Know What Personal Data You Hold, Who Can See It, and What Happens If It Leaks
GullySystem maps the personal data your systems hold, builds consent records, access roles, retention rules and a breach response you can actually follow, and prepares your software for India’s Digital Personal Data Protection Act. Your lawyer decides compliance. We do the engineering.
- We map what you hold before recommending anything
- Engineering and documentation, with your lawyer taking the legal call
- No guarantee of compliance from us or from anyone selling software
We work on the data side of this with clinics holding patient records, schools holding children’s details, lending businesses holding KYC documents, e-commerce brands holding addresses and payment records, and service companies whose enquiry forms have been collecting more than anyone realised since 2018. The work is engineering: consent captured properly, roles that limit who sees what, retention that actually deletes, and a breach plan somebody can follow at eleven at night.
Could You Say Today Exactly Where Your Customers’ Personal Data Is Stored?
Nobody Knows Every Place a Phone Number Lives
It is in the CRM, the billing software, an exported sheet on a shared drive, three WhatsApp groups, an old enquiry inbox and a backup from 2019. Asked to list them, the team would miss half.
Every Login Can See Everything
The intern doing data entry can open the same customer records as the owner, including addresses, ID documents and payment history, because roles were never set up and it was simpler that way.
The Form Asks for More Than It Needs
A contact form collects date of birth, full address and a free-text box because those fields were in the template. None of it is used. All of it now has to be protected, stored and eventually deleted.
Data Is Never Deleted, Only Accumulated
Enquiries from six years ago, candidates who never joined, customers who left in 2020. Nothing has a retention rule, so the volume of personal data you are responsible for only ever grows.
Customer Records Sit in a Former Employee’s Google Account
The sheet was created on a personal login, shared with a link, and forwarded onward. When they left, the handover covered the laptop and the SIM, not the file that is still accessible.
A Marketing Tool Was Wired to the Form and Forgotten
Somebody connected the website form to an email platform during a campaign. Every enquiry since has been copied into a third-party system nobody reviews, under an account whose password is in a chat thread.
No Plan for the Morning You Find Out
If a laptop is stolen, a database is exposed or an employee copies the customer list on the way out, nobody knows who to call, what to check first, who has to be told or what to write down.
Data protection is not a document you buy. It is knowing what you hold, collecting less of it, limiting who can open it, deleting what you no longer need, and being able to act on the morning something goes wrong.
Map It, Reduce It, Control Access to It, Then Prepare for the Bad Day
We start with a data map: every system, form, sheet, inbox and backup that holds personal data, what is in it, why, who can reach it and how long it stays. From that we cut what you do not need, build consent and access controls into the software, set retention that actually runs, and write a breach response your team can follow under pressure.
Collect Less in the First Place
The cheapest personal data to protect is the data you never asked for. We go through every form and field and remove what nobody uses, which shrinks the problem before any control is built.
Consent With a Purpose and a Date
A record of what each person agreed to, when, through which form, in which language, and a withdrawal that actually stops the processing rather than setting a flag nobody reads.
Built Into the Software, Not a Policy on the Wall
Roles, field masking, audit logs, retention jobs and deletion paths implemented in the systems themselves, because a rule that depends on staff remembering it is not a control.
What Changes Once Data Protection Is Engineered
Focus on business value before discussing technology. Here is what your team accomplishes in week one.
You Can Answer the Question in One Page
What personal data you hold, in which systems, why, who can reach it and how long it stays, written down and kept current rather than reconstructed in a panic.
Forms Stop Asking for Things Nobody Uses
Fields that existed because the template had them are gone. Every field that survives has a reason somebody can state, which makes the rest of the work smaller.
Staff See What Their Job Needs
The counter sees enough to serve a customer, the accounts desk sees the ledger, and full records need a reason. Exports are limited and logged rather than one click from any login.
Consent and Withdrawal Both Work
Purpose, timestamp and source stored for each person, an opt-out that removes them from the actual sending list, and a request path that reaches a real inbox somebody watches.
Old Data Leaves on Schedule
Enquiries, candidate records and closed accounts age out according to a rule that runs by itself, so the volume you are responsible for stops growing without limit.
The Bad Morning Has a Checklist
Who is called first, what is isolated, what evidence is preserved, who has to be told and what is written down, agreed while everyone is calm rather than invented at eleven at night.
What Data Protection and DPDP Readiness Work Includes
Everything required from operational discovery to production deployment and long-term maintenance.
Personal Data Discovery and Mapping
Every database, application, form, spreadsheet, inbox, shared drive and backup examined for personal data, with what is held, why, who can reach it and where it flows next.
Data Minimisation Review
A field-by-field pass over your forms and screens asking who uses each one and for what, ending with a list of fields to stop collecting and data to stop copying.
Consent Capture and Records
Consent built into forms, counter software and messaging flows with purpose, timestamp, language and source stored, plus a withdrawal path that reaches every downstream system.
Privacy Notice and Purpose Documentation
A plain notice stating what you collect, why, who it goes to and how long you keep it, drafted from the actual data map rather than copied from another company’s website.
Role-Based Access Design
Permissions rebuilt around jobs, with field-level masking for identifiers, restrictions on bulk export, and a review of who currently holds administrator rights and why.
Retention and Deletion Rules
A retention schedule per record type, implemented as jobs that archive or delete on time, with the handling of backups written down rather than assumed.
Data Principal Request Handling
A working path for someone asking what you hold, asking for a correction or asking for erasure: where the request lands, who acts, how identity is checked and what is recorded.
Security Controls and Hardening
Encryption in transit and at rest, password and two-step login policy, server and database hardening, logging that survives an incident, and removal of default or shared accounts.
Third-Party and Processor Review
The list of vendors touching your data, what each receives, where it is hosted, what the contract says about it, and which forgotten integrations should be disconnected.
Breach Detection and Response Plan
Alerting for the events worth noticing, a written runbook naming who does what in the first hour, the notification steps the Rules set out, and a template for recording the incident.
Staff Handling Rules and Training
Short, practical training on exports, WhatsApp groups, personal drives, customer photographs and what happens to access on the day somebody leaves.
Readiness Assessment and Roadmap
A written report ordered by priority: what to fix now, what to plan, what is fine as it is, with your lawyer’s view built in where the question is legal rather than technical.
Where This Work Matters Most
Real-world business processes we configure and automate.
Clinic Group: Patient Records Open to the Whole Front Desk
Every receptionist login could open any patient’s history across three branches. We built roles so the desk sees what it needs to register and bill, clinical notes need a clinical login, and every record opened is logged. The scanned ID documents nobody had looked at since 2019 were given a retention rule.
Lending Business: KYC Documents on a Shared Drive
Aadhaar and PAN scans collected by field agents sat in a folder any staff member could browse, some of them also forwarded on WhatsApp. Uploads were moved into the loan record with restricted access, masking applied to the identifier on screen, and a rule written for what happens to documents after an application is rejected.
School: Children’s Data Held Long After They Left
Admission forms, photographs, parent phone numbers and medical notes going back a decade, in one system with no retention rule and no role separation. We separated what the office needs from what teachers need, and set retention with the management deciding, on their lawyer’s advice, what had to be kept and for how long.
Therapy Practice: A Contact Form That Asked Too Much
The website form had a free-text box asking what brings you to therapy, feeding a shared office inbox and an email marketing tool somebody had connected during a campaign. The box was removed, the marketing tool disconnected, enquiries routed to one private inbox, and advertising pixels taken off the booking pages entirely.
E-Commerce Brand: Addresses, Orders and a Departed Developer
Customer addresses and order history were readable through an admin login shared by four people, and a former developer’s account still had database access. Individual accounts with two-step login replaced the shared one, the old credentials were revoked, export was restricted and logged, and alerting was added for bulk downloads.
Manufacturer: A Case Where Very Little Was Needed
A firm selling only to other businesses held little beyond contact names, GST numbers and purchase history. We tightened access, removed two unused fields, wrote a short notice and stopped. Spending on a large programme there would have been money wasted, and we said so in the report.
Is This Service Right for Your Business?
We partner with established businesses that have outgrown manual processes and want reliable systems.
Businesses Holding Health, Financial or Children’s Data
Clinics, diagnostic centres, therapy practices, lenders, insurance intermediaries and schools, where the records are sensitive and the consequences of exposure are personal.
Companies With Customer Data Spread Across Systems
Where the same person exists in the CRM, the billing software, a marketing tool, a courier portal and four spreadsheets, and nobody has ever counted the copies.
Businesses Building or Rebuilding an Application
The cheapest time to get consent, roles, logging and retention right is while the screens are being designed, not after go-live.
Firms Being Asked About Data by Customers
Larger clients, hospitals, banks and companies abroad increasingly send a security questionnaire before signing. Answering it honestly requires knowing what you hold.
Owners Who Have Just Had a Scare
A stolen laptop, a departed employee with the customer list, a phishing email that worked. The useful response is a map, tighter access and a written plan, not a new antivirus licence.
When You Do Not Need a Large Programme
A business holding only company contact details, GST numbers and purchase history has a much smaller problem than a clinic, and should spend accordingly. If you collect little, keep it in one system and control who logs in, tightening access and writing a short notice may be all the engineering that is justified. Anyone selling you a compliance package without first looking at what you actually hold is selling a document, not a control. We would rather write a short report that says you are largely fine.
Enterprise Capabilities in Plain Business Terms
Data Inventory and Flow Map
Every store of personal data listed with purpose, sensitivity, access, location and onward flow, in a form your team can maintain.
Consent Records With Purpose
Purpose, timestamp, language, source and version stored per person, with the history of changes kept.
Working Withdrawal Path
Opting out removes the person from the actual sending lists and downstream systems, tested end to end rather than assumed.
Role and Field-Level Permissions
Access decided by job, with identifiers masked on screens that do not need them and full records requiring a reason.
Bulk Export Controls
Downloads limited to specific roles, logged with who, when and how many rows, with alerting on unusual volumes.
Audit Logging
Who opened, changed, exported or deleted which record, stored where it cannot be edited by the people it records.
Retention Jobs
Scheduled archival and deletion per record type, with a report of what was removed and when.
Erasure and Access Request Handling
A defined path from request to action, including identity checks, what gets produced and how backups are treated.
Encryption and Key Handling
Data encrypted in transit and at rest, with keys managed properly rather than sitting in the application’s own code.
Processor Register
A maintained list of vendors touching your data, what each receives, where it is hosted and what the contract covers.
Breach Runbook
A written first hour: who is called, what is isolated, what evidence is kept, who is told and what is recorded.
Joiner and Leaver Access Control
Access granted by role on joining and removed on the last day, with a periodic review of who still holds what.
Our Structured 6-Step Delivery Process
A transparent path from your first conversation to a reliable production release.
Discovery and Data Mapping
We go through your systems, forms, drives, inboxes and backups and record what personal data sits where. From you we need read access to those systems and an honest account of the informal places data lives, including WhatsApp groups and personal drives.
Risk Review and Minimisation
We rank what we found by sensitivity and exposure, and mark what you should stop collecting. From you we need someone from each department who can say whether a field is actually used, because only they know.
Readiness Report and Roadmap
A written report ordered by priority: fix now, plan later, leave alone. From you we need your lawyer’s involvement at this point, because several items are legal questions dressed as technical ones.
Engineering the Controls
Consent capture, roles, masking, logging, retention jobs and request handling built into the systems. From you we need decisions on retention periods and a test environment rather than live data to work in.
Breach Plan and Staff Rules
The runbook written, alerting configured and short practical training for staff. From you we need the names of the people who will actually be called, and their agreement to be on that list.
Verification and Review Rhythm
We test that deletion deletes, that withdrawal stops the messages and that access is what the roles say. From you we need an owner for this inside the business and a date in the calendar to review it again.
What You Receive Upon Project Completion
Everything required to run, maintain, and expand your software without vendor lock-in.
Connects With the Systems You Already Rely On
We build bridges between your software so you don't have to replace functional existing tools.
Business Systems Holding Data
- Custom applications and portals
- Zoho CRM and Zoho One
- Tally
- Odoo
- Clinic, school and lending software
Identity and Access
- Google Workspace
- Microsoft 365 and Entra ID
- Two-step verification
- Password managers
- Single sign-on
Hosting and Storage
- AWS
- Azure
- Google Cloud
- Indian data centre hosting
- Encrypted backup storage
Customer Channels
- Website forms
- WhatsApp Business Platform
- Email marketing tools
- Payment gateways
- Courier and logistics portals
Monitoring and Logging
- Centralised log storage
- Alerting on bulk exports
- Uptime and intrusion monitoring
- Backup restore testing
Selected for Reliability, Speed, and Longevity
Technology chosen to match your operational scale and long-term maintainability.
Access Control
Data Protection
Discovery and Classification
Logging and Alerting
Retention and Deletion
Why Business Owners Choose GullySystem
We Do the Engineering, Your Lawyer Does the Law
We engineer controls, write documentation and produce evidence. The legal interpretation belongs to your advocate, and we work alongside them rather than pretending to replace them.
Nobody Can Sell You Compliance
No software, certificate or package makes a business compliant. What exists is a set of controls you can show and a record of decisions you can defend. We will not tell you otherwise to close a sale.
The Map Comes Before the Policy
A privacy notice written before anyone has looked at your systems describes a company that does not exist. We find out what you actually hold first, and the documents follow from that.
We Look for Data to Delete
Most reviews add controls. We start by removing fields nobody uses and records nobody needs, because the data you no longer hold cannot leak and costs nothing to protect.
Controls Inside the Software
Roles, masking, logging and retention jobs implemented in the systems themselves. A rule that depends on staff remembering it every day is not a control, it is a hope.
We Test That Deletion Deletes
Erasure paths, opt-outs and access restrictions are verified end to end, including what remains in backups, because these are the things that turn out not to work exactly when they are needed.
Flexible Engagement Options
Choose an engagement model that matches your operational scope, budget, and timeline.
Data Protection Assessment
Discovery, mapping, risk review and a written report ordered by priority, delivered on its own so you can decide what to do and in what order.
Readiness Implementation
Consent capture, access roles, masking, logging, retention jobs, request handling and the breach runbook, engineered into the systems you actually run.
Privacy by Design in a Build
Data protection designed into a new application as it is built, which costs a fraction of retrofitting the same controls into a system already carrying live records.
Ongoing Review
Access reviews, the processor register kept current, retention jobs checked, new systems added to the map, and the breach plan rehearsed rather than filed.
Frequently Asked Questions
Straightforward answers to the questions owners ask before getting started.
When do the DPDP obligations actually apply to us?
India’s Digital Personal Data Protection Act, 2023 is law, and the Digital Personal Data Protection Rules, 2025 set out how it works in practice. Under those Rules, duties such as the privacy notice and security safeguards take effect in May 2027. A shorter timeline has been proposed, so confirm the current date with your lawyer rather than relying on any date on a vendor’s website, including ours. The practical advice is to build for those duties now, because mapping data, fixing access and adding retention take months and cannot be done in the last fortnight.
Can you make us DPDP compliant?
No, and be careful with anyone who says they can. Compliance is a legal conclusion about your business, drawn by your lawyer, and it depends on decisions only you can make about purposes, retention and risk. What we can do is engineering and evidence: map what you hold, cut what you do not need, build consent records, access roles, retention and logging, write the breach runbook and document the decisions. That is what a regulator, a customer or a court would look at. The word compliant is not ours to give.
What is the first thing we should do?
Find out what you hold. Almost every business underestimates it, because personal data is not only in the CRM. It is in exported spreadsheets, shared drives, an old enquiry inbox, WhatsApp groups, a marketing tool somebody connected once, backups and a former employee’s personal Google account. Until that map exists, every policy is guesswork and every control is applied to the wrong place. The mapping usually also produces the quickest wins, because it turns up data you can simply stop collecting or delete.
Does our data have to be stored in India?
Ask your lawyer, because the position depends on rules about transfers outside India and on your own sector. Banking, insurance, health and payment businesses often have sector rules that bite harder than the general law. What we can tell you is the engineering side: which of your systems and vendors currently store data outside India, what the options are for hosting in an Indian region, and what moving would cost and break. We put that in the report so the legal decision is made with the facts in front of it.
What has to happen if we have a data breach?
Act, then tell. The Rules require that affected individuals are informed and that the Data Protection Board is notified, within the timelines the Rules set, so this is not something to work out on the night. Practically, the runbook we write names who is called first, what gets isolated or shut off, what evidence is preserved before anyone starts fixing things, who signs off the notification and what gets recorded. Preserving logs matters more than people expect, because a team in a hurry often destroys the evidence of what happened while trying to stop it.
Do we need consent for every message we send a customer?
Not for everything, and the distinction matters. Sending an invoice, a delivery update or a service notice to a customer you are already dealing with is different from marketing to a list. Consent has to be specific, informed and withdrawable, and the withdrawal has to actually work, which is where most businesses fail: the opt-out sets a flag and the next campaign is sent from an exported sheet anyway. We add consent capture with purpose and date, and test that withdrawal removes the person from the real sending list.
How long should we keep customer data?
Only as long as the purpose you collected it for lasts, plus whatever a separate law requires you to keep. Tax, company and sector rules often force you to retain invoices and financial records for years, and those requirements win. The data that usually has no justification is the accumulated middle: enquiries from six years ago, candidates who never joined, closed accounts nobody will service again. Your lawyer sets the periods. We implement them as jobs that run on schedule, and report what was removed.
What about data sitting in old backups?
Backups are the honest hard part and anyone who waves it away has not implemented this before. You cannot practically reach into an encrypted backup from last March and remove one person. The workable approach is to set a backup lifecycle so old copies expire on a defined schedule, keep a record of erasure requests, and re-apply them if a backup is ever restored. That position is written down rather than left unsaid, because it is exactly the question you will be asked after an incident.
Do we need to appoint a Data Protection Officer?
Whether a formal appointment is required depends on how the law classifies your business, and that is a question for your lawyer. What every business needs regardless is a named person who actually owns this: who receives requests from customers, who is called when something goes wrong, who reviews access every few months and who keeps the data map current. In most small and medium businesses this sits with an owner, a finance head or an operations head rather than a new hire.
How much does this cost?
It follows how much you hold and how spread out it is. An assessment for a business with one system, a website form and a few hundred customers is modest work. A clinic group with three branches, scanned documents, an old application and years of accumulated records is a different scale. The main drivers are the number of systems to map, how much data is unstructured, how much has to be built rather than configured, whether an existing application needs re-engineering, and whether ongoing review is included. We quote after the discovery, so the number reflects what we found.
Can you work with our existing lawyer or auditor?
Yes, and it usually goes better that way. We take the technical side: what exists, what is exposed, what can be built and what it would cost. They take the legal positions: purposes, lawful basis, retention periods, contractual terms with vendors and what has to be notified. Our report is written to be handed straight to them, with the technical findings stated plainly and the legal questions marked as legal questions rather than answered by us.
We are a small business. Does any of this really apply to us?
Size does not exempt you, but it does change what is proportionate. A ten-person firm holding company contacts and purchase history has a genuinely small problem and should spend accordingly: tighten who can log in, remove fields nobody uses, write a short notice, and stop. A ten-person clinic holding patient histories and scanned IDs has a real one. The mistake is assuming smallness makes you invisible, because most incidents at this size are not attacks at all but an employee leaving with the customer list or a shared drive nobody ever reviewed.
Should we build data protection into a new application or add it later?
During the build, always, because the difference in cost is large. Consent fields, role-based access, audit logging, masking and retention are cheap when they are designed with the screens and expensive when they are retrofitted into a system already holding live records and habits. Retrofitting also means migrating data into new structures and retraining staff who have learnt the old permissions. If you are commissioning software now, this is one of the few places where spending earlier genuinely costs less overall.
Let’s Build the Right Software for Your Business
Tell us about your current operational challenge, spreadsheet bottleneck, or software requirement. An experienced engineer will review your workflow and reply within one business day.
- No obligation consultation
- Senior engineer reviews your brief
- Your operational details stay 100% confidential
Discuss Your Requirement
Fill out this brief form and we’ll get back to you within one working day.
Related Practices & Services
Cybersecurity and Application Security
Testing authentication, permissions, code and configuration, with ranked findings, fix support and a retest that confirms each item is closed.
Cloud Engineering and Managed Infrastructure
Hosting, encryption, backups with tested restores and security baselines for the systems the data actually sits on.
Custom Software and Product Engineering
Applications with consent, roles, logging and retention designed in from the first screen rather than added afterwards.
Managed IT Support
The everyday controls: accounts created and removed properly, devices patched, backups tested and access reviewed.