline; it does not pre-empt those comparisons with an invented ranking. An invalid page or untested connector is a question to resolve, not permission to fabricate a finding.
7. Build, buy or commission: alternative mechanisms
Treat each path as a scoped hypothesis. Buying can be sensible where a documented component fits the estate and passes its test contract. Building can be sensible where policy semantics, integration or ownership require changes not supplied in the proposal. Commissioning can provide scarce delivery capacity while leaving accountability and long-term maintenance with named owners. None is intrinsically compliant or cheaper.
For a discovery component, compare supported sources and identifier/language quality on a labelled corpus, including excluded formats and missed records. For a workflow suite, compare the exact rights, exception, withdrawal and retention behaviours needed. For a custom policy service, price maintenance, security review, replay/ordering and operational coverage, not only initial code. For a services engagement, define which artifacts and operational skills the buyer owns at handoff. A vendor publication proves none of those delivery outcomes.
Hybrid architecture is a plausible option, not the scan’s empirical conclusion. It can preserve existing investments and reduce raw-data movement while adding cross-system identity and evidence reconciliation. A purchased connector can still need buyer-written restrictions; a custom workflow can still depend on commercial infrastructure. Map those dependencies before comparing total cost.
The acceptance unit is the scoped control in its intended environment. Procurement changes who supplies or operates pieces; it does not remove the fiduciary’s responsibility for processing undertaken by it or on its behalf (ACT:330–337).[1] A green demo is therefore neither a transfer of accountability nor a certificate that all relevant obligations have been satisfied.
8. Two hypothetical procurement decisions
Assumptions. These are authored shortlist exercises, not live trials or a three-vendor competition. The decision artifact separates documentary evidence from hypothetical estate fit. No supplier price, capability pass or signed commitment is fabricated.
Company case — split the work before shortlisting. CASE-001 has a lending monolith, warehouse, separate training/serving environment and marketing processor. The immediate need is to reject unauthorised training, accept marketing withdrawal and account for a missing processor acknowledgement. A privacy suite is a candidate for case orchestration, but the purpose gate and existing job paths require explicit integration. Seqrite’s retained workflow claims support asking for a scoped demonstration, not assuming those integrations work.[6] Privado’s repository scan supports a separate hypothesis about finding code-level flows, not a substitute for the runtime gate.[5] The matrix records both as open research paths with owners and falsifiers. If the scan misses the known export, its coverage is insufficient for that use. If the runtime workflow rejects withdrawal or reports complete erasure with a missing target, it fails the mandatory criterion. No amount of attractive UI or recognised terminology repairs that failure.
Narrow S3 case — do not buy an entire programme to answer a bucket question. Suppose a distinct bounded work package needs sensitive-data visibility in existing S3 storage, with rights/consent workflow already owned elsewhere. Macie’s documented S3 scope makes it a candidate component, subject to file-type, regional, identifier-quality and findings-integration checks.[7] The pricing work must include bucket/object/inspection dimensions and related requests, not only GB.[8] If the actual need expands to non-S3 systems or processor erasure, the work package changes; the documented component scope cannot be stretched by renaming it “DPDP platform”. The answer might become a suite, additional components or custom integration, but that decision requires new evidence.
These cases lead to different test contracts before any ranking. The first prioritises cross-system semantics and operating ownership; the second isolates discovery and cost meters. Their common gate is honest scope. The matrix can return “insufficient evidence” without inventing a winner, and can retain more than one option when each addresses a different layer.
Reader exercise: turn one claim into a falsifiable request
Choose one proposed module. State the exact processing path, data scope, assumed deployment, required permitted action and required denied action. Name the identity/authority facts that are trusted and how a failed callback will be represented. Attach the retained source passage that establishes the vendor’s claim, then list what the PoV must establish beyond it. Do not use a test that all suppliers pass by returning an HTTP status without demonstrating the underlying effect.
For a withdrawal path, distinguish accepting the request, enforcing current policy, processor propagation, lawful retention and disposal. For discovery, distinguish supported corpus coverage, sampled quality and unknown systems. For both, define ownership of raw evidence and exit export. This is the point at which a landscape becomes useful procurement work: the claim is converted into a decision that could genuinely go the other way.
9. What remains for a live decision
Before procurement, revalidate current product/version evidence and contracting entities, establish actual sector/control scope, obtain comparable prices and integration estimates, and exercise the proposed deployment. Those are deliberately open fields in the supplied decision matrix. The inception inventory is verified as a source artifact, not promoted to completed due diligence. Later chapters must retain the same separation of documentation, test observation and unknowns.
The question that hands the book its next chapter
Within the landscape, the most visible and most frequently consulted category is the global strategy and audit firms — McKinsey and the Big Four — whose “approaches” tempt the enterprise to outsource not just delivery capacity but the analysis itself. Chapter 26 takes up McKinsey and Big Four Approaches: how to use their methodology without ever mistaking it for the law.
References (sources retained)
dpdp_solution_landscape.xlsx: unchanged source inventory, actual schema/hash check in the Q05 packet.research/solutions/SOLUTIONS_LANDSCAPE.md: bounded inception synthesis; not a ranking.out/remediation/Q05/landscape-decisions.json: completed hypothetical research decisions with open PoVs, no fabricated supplier results.- Retained claim passages V18, V23, V35 and V36 resolve to the source-key paths below; exact URL/date/hash manifest is
out/remediation/Q05/source-manifest.json.
Source keys and evidence limits
Line locators use newline-based retained text, not PDF page numbers. Primary sources were reread locally; no complete live legal-update search or entity-specific opinion is asserted. Vendor passages are documented claims, not observed capabilities.
COMM:research/legal/evidence/02_gsr_843e_commencement.txt.RULES:research/legal/evidence/05_gsr_846e_dpdp_rules_2025.txt.CORR:research/legal/evidence/06_gsr_892e_corrigendum.txt.V18:research/solutions/evidence/18-docs.privado.ai-quick-start-privado.md.V23:research/solutions/evidence/23-www.seqrite.com-data-privacy-compliance-management-solutions-seqrite.md.V35:research/solutions/evidence/35-docs.aws.amazon.com-what-is-amazon-macie-amazon-macie.md.V36:research/solutions/evidence/36-aws.amazon.com-sensitive-data-discovery-amazon-macie-pricing-amazon-web-services.md.ACT:research/legal/evidence/01_dpdp_act_2023_gazette.txt.
Sources
[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) [2] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — G.S.R. 843(E), DPDP Act commencement notification [3] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) [4] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — Corrigenda to G.S.R. 846(E), G.S.R. 892(E) [5] https://docs.privado.ai/getting-started-with-privado/getting-started-with-privado — Quick Start | Privado [6] https://www.seqrite.com/data-privacy — Data Privacy Compliance & Management Solutions | Seqrite [7] https://docs.aws.amazon.com/macie/latest/user/what-is-macie.html — What is Amazon Macie? - Amazon Macie [8] https://aws.amazon.com/macie/pricing — Sensitive Data Discovery – Amazon Macie Pricing – Amazon Web Services
Contents · Reader guide and citation conventions · Artifact index