DPDP Privacy Operations & Evidence Platform · Powered by Kestryl PIIScan

Turn personal-data findings into governed DPDP work.

Turn personal-data findings into governed DPDP work — with named ownership, approved actions, visible exceptions and reviewable evidence. Kestryl PIIScan provides discovery, extraction, fingerprint-based detection, validation and supported remediation; the Cockpit provides the governed workflow, approvals, response operations and evidence layer.

The moment

The clock started in November 2025. The penalties are written down.

India notified the DPDP Rules on 14 November 2025 with an eighteen-month phased implementation path. Organisations must translate applicable requirements into owned, reviewable operating work. Kestryl supports request, breach, retention and remediation workflows against the response periods and controls configured by the organisation’s privacy programme and applicable law.

Most enterprises will meet this the expensive way: one project per obligation, one project per system, a spreadsheet to reconcile them, and a scramble before every audit. Kestryl Cockpit for DPDP is the alternative — one corpus, one journey, one evidence pack — built on infrastructure you already own.

Facts as published by the Press Information Bureau, Government of India and summarised in KPMG’s guidance to the DPDP Rules. Confirm applicability with counsel.

DPDP timing and penalty exposureOutcome / requirement
Configured response periodsfor applicable request and grievance workflows
Up to ₹250 crorefor failing to maintain reasonable security safeguards
Up to ₹200 crorefor failing to notify a personal-data breach
18 monthsphased compliance window from notification of the Rules

What you get

Three outcomes a CxO can defend in front of the Board.

01 / DISCOVERY

Fingerprint-based data reality

Kestryl PIIScan identifies configured personal-data patterns across structured enterprise records and supported documents and attachments, then feeds validated findings into the Cockpit.

02 / GOVERNED ACTION

One attributable operating journey

Discover → Review → Own → Govern → Act → Evidence → Respond. Named owners, role-separated approvals and visible exceptions keep high-risk work controlled.

03 / EVIDENCE

One reviewable operating record

The Cockpit retains the decisions, disposition history, evidence metadata and logs required for the operating record according to configured policy.

Supported remediation, governed by the Cockpit
Kestryl Cockpit governs extraction, review, approval and remediation workflows across structured data and documents. Kestryl executes supported field and document remediation, with role-separated approvals and an attributable evidence trail.

Customer-controlled deployment

Your data stays inside your security boundary.

Kestryl is designed to operate within the customer-controlled environment — on-premises, in the customer data center, or within the customer’s cloud environment. Source systems and sensitive source data remain within the customer’s security boundary while Kestryl performs discovery, review and governed actions against the approved scope.

DEPLOYMENT

Customer-controlled by design

Deployment can be on-premises, in a customer data center, or in a customer-controlled Azure or Google Cloud environment, depending on the approved architecture.

SECURITY

Built for enterprise security-control review

Designed to support SOC 2-aligned controls and evidence. Kestryl deployments are designed around encryption at rest and in transit, controlled access, audit logging and customer-controlled data handling.

RETENTION

Evidence retained by configured policy

Source personal data remains within the customer-controlled environment. The Cockpit retains the evidence, decisions and disposition logs required for the operating record. Retention of those records is configurable.

Not another consent-management platform.
Kestryl connects discovery, remediation and evidence to the consent and privacy systems your organisation already uses. Consent capture remains with the appropriate consent-management platform; Kestryl focuses on finding the personal data, governing the required action and preserving the evidence.

Coverage

The ten systems where Indian personal data actually lives.

Each connects through an Informatica IDMC Cloud Data Integration connector that already exists and is already documented. Each exposes a catalog the cockpit can read, and each has a vendor-documented route to its attachments.

SalesforceCRM and attachments
SAP S/4HANA & ECCERP and ArchiveLink
SAP SuccessFactorsHR records
SAP AribaProcurement documents
Oracle E-Business SuiteERP records
Oracle NetSuiteERP and File Cabinet
Microsoft Dynamics 365CRM records
ServiceNowCases and knowledge
WorkdayHR and finance
SharePoint OnlineSites and documents

Connectors per Informatica’s IDMC Cloud Data Integration documentation. Attachment retrieval is delivered by a separate extractor module against each vendor’s documented interface and is scoped per engagement; SAP Ariba’s document interface is confirmed per module.

The DPDP board

Fourteen obligations. One screen. Honest about which is which.

The board distinguishes evidence available from the approved scope, work contributed by the Cockpit, and responsibilities that remain with the organisation and qualified advisers. Evidence, ownership and action — not a software-generated legal certification.

Illustrative DPDP obligation board · PDI assessment, not a legal determination
#ObligationStatusWhere it lives
1Notice to individualsCockpit contributesPreference Manager forms
2Consent and withdrawalExternal privacy platformSalesforce Privacy Center or equivalent platform
3Purpose limitation, minimisationProven from the corpusInventory → policy scope
4AccuracyCockpit contributesCorrection request
5Erasure and retentionEvidenced from configured scopeErasure screen · disposition · residual scan
6Security safeguards and logsProven from the corpusMasking · chained log · telemetry
7Breach noticeCockpit contributesInventory scopes fields and counts
8Access requestsEvidenced from configured scopeRequests screen · configured response period
9Correction and erasure requestsEvidenced from configured scopeRequests screen · disposition · residual
10Grievance and nominationCockpit contributesRequest as a ticket
11Children’s dataYour programme, informed by the corpusDate-of-birth and guardian fields located
12Significant Data Fiduciary: DPO, audit, DPIAProven from the corpusEvidence pack
13Cross-border transferYour programme, informed by the corpusRecords in scope confirmed
14ProcessorsCockpit contributesEvidence pack

Status is PDI’s assessment against Salesforce Help and Object Reference, the Informatica CDGC data sheet, and PDI’s published Kestryl pages. DPDP references per the MeitY text and PIB explainer. Confirm sections with counsel before external use.

Control

What leadership can count on.

  • Customer-controlled boundarySource systems and sensitive source data remain within the customer-controlled environment while Kestryl works against the approved scope.
  • Evidence without another unnecessary repositoryThe Cockpit is designed to work from record identifiers, counts, decisions and evidence metadata rather than creating another unnecessary persistent repository of personal data.
  • Danger needs intentHigh-risk actions use role-separated controls so the operating record preserves who requested, approved and executed the action.
  • Signed, not typedData owners attest to classifications on a 90, 180 or 365-day cadence with a dated, initialled statement that goes to the chained log. Overdue lists drive reminders and escalations.
  • Every asset under one policyRetention policies carry a period, a trigger, a review date and an owner. The list of assets with no policy is the first thing an auditor sees — so it is the first thing you fix.

CORPUS PINNED · RULE FINGERPRINT IN THE RUN HEADER · MODE DECLARED BEFORE THE FIRST ROW IS READ

Stated plainly

How the cockpit operates.

Powered by Kestryl PIIScan, the Cockpit governs discovery findings through ownership, review, approval, DPDP operations, remediation governance, response workflow and evidence. Kestryl executes supported remediation for structured fields and supported documents. The exact source, document and action scope is confirmed for each deployment.

Integrates with Salesforce Privacy Center or equivalent privacy platforms, depending on deployment, to exchange relevant consent, privacy and workflow evidence. Kestryl does not require Salesforce Privacy Center. Where another privacy or consent-management platform is in place, the deployment can integrate with the appropriate equivalent platform.

The click-through uses synthetic data for illustration. DPDP board statuses are PDI assessments, not legal determinations.

FAQ

Frequently asked questions

Is this a new product or an extension of Kestryl?

An extension. Powered by Kestryl PIIScan, Kestryl Cockpit for DPDP adds governed workflow, ownership, review, approval, DPDP operations and evidence to Kestryl discovery and supported remediation.

Which systems does it cover?

The deployment scope can include Salesforce, SAP, Oracle, Microsoft, ServiceNow, Workday and SharePoint sources through supported connectors and documented interfaces. Structured records, supported documents and attachments are scoped per engagement.

Is Kestryl Cockpit for DPDP a hosted SaaS product?

Kestryl is software designed to operate within the customer’s controlled environment. Depending on the deployment, it can operate within an on-premises environment, customer data center or customer-controlled cloud environment. Marketplace packaging and deployment mechanics may vary, but the product is designed to keep sensitive source data within the customer’s security boundary.

Does Kestryl replace our consent-management platform?

No. Consent management is a separate capability. Kestryl can integrate with Salesforce Privacy Center or an equivalent privacy platform depending on the deployment, while Kestryl focuses on personal-data discovery, governed action and evidence.

Can Kestryl execute remediation?

Yes. Kestryl Cockpit governs the extraction, review, approval and remediation workflow across structured data and supported documents. Kestryl executes supported field and document remediation, while role-separated controls preserve who requested, approved and executed the action.

How does Kestryl protect sensitive data?

Kestryl is designed to operate within the customer’s security boundary, with encryption at rest and in transit, controlled access, audit logging and configurable evidence retention. The architecture is designed to support SOC 2-aligned controls and evidence without creating an unnecessary persistent copy of source personal data in the Cockpit.

Does the cockpit make us DPDP compliant?

No product does. The Cockpit provides operational evidence supporting a DPDP programme. Legal applicability, statutory interpretation, consent design, notices, exceptions, holds and grievance handling remain with the customer and qualified advisers.

Why Pacific Data Integrators

Software for the operating model. Services where you choose them.

PDI software: Kestryl PIIScan provides discovery, scanning, fingerprint detection and supported remediation. Kestryl Cockpit for DPDP provides the privacy-operations, governance-workflow and evidence layer.

Optional PDI services: deployment, integration, enterprise source onboarding, Informatica-related integration, source-system remediation integration, configuration and operated support. These services are separate from the product capabilities.