// data · privacy · tech — bengaluru

Privacy, DPDP and the law that keeps up with code.

Cipher & Co. is a data-protection and technology practice for companies that ship software. We turn the DPDP Act, GDPR and your contract stack into something your engineers and your board can both live with.

DPDP Act, 2023 GDPR / Art. 28 72-hr breach clock AI governance
Server racks in a data centre — the infrastructure behind the personal data we help companies protect.

// counsel to data-heavy, regulated teams

Fintech Healthtech SaaS & B2B Payments Consumer internet Deeptech & AI
40+
breach & incident engagements handled end to end
120+
DPAs and processor agreements negotiated
15+ yrs
at the Bengaluru bar across the founding team
// practice

Four ways we cover your data.

One team for the whole lifecycle — from the notice a user sees, to the DPA your vendor signs, to the 2am call when something leaks. No hand-offs, no translation layer between "legal" and "engineering."

0x01// compliance

DPDP & GDPR compliance

Get audit-ready under the Digital Personal Data Protection Act, 2023 and GDPR — without freezing your roadmap. We design the programme, not just the paperwork.

  • Data-flow mapping & RoPA
  • Notices, consent & DPIAs
  • Cross-border transfer strategy
  • Significant Data Fiduciary readiness
0x02// incident

Data-breach response

When it goes wrong, you get counsel on the phone in the first hour — coordinating forensics, the regulator and your comms while the clock runs.

  • Retained 24×7 breach hotline
  • Data Protection Board notification
  • Forensics & vendor coordination
  • User comms & post-incident report
0x03// contracts

Technology contracts

The paper that moves your product — MSAs, DPAs, cloud and processor terms — drafted to be signed, not stuck in a six-week redline war.

  • SaaS / MSAs & order forms
  • Data processing agreements
  • IP assignment & open-source
  • API terms, SLAs & DPAs
0x04// governance

AI governance

Ship models without shipping liability. We build the policy scaffolding around training data, deployment and the vendor AI clauses hiding in your stack.

  • Model & training-data governance
  • Acceptable-use & risk policies
  • Vendor AI & sub-processor review
  • DPDP-aligned accountability

// principle 001

Under the DPDP Act, consent is the contract. We make sure yours reads that way in court, in code and to a user.

// incident · the first 72 hours

When it breaks at 2am, we pick up.

A data breach is a legal event on a deadline. The DPDP Act expects notification to the Data Protection Board of India and to affected principals — and every hour of silence is a decision. A retainer means the plan already exists before the incident does.

T + 0

Detect & contain

Your team isolates the incident; you dial the retained line.

T + 1 hr

Counsel engaged

Privilege is set up, the response is scoped, roles are assigned.

T + 24 hr

Scope & forensics

What data, whose, how much — evidence preserved for the regulator.

T + 72 hr

Notify the Board & principals

Filings and user comms go out — accurate, on time, defensible.

T + 30 d

Remediate & close

Root-cause fixes, an evidence pack and a closure report you can stand behind.

A technology lawyer reviewing systems alongside an engineering team. // embedded with your team
// approach

We read the code, then write the clause.

Most privacy advice arrives as a PDF and dies in a Notion page. Ours ships with the product. We sit with your engineers, understand the data before we opine on it, and leave you with policies your team will actually follow.

01 →

Map

A data-flow and risk audit of what you collect, where it lives and who touches it — the honest inventory that everything else depends on.

02 →

Build

Notices, consent flows, DPAs and internal policies — drafted for your stack, not lifted from a template pack.

03 →

Defend

Retained counsel on call: the breach hotline, regulator liaison and the contract redlines that come up every week.

Bengaluru skyline at dusk — home to the technology teams we act for. Residency Road · Bengaluru 560025
// the firm

A boutique built for the data economy.

We are a small, deliberately senior team. No pyramid, no juniors learning on your matter. Founded by lawyers who spent years in-house at Bengaluru product companies, Cipher & Co. exists because privacy and technology law stopped being a side-desk and became the whole business.

Ishani Varma

Founding Partner · Data Protection & Privacy

15+ years at the Bengaluru bar advising fintech and health platforms on the DPDP Act, GDPR and cross-border data. Leads compliance and regulator engagement.

Rohan Pai

Partner · Technology Transactions & AI

Former in-house counsel to a Bengaluru SaaS company. Runs the contracts and AI-governance practice — from DPAs to model-deployment policy.

Sadia Qureshi

Counsel · Cybersecurity & Breach Response

Leads the incident practice and the 24×7 hotline, coordinating forensics, notification and post-breach remediation under pressure.

// faq

Questions we get before the first call.

Q1What does the DPDP Act actually mean for my startup?
If you handle personal data of people in India, the Digital Personal Data Protection Act, 2023 applies to you — regardless of size. In practice it means clear notices, a lawful basis (usually consent), a way for users to withdraw it, security safeguards and a breach-notification duty. We translate that into a programme that fits your stage, so you are covered without over-engineering it.
Q2We think we've had a breach — what happens in the first hour?
Call the retained line. We set up privilege, help your team contain and preserve evidence, and start scoping what data was affected. From there we manage forensics, the notification clock to the Data Protection Board and affected users, and your public comms — so the response is one coordinated effort, not five people guessing.
Q3Do we need a Data Protection Officer or a Consent Manager?
It depends on your volume and sensitivity of data and whether you are likely to be classified a Significant Data Fiduciary. We assess that early, tell you plainly whether you need a DPO or a registered Consent Manager, and help you appoint or structure the role rather than leaving you to guess.
Q4Can you review our vendor, DPA and sub-processor stack?
Yes — this is a core part of the practice. We audit the agreements you have signed, flag the processor and cross-border gaps, and give you a redline playbook so future contracts move faster. Most teams are surprised how much risk is sitting in DPAs nobody read.
Q5Do you actually work with our engineering team?
Always. We would rather read your data model than a summary of it. Expect us in your architecture reviews and Slack, not just on a quarterly call — that is the only way privacy advice survives contact with a real product.
Q6Is the first consultation really free?
Yes. The initial consultation is free and without obligation — we use it to understand your data, your stage and the risk, and to tell you honestly whether you need us yet. If there is a fit, we scope the engagement and quote on request. Book it here.
// ready when your data is

Talk to a data-protection lawyer, not a chatbot.

Tell us what you're building and where the data goes. We'll tell you, plainly, what the DPDP Act and your contracts actually require — and where you're already fine.

Book a free consult Call +91 93157 76817 reply within one business day