ABOUT INDISEC
WHY NOW
The Digital Personal Data Protection Act made every organisation that handles personal data a Data Fiduciary, with duties that do not scale on good intentions: know what personal data you hold and why, collect consent you can actually evidence, answer a Data Principal inside a deadline, and notify a breach without waiting for certainty.
Most of that work currently lives in spreadsheets, email threads, and the memory of whoever set it up. It holds until the first regulator letter, the first deletion request, or the first diligence questionnaire. Closing that gap is why IndiSec exists.
HOW WE WORK
Discovery across your systems, classification of whatever turns up, and continuous tracking of the obligations that attach to it. This is the work that defeats a quarterly spreadsheet.
Where a judgement is required - is this a reportable breach, is this consent valid, is this use legitimate - a qualified lawyer decides. Not a model, and not a checkbox.
Every decision lands in a register you can hand to a regulator, an auditor, or an acquirer, with the reasoning attached to it.
THE DOCKET
Gap & Risk Assessment
Where you stand against the Act today, and what it will take to close.
Data Discovery & Classification
Find the personal data you hold, across the systems you forgot about.
Consent Management
Collect consent you can evidence, and withdraw it just as cleanly.
Compliance Obligation Management
Every duty tracked to an owner and a date, not a shared inbox.
Customer Notification & Breach
Draft, review and send notification against the clock.
Virtual DPO (vDPO)
A named, qualified DPO on retainer, with the bench behind them.
THE BENCH
The people who sign off on your compliance are named, and their credentials are on the record: a former Standing Counsel for the Government of Haryana, a former CIO, chartered accountants, and privacy practitioners who have advised global clients. Nobody here is anonymous.
