Enterprise Modules

Cover Your Highest-Penalty Exposure

Children's data, DPIA, SDF obligations, algorithm registry. The modules that carry the steepest per-violation penalties in the Act.

Your penalty exposure
₹200Crchildren's data violations (S.9)
₹150CrSDF/DPIA obligations (S.10)

A single children's data violation is ₹200 crore. SDF obligations can be imposed retroactively with no grace period.

Children's Data Module

DPDPA S.9 — ₹200 Cr

Age gate widget, verifiable parental consent via OTP, default restrictions on minor accounts (no targeting, profiling, tracking), and annual consent review scheduler.

SDF / DPIA Module

DPDPA S.10 — ₹150 Cr

20-question DPIA wizard with automatic risk scoring, algorithm registry for automated decisions, cross-border transfer tracking, and annual DPIA review scheduler.

Comprehensive coverage in one workflow

1
Deploy age gate
Embed the JS age gate widget. Users below 18 are flagged and routed through parental consent flow.
2
Parental OTP consent
Guardian email receives an OTP. Verified consent is cryptographically stored with expiry tracking.
3
Restrictions enforced
Ad targeting, profiling, data sharing, and behavioral tracking automatically disabled for minor accounts.
4
Run DPIA wizard
20-question assessment generates a risk score (LOW/MEDIUM/HIGH/CRITICAL) and required controls list.
5
Register algorithms
Log every automated decision system with risk classification and human oversight status.

Everything for S.9, S.10, and SDF obligations

Children

Age Gate Widget

Embeddable JS widget checks date of birth, returns isMinor flag. Integrates with any form or flow.

Parental Consent with OTP

Guardian OTP email flow, 24-hour expiry, bcrypt-secured verification. Creates ChildAccount on success.

Minor Tracking Prohibition

Default restrictions: ad targeting, profiling, data sharing, behavioral tracking — all off by default for minors.

SDF

DPIA 20-Question Wizard

5 categories × 4 questions. Risk score 0–100. Automatically sets COMPLETED status on 20 answers.

Algorithm Risk Registry

Document every automated decision system: output type (Decision/Scoring/Profiling), risk level, human oversight status.

Cross-Border Transfer Tracking

Log data transfers by mechanism (ADEQUACY, SCC, CONSENT, LI), destination country, and encryption status. CSV export.

₹200Cr
Children's data penalty
₹150Cr
SDF/DPIA penalty
20
DPIA questions
0
Grace period
Available from Enterprise plan onwards

Children's Data module and SDF/DPIA module are Enterprise-only features.

DPDPA S.9 & S.10 obligations — answered

What processing of children's data is prohibited under DPDPA S.9?+

DPDPA S.9 prohibits three categories of processing for children (under 18) without exception: (1) targeted advertising directed at children, (2) tracking or behavioural monitoring of children, and (3) processing that may have a detrimental effect on the wellbeing of the child. It also requires verifiable parental or guardian consent before any other processing of a child's personal data. DPDPA Shield enforces all four restrictions automatically on ChildAccount records.

When does a company become a Significant Data Fiduciary (SDF)?+

The Central Government designates SDFs based on the volume and sensitivity of personal data processed, potential risk to national security or public order, risk of harm to data principals, and impact on sovereignty and integrity of India. There is no fixed threshold — designation is by government notification. Once designated, SDFs must appoint an Indian-resident DPO, conduct DPIAs, maintain an algorithm audit registry, and file periodic compliance reports.

What is a Data Protection Impact Assessment (DPIA) and when is it required?+

A DPIA is a structured assessment of the privacy risks introduced by a new processing activity. Under DPDPA, DPIAs are mandatory for Significant Data Fiduciaries before deploying any new automated processing system. DPDPA Shield's 20-question DPIA wizard covers 5 categories — Scope & Scale, Data Sensitivity, Data Subject Rights, Security Controls, and Governance — and outputs a risk score (LOW/MEDIUM/HIGH/CRITICAL) plus a required controls checklist.

Is there a timeline for SDF designation after DPDPA takes effect?+

The Act provides no fixed timeline for SDF designation — notifications can be issued at any point after commencement. Companies processing large volumes of sensitive data (health, financial, children's data) should prepare SDF-level controls proactively. Retroactive designation with no grace period is the highest-risk scenario. DPDPA Shield's Enterprise modules are designed precisely for this preparedness posture.

Cover your highest-penalty exposure today.

Enterprise plan includes all modules. Talk to us about SDF compliance readiness.