Fingerprint-based data reality
Kestryl PIIScan identifies configured personal-data patterns across structured enterprise records and supported documents and attachments, then feeds validated findings into the Cockpit.
DPDP Privacy Operations & Evidence Platform · Powered by Kestryl PIIScan
Turn personal-data findings into governed DPDP work — with named ownership, approved actions, visible exceptions and reviewable evidence. Kestryl PIIScan provides discovery, extraction, fingerprint-based detection, validation and supported remediation; the Cockpit provides the governed workflow, approvals, response operations and evidence layer.
The moment
India notified the DPDP Rules on 14 November 2025 with an eighteen-month phased implementation path. Organisations must translate applicable requirements into owned, reviewable operating work. Kestryl supports request, breach, retention and remediation workflows against the response periods and controls configured by the organisation’s privacy programme and applicable law.
Most enterprises will meet this the expensive way: one project per obligation, one project per system, a spreadsheet to reconcile them, and a scramble before every audit. Kestryl Cockpit for DPDP is the alternative — one corpus, one journey, one evidence pack — built on infrastructure you already own.
Facts as published by the Press Information Bureau, Government of India and summarised in KPMG’s guidance to the DPDP Rules. Confirm applicability with counsel.
| DPDP timing and penalty exposure | Outcome / requirement |
|---|---|
| Configured response periods | for applicable request and grievance workflows |
| Up to ₹250 crore | for failing to maintain reasonable security safeguards |
| Up to ₹200 crore | for failing to notify a personal-data breach |
| 18 months | phased compliance window from notification of the Rules |
What you get
Kestryl PIIScan identifies configured personal-data patterns across structured enterprise records and supported documents and attachments, then feeds validated findings into the Cockpit.
Discover → Review → Own → Govern → Act → Evidence → Respond. Named owners, role-separated approvals and visible exceptions keep high-risk work controlled.
The Cockpit retains the decisions, disposition history, evidence metadata and logs required for the operating record according to configured policy.
Supported remediation, governed by the Cockpit
Kestryl Cockpit governs extraction, review, approval and remediation workflows across structured data and documents. Kestryl executes supported field and document remediation, with role-separated approvals and an attributable evidence trail.
Customer-controlled deployment
Kestryl is designed to operate within the customer-controlled environment — on-premises, in the customer data center, or within the customer’s cloud environment. Source systems and sensitive source data remain within the customer’s security boundary while Kestryl performs discovery, review and governed actions against the approved scope.
Deployment can be on-premises, in a customer data center, or in a customer-controlled Azure or Google Cloud environment, depending on the approved architecture.
Designed to support SOC 2-aligned controls and evidence. Kestryl deployments are designed around encryption at rest and in transit, controlled access, audit logging and customer-controlled data handling.
Source personal data remains within the customer-controlled environment. The Cockpit retains the evidence, decisions and disposition logs required for the operating record. Retention of those records is configurable.
Not another consent-management platform.
Kestryl connects discovery, remediation and evidence to the consent and privacy systems your organisation already uses. Consent capture remains with the appropriate consent-management platform; Kestryl focuses on finding the personal data, governing the required action and preserving the evidence.
Coverage
Each connects through an Informatica IDMC Cloud Data Integration connector that already exists and is already documented. Each exposes a catalog the cockpit can read, and each has a vendor-documented route to its attachments.
Connectors per Informatica’s IDMC Cloud Data Integration documentation. Attachment retrieval is delivered by a separate extractor module against each vendor’s documented interface and is scoped per engagement; SAP Ariba’s document interface is confirmed per module.
The DPDP board
The board distinguishes evidence available from the approved scope, work contributed by the Cockpit, and responsibilities that remain with the organisation and qualified advisers. Evidence, ownership and action — not a software-generated legal certification.
| # | Obligation | Status | Where it lives |
|---|---|---|---|
| 1 | Notice to individuals | Cockpit contributes | Preference Manager forms |
| 2 | Consent and withdrawal | External privacy platform | Salesforce Privacy Center or equivalent platform |
| 3 | Purpose limitation, minimisation | Proven from the corpus | Inventory → policy scope |
| 4 | Accuracy | Cockpit contributes | Correction request |
| 5 | Erasure and retention | Evidenced from configured scope | Erasure screen · disposition · residual scan |
| 6 | Security safeguards and logs | Proven from the corpus | Masking · chained log · telemetry |
| 7 | Breach notice | Cockpit contributes | Inventory scopes fields and counts |
| 8 | Access requests | Evidenced from configured scope | Requests screen · configured response period |
| 9 | Correction and erasure requests | Evidenced from configured scope | Requests screen · disposition · residual |
| 10 | Grievance and nomination | Cockpit contributes | Request as a ticket |
| 11 | Children’s data | Your programme, informed by the corpus | Date-of-birth and guardian fields located |
| 12 | Significant Data Fiduciary: DPO, audit, DPIA | Proven from the corpus | Evidence pack |
| 13 | Cross-border transfer | Your programme, informed by the corpus | Records in scope confirmed |
| 14 | Processors | Cockpit contributes | Evidence pack |
Status is PDI’s assessment against Salesforce Help and Object Reference, the Informatica CDGC data sheet, and PDI’s published Kestryl pages. DPDP references per the MeitY text and PIB explainer. Confirm sections with counsel before external use.
Control
CORPUS PINNED · RULE FINGERPRINT IN THE RUN HEADER · MODE DECLARED BEFORE THE FIRST ROW IS READ
Stated plainly
Powered by Kestryl PIIScan, the Cockpit governs discovery findings through ownership, review, approval, DPDP operations, remediation governance, response workflow and evidence. Kestryl executes supported remediation for structured fields and supported documents. The exact source, document and action scope is confirmed for each deployment.
Integrates with Salesforce Privacy Center or equivalent privacy platforms, depending on deployment, to exchange relevant consent, privacy and workflow evidence. Kestryl does not require Salesforce Privacy Center. Where another privacy or consent-management platform is in place, the deployment can integrate with the appropriate equivalent platform.
The click-through uses synthetic data for illustration. DPDP board statuses are PDI assessments, not legal determinations.
FAQ
An extension. Powered by Kestryl PIIScan, Kestryl Cockpit for DPDP adds governed workflow, ownership, review, approval, DPDP operations and evidence to Kestryl discovery and supported remediation.
The deployment scope can include Salesforce, SAP, Oracle, Microsoft, ServiceNow, Workday and SharePoint sources through supported connectors and documented interfaces. Structured records, supported documents and attachments are scoped per engagement.
Kestryl is software designed to operate within the customer’s controlled environment. Depending on the deployment, it can operate within an on-premises environment, customer data center or customer-controlled cloud environment. Marketplace packaging and deployment mechanics may vary, but the product is designed to keep sensitive source data within the customer’s security boundary.
No. Consent management is a separate capability. Kestryl can integrate with Salesforce Privacy Center or an equivalent privacy platform depending on the deployment, while Kestryl focuses on personal-data discovery, governed action and evidence.
Yes. Kestryl Cockpit governs the extraction, review, approval and remediation workflow across structured data and supported documents. Kestryl executes supported field and document remediation, while role-separated controls preserve who requested, approved and executed the action.
Kestryl is designed to operate within the customer’s security boundary, with encryption at rest and in transit, controlled access, audit logging and configurable evidence retention. The architecture is designed to support SOC 2-aligned controls and evidence without creating an unnecessary persistent copy of source personal data in the Cockpit.
No product does. The Cockpit provides operational evidence supporting a DPDP programme. Legal applicability, statutory interpretation, consent design, notices, exceptions, holds and grievance handling remain with the customer and qualified advisers.
Why Pacific Data Integrators
PDI software: Kestryl PIIScan provides discovery, scanning, fingerprint detection and supported remediation. Kestryl Cockpit for DPDP provides the privacy-operations, governance-workflow and evidence layer.
Optional PDI services: deployment, integration, enterprise source onboarding, Informatica-related integration, source-system remediation integration, configuration and operated support. These services are separate from the product capabilities.