Changelog
A running record of what has actually shipped on DPDPA Shield, newest first. Every entry is a real release with a real date, not a roadmap.
One summary per release day, covering customer-facing changes only. Internal work, infrastructure and website updates are not listed. Dates are the day the change reached production.
Want these by email? hello@dpdpashield.in
6 releases
Software your suppliers ship is now checked against publicly known vulnerabilities, so a known issue reaches you rather than sitting unnoticed.
Rate the exposure each supplier relationship carries, and export a dated snapshot of your supplier coverage for an auditor.
Collect and assess the software documentation your suppliers provide, or request it from them by link. Each document is graded so gaps are obvious.
Retention protections on evidence we store are now verified after writing rather than assumed.
Run discovery across many machines at once and see every endpoint in one place, including whether exposure is rising or falling over time.
Connecting a cloud account now shows exactly what to configure on your side, and says so plainly when something is unavailable.
10 releases
Download the discovery agent and its setup instructions directly from the platform, with version tracking so you know when a newer build is out.
See discovered data as a graph you can filter and focus, and link affected systems to an incident to understand what a breach actually touched.
Discovery runs on a schedule with alerts when a scan is missed or something changes, and what it finds can be turned into records of processing.
Discover where personal data actually lives across your databases and file stores, from inside your own network. Nothing leaves your environment.
Match the cookie banner to your own brand, and remove our name entirely on plans that include white-label.
Publish your cookie banner in the scheduled Indian languages, with a first pass you review before it goes live.
A cookie consent banner that holds trackers until consent is given, plus scanning that flags trackers on your site you never declared.
Every document the platform produces now shares a single branded layout, so anything handed to a regulator looks like it came from one system.
An acceptable use policy published, and every legal page rewritten so it can be read without a lawyer sitting next to you.
A module by module review of everything the platform accepts from the outside world, from public forms to uploaded files.
9 releases
Bring your existing vendor list in from a spreadsheet, with a preview and per-row warnings before anything is saved.
Translate a notice and everything in it into every supported language in one action, then review before publishing.
A notice is marked live based on real activity rather than on being published, and consent analytics can be sliced several ways with exports that match.
Export consent records as a formatted spreadsheet, or produce a one-page proof for one individual when someone asks about a specific consent.
Run a full simulated breach against ready-made scenarios, with the real clocks running. Drills never touch your live compliance position.
Both regulatory deadlines now run side by side from the moment an incident is logged, with the required notifications generated and evidence stored so it cannot be altered.
Consent collected in person now carries the same evidence trail as a web consent, and the person can exercise their rights through the same portal.
Build collection forms by dragging fields into place, and capture identity documents with sensitive numbers masked automatically.
Collect consent in person with a QR code, anywhere a paper form used to sit. Includes invitation campaigns and confirmations.
8 releases
Every deadline across the platform in one calendar, plus a live status page backed by our own uptime monitoring.
Finer control over what alerts you and when, plus one-click fixes for the most common compliance gaps and a trend history behind your financial exposure.
Free DPDPA courses with a verifiable certificate, alongside a glossary, downloadable templates, a maturity assessment and a breach cost estimator.
Serve your DPO contact page and privacy policy from your own domain, as the rights portal already did.
Compare any two versions of a notice, and get told when a change legally requires fresh consent. Notices people have consented to are preserved rather than deleted.
A public withdrawal page with confirmation to the individual, an alert to your team and a deadline to actually stop the processing.
Processing purposes now carry the full set of details the Act expects, and every data flow shows a clear compliance status.
Consultants and managed service providers get an operations-first view built around client health, rather than a sales pipeline they do not use.
8 releases
A public compliance profile page you control, and your compliance gaps translated into rupee exposure using the penalties in the Act.
Link a risk to the incidents it caused and the data it affects, and chart how your register has moved over time.
A board-ready report, and a secure link that lets a risk owner outside the platform update their risk without an account.
Every account is now created through an expiring invite link where the person chooses their own password. No temporary password is ever emailed.
A separate portal for resellers and consultants, covering client health, deal registration, a demo sandbox, commissions and training.
Tasks raised automatically for overdue retention and missing agreements, plus AI help drafting a privacy policy and classifying data you add.
Bring your data inventory in from a spreadsheet with validation, and export your records of processing in the format you need.
A risk register mapped to DPDPA obligations, with a heatmap, owner assignment, bulk import and export.
13 releases
Scan any website for trackers with no account, and a consent widget that opens compact and expands into full detail on request.
Every vendor scored out of 100 from publicly available signals, with no paid data feeds and no extra cost to you.
A compliance assistant that knows your actual position, cloud findings mapped to the rules they relate to, and regulatory updates scored for relevance to you.
Every DPDPA obligation tracked as pass, warning or fail, with a heatmap, a deadline timeline and a board report in seconds.
The compliance score now weights each gap by the penalty it carries under the Act, so the number tells you where the money is.
In-app notifications driven by real events, a signup assessment that produces a risk profile, and a rights portal on your own domain.
Full dark mode across the dashboard, remembered between sessions.
Isolation between organisations is now enforced by the database itself, not by application code alone.
Parental consent for under-18s, a privacy policy builder with version history, and impact assessments with transfer records.
Track data assets, flows, processors and retention in one place, with a records of processing export.
Clear usage bars for every limit on your plan, enforced consistently, with room to adjust where a plan does not quite fit.
Renamed from ComplianceOS, with the product focused squarely on Indian data protection rather than compliance in general.
A guided first-run setup, full organisation and team settings, and notices translatable into the scheduled Indian languages.
3 releases
Log an incident and get a severity, the statutory countdown and the reports a regulator expects, alongside a single compliance score across every module.
A public portal where people exercise their rights, with the statutory clock tracked from submission and a full history on every request.
Consent notice builder, embeddable consent widget, tamper-proof proof storage and consent analytics.
That is 7 months of shipping against one law. Book a demo and we will walk through the parts that matter for your organisation.