#1
Monthly Rank
#147
Lifetime Rank
Share
4 September 2026
PrivaShield: Continuous DPDP Compliance

PrivaShield: Continuous DPDP Compliance

Self-hosted DPDP Act 2023 compliance. From gap analysis to breach response, without your data ever leaving your servers.

Gallery

About the Project

PrivaShield is a self-hosted continuous compliance platform built for India’s Digital Personal Data Protection (DPDP) Act, 2023.

Most organisations still approach compliance as a one-time exercise: conduct an audit, prepare the required documents, and move on. The problem is that compliance changes as the business changes. A new vendor, data flow, employee, or product feature can quickly make that work outdated.

PrivaShield is designed to keep compliance up to date as the organisation evolves. It helps teams generate and manage required legal documents such as Privacy Notices, DPAs, consent records, and GRO appointment letters. It maintains a live ROPA register that connects processing activities with their legal basis, while also providing tools for consent management, DPIAs, and third-party risk assessments. This includes a Subject portal, a self-service portal where data principals can submit and track requests for access, correction, erasure, and portability of their personal data.

It can also scan devices and cloud storage for exposed personal data and provides a data principal portal for handling requests such as access, correction, erasure, and portability.

The platform is self-hosted, so client data stays within the organisation’s own infrastructure rather than being sent to a third-party compliance platform.

To open the Admin portal : https://demo-beige-kappa-70.vercel.app/admin To open the Subject portal : https://demo-beige-kappa-70.vercel.app/portal **Login Credentials ** Admin: [email protected] / Demo@123 Subject Portal: [email protected] / Demo@123

PrivaShield is built for law firms, internal compliance teams, PII collecting institutions and businesses that need to maintain and demonstrate DPDP compliance on an ongoing basis, rather than simply complete an audit and receive a report.

Practice Areas

Key Features

Compliance Dashboard

  • Overview of document status, active consents, ROPA activities, and pending DSRs
  • Track compliance activity and progress over the last 30 days

Documents & Disclosures

  • Generate Privacy Notices, DPAs, Consent Artifact Templates, and GRO Appointment Letters
  • Legislative Vault with version history and controls for mandatory, portal, and enforcement requirements
  • Support for multiple entities and organisations

Consent Management

  • Track opt-in and opt-out consent for each processing activity
  • Mark consent as mandatory or optional
  • View consent activity and lifecycle history
  • Tamper-evident and auditable consent records
  • Track consent collected through external systems

Governance

  • ROPA register covering processing activities, legal basis, cross-border transfers, and DPIA risk
  • Record processing activity, rule changes, and consent history in one compliance trail
  • Manage notices and organisational units across multiple entities

Data Subject Rights

  • DSR Desk for managing requests, SLAs, and turnaround times
  • Handle grievances and route them to the appropriate GRO or DPO
  • Subject Portal for Access, Correction, Erasure, and Portability requests
  • Support delegate nomination under Section 10(3) where a data principal is unable to act

GRC Tools

  • DPIA workspace for assessing processing risks
  • TPRM tools for reviewing vendors and DPAs
  • Breach triage with a workflow for Data Protection Board notifications
  • Immutable archive for compliance and audit records

Incident Control

  • Live breach response view with response deadlines and countdowns
  • Guided workflow covering containment, assessment, penalty exposure, notification, and remediation

Data Discovery & Mapping

  • Scan devices and cloud storage for personal data
  • Prioritise findings based on risk and detection confidence
  • Manage the devices and agents used for scanning
  • Map how data moves through the organisation — from collection and storage to processing and sharing

Deployment

  • Self-hosted deployment on the client’s infrastructure using Docker
  • Client-owned Supabase instance, with no access to client data by third parties
  • AI-assisted features use an API key provided and controlled by the client

Help Needed

Open to feedback on the compliance automation approach, and thoughts on distribution to law firms in India.

About the Creator

ST
Siddartha Talaka
Law Student
LinkedIn