Pilots, pricing, partners and objections
A pilot proves an operating path with synthetic/test subjects before it touches production PII. It has a named entity, two systems, one purpose/notice, one withdrawal, one rights case, five record classes, one incident tabletop and one processor.
Discovery questions
Section titled “Discovery questions”- Which legal entities, licences and India-facing products are in scope?
- Where are consent/notice and rights/grievance handled today?
- What are the hardest KYC/transaction/claim/clinical/employment retention conflicts?
- Which two systems prove end-to-end propagation?
- Which incident clocks, authority portals and contracts apply now?
- Where do support, logs, backups, keys and subprocessors sit?
- Which deployment/security constraints are non-negotiable?
- What evidence did the last audit or customer questionnaire request?
- Who can approve legal grounds, retention and notification?
- What would cause the pilot to stop?
30/60/90 days
Section titled “30/60/90 days”Days 1–30: source/entity/applicability and architecture workshop; inventory/import; deployment security; purpose/notice; retention conflict; success baseline.
Days 31–60: configure consent/withdrawal and rights/grievance; integrate two test systems; processor record; evidence collection; accessibility/security testing.
Days 61–90: incident tabletop; restore/re-deletion; partial-failure exercise; audit/export; executive review, TCO and rollout decision.
Proof of value
Section titled “Proof of value”- approved source-to-control map for pilot scope;
- two systems reconcile withdrawal/request with no raw PII in control plane beyond approved budget;
- one lawful-retention exception explained and evidenced;
- incident clocks and offline fallback work;
- signed pack reproduced by auditor;
- customer exports all pilot data/configuration and verifies exit;
- users complete critical flows with keyboard/mobile/assisted route.
Do not use “more consent grants” or “fewer grievances” as value metrics.
Commercial structure
Section titled “Commercial structure”Paid readiness assessment may be credited to annual subscription. Pilot is fixed scope/fee with clear connector assumptions, customer responsibilities and data handling. Production price uses deployment/support, entity band and connector/sector options. Implementation change requests are separate from product usage.
TCO model
Section titled “TCO model”| Cost | Customer inputs |
|---|---|
| licence/subscription | tier, entities, environments, support |
| platform | cloud/Kubernetes, DB/object/KMS, observability |
| implementation | entity/source workshops, migration, integrations |
| operations | privacy, legal, system owners, incident, vendor risk |
| assurance | pen test, accessibility, independent audit, sector counsel |
| change | regulatory updates, new product/entity/connector |
| exit | export, cutover, verification and deletion |
Compare with internal spreadsheet/custom portal engineering, ongoing law maintenance, connector support, audit preparation and incident risk—not only licence fee.
Partner strategy
Section titled “Partner strategy”- systems integrators implement enterprise/sector connectors;
- law firms review facts, sources and disputed interpretations without endorsing software;
- audit firms consume evidence but retain independence;
- MSSPs operate incident/security and SME managed privacy under scoped access;
- Indian cloud/data-centre partners enable residency/VPC/on-prem;
- industry associations distribute sector templates and training.
Partner certification proves product skill, not legal compliance or auditor independence.
Common objections
Section titled “Common objections”“We already have a GRC.” Keep GRC as risk/system of record; OpenDPDP provides Principal-facing cases, receipts, distributed system tasks and evidence through an adapter.
“We can build a portal.” Compare ongoing legal config, identity, propagation, retention, incident clocks, tenant security, accessibility, connectors and exit—not the intake form.
“Open source is insecure.” Public review is neither safety nor insecurity. Show threat model, signed builds, SBOM, patch policy, support/LTS and deployment controls.
“Keep all data on-prem.” Run control plane/agents on-prem; define offline updates and customer KMS. Confirm that support and build/update channels also meet policy.
“The law starts in 2027.” Main duties do, but system inventory, contracts, identity, integrations, retention and operational tests have long lead times; some adjacent/sector duties already apply.
“Are you a Consent Manager?” Enterprise consent tooling is not statutory registration. The statutory track is separately governed and cannot claim status before Board approval.
Procurement pack
Section titled “Procurement pack”Architecture/data flow, deployment/residency, subprocessor list, encryption/key design, access/ support, SDLC/SBOM/VDP, tenant tests, incident/BCP, backup/exit, accessibility, open-source licences, SLO/support and claims boundary. Answers are versioned and evidence-linked.