Policy says
“Customer data can be deleted.”
Engineering has to prove
Where every relevant copy exists, how deletion propagates, what downstream systems receive the request and what evidence remains.
ENGINEERING ASSURANCE · INDIA DPDP
7Unit examines how personal data actually moves through your applications, cloud, vendors and operational workflows — then verifies the engineering controls behind consent, access, retention, deletion and security.
You leave with evidence of what we observed, the gaps that matter, and a prioritised engineering roadmap for fixing them.
India DPDP focused · Engineering-led · Evidence-backed
THE GAP
Most organisations already have some combination of privacy notices, security policies, consent language, vendor agreements, retention policies, access-control policies, and ISO or security processes.
The harder question is whether those commitments survive contact with the actual technology stack.
Policy says
“Customer data can be deleted.”
Engineering has to prove
Where every relevant copy exists, how deletion propagates, what downstream systems receive the request and what evidence remains.
Policy says
“Only authorised people can access personal data.”
Engineering has to prove
Who actually has access across production systems, cloud accounts, databases, CRMs, spreadsheets and vendor platforms.
Policy says
“We obtain consent.”
Engineering has to prove
Which person consented, to what notice version, for which processing purpose, when it occurred, whether it changed and whether downstream processing respected it.
Policy says
“We retain data only as long as necessary.”
Engineering has to prove
Where retention rules actually execute and where forgotten copies remain.
That gap between stated control and engineering reality is what we assess.
Know what your systems actually do before an auditor, customer, regulator, board member or incident forces you to find out.
ENGINEERING SCOPE
We start with the systems actually involved in collecting, processing, storing, sharing and deleting personal data.
01
We identify the systems involved in collecting, processing, storing, sharing and deleting personal data.
Goal: understand where personal data enters, moves, resides and leaves.
02
The engineering question is not only “Is there a checkbox?” It is: can the organisation trace the authority behind processing?
03
We assess relevant controls. This is not a penetration test.
04
We look for engineering patterns that create unnecessary exposure of personal information.
05
We review relevant implementation evidence. This engagement does not replace a dedicated penetration test, vulnerability assessment or certification audit.
06
We assess whether retention and erasure actually execute across the landscape.
07
Focus is data flow and engineering evidence. Legal contract interpretation can remain with the organisation’s legal and compliance advisers.
08
Can the request be executed through the real system landscape and evidenced afterwards?
09
We assess reconstructability. This does not guarantee breach prevention.
THE METHOD
01
Understand your organisation, systems, vendors, data categories and applicable workflows.
System & data landscape
02
Map where personal information enters, moves, resides and leaves.
Data surface & flow map
03
Examine the engineering implementation behind relevant controls — application behaviour, configuration, architecture, APIs, identity/access, data stores, integrations, operational workflows, and engineering interviews where necessary.
Control observations
04
Record what was observed, configured or attested. We do not turn an assumption into a technical fact.
Evidence-backed assurance record
05
Translate findings into engineering work, classified by risk, business impact, remediation complexity, control dependency and regulatory relevance.
Prioritised remediation roadmap
EVIDENCE CLASSES
We do not turn an assumption into a technical fact.
We directly inspected evidence or behaviour.
A control or expected behaviour is configured but may require further runtime evidence.
The organisation confirms something that cannot currently be directly observed.
WHAT YOU LEAVE WITH
The purpose of the assessment is to tell leadership and engineering exactly what is known, what is missing and what should happen next.
Evidence-backed findings across the assessed systems and controls.
A leadership-level explanation of material risks, priorities and engineering implications.
A view of where relevant personal information enters, moves and resides.
What was observed, configured or attested.
Findings ranked by risk and relevance.
What should be fixed first, what depends on what, and which work is engineering versus governance/legal.
Which controls would benefit from continuous evidence collection after remediation. TRACE is optional.
FROM THE FIELD · HEALTHCARE
Patient information rarely stays inside one application. It can move between enquiry channels, registration, clinical platforms, diagnostics, billing, pharmacy, messaging, CRM, cloud storage and third-party services.
The assurance problem is therefore often not whether each application has a privacy policy. It is whether the organisation can trace where every relevant copy exists, who can access it, what happens when access changes, how deletion or retention propagates, and what evidence remains afterwards.
The biggest privacy gaps are often found in the hand-offs between systems.
Read the Healthcare insight →FROM THE FIELD · EDTECH
Consent becomes an engineering problem when the organisation needs to prove who authorised processing, which notice applied, whose data was covered and whether downstream systems continued to respect that authority.
Particularly where children's personal data is involved, the evidence chain matters.
Capturing consent is easy. Proving the authority behind downstream processing is harder.
Read the EdTech insight →BEYOND ONE REGULATION
DPDP may be the immediate reason to assess your systems. But access control, evidence, retention, deletion, identity, vendor handling, security safeguards and auditability do not become irrelevant after one compliance exercise.
The same engineering reality may become relevant when your organisation works toward ISO 27001, SOC 2, GDPR, HIPAA, customer security reviews, vendor assessments or internal governance requirements.
The engineering evidence created during the assessment can support broader assurance work, subject to the requirements of the applicable framework and qualified assessors.
Relevant to / evidence can support
WHY AN ENGINEERING COMPANY
A compliance finding eventually becomes an engineering ticket:
7Unit does not stop at identifying the gap. We are a product engineering company. If remediation requires engineering work, we can help design and implement it—or work alongside your existing engineering team.
Assess. Prove. Fix.
TRACE can continuously verify what needs to keep holding.
AFTER THE REPORT
Path A
We provide the evidence and remediation roadmap. Your engineering, security and compliance teams execute.
No TRACE purchase required.
Path B
We scope the engineering work separately and implement agreed fixes.
No hidden lock-in.
Path C
For controls where continuous assurance makes sense, TRACE can be deployed as the operational evidence layer.
Explore TRACE →The assessment has value even if you never deploy TRACE.
WHAT IS TRACE?
It helps organisations maintain evidence around important privacy, security and operational controls after the initial engineering assessment.
Assessment tells you what needs attention. TRACE helps you keep proving what continues to hold.
Explore TRACEWe will tell you if another specialist is the better starting point.
FIXED-SCOPE ASSESSMENT
Pricing is determined by the number of systems, integrations, business units and data-processing complexity included in the assessment.
You receive a fixed assessment scope before work begins — a structured engagement, not open-ended consulting billing.
No. 7Unit performs an engineering-led assessment of systems, data flows and technical/operational controls. Legal interpretation should remain with qualified counsel or privacy professionals where required.
No. The engagement identifies engineering gaps, captures relevant evidence and gives your organisation a remediation roadmap. Compliance ultimately depends on technical, organisational, legal and operational measures — no assessment or software should be treated as an automatic guarantee of compliance.
Traditional compliance work may focus heavily on policies, governance and documented procedures. This engagement concentrates on the engineering layer underneath them: are the systems actually behaving as intended, and can that behaviour be evidenced?
No. Security testing may be recommended separately where relevant. This is a broader engineering-assurance assessment covering data flows, consent, rights operations, access, retention, integrations, evidence and applicable technical safeguards.
No. The assessment is valuable independently. TRACE is an optional continuous-assurance layer for organisations that want ongoing evidence after assessment or remediation.
Yes. The output should be usable by your own engineering team. 7Unit can also implement remediation where requested.
This engagement is currently structured around India DPDP readiness. However, many engineering controls and evidence artefacts can also support broader privacy and security assurance activities such as ISO 27001, SOC 2, GDPR, HIPAA and customer security assessments, subject to each framework’s requirements.
Depending on scope: applications, websites, APIs, databases, cloud infrastructure, CRM, ERP/HR systems, communications tools, analytics, third-party integrations and other systems handling relevant personal information.
This depends on scope and risk. We use the least-privilege evidence-access approach possible. Access requirements are established securely during engagement scoping — never through this marketing page.
It is a fixed-scope assessment. Pricing is determined by the number of systems, integrations, business units and data-processing complexity included. After a short scoping conversation we define systems and evidence boundaries, then you receive a fixed assessment scope — not open-ended consulting billing.
Tell us what your systems look like. We will map the relevant systems, inspect the engineering controls behind your DPDP obligations and show you where evidence holds—and where it doesn't.
No software purchase required.
If everything already holds, the assessment should be able to show that too.