Data protection consultancy
Data protection consultancy means designing and implementing the security processes, policies and technology that keep personal and business data defensible. Samaniz delivers this aligned to ISO 27001, NIST SP 800-53 and India's DPDP Act.
Scope
Enterprise risk management frameworks and policies aligned to ISO 27001 and NIST SP 800-53.
Role-based access control, MFA, privileged access management, and scheduled access reviews.
Information assets identified and classified by criticality and sensitivity.
Critical data protected through backup and recovery tooling, with encryption enabled throughout.
DPDP
Personal data spread across systems, inventoried informally
Consent captured once, then left to age
Vendors processing data under informal terms
Breach notification handled ad hoc
Deletion requests arriving with ownership unassigned
Retention driven by habit rather than policy
General information. Legal interpretation stays with your counsel.