Skip to main content
GullySystem
Data Protection and DPDP Readiness

Know What Personal Data You Hold, Who Can See It, and What Happens If It Leaks

GullySystem maps the personal data your systems hold, builds consent records, access roles, retention rules and a breach response you can actually follow, and prepares your software for India’s Digital Personal Data Protection Act. Your lawyer decides compliance. We do the engineering.

  • We map what you hold before recommending anything
  • Engineering and documentation, with your lawyer taking the legal call
  • No guarantee of compliance from us or from anyone selling software

We work on the data side of this with clinics holding patient records, schools holding children’s details, lending businesses holding KYC documents, e-commerce brands holding addresses and payment records, and service companies whose enquiry forms have been collecting more than anyone realised since 2018. The work is engineering: consent captured properly, roles that limit who sees what, retention that actually deletes, and a breach plan somebody can follow at eleven at night.

The operational challenge

Could You Say Today Exactly Where Your Customers’ Personal Data Is Stored?

!

Nobody Knows Every Place a Phone Number Lives

It is in the CRM, the billing software, an exported sheet on a shared drive, three WhatsApp groups, an old enquiry inbox and a backup from 2019. Asked to list them, the team would miss half.

!

Every Login Can See Everything

The intern doing data entry can open the same customer records as the owner, including addresses, ID documents and payment history, because roles were never set up and it was simpler that way.

!

The Form Asks for More Than It Needs

A contact form collects date of birth, full address and a free-text box because those fields were in the template. None of it is used. All of it now has to be protected, stored and eventually deleted.

!

Data Is Never Deleted, Only Accumulated

Enquiries from six years ago, candidates who never joined, customers who left in 2020. Nothing has a retention rule, so the volume of personal data you are responsible for only ever grows.

!

Customer Records Sit in a Former Employee’s Google Account

The sheet was created on a personal login, shared with a link, and forwarded onward. When they left, the handover covered the laptop and the SIM, not the file that is still accessible.

!

A Marketing Tool Was Wired to the Form and Forgotten

Somebody connected the website form to an email platform during a campaign. Every enquiry since has been copied into a third-party system nobody reviews, under an account whose password is in a chat thread.

!

No Plan for the Morning You Find Out

If a laptop is stolen, a database is exposed or an employee copies the customer list on the way out, nobody knows who to call, what to check first, who has to be told or what to write down.

Data protection is not a document you buy. It is knowing what you hold, collecting less of it, limiting who can open it, deleting what you no longer need, and being able to act on the morning something goes wrong.

GullySystem Solution

Map It, Reduce It, Control Access to It, Then Prepare for the Bad Day

We start with a data map: every system, form, sheet, inbox and backup that holds personal data, what is in it, why, who can reach it and how long it stays. From that we cut what you do not need, build consent and access controls into the software, set retention that actually runs, and write a breach response your team can follow under pressure.

Collect Less in the First Place

The cheapest personal data to protect is the data you never asked for. We go through every form and field and remove what nobody uses, which shrinks the problem before any control is built.

Consent With a Purpose and a Date

A record of what each person agreed to, when, through which form, in which language, and a withdrawal that actually stops the processing rather than setting a flag nobody reads.

Built Into the Software, Not a Policy on the Wall

Roles, field masking, audit logs, retention jobs and deletion paths implemented in the systems themselves, because a rule that depends on staff remembering it is not a control.

Operational ROI

What Changes Once Data Protection Is Engineered

Focus on business value before discussing technology. Here is what your team accomplishes in week one.

Mapped

You Can Answer the Question in One Page

What personal data you hold, in which systems, why, who can reach it and how long it stays, written down and kept current rather than reconstructed in a panic.

Less Held

Forms Stop Asking for Things Nobody Uses

Fields that existed because the template had them are gone. Every field that survives has a reason somebody can state, which makes the rest of the work smaller.

Role-Based

Staff See What Their Job Needs

The counter sees enough to serve a customer, the accounts desk sees the ledger, and full records need a reason. Exports are limited and logged rather than one click from any login.

On Record

Consent and Withdrawal Both Work

Purpose, timestamp and source stored for each person, an opt-out that removes them from the actual sending list, and a request path that reaches a real inbox somebody watches.

Retention

Old Data Leaves on Schedule

Enquiries, candidate records and closed accounts age out according to a rule that runs by itself, so the volume you are responsible for stops growing without limit.

Rehearsed

The Bad Morning Has a Checklist

Who is called first, what is isolated, what evidence is preserved, who has to be told and what is written down, agreed while everyone is calm rather than invented at eleven at night.

Scope of service

What Data Protection and DPDP Readiness Work Includes

Everything required from operational discovery to production deployment and long-term maintenance.

01

Personal Data Discovery and Mapping

Every database, application, form, spreadsheet, inbox, shared drive and backup examined for personal data, with what is held, why, who can reach it and where it flows next.

02

Data Minimisation Review

A field-by-field pass over your forms and screens asking who uses each one and for what, ending with a list of fields to stop collecting and data to stop copying.

03

Consent Capture and Records

Consent built into forms, counter software and messaging flows with purpose, timestamp, language and source stored, plus a withdrawal path that reaches every downstream system.

04

Privacy Notice and Purpose Documentation

A plain notice stating what you collect, why, who it goes to and how long you keep it, drafted from the actual data map rather than copied from another company’s website.

05

Role-Based Access Design

Permissions rebuilt around jobs, with field-level masking for identifiers, restrictions on bulk export, and a review of who currently holds administrator rights and why.

06

Retention and Deletion Rules

A retention schedule per record type, implemented as jobs that archive or delete on time, with the handling of backups written down rather than assumed.

07

Data Principal Request Handling

A working path for someone asking what you hold, asking for a correction or asking for erasure: where the request lands, who acts, how identity is checked and what is recorded.

08

Security Controls and Hardening

Encryption in transit and at rest, password and two-step login policy, server and database hardening, logging that survives an incident, and removal of default or shared accounts.

09

Third-Party and Processor Review

The list of vendors touching your data, what each receives, where it is hosted, what the contract says about it, and which forgotten integrations should be disconnected.

010

Breach Detection and Response Plan

Alerting for the events worth noticing, a written runbook naming who does what in the first hour, the notification steps the Rules set out, and a template for recording the incident.

011

Staff Handling Rules and Training

Short, practical training on exports, WhatsApp groups, personal drives, customer photographs and what happens to access on the day somebody leaves.

012

Readiness Assessment and Roadmap

A written report ordered by priority: what to fix now, what to plan, what is fine as it is, with your lawyer’s view built in where the question is legal rather than technical.

Practical applications

Where This Work Matters Most

Real-world business processes we configure and automate.

Clinic Group: Patient Records Open to the Whole Front Desk

Every receptionist login could open any patient’s history across three branches. We built roles so the desk sees what it needs to register and bill, clinical notes need a clinical login, and every record opened is logged. The scanned ID documents nobody had looked at since 2019 were given a retention rule.

Lending Business: KYC Documents on a Shared Drive

Aadhaar and PAN scans collected by field agents sat in a folder any staff member could browse, some of them also forwarded on WhatsApp. Uploads were moved into the loan record with restricted access, masking applied to the identifier on screen, and a rule written for what happens to documents after an application is rejected.

School: Children’s Data Held Long After They Left

Admission forms, photographs, parent phone numbers and medical notes going back a decade, in one system with no retention rule and no role separation. We separated what the office needs from what teachers need, and set retention with the management deciding, on their lawyer’s advice, what had to be kept and for how long.

Therapy Practice: A Contact Form That Asked Too Much

The website form had a free-text box asking what brings you to therapy, feeding a shared office inbox and an email marketing tool somebody had connected during a campaign. The box was removed, the marketing tool disconnected, enquiries routed to one private inbox, and advertising pixels taken off the booking pages entirely.

E-Commerce Brand: Addresses, Orders and a Departed Developer

Customer addresses and order history were readable through an admin login shared by four people, and a former developer’s account still had database access. Individual accounts with two-step login replaced the shared one, the old credentials were revoked, export was restricted and logged, and alerting was added for bulk downloads.

Manufacturer: A Case Where Very Little Was Needed

A firm selling only to other businesses held little beyond contact names, GST numbers and purchase history. We tightened access, removed two unused fields, wrote a short notice and stopped. Spending on a large programme there would have been money wasted, and we said so in the report.

Audience fit

Is This Service Right for Your Business?

We partner with established businesses that have outgrown manual processes and want reliable systems.

Businesses Holding Health, Financial or Children’s Data

Clinics, diagnostic centres, therapy practices, lenders, insurance intermediaries and schools, where the records are sensitive and the consequences of exposure are personal.

Companies With Customer Data Spread Across Systems

Where the same person exists in the CRM, the billing software, a marketing tool, a courier portal and four spreadsheets, and nobody has ever counted the copies.

Businesses Building or Rebuilding an Application

The cheapest time to get consent, roles, logging and retention right is while the screens are being designed, not after go-live.

Firms Being Asked About Data by Customers

Larger clients, hospitals, banks and companies abroad increasingly send a security questionnaire before signing. Answering it honestly requires knowing what you hold.

Owners Who Have Just Had a Scare

A stolen laptop, a departed employee with the customer list, a phishing email that worked. The useful response is a map, tighter access and a written plan, not a new antivirus licence.

When You Do Not Need a Large Programme

A business holding only company contact details, GST numbers and purchase history has a much smaller problem than a clinic, and should spend accordingly. If you collect little, keep it in one system and control who logs in, tightening access and writing a short notice may be all the engineering that is justified. Anyone selling you a compliance package without first looking at what you actually hold is selling a document, not a control. We would rather write a short report that says you are largely fine.

Feature matrix

Enterprise Capabilities in Plain Business Terms

Data Inventory and Flow Map

Every store of personal data listed with purpose, sensitivity, access, location and onward flow, in a form your team can maintain.

Consent Records With Purpose

Purpose, timestamp, language, source and version stored per person, with the history of changes kept.

Working Withdrawal Path

Opting out removes the person from the actual sending lists and downstream systems, tested end to end rather than assumed.

Role and Field-Level Permissions

Access decided by job, with identifiers masked on screens that do not need them and full records requiring a reason.

Bulk Export Controls

Downloads limited to specific roles, logged with who, when and how many rows, with alerting on unusual volumes.

Audit Logging

Who opened, changed, exported or deleted which record, stored where it cannot be edited by the people it records.

Retention Jobs

Scheduled archival and deletion per record type, with a report of what was removed and when.

Erasure and Access Request Handling

A defined path from request to action, including identity checks, what gets produced and how backups are treated.

Encryption and Key Handling

Data encrypted in transit and at rest, with keys managed properly rather than sitting in the application’s own code.

Processor Register

A maintained list of vendors touching your data, what each receives, where it is hosted and what the contract covers.

Breach Runbook

A written first hour: who is called, what is isolated, what evidence is kept, who is told and what is recorded.

Joiner and Leaver Access Control

Access granted by role on joining and removed on the last day, with a periodic review of who still holds what.

Execution roadmap

Our Structured 6-Step Delivery Process

A transparent path from your first conversation to a reliable production release.

01

Discovery and Data Mapping

We go through your systems, forms, drives, inboxes and backups and record what personal data sits where. From you we need read access to those systems and an honest account of the informal places data lives, including WhatsApp groups and personal drives.

02

Risk Review and Minimisation

We rank what we found by sensitivity and exposure, and mark what you should stop collecting. From you we need someone from each department who can say whether a field is actually used, because only they know.

03

Readiness Report and Roadmap

A written report ordered by priority: fix now, plan later, leave alone. From you we need your lawyer’s involvement at this point, because several items are legal questions dressed as technical ones.

04

Engineering the Controls

Consent capture, roles, masking, logging, retention jobs and request handling built into the systems. From you we need decisions on retention periods and a test environment rather than live data to work in.

05

Breach Plan and Staff Rules

The runbook written, alerting configured and short practical training for staff. From you we need the names of the people who will actually be called, and their agreement to be on that list.

06

Verification and Review Rhythm

We test that deletion deletes, that withdrawal stops the messages and that access is what the roles say. From you we need an owner for this inside the business and a date in the calendar to review it again.

Asset handover

What You Receive Upon Project Completion

Everything required to run, maintain, and expand your software without vendor lock-in.

Personal data inventory and flow map across every system
Field-by-field minimisation list of what to stop collecting
Prioritised readiness report: fix now, plan later, leave alone
Consent capture implemented with purpose, source and timestamp
Privacy notice drafted from your actual data map
Role and permission matrix, with masking and export rules
Retention schedule implemented as scheduled jobs
Request handling path for access, correction and erasure
Breach response runbook with named roles and a recording template
Processor register listing every vendor that touches your data
Connected ecosystem

Connects With the Systems You Already Rely On

We build bridges between your software so you don't have to replace functional existing tools.

Business Systems Holding Data

  • Custom applications and portals
  • Zoho CRM and Zoho One
  • Tally
  • Odoo
  • Clinic, school and lending software

Identity and Access

  • Google Workspace
  • Microsoft 365 and Entra ID
  • Two-step verification
  • Password managers
  • Single sign-on

Hosting and Storage

  • AWS
  • Azure
  • Google Cloud
  • Indian data centre hosting
  • Encrypted backup storage

Customer Channels

  • Website forms
  • WhatsApp Business Platform
  • Email marketing tools
  • Payment gateways
  • Courier and logistics portals

Monitoring and Logging

  • Centralised log storage
  • Alerting on bulk exports
  • Uptime and intrusion monitoring
  • Backup restore testing
Engineering foundation

Selected for Reliability, Speed, and Longevity

Technology chosen to match your operational scale and long-term maintainability.

Access Control

Role-based permissionsField-level maskingSingle sign-onTwo-factor authentication

Data Protection

TLS in transitEncryption at restKey management servicesTokenisation of identifiers

Discovery and Classification

Database scanning scriptsPattern matching for identifiersFile share crawlers

Logging and Alerting

Append-only audit logsCentralised log storageAnomaly alerts on exports

Retention and Deletion

Scheduled purge jobsArchival storage tiersBackup lifecycle rules
The GullySystem difference

Why Business Owners Choose GullySystem

We Do the Engineering, Your Lawyer Does the Law

We engineer controls, write documentation and produce evidence. The legal interpretation belongs to your advocate, and we work alongside them rather than pretending to replace them.

Nobody Can Sell You Compliance

No software, certificate or package makes a business compliant. What exists is a set of controls you can show and a record of decisions you can defend. We will not tell you otherwise to close a sale.

The Map Comes Before the Policy

A privacy notice written before anyone has looked at your systems describes a company that does not exist. We find out what you actually hold first, and the documents follow from that.

We Look for Data to Delete

Most reviews add controls. We start by removing fields nobody uses and records nobody needs, because the data you no longer hold cannot leak and costs nothing to protect.

Controls Inside the Software

Roles, masking, logging and retention jobs implemented in the systems themselves. A rule that depends on staff remembering it every day is not a control, it is a hope.

We Test That Deletion Deletes

Erasure paths, opt-outs and access restrictions are verified end to end, including what remains in backups, because these are the things that turn out not to work exactly when they are needed.

Commercial models

Flexible Engagement Options

Choose an engagement model that matches your operational scope, budget, and timeline.

Data Protection Assessment

Find out where you stand

Discovery, mapping, risk review and a written report ordered by priority, delivered on its own so you can decide what to do and in what order.

Readiness Implementation

Build the controls

Consent capture, access roles, masking, logging, retention jobs, request handling and the breach runbook, engineered into the systems you actually run.

Privacy by Design in a Build

While the software is being made

Data protection designed into a new application as it is built, which costs a fraction of retrofitting the same controls into a system already carrying live records.

Ongoing Review

Revisited periodically

Access reviews, the processor register kept current, retention jobs checked, new systems added to the map, and the breach plan rehearsed rather than filed.

Common questions

Frequently Asked Questions

Straightforward answers to the questions owners ask before getting started.

When do the DPDP obligations actually apply to us?

India’s Digital Personal Data Protection Act, 2023 is law, and the Digital Personal Data Protection Rules, 2025 set out how it works in practice. Under those Rules, duties such as the privacy notice and security safeguards take effect in May 2027. A shorter timeline has been proposed, so confirm the current date with your lawyer rather than relying on any date on a vendor’s website, including ours. The practical advice is to build for those duties now, because mapping data, fixing access and adding retention take months and cannot be done in the last fortnight.

Can you make us DPDP compliant?

No, and be careful with anyone who says they can. Compliance is a legal conclusion about your business, drawn by your lawyer, and it depends on decisions only you can make about purposes, retention and risk. What we can do is engineering and evidence: map what you hold, cut what you do not need, build consent records, access roles, retention and logging, write the breach runbook and document the decisions. That is what a regulator, a customer or a court would look at. The word compliant is not ours to give.

What is the first thing we should do?

Find out what you hold. Almost every business underestimates it, because personal data is not only in the CRM. It is in exported spreadsheets, shared drives, an old enquiry inbox, WhatsApp groups, a marketing tool somebody connected once, backups and a former employee’s personal Google account. Until that map exists, every policy is guesswork and every control is applied to the wrong place. The mapping usually also produces the quickest wins, because it turns up data you can simply stop collecting or delete.

Does our data have to be stored in India?

Ask your lawyer, because the position depends on rules about transfers outside India and on your own sector. Banking, insurance, health and payment businesses often have sector rules that bite harder than the general law. What we can tell you is the engineering side: which of your systems and vendors currently store data outside India, what the options are for hosting in an Indian region, and what moving would cost and break. We put that in the report so the legal decision is made with the facts in front of it.

What has to happen if we have a data breach?

Act, then tell. The Rules require that affected individuals are informed and that the Data Protection Board is notified, within the timelines the Rules set, so this is not something to work out on the night. Practically, the runbook we write names who is called first, what gets isolated or shut off, what evidence is preserved before anyone starts fixing things, who signs off the notification and what gets recorded. Preserving logs matters more than people expect, because a team in a hurry often destroys the evidence of what happened while trying to stop it.

Do we need consent for every message we send a customer?

Not for everything, and the distinction matters. Sending an invoice, a delivery update or a service notice to a customer you are already dealing with is different from marketing to a list. Consent has to be specific, informed and withdrawable, and the withdrawal has to actually work, which is where most businesses fail: the opt-out sets a flag and the next campaign is sent from an exported sheet anyway. We add consent capture with purpose and date, and test that withdrawal removes the person from the real sending list.

How long should we keep customer data?

Only as long as the purpose you collected it for lasts, plus whatever a separate law requires you to keep. Tax, company and sector rules often force you to retain invoices and financial records for years, and those requirements win. The data that usually has no justification is the accumulated middle: enquiries from six years ago, candidates who never joined, closed accounts nobody will service again. Your lawyer sets the periods. We implement them as jobs that run on schedule, and report what was removed.

What about data sitting in old backups?

Backups are the honest hard part and anyone who waves it away has not implemented this before. You cannot practically reach into an encrypted backup from last March and remove one person. The workable approach is to set a backup lifecycle so old copies expire on a defined schedule, keep a record of erasure requests, and re-apply them if a backup is ever restored. That position is written down rather than left unsaid, because it is exactly the question you will be asked after an incident.

Do we need to appoint a Data Protection Officer?

Whether a formal appointment is required depends on how the law classifies your business, and that is a question for your lawyer. What every business needs regardless is a named person who actually owns this: who receives requests from customers, who is called when something goes wrong, who reviews access every few months and who keeps the data map current. In most small and medium businesses this sits with an owner, a finance head or an operations head rather than a new hire.

How much does this cost?

It follows how much you hold and how spread out it is. An assessment for a business with one system, a website form and a few hundred customers is modest work. A clinic group with three branches, scanned documents, an old application and years of accumulated records is a different scale. The main drivers are the number of systems to map, how much data is unstructured, how much has to be built rather than configured, whether an existing application needs re-engineering, and whether ongoing review is included. We quote after the discovery, so the number reflects what we found.

Can you work with our existing lawyer or auditor?

Yes, and it usually goes better that way. We take the technical side: what exists, what is exposed, what can be built and what it would cost. They take the legal positions: purposes, lawful basis, retention periods, contractual terms with vendors and what has to be notified. Our report is written to be handed straight to them, with the technical findings stated plainly and the legal questions marked as legal questions rather than answered by us.

We are a small business. Does any of this really apply to us?

Size does not exempt you, but it does change what is proportionate. A ten-person firm holding company contacts and purchase history has a genuinely small problem and should spend accordingly: tighten who can log in, remove fields nobody uses, write a short notice, and stop. A ten-person clinic holding patient histories and scanned IDs has a real one. The mistake is assuming smallness makes you invisible, because most incidents at this size are not attacks at all but an employee leaving with the customer list or a shared drive nobody ever reviewed.

Should we build data protection into a new application or add it later?

During the build, always, because the difference in cost is large. Consent fields, role-based access, audit logging, masking and retention are cheap when they are designed with the screens and expensive when they are retrofitted into a system already holding live records and habits. Retrofitting also means migrating data into new structures and retraining staff who have learnt the old permissions. If you are commissioning software now, this is one of the few places where spending earlier genuinely costs less overall.

Let’s Connect

Let’s Build the Right Software for Your Business

Tell us about your current operational challenge, spreadsheet bottleneck, or software requirement. An experienced engineer will review your workflow and reply within one business day.

  • No obligation consultation
  • Senior engineer reviews your brief
  • Your operational details stay 100% confidential

Discuss Your Requirement

Fill out this brief form and we’ll get back to you within one working day.

Your details are private and secure. Protected by reCAPTCHA.