Skip to content
RegulensR

IT & ITeS · India

DPDP and CERT-In delivered to engineering as backlog items

A capability centre separated its processor and fiduciary obligations under DPDP, rebuilt incident response around the six-hour clock, and pushed obligations into Jira with acceptance criteria.

Meridian GCC

Global capability centre, 6 delivery centres, 14,000 employees

Regulatory IntelligenceObligations LibraryCopilot
reporting clock met with escalation, evidenced
6 hrsreporting clock met with escalation, evidenced
processor and fiduciary, correctly separated
2 registersprocessor and fiduciary, correctly separated
labour obligations brought under one view
5 stateslabour obligations brought under one view
obligation delivery to engineering teams
Jira-nativeobligation delivery to engineering teams

The challenge

Where they started

The privacy programme had been built for client contractual requirements, mostly GDPR-shaped. DPDP obligations as a Data Fiduciary for its own 14,000 employees had no owner. The incident response process had a triage stage that consumed most of the CERT-In six-hour window before anyone considered reporting. And six delivery centres across five states carried shops and establishments, professional tax and POSH obligations that HR managed locally with no group visibility.

The approach

What we did

  • Split the DPDP register into processor obligations for client data and fiduciary obligations for employee and candidate data
  • Rebuilt incident intake as a single channel receiving internal detections and vendor security bulletins alike, with a rostered reporting authority
  • Mapped CERT-In and DPDP breach obligations as separate workflows with different triggers and recipients
  • Scoped state labour obligations to each delivery centre, with POSH committee status tracked per location
  • Delivered obligations into Jira as stories with Given/When/Then acceptance criteria and rule citations
“Our engineers were never going to read the DPDP Rules. Getting the obligation as a story with acceptance criteria, cited back to the rule, is the only version of this that works.”
Director, Privacy & Compliance · Privacy & Compliance · Meridian GCC

Talk to someone with a footprint like Meridian GCC

For serious evaluations we introduce you to a reference customer in your sector — including one who will be candid about the parts that took longer than planned.