ENGINEERING ASSURANCE · INDIA DPDP

Can your systems prove what your privacy policy promises?

7Unit examines how personal data actually moves through your applications, cloud, vendors and operational workflows — then verifies the engineering controls behind consent, access, retention, deletion and security.

You leave with evidence of what we observed, the gaps that matter, and a prioritised engineering roadmap for fixing them.

India DPDP focused · Engineering-led · Evidence-backed

Built for organisations where personal data moves across real systems.

  • Healthcare
  • EdTech
  • SaaS
  • Financial Services
  • HR & Payroll
  • Digital Platforms

THE GAP

Having the policy is not the same as implementing the control.

Most organisations already have some combination of privacy notices, security policies, consent language, vendor agreements, retention policies, access-control policies, and ISO or security processes.

The harder question is whether those commitments survive contact with the actual technology stack.

  • privacy notices
  • security policies
  • consent language
  • vendor agreements
  • retention policies
  • access-control policies
  • ISO or security processes

Policy says

Customer data can be deleted.

Engineering has to prove

Where every relevant copy exists, how deletion propagates, what downstream systems receive the request and what evidence remains.

Policy says

Only authorised people can access personal data.

Engineering has to prove

Who actually has access across production systems, cloud accounts, databases, CRMs, spreadsheets and vendor platforms.

Policy says

We obtain consent.

Engineering has to prove

Which person consented, to what notice version, for which processing purpose, when it occurred, whether it changed and whether downstream processing respected it.

Policy says

We retain data only as long as necessary.

Engineering has to prove

Where retention rules actually execute and where forgotten copies remain.

That gap between stated control and engineering reality is what we assess.

Know what your systems actually do before an auditor, customer, regulator, board member or incident forces you to find out.

ENGINEERING SCOPE

We follow the data, not the checklist.

We start with the systems actually involved in collecting, processing, storing, sharing and deleting personal data.

01

Data Surface

We identify the systems involved in collecting, processing, storing, sharing and deleting personal data.

  • websites
  • web applications
  • mobile applications
  • APIs
  • CRM
  • ERP
  • HRMS
  • cloud infrastructure
  • databases
  • file stores
  • spreadsheets
  • email
  • WhatsApp / messaging
  • analytics tools
  • third-party processors
  • AI systems where relevant

Goal: understand where personal data enters, moves, resides and leaves.

02

Consent & Notices

The engineering question is not only “Is there a checkbox?” It is: can the organisation trace the authority behind processing?

  • consent capture
  • notice presentation
  • notice/version traceability
  • withdrawal flows
  • processing authority
  • parental/guardian consent where applicable
  • downstream propagation

03

Identity & Access

We assess relevant controls. This is not a penetration test.

  • authentication
  • privileged access
  • role separation
  • employee access
  • terminated-user handling
  • tenant isolation
  • administrative access
  • MFA where applicable
  • service credentials

04

PII Handling

We look for engineering patterns that create unnecessary exposure of personal information.

  • collected
  • transferred
  • persisted
  • exposed
  • logged
  • exported
  • shared
  • backed up
  • copied into operational tools

05

Security Safeguards

We review relevant implementation evidence. This engagement does not replace a dedicated penetration test, vulnerability assessment or certification audit.

  • encryption
  • access protection
  • credential handling
  • application controls
  • cloud configuration
  • logging
  • monitoring
  • backup protection
  • operational access

06

Retention & Deletion

We assess whether retention and erasure actually execute across the landscape.

  • retention logic
  • scheduled deletion
  • account closure
  • rights-request execution
  • downstream copies
  • vendor handling
  • archived records
  • backup implications
  • proof of execution

07

Vendors & Integrations

Focus is data flow and engineering evidence. Legal contract interpretation can remain with the organisation’s legal and compliance advisers.

  • CRMs
  • cloud services
  • communication platforms
  • analytics
  • payment providers
  • support systems
  • SaaS tools
  • external APIs

08

Rights & Operational Readiness

Can the request be executed through the real system landscape and evidenced afterwards?

  • access
  • correction
  • erasure
  • withdrawal
  • grievance-related workflows

09

Breach & Evidence Readiness

We assess reconstructability. This does not guarantee breach prevention.

  • logging
  • visibility
  • incident evidence
  • ownership
  • system traceability
  • ability to reconstruct relevant events

THE METHOD

We don't start with a questionnaire.

  1. 01

    Discover

    Understand your organisation, systems, vendors, data categories and applicable workflows.

    System & data landscape

  2. 02

    Surface

    Map where personal information enters, moves, resides and leaves.

    Data surface & flow map

  3. 03

    Validate

    Examine the engineering implementation behind relevant controls — application behaviour, configuration, architecture, APIs, identity/access, data stores, integrations, operational workflows, and engineering interviews where necessary.

    Control observations

  4. 04

    Evidence

    Record what was observed, configured or attested. We do not turn an assumption into a technical fact.

    Evidence-backed assurance record

  5. 05

    Prioritise

    Translate findings into engineering work, classified by risk, business impact, remediation complexity, control dependency and regulatory relevance.

    Prioritised remediation roadmap

EVIDENCE CLASSES

We do not turn an assumption into a technical fact.

Observed

We directly inspected evidence or behaviour.

Configured

A control or expected behaviour is configured but may require further runtime evidence.

Attested

The organisation confirms something that cannot currently be directly observed.

WHAT YOU LEAVE WITH

Not another 80-page compliance PDF.

The purpose of the assessment is to tell leadership and engineering exactly what is known, what is missing and what should happen next.

Engineering Assurance Report

Evidence-backed findings across the assessed systems and controls.

Executive Readout

A leadership-level explanation of material risks, priorities and engineering implications.

System & Data Surface Map

A view of where relevant personal information enters, moves and resides.

Evidence Register

What was observed, configured or attested.

Prioritised Gap Register

Findings ranked by risk and relevance.

Remediation Roadmap

What should be fixed first, what depends on what, and which work is engineering versus governance/legal.

TRACE Readiness Map

Which controls would benefit from continuous evidence collection after remediation. TRACE is optional.

Field insight

FROM THE FIELD · HEALTHCARE

Privacy risk often lives between systems.

Patient information rarely stays inside one application. It can move between enquiry channels, registration, clinical platforms, diagnostics, billing, pharmacy, messaging, CRM, cloud storage and third-party services.

The assurance problem is therefore often not whether each application has a privacy policy. It is whether the organisation can trace where every relevant copy exists, who can access it, what happens when access changes, how deletion or retention propagates, and what evidence remains afterwards.

The biggest privacy gaps are often found in the hand-offs between systems.

Read the Healthcare insight →

FROM THE FIELD · EDTECH

A checkbox is not a consent system.

Consent becomes an engineering problem when the organisation needs to prove who authorised processing, which notice applied, whose data was covered and whether downstream systems continued to respect that authority.

Particularly where children's personal data is involved, the evidence chain matters.

Capturing consent is easy. Proving the authority behind downstream processing is harder.

Read the EdTech insight →

BEYOND ONE REGULATION

One engineering reality. Many assurance requirements.

DPDP may be the immediate reason to assess your systems. But access control, evidence, retention, deletion, identity, vendor handling, security safeguards and auditability do not become irrelevant after one compliance exercise.

The same engineering reality may become relevant when your organisation works toward ISO 27001, SOC 2, GDPR, HIPAA, customer security reviews, vendor assessments or internal governance requirements.

The engineering evidence created during the assessment can support broader assurance work, subject to the requirements of the applicable framework and qualified assessors.

Relevant to / evidence can support

  • DPDP
  • ISO 27001
  • SOC 2
  • GDPR
  • HIPAA

WHY AN ENGINEERING COMPANY

Because compliance eventually reaches the code.

A compliance finding eventually becomes an engineering ticket:

  • change the consent flow
  • modify an API
  • restrict a role
  • encrypt a field
  • remove PII from logs
  • change cloud configuration
  • build deletion propagation
  • automate retention
  • add audit evidence
  • change an integration
  • redesign identity handling

7Unit does not stop at identifying the gap. We are a product engineering company. If remediation requires engineering work, we can help design and implement it—or work alongside your existing engineering team.

Assess. Prove. Fix.

TRACE can continuously verify what needs to keep holding.

AFTER THE REPORT

You decide what happens next.

Path A

Your team fixes it

We provide the evidence and remediation roadmap. Your engineering, security and compliance teams execute.

No TRACE purchase required.

Path B

7Unit helps remediate it

We scope the engineering work separately and implement agreed fixes.

No hidden lock-in.

Path C

Keep critical controls continuously visible

For controls where continuous assurance makes sense, TRACE can be deployed as the operational evidence layer.

Explore TRACE →

The assessment has value even if you never deploy TRACE.

WHAT IS TRACE?

TRACE is 7Unit's Engineering Assurance Platform.

It helps organisations maintain evidence around important privacy, security and operational controls after the initial engineering assessment.

Assessment tells you what needs attention. TRACE helps you keep proving what continues to hold.

Explore TRACE

This assessment is useful when…

  • You process meaningful volumes of customer, employee, patient, student or user data.
  • Personal information flows through multiple systems or vendors.
  • Your engineering team has implemented privacy/security controls but evidence is fragmented.
  • You are preparing for DPDP operational readiness.
  • Your customers increasingly ask security/privacy questions.
  • You are pursuing or maintaining broader assurance programmes.
  • Nobody can confidently answer where all personal data currently resides.
  • Rights requests would require several teams to coordinate manually.
  • Compliance documentation exists but engineering validation has not been performed.

This may be premature if…

  • You have not yet identified your core business systems.
  • You process almost no personal data.
  • You only need legal interpretation or policy drafting.
  • You are specifically looking for statutory certification.
  • You need only a vulnerability assessment or penetration test.

We will tell you if another specialist is the better starting point.

FIXED-SCOPE ASSESSMENT

Pricing follows the systems in scope.

Pricing is determined by the number of systems, integrations, business units and data-processing complexity included in the assessment.

You receive a fixed assessment scope before work begins — a structured engagement, not open-ended consulting billing.

  • SystemsApplications, data stores and operational tools that handle personal data
  • IntegrationsVendors, APIs and downstream copies that change the evidence surface
  • Business unitsHow many operating contexts must be assessed as one engagement
  • ComplexityData categories, rights workflows and control depth in those systems
Get assessment scope
7UNIT / FAQ

Questions about the Engineering Assurance Assessment

Is this a legal DPDP audit?

No. 7Unit performs an engineering-led assessment of systems, data flows and technical/operational controls. Legal interpretation should remain with qualified counsel or privacy professionals where required.

Will this make us DPDP compliant?

No. The engagement identifies engineering gaps, captures relevant evidence and gives your organisation a remediation roadmap. Compliance ultimately depends on technical, organisational, legal and operational measures — no assessment or software should be treated as an automatic guarantee of compliance.

How is this different from a traditional compliance audit?

Traditional compliance work may focus heavily on policies, governance and documented procedures. This engagement concentrates on the engineering layer underneath them: are the systems actually behaving as intended, and can that behaviour be evidenced?

Is this a penetration test?

No. Security testing may be recommended separately where relevant. This is a broader engineering-assurance assessment covering data flows, consent, rights operations, access, retention, integrations, evidence and applicable technical safeguards.

Do we have to buy TRACE?

No. The assessment is valuable independently. TRACE is an optional continuous-assurance layer for organisations that want ongoing evidence after assessment or remediation.

Can our engineering team perform the remediation?

Yes. The output should be usable by your own engineering team. 7Unit can also implement remediation where requested.

Does this only apply to DPDP?

This engagement is currently structured around India DPDP readiness. However, many engineering controls and evidence artefacts can also support broader privacy and security assurance activities such as ISO 27001, SOC 2, GDPR, HIPAA and customer security assessments, subject to each framework’s requirements.

What systems can you assess?

Depending on scope: applications, websites, APIs, databases, cloud infrastructure, CRM, ERP/HR systems, communications tools, analytics, third-party integrations and other systems handling relevant personal information.

Will you need production access?

This depends on scope and risk. We use the least-privilege evidence-access approach possible. Access requirements are established securely during engagement scoping — never through this marketing page.

How is the assessment priced?

It is a fixed-scope assessment. Pricing is determined by the number of systems, integrations, business units and data-processing complexity included. After a short scoping conversation we define systems and evidence boundaries, then you receive a fixed assessment scope — not open-ended consulting billing.

START WITH THE SYSTEMS

Before you buy another compliance tool, find out what actually needs fixing.

Tell us what your systems look like. We will map the relevant systems, inspect the engineering controls behind your DPDP obligations and show you where evidence holds—and where it doesn't.

No software purchase required.

If everything already holds, the assessment should be able to show that too.

What brought you here?

By submitting this form, you agree that 7Unit may use your name, work email, company, and the organisation context you share to respond to this Engineering Assurance Assessment enquiry and define scope — not for marketing lists. Privacy Policy · DPDP rights. You can withdraw consent anytime via hello@7unit.tech.