Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Blog

DPDPA compliance checklist (India)

Processor inventory and DSAR clocks under India's DPDPA. A practical operator checklist.

Operator checklist, not a certification

India's Digital Personal Data Protection Act puts obligations on data fiduciaries and processors. I am not going to brief the Act like a law firm. Counsel classifies your entity (including significant fiduciary questions) before this list means anything. Assume that work is done, or stop here and do it.

What I will give you is the operational join: OAuth inventory as processor discovery, security hygiene that actually touches refresh tokens, DSAR clocks that are not copy-pasted from GDPR, and a breach runbook that starts with revoke. ScopeMantle can run inventory and DSAR ops. We do not certify DPDPA. We do not hold an attestation we have not published. Partners: India MSSP program.

1. Processor inventory

  • Live export from Google Workspace and Okta. Client ID as key. See the vendor inventory template.
  • Significant fiduciaries document every SaaS that touches personal data, PO or not.
  • Vendor HQ / residency column. That is a triage flag for transfer conversations. It is not a legal conclusion.
  • DPA or contract queue for unattested grants. Do not stall a subject clock waiting for paper.
  • Consent-manager vs OAuth analytics grant: if the banner says no and the grant says mail or profile, that is a DPIA conversation, not an automatic product block.

2. Reasonable security (OAuth-shaped)

  • Scope Sanity (or a written rubric) on high-risk scopes. Mail and directory first.
  • Revoke stale grants. Ninety days without attestation is a reasonable operator SLA. Write your own if counsel wants a different number.
  • Breach-feed revoke tested. Tabletop, not a policy sentence.
  • MFA on the IdP. Necessary. Not sufficient. Token replay skips the login UI. Say that in the security note so nobody ticks MFA and goes home.

3. DSAR and consent withdrawal

  • Case management with a clock you can show. Day 0 is valid request after identity check.
  • Operator templates from the playbook, header swapped for DPDPA language by counsel. Not lawyer-reviewed by us.
  • Erasure includes IdP revoke. A letter without revoke leaves the token live.
  • Consent withdrawal for a marketing tool should trigger the same grant review, not only a banner change.

India timelines are not GDPR's thirty days by default. Do not print 30 in the subject letter because a European template was handy.

4. Breach notification readiness

  • Client-ID-to-privacy-contact map, built in peacetime.
  • IR runbook leads with grant revoke, then notice decisions. Security does not freelance the notice.
  • Inventory snapshot hashed at detect time so you can show who had access.

What to tell counsel and what to tell an auditor

Counsel: "Here is the grant list, HQ column, and where it disagrees with the consent banner. We need classification and clock language." Auditor or customer due diligence: "Processor discovery includes IdP OAuth. MFA is on. Revoke is tested. We do not claim a DPDPA seal from ScopeMantle."

Failure modes

  • Running this checklist before entity classification.
  • Copying GDPR clocks.
  • Treating HQ column as a completed transfer assessment.
  • Promising Entra completeness. It is Beta.
  • Letting an MSSP send subject letters without your counsel.

What to do this week

  1. Confirm classification status with counsel. If unknown, do not publish a "we are DPDPA ready" page.
  2. Export OAuth grants. Add an HQ column even if half the cells are "unknown."
  3. Diff one consent-banner vendor against the grant list.
  4. Read the playbook. Trial ScopeMantle at $5 / $6 if you want the list to stay current. No seat min. Custom 500+.

Worked examples (generic)

IT services firm, 800 people, Google Workspace, contractors on a separate Okta. Export both. Contractor leftover grants will dominate the first review. Classification with counsel may put you in significant-fiduciary conversations if you handle large volumes of individual data for clients. Your processor list for a client DSAR is not the same as your own employee-data list. Keep two inventories.

D2C brand, consent manager plus three analytics OAuth grants. Banner says analytics optional. Grants say profile read. That is a DPIA ticket, not an automatic revoke, unless counsel says otherwise. Inventory made the contradiction visible. The banner alone did not.

US parent, India subsidiary. HQ column will light up. Do not let the parent's GDPR RoPA stand in for the subsidiary's DPDPA work. Clocks and fiduciary duties are not a copy-paste. Shared ScopeMantle tenant is fine if you can filter by OU / group. Shared letters are not.

Operator backlog (first 30 days)

  1. Classification memo from counsel, dated.
  2. Hashed OAuth export.
  3. HQ column filled or marked unknown.
  4. Consent vs grant diff for the top ten marketing tools.
  5. DSAR header language approved (not our operator default).
  6. Revoke tabletop recorded.
  7. Entra footnote if Microsoft mail is in use.
  8. Subprocessor list updated if you added ScopeMantle or an MSSP.

If you skip item 1, delete the rest of the marketing claims on your site. The MSSP program is for partners who will enforce that order. If your partner will not, get another partner.

What we will not write for you

A transfer mechanism. A significant-fiduciary determination. A notice to the Board under the Act. A children's-data position. Those are legal work. We will give you the grant list, the clocks you configured, and the revoke log. $5 / $6, no seat min, custom 500+. HIPAA still not attested. No fake customer counts.

Tabletop script (India-shaped)

Inject: a US analytics vendor discloses token theft. Your India subsidiary's Workspace has 40 grants to that client ID. Personal data of customers and of employees may be in mail scopes. Counsel is in Bengaluru. Security is in the parent SOC.

Run: revoke first with parent SOC if they hold Admin. Snapshot inventory. Counsel decides notice under DPDPA, not under the parent's GDPR muscle memory. Do not send a GDPR letterhead. Do not wait for the US vendor's blog post to finish legal review before you revoke. Those are different clocks.

Debrief: who had Admin, whether Entra blindness mattered, whether the HQ column would have ranked this vendor higher last month. Record hours. Store next to the board export if you use one.

What "reasonable security" can mean here, operationally

I will not define the legal standard. I will list artifacts that usually help the conversation: MFA on, grant inventory dated, stale mail-scope grants revoked or excepted, tabletop recorded, offboarding leftover count, vendor questionnaire that asks about refresh-token storage. If someone tries to satisfy the conversation with an antivirus screenshot, stop them.

Field guide: first month inside a subsidiary

Week 1 is counsel and classification, or it is a pause. Week 2 is dual export if contractors live on a second IdP. Week 3 is consent-versus-grant diff for the marketing stack. Week 4 is a tabletop with parent SOC and local counsel on the same call so the GDPR letterhead does not sneak in. If any week is skipped because a conference booth needed a slogan, restart.

Two inventories when you process both employee data and client-customer data. Mixing them in one CSV is how you email the wrong vendor about the wrong subject. Filename the snapshots with the entity name, not just the case ID.

What significant-fiduciary conversations actually ask for

They ask who processes, what categories, what security, what notice you can give. OAuth inventory helps the who. Scopes help the what. Revoke logs and MFA help the security story. Notice is counsel. Do not let an analyst fill notice language from a European template. India clocks are not a copy-paste.

HQ column is triage. Unknown is allowed. Blocked is not a product auto-decision. Transfer mechanism stays legal work. We will not sell it as a toggle.

Educational only. No DPDPA stamp. No HIPAA. Entra Beta. $5 / $6, no seat min. Partners: program. Templates: playbook.

Mistakes I keep seeing after the first workshop

People export once and call it culture. People revoke by display name after a rebrand. People promise Entra completeness. People put OAuth rows in the user-access matrix. People send DSAR mail without a case ID. People treat a CASB invoice as grant inventory. People change a score threshold the night before audit. People staff an MSSP sprint with someone who cannot read a scope string. Each of those has a fix already on this page. The failure is skipping the fix because the demo looked polished.

Write the one thing you will not skip this week. Put it on a calendar. If you want the inventory to stay current, the 30-day trial is the productized version of the export. Five dollars per employee per month billed annually, or six dollars monthly. No seat minimum. Custom terms at 500+ employees. Microsoft Entra stays labelled Beta. HIPAA is not attested. Templates stay operator-reviewed. No fabricated customer counts on the customers page.

If you are evaluating us next to a GRC tool, keep both jobs honest. If you are evaluating us next to a consent-intercept tool, stack prevention and inventory. If you are an MSP, register the deal before the demo and keep the counsel gate in the SOW. If you are writing a board slide, use last quarter as the only benchmark we will stand behind. That is enough program for a quarter. The next quarter is whether the leftover-grant count actually moved.

A note for in-house counsel at the India entity

This checklist assumes you already classified the entity. If not, ignore the rest until you have. OAuth inventory is discovery, not a transfer assessment. HQ column is triage. Clocks are yours to set in the letters. Operator templates are starting points. Parent SOC can revoke. They should not draft the notice. MFA is necessary and not sufficient. Educational only. No stamp from us.

What you can do without buying anything

Export the IdP list. Deduplicate on client ID. Revoke three rows you cannot explain. Write the CC9.2 versus CC6.7 sentence for your auditor. Add OAuth grants equals zero to offboarding. Put an extension allow-list in one OU. Schedule a Friday tabletop with a fictional client ID. Hash a file and put it in GRC. Those steps do not require ScopeMantle. They do require a calendar and a human who will not skip them.

When those steps start to rot (and they will, usually by week six), the productized version is daily Google and Okta sync, scores, attestation expiry, bulk revoke, and DSAR snapshot on the same inventory. Price is public. Beta labels stay on the page. We will not invent a case study to make the last paragraph feel finished. Start the trial if the calendar is already losing.

Print the first-month backlog from this article and tick it in a shared tracker. If item one (classification memo) is empty, do not publish readiness language on the company site. That single rule prevents more harm than another tool evaluation.

Related reading stays on the internal paths already linked above: platform, integrations, demo, and the companion resources or blog posts for this topic. Use those links when you brief a colleague so they get the same product truth: public $5 / $6 pricing, no seat minimum, custom at 500+, Entra labelled Beta, DSAR templates operator-reviewed, no HIPAA attestation, no invented logos. That is the briefing. Everything else is the procedure you can run this week.

FAQ

Common questions

About ScopeMantle

ScopeMantle is an OAuth-grant audit and DSAR-automation platform for mid-market SaaS companies, sold primarily through an open MSSP partner program (70/30 wholesale split, deal registration, no direct-sale conflict in partner territories) and secondarily direct. Built in 2026.

Explore the partner program →

70 / 30 wholesale · deal registration honoured · no direct-sale conflict

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.