Kestryl · Native DPDP operating surface

One copy of your data. Every DPDP obligation answered from it.

Kestryl Cockpit for DPDP brings the personal data held across Salesforce and nine other enterprise systems into one governed corpus on the Informatica Secure Agent you already run — then computes what India’s Digital Personal Data Protection law asks of you, proves what was done, and hands your board the evidence. Adding another system is a row on a screen, not a programme.

The moment

The clock started in November 2025. The penalties are written down.

India notified the DPDP Rules on 14 November 2025 with an eighteen-month phased path to full compliance. Every access, correction or erasure request must be answered within ninety days. A personal-data breach must be reported to the Board and to affected individuals. Failing to maintain reasonable security safeguards carries a penalty of up to ₹250 crore; failing to notify a breach, up to ₹200 crore.

Most enterprises will meet this the expensive way: one project per obligation, one project per system, a spreadsheet to reconcile them, and a scramble before every audit. Kestryl Cockpit for DPDP is the alternative — one corpus, one journey, one evidence pack — built on infrastructure you already own.

Facts as published by the Press Information Bureau, Government of India and summarised in KPMG’s guidance to the DPDP Rules. Confirm applicability with counsel.

What you get

Three outcomes a CxO can defend in front of the Board.

01 / CORPUS

One corpus, ten systems

Salesforce, SAP, Oracle, Microsoft, ServiceNow, Workday and SharePoint read through Informatica’s own connectors into a read-only copy on a server you control, in the region you choose. Tables and their attachments, decided once, inherited by everything after.

02 / JOURNEY

One journey, drawn on the screen

Corpus → Scan → Review → Attest → Retention → Requests → Erasure → Evidence → DPDP. The ninety-day clock and the 48-hour erasure notice are on the screen, not in someone’s memory.

03 / EVIDENCE

One evidence pack, no original values

Six questions a regulator asks, six artefacts that answer them — signed with the rule fingerprint and the run ID, assembled per run and per request, containing counts and decisions but never a personal value.

The engine underneath
Every value is checked against its published validation, a confidence floor is set by you, masking needs deliberate approval, and the chained log is designed so edits are detectable. The cockpit makes that discipline operable by a Data Protection Officer rather than an engineer.

Coverage

The ten systems where Indian personal data actually lives.

Each connects through an Informatica IDMC Cloud Data Integration connector that already exists and is already documented. Each exposes a catalog the cockpit can read, and each has a vendor-documented route to its attachments.

SalesforceCRM and attachments
SAP S/4HANA & ECCERP and ArchiveLink
SAP SuccessFactorsHR records
SAP AribaProcurement documents
Oracle E-Business SuiteERP records
Oracle NetSuiteERP and File Cabinet
Microsoft Dynamics 365CRM records
ServiceNowCases and knowledge
WorkdayHR and finance
SharePoint OnlineSites and documents

Connectors per Informatica’s IDMC Cloud Data Integration documentation. Attachment retrieval is delivered by a separate extractor module against each vendor’s documented interface and is scoped per engagement; SAP Ariba’s document interface is confirmed per module.

The DPDP board

Fourteen obligations. One screen. Honest about which is which.

Seven obligations are proven at record level directly from the corpus. The remaining seven are carried by Salesforce Privacy Center’s consent tools, contributed to by the cockpit, or belong to your programme — and the board says so, in colour, so nobody mistakes a dashboard for a legal opinion.

Illustrative DPDP obligation board · PDI assessment, not a legal determination
#ObligationStatusWhere it lives
1Notice to individualsCockpit contributesPreference Manager forms
2Consent and withdrawalCarried by Salesforce Privacy CenterPreference Manager · Consent API
3Purpose limitation, minimisationProven from the corpusInventory → policy scope
4AccuracyCockpit contributesCorrection request
5Erasure, retention, 48-hour noticeProven from the corpusErasure screen · residual scan
6Security safeguards and logsProven from the corpusMasking · chained log · telemetry
7Breach noticeCockpit contributesInventory scopes fields and counts
8Access requests, 90 daysProven from the corpusRequests screen
9Correction and erasure requests, 90 daysProven from the corpusRequests screen · residual
10Grievance and nominationCockpit contributesRequest as a ticket
11Children’s dataYour programme, informed by the corpusDate-of-birth and guardian fields located
12Significant Data Fiduciary: DPO, audit, DPIAProven from the corpusEvidence pack
13Cross-border transferYour programme, informed by the corpusRecords in scope confirmed
14ProcessorsCockpit contributesEvidence pack

Status is PDI’s assessment against Salesforce Help and Object Reference, the Informatica CDGC data sheet, and PDI’s published Kestryl pages. DPDP references per the MeitY text and PIB explainer. Confirm sections with counsel before external use.

Control

What leadership can count on.

  • Data stays putThe corpus is a read-only copy on a Secure Agent Server you host, in your region. No egress during a scan. Enforcement runs in your systems of record; the cockpit proves it ran.
  • No value on screenReviewers decide on record IDs, never on the personal value itself. The counter that says “original values shown: zero” is there to be read aloud in the room.
  • Danger needs intentMasking needs two keys. Scheduling an erasure notice and scheduling the erasure are two separate actions with two separate log entries.
  • Signed, not typedData owners attest to classifications on a 90, 180 or 365-day cadence with a dated, initialled statement that goes to the chained log. Overdue lists drive reminders and escalations.
  • Every asset under one policyRetention policies carry a period, a trigger, a review date and an owner. The list of assets with no policy is the first thing an auditor sees — so it is the first thing you fix.

CORPUS PINNED · RULE FINGERPRINT IN THE RUN HEADER · MODE DECLARED BEFORE THE FIRST ROW IS READ

Stated plainly

Where the build stands.

The Kestryl engine, the IDMC Secure Agent and the ten CDI connectors are shipping products. The cockpit screens on these pages are the design standard now being built; the click-through shown to leadership uses synthetic data. The attachment extractor is built as a separate module against each vendor’s documented interface. Handing a confirmed field to a Privacy Center policy is a guided step today — Salesforce publishes no API to create a policy definition. Per-individual scans and the full India identifier pack (PAN, mobile, IFSC; Aadhaar is already in the rule library) are on the enhancement path.

We would rather you hear this from us than discover it in a pilot. DPDP board statuses are PDI assessments, not legal determinations.

FAQ

Frequently asked questions

Is this a new product or an extension of Kestryl?

An extension. Kestryl Cockpit for DPDP is the operating surface on top of the Kestryl engine, running on the Informatica IDMC Secure Agent Server you host. The engine finds and remediates personal data; the cockpit turns that into the DPDP journey and the fourteen-obligation board.

Which systems does it cover?

Ten systems through Informatica’s own IDMC CDI connectors: Salesforce, SAP S/4HANA and ECC, SAP SuccessFactors, SAP Ariba, Oracle E-Business Suite, Oracle NetSuite, Microsoft Dynamics 365, ServiceNow, Workday and SharePoint Online. Others connect through JDBC or ODBC. Attachments are reached through each vendor’s documented interface by a separate extractor module, scoped per engagement.

Does our data leave India, or our environment?

No. The corpus is a read-only copy on a Secure Agent Server you control, in the region you choose; the design shows a Mumbai host with no egress during a scan. Enforcement of erasure and retention happens in Salesforce Privacy Center or your other systems’ native tools; the cockpit proves the result.

Does the cockpit make us DPDP compliant?

No product does. Seven of the fourteen obligations are proven at record level from the corpus; the other seven are carried by Privacy Center, contributed to by the cockpit, or remain your programme — and the board says which. Legal applicability, consent design, notices and grievance handling remain decisions for you and your counsel.

Why Pacific Data Integrators

Fifteen years inside the systems your data lives in.

PDI has spent 15+ years and 100+ implementations inside Informatica, Salesforce, Snowflake and Databricks for banks, insurers, healthcare, government and retail. Kestryl Cockpit for DPDP is what that experience looks like pointed at one law: not another scanner, but the operating surface that lets a privacy officer run the whole obligation from one screen and prove it.