Sushant Pasumarty
Founder & CEO, Meridian Bridge Strategy
Your CA keeps you out of tax trouble. A fractional DPO keeps you out of ₹250 Crore trouble. Same retainer model, same ongoing relationship, same accountability.
Formally, only "Significant Data Fiduciaries" are required to appoint a DPO. But here's what actually matters:
When the Data Protection Board investigates a breach, they ask: "Who was responsible for data protection?" If your answer is "nobody" — you've handed them a fine with no defense.
DPDP makes no distinction based on revenue or team size. Even 100 customers makes you a Data Fiduciary with identical obligations to Amazon or Flipkart.
If you process high volumes of personal data, sensitive data, or data of children — the government can classify you as an SDF. Then a DPO becomes legally mandatory.
Even if not mandatory, having a DPO is your strongest defense. It proves you took "reasonable safeguards" — the exact phrase the Board evaluates when deciding penalties.
Broken down by frequency — so you know what happens when:
Under DPDP, someone has to be the official person customers can contact about their data. That's the DPO.
Compliance isn't a one-time project — it drifts. The DPO keeps things from slipping.
Targeted checks to make sure nothing broke since last review. Keeps you audit-ready year-round.
Full re-assessment once a year. New hires get trained, policies get updated, certificate gets renewed.
When a breach happens, 72 hours is all you get. The DPO is your crisis manager — not your IT guy figuring it out on Google.
From first call to full coverage in 4 weeks:
Week 1
Map every system that touches personal data. Every tool, every spreadsheet, every WhatsApp group. Build the inventory that answers the Board's first question.
Week 2
Identify every compliance gap against DPDP requirements. Prioritize by risk: what can get you fined first? Build the implementation roadmap.
Week 3-4
Consent flows, privacy policies, vendor DPAs, deletion mechanisms, breach protocol, team training. Execute the roadmap. Ship the compliance architecture.
Ongoing
Monthly ops, quarterly audits, annual refresh, 24/7 breach response. Your dedicated DPO on retainer — 3-5 companies max, so you always get the attention you need.
Full-Time DPO Hire
₹2.5-5L/mo
+ office + benefits + bench time
Overkill for most companies
Fractional DPO
₹50K–₹3L/mo
Scales with your complexity
One DPO, 3-5 companies max
Non-Compliance
₹50Cr+
Per violation, penalties stack
Not a real option
Your CA keeps you out of tax trouble. A fractional DPO keeps you out of ₹250 Crore trouble.
Book Your Free Clarity Call