Legal Register
Part V — Solutions, Accelerators & Build-vs-Buy
Part V — Solutions, Accelerators & Build-vs-Buy
Chapter 27 · 2,511 words
13 min read

Chapter 27 — Indian Technology Firms and Specialist Providers

1. Proximity is a question, not a score

A buyer may prefer a team that can work in its languages, time zones and sector environment. Those are legitimate requirements to investigate. They are not grounds for assigning a higher probability of successful integration to an entire nationality or provider category. The retained sources do not establish such a comparative advantage. Evaluate the named delivery team, product edition, operating hours and target interfaces instead.

“Indian provider” also obscures the object being purchased. An assessment service, recurring privacy operator, consent product and repository scanner have different outputs. A large services firm may supply both people and proprietary tools; a security vendor may also offer a broad privacy-management product. The correct classification sits at product or service level, not at parent-brand level. This changes the shortlist before any scoring begins.

The useful procurement unit is a boundary: who controls a dataset, who makes the purpose decision, which system enforces it, and who keeps the evidence when execution fails. In CASE-001, the Company’s marketing processor ENT-004 operates SYS-003, while SYS-010 issues authority events and SYS-013 tracks processor execution. A bidder may supply only one part. The client still needs an owner for the whole interaction.

2. Named comparison: people, products and engineering components

The left side of this table reports captured claims. The right side is the author’s proposed investigation, not a statement of measured fit. All source ranges are newline-based within the retained file identified by the reference.

Provider / offeringDocumented category and DPDP specificityArtifact to request and operating unknown
Infosys Data Protection and Privacy Services / iEDPSServices plus a named discovery/classification tool used with partner products.[24] Lines 55–87. A separate DPDP article describes iEDPS, Securiti.ai and the 4D stages Diagnose, Design, Deliver, Defend.[25] Lines 37–54.Ask for the licensed product boundary, actual connector architecture and separate partner dependencies. Request a discovery result with unsupported stores listed, a mapped remediation backlog and who maintains each connector. The article is historical framing, not verified final-Rules implementation.
TCS’ Consent Management SolutionProductized consent/privacy capability, not merely generic consulting: consent collection/enforcement, master-store rights integration, PIA, processing records, incident tracking and inventory/mapping are listed.[26] Lines 155–174. Separate DPDPA/converged-GRC material discusses cross-functional operations.[27] Lines 84–88.Request a receipt schema, server-side enforcement demonstration, current DPDP mapping and deployment/API contract. UI masking and published “ready-to-use APIs” do not establish denial of an unauthorised backend job.
Wipro Data Privacy Strategy & GovernanceGeneric advisory and implementation services. The page names assessments, vendor risk, privacy by design, DPO-as-a-service and breach/consent-rights automation, with GDPR-oriented framing.[28] Lines 31–35.Request a current DPDP work package, asset list, versioned source mapping and operator responsibility. “No named DPDP product verified here” does not mean Wipro offers none.
Tsaaro DPO as a Service / Privacy Compliance ServicesOutsourced privacy capacity and advisory services; DPDPA appears alongside multi-jurisdictional services. Documented tasks include strategy, monitoring, assessments, rights, incident coordination and training.[20] Lines 90–98.[21] Lines 92–150.Request named personnel and backups, workload assumptions, decision authority, approved tooling, case evidence and client escalation route. An outsourced service label does not itself establish the statutory DPO appointment.
Seqrite Data Privacy / Seqrite DPDP Act Compliance SolutionCommercial privacy-management platform in a security portfolio, not just the security slice: discovery, consent/preferences, rights cases, assessments and breach workflows are claimed.[23] Lines 73–109. Modular licensing and cloud/on-premise/hybrid deployment are expressly described.[23] Lines 189–219.Request exact modules/editions, target connectors, deployment diagram, tenancy and support paths. Test the consent and rights claims rather than excluding them on the basis of Seqrite’s security heritage.
Privado repository scannerDeveloper-facing code scanning/data-flow evidence. Quick Start documents privado scan <source directory>, local .privado/privado.json output and optional dashboard synchronization; it says no code is sent to the cloud.[18] Lines 25–41.Request supported languages, static-analysis limits, findings schema, scan exclusions and the actual synchronization payload. Repository discovery is not proof of runtime rights, consent or erasure orchestration.

The comparison yields concrete alternatives. If the missing capability is case handling, a repository scanner is not a substitute for an operator or case system. If the missing capability is code-to-data-flow visibility, buying a managed DPO service does not by itself supply it. A Seqrite module and a TCS solution may warrant a consent/rights PoV, while Infosys’ named discovery tool warrants a different test boundary. These are shortlist hypotheses; none is a procurement award.

3. What changes when claims are read closely

Infosys’ retained DPDP article is particularly useful because it exposes both an accelerator and a delivery decomposition. Diagnose produces a gap/recommendation starting point; Design concerns controls; Deliver concerns implementation; Defend concerns recurring assessment.[25] Lines 45–54. The author’s adaptation would make each stage hand over a specific object: a processing scope and unknown-set register, a control design, a tested interface, and an operating test schedule. The next stage should not inherit a green label without the object that supports it.

The same article uses Bill-era language and broad summaries about consent and deletion.[25] Lines 19–35. Do not transplant those legal summaries into the final-Rules register. The useful contribution is a documented method and tool positioning, not a complete statement of current law. A bidder should explain how its current assets differ from that retained publication.

TCS’ feature list includes portability and restrictions on sale/sharing.[26] Line 160. Those can be useful global-product functions, but they are not thereby DPDP rights. Sections 11–12 describe access information, correction, completion, updating and erasure with specified scope and exceptions; they do not establish a general portability right.[1] Lines 441–476. The buyer can contract for export capability while calling it a contractual feature rather than a statutory entitlement. “DSAR” vocabulary is not a failure: wrong operational semantics are.

Seqrite’s broad claims must remain broad claims, neither suppressed nor accepted. Its deployment FAQ gives a reason to request an on-premise or hybrid design, not proof that all telemetry, support access, updates and disaster recovery remain within the requested boundary.[23] Lines 193–219. Its multilingual consent description and connector counts require edition-specific demonstrations before use. A buyer should not infer full write/delete support from a discovery connector count; read-only discovery and reliable processor execution are separate capabilities.

Privado’s documentation is a stronger basis for an inspectable scan experiment than a generic feature banner, but still not an experiment performed by this book. The result file can reveal code paths and data categories without proving that every production data store or dynamically configured destination was scanned. Optional cloud synchronization creates a separate review question even if source code remains local: findings may expose system names, flow relationships or sensitive context. Inspect the payload rather than treating “no code” as “no data movement.”[18] Lines 35–41.

4. A legally scoped PoV, not a universal deletion demonstration

Use synthetic identifiers and buyer-controlled isolated systems. Do not begin with a demand to execute destructive tests on customer production data. The following scenarios are proposed acceptance specifications; the later scorecard’s local calculations do not constitute execution of these vendor workflows.

Core obligations in these scenarios assume the retained eighteen-month commencement schedule remains unchanged. The commencement notification, Rule 1 and corrigendum are the authority for that assumption, not provider publications.[39] Lines 49–59.[40] Lines 1005–1010.[41] Lines 25–38.

Scenario / legal anchorHypothetical input and buyer testRequired decision and evidence, not just UI output
Withdrawal — Section 6(4)–(6)SUB-001 withdraws CONSENT-002 for PUR-002; replay an earlier grant and delay ENT-004’s acknowledgement.Accept withdrawal; deny new marketing under the buyer’s immediate-gate design; preserve missing acknowledgement as unresolved and escalate. Test later stale replay. Cessation is required within reasonable time with the statutory exception for processing required/authorised without consent; the local gate is a stricter engineering choice.[1] Lines 232–249.
Erasure/retention — Section 8(7), Section 12(3), Rule 8(3)RIGHTS-001 spans marketing data, loan records and restricted evidence; a separate hold applies only to its reviewed transaction scope.Issue a dataset/purpose decision. Remove eligible active copies, restrict data that must be retained, track processor action and test restore quarantine. Lawful retention is not failed deletion or marketing permission.[1] Lines 351–359, 473–476.[40] Lines 1153–1166.
Access/correction — Sections 11 to 12, Rule 14Submit a compound request with verified actor identity, source and derived records, and a changed contact field.Produce the scoped summary and sharing information; make and reconcile correction tasks; keep exceptions and incomplete processors visible. Do not invent a 48-hour statutory correction SLA.[1] Lines 441–476.[40] Lines 1294–1318.
Child restriction — Section 9A synthetic child-targeting proposal contains a valid parent token but no applicable exemption.Reject the targeting proposal; do not merely request re-consent. Keep any separate permitted child-processing branch conditional on its actual purpose/class requirements.[1] Lines 386–403.[40] Lines 1269–1275.
Legacy notice — Section 5(2)A pre-commencement consent record is usable for its original purpose, with no training grant.Provide re-notice as soon as reasonably practicable under the provision; do not label re-notice a universal fresh-consent deadline or silently create training authority.[1] Lines 182–202.

The retention scenario is intentionally not “every system returns 404.” An API may return 404 because authentication failed, a query was scoped differently or an index was removed while underlying data persists. Conversely, a restricted record retained under an applicable law should not be destroyed just to satisfy a demo. Ask for a coverage denominator: all in-scope systems, each expected action, outcome, exception source and unresolved item. A single missing eligible replica is an open defect, not an allowable two-percent erasure miss rate. Discovery recall and execution completeness are different measures.

The source for a genuine forty-eight-hour notice appears in Rule 8(2), before specified-period erasure under that rule; it is not a correction clock.[40] Lines 1142–1152. Rule 14(3) concerns a published grievance-response period not exceeding ninety days.[40] Lines 1308–1311. Buyer-chosen response objectives should be labelled contractual targets and assessed against actual workload and applicable obligations. The CASE-001 five-minute processor target is such an illustration, not a regulator-prescribed deadline.

5. Accountability when capacity is outsourced

A DPOaaS contract should say whether it supplies advisory support, operational case handlers or an individual proposed for a statutory appointment. In the SDF branch, section 10(2)(a) requires an India-based individual responsible to the governing body, representing the SDF and serving as the grievance contact.[1] Lines 418–426. A vendor brand cannot fill those particulars. CASE-001 is not designated as an SDF; its privacy function is an operating choice rather than a fictional statutory appointment.

Keep the Company’s business decision owner separate from the advisor’s advice and the operator’s execution. The vendor should not approve its own data reuse simply because it operates the workflow. Section 8(1) preserves the fiduciary’s responsibility, and section 8(2) requires a valid contract for the specified processor engagement.[1] Lines 330–337. Contractual assistance, evidence exports, subprocessors, incident escalation and access revocation need detail, but the contract cannot turn a factually independent use into processing only on the Company’s instructions.

Independence is similarly fact-specific. The SDF auditor must be independent under section 10(2)(b).[1] Lines 427–429. The author’s procurement safeguard is separate challenge of implementation and operation, with recorded conflicts and counsel review of the actual arrangement. Do not describe a universal same-firm ban as though the retained provision spells it out. Ask who pays, directs, implements, operates and evaluates each control; a single answer repeated across all roles requires scrutiny.

6. Two bounded selection decisions

In the first hypothetical decision, CASE-001 has functioning engineering teams but insufficient operational coverage for rights cases and processor exceptions. Tsaaro’s documented service tasks and Wipro’s DPOaaS/automation service description justify investigating a people-led package.[21] Lines 112–138.[28] Line 35. The Company asks for a coverage roster, per-case effort assumptions, tool permissions, escalation behavior and exportable case history. It does not buy “statutory accountability.” If the proposal depends on a new proprietary platform, that dependency becomes a separate technical and commercial evaluation.

In the second decision, an engineering team already operates its own rights service but cannot reconstruct notice/consent receipts across channels. It investigates the documented TCS and Seqrite consent functions rather than buying a broad privacy staffing engagement.[26] Lines 155–164.[23] Lines 87–109. Its decisive test is downstream enforcement when a grant is stale, not a dashboard screenshot. It may retain Privado separately for repository-flow discovery, but does not score that scanner as if it could replace the missing consent runtime.

A third useful outcome is no award for the requested scope. If every bidder leaves the legacy monolith connector outside its commitment, the client must price and staff that interface itself or narrow the deployment. It must not rename the gap “client responsibility” and then omit it from the implementation plan. The incomplete interface remains a gate regardless of a high score elsewhere.

7. Handover that survives the provider

The retained artifact should state the offering and edition, source date, exact claim, proposed use, accountable client owner, operator, target systems, test result status, exclusions and evidence location. For services, include named-role coverage and continuity arrangements. For products, include module entitlement and configuration exports. For custom connectors, include source/licence rights, build instructions and upgrade responsibility. These are recommended procurement controls, not a statutory document format.

At handover, a client operator should be able to open a failed case, explain its retention decision, retry only the eligible action and distinguish acknowledgement from demonstrated effect. Training that covers only the happy path is not operational transfer. Evidence must remain accessible when the provider is replaced; sensitive payloads need appropriate restrictions rather than indiscriminate export into a tender folder.

Chapter 28 narrows the comparison to privacy suites, cloud services and engineering components. The lesson carried forward is classification by the actual thing being bought, followed by tests at its boundaries—not faith in a company category.

Source notes

References identify first-party claims or retained primary law at point of use. Exact retained file, URL, date and hash mappings are in out/remediation/q08/source-manifest.json; no provider capability was independently demonstrated.

Retained file map

The line ranges cited above refer to these exact local captures:

Sources

[1] https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdfhttps://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf [18] https://docs.privado.ai/getting-started-with-privado/getting-started-with-privado [20] https://tsaaro.com/services [21] https://tsaaro.com/dpo-data-protection-officer [23] https://www.seqrite.com/data-privacy [24] https://www.infosys.com/services/cyber-security/offerings/data-privacy-protection.html [25] https://blogs.infosys.com/emerging-technology-solutions/datanext/india-dpdp-demystify-the-data-protection-controls.html [26] https://www.tcs.com/what-we-do/services/cybersecurity/solution/consent-management-solution [27] https://www.tcs.com/insights/blogs/dpdpa-compliance-why-converged-grc-matters [28] https://www.wipro.com/consulting/data-privacy-strategy-and-governance [39] https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf — G.S.R. 843(E), DPDP Act commencement notification [40] https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf — Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) [41] https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf — Corrigenda to G.S.R. 846(E), G.S.R. 892(E)


Contents · Reader guide and citation conventions · Artifact index