DPDP work includes legal calls. The buyer question is simple: which lawyer answers when the Board sends the breach notice?
The software framing
DPDP carries penalties up to ₹250 crore, and the whole market sells it as a software configuration problem.
I read eight vendor sites page by page. None names a lawyer anywhere in delivery.
The penalty schedule shows the number behind the question.
Three calls a dashboard cannot make
- Lawful grounds of processing is a legal determination.
- Vendor Data Processing Agreements are contracts somebody must draft and negotiate. The DPA guide explains the contract.
- A 72-hour breach notification is a legal exposure event before engineering starts. Read the breach guide for the term.
A dashboard performs none of those.
The question for every vendor
The gap has a structural cause. A SaaS company cannot bolt on a practising lawyer, and most boutiques have none as a partner.
Ask any vendor you shortlist: when the Board sends the breach notice, which lawyer answers it? And is it their expertise?
The vendor checklist gives you more questions before you sign.
The delivery answer
My firm was built with one.
MBS delivers with a practising lawyer as partner on every engagement.
Confirm who owns each legal question before you compare software.
Ask before you sign
Ask which lawyer answers when the Board sends the breach notice.
Ask whether that lawyer has the relevant expertise.
Name who decides the lawful grounds of processing.
Name who drafts and negotiates the Vendor Data Processing Agreement.
Confirm who handles the legal call before engineering starts.
Next step
Read the public DPDP scope and see how the delivery work fits together.
See the DPDP scope →Related reading
Written by Sushant Pasumarty
DPDP consultant. Founder, Meridian Bridge Strategy. This page began as field notes from live client work.