Case study: how we made DreamyHook DPDP-compliant
Before we sold DPDP compliance to anyone, we ran the full program on ourselves — and documented every step. This is that playbook.
- To core readiness
- 6 wks
- Collection points consented
- 100%
- Outstanding critical gaps
- 0
- Tested breach drill
- 1
We had a rule before launching this consultancy: we would not sell DPDP compliance we hadn't done ourselves. So we made DreamyHook Digital Media fully DPDP-compliant first — and wrote down exactly how. This is the playbook we now run for clients.
The challenge
As a software and AI studio, we hold personal data in more places than you'd think: marketing and CRM, client project systems, recruitment, analytics, and the tools our own products use. Like most businesses, we'd accumulated data across a dozen systems without a single map of it.
What we did
1. Mapped everything (Readiness Audit)
We inventoried every system that touches personal data, built a record of processing (ROPA), and rated each gap by risk. This alone surfaced collection points we'd forgotten existed.
2. Fixed consent (Consent Management)
We rewrote every notice to be clear and itemized, rebuilt consent capture with genuine granular choice, and added a preference center where anyone can withdraw in one click. Our cookie banner is the public-facing piece.
3. Automated rights (Data Principal Rights)
We built a self-service workflow for access, correction, and erasure, with SLA tracking so nothing slips past its deadline — and so erasure actually propagates across systems.
4. Hardened security (Technical Implementation)
Encryption in transit and at rest, role-based access, audit logging, and a defensible backup-deletion policy.
5. Got breach-ready
We wrote a notification runbook for the Board and affected users — then drilled it, because an untested runbook is just a document.
The outcome
In about six weeks we reached core readiness: every collection point consented, a working rights workflow, security controls in place, and a tested breach process — with no outstanding critical gaps.
More importantly, we learned where the real effort lives: not in the policy, but in the engineering. That's exactly why we built this consultancy around the build.
Want the same?
We'll run this playbook for you. Start with the free DPDP Quick Scan or a readiness audit.
Details generalized for publication. Your engagement is scoped to your business.
Outcomes
- Complete data map and ROPA across all internal and client-facing systems
- Itemized, withdrawable consent on every collection point
- Self-service access and erasure workflow with SLA tracking
- Encryption, access controls, and audit logging across the stack
- A tested 72-hour breach-notification runbook
"We refused to sell compliance we hadn't lived. Running the program on ourselves taught us where the real work is — the engineering, not the paperwork."