Resources
Compliance guides, without the consulting markup.
Practical walkthroughs of the frameworks we build for — DPDP, the EU AI Act, and the operational habits that keep a compliance programme current between audits.
The DPDP Consent Manager: What It Is and Why It Matters
India's DPDP Act introduces a Consent Manager — a registered intermediary for giving, managing, and withdrawing consent. What it is, who needs to care, and how to prepare.
EU AI Act High-Risk Systems: Which AI Falls In, and What It Demands
The high-risk tier carries almost all of the EU AI Act's obligations. Which systems land there, the two ways a system qualifies, and the duties that follow.
The EU AI Act Compliance Checklist: Classify, Document, Govern
A practical walkthrough of the EU AI Act's risk tiers and the concrete obligations each one triggers — so you can classify your systems and know what evidence you need.
ISO 42001 Explained: An AI Management System, Not Just a Checklist
What ISO/IEC 42001 actually is, how it relates to the EU AI Act, and why a management-system approach to AI governance outlasts a one-time assessment.
AI Governance for Startups: A Lightweight Operating Model
You don't need a governance department to govern AI responsibly. A minimal, practical operating model startups can run today — and grow into as obligations arrive.
DPDP Readiness: A Practical Guide for Startups and Mid-Market Teams
What India's Digital Personal Data Protection Act actually requires, and a step-by-step readiness path you can run without a large compliance team.
How to Run a Data Protection Impact Assessment (DPIA)
When a DPIA is needed, the steps to run one properly, and how to make it a living record rather than a document you file and forget.
DPDP vs GDPR: What's the Same, What's Different, and Why It Matters
If you already comply with GDPR, how much of that carries over to India's DPDP Act? A side-by-side on scope, consent, rights, transfers, and penalties.
Third-Party Risk: Why Your Vendors Are Your Compliance Exposure
Under DPDP and the EU AI Act, a processor's failure is your liability. A practical approach to inventorying vendors, flowing down obligations, and keeping the register current.
Audit-Ready: Building an Evidence Trail That Survives Scrutiny
Why 'we have a policy' is not evidence, what auditors and customers actually ask for, and how to maintain a defensible trail continuously instead of scrambling before each audit.
