Why DPDPA compliance requires ongoing attention
The DPDPA imposes continuing obligations, not one-time duties. Section 6 requires consent for each specified purpose; when a product adds a new feature that processes personal data for a new purpose, the notice must be updated and fresh consent obtained. Section 8(7) requires erasure when the purpose is fulfilled or the Data Principal withdraws consent; the retention schedule must be actively enforced, not just written.
Rule 7 requires the Data Fiduciary to notify the Board of a personal data breach and to notify each affected Data Principal. The breach response plan, the contact routes and the notification templates must be current and tested.
Rule 14 requires grievances from Data Principals to be resolved within the prescribed timelines. The process must be staffed and monitored continuously.
These are not tasks that end when the initial compliance programme is delivered. They are tasks that begin.
What a retainer typically covers
The scope is agreed at the start of the engagement and reviewed annually. A typical retainer includes:
- Quarterly compliance reviews: the consent framework, notice wording, retention schedules and vendor register are checked against the current product and vendor landscape.
- Breach advisory: on-call support for incident triage, Board notification drafting (Rule 7), affected-principal notification and evidence preservation.
- Board and regulatory queries: drafting responses to the Data Protection Board, coordinating with the DPO, and advising on directions under Section 25.
- Vendor and processor updates: reviewing new or renewed processor contracts against Section 8(1) and 8(2), and updating the vendor register.
- New processing activities: advising on whether a new product, feature, partnership or acquisition changes the consent basis, the notice, or the data map.
- Annual audit and DPIA coordination: for Significant Data Fiduciaries, coordinating the audit and DPIA cycle under Rule 13.
- Training refreshers: periodic awareness sessions for staff who handle personal data, updated for any changes in the law or the organisation’s processing.
How the retainer is structured
A retainer is usually a fixed monthly or quarterly fee that covers a defined scope of advisory hours. Matters outside the scope, such as a major new implementation or litigation before the Board, are agreed separately.
The engagement includes a primary point of contact within the law firm, a response-time commitment for urgent matters (such as breach advisory), and a quarterly written summary of the advice given and the actions taken.
How a retainer differs from a one-time compliance project
A compliance project builds the programme: the data map, the notices, the consent mechanism, the policies, the vendor contracts, the breach plan, the training. It has a start date, a plan and an end date.
A retainer maintains and evolves the programme after the project ends. It is not a repeat of the project. It assumes the programme is already in place and focuses on keeping it current as the business, the vendor landscape and the law change.
How AMLEGALS delivers the retainer
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
To propose a retainer, the team needs to understand your current programme maturity, the number of Data Principals, your vendor and processor landscape, and any Significant Data Fiduciary obligations.

