A secure, structured compliance workspace for lawyers, DPOs, privacy consultants, and auditors managing real client engagements.
Privacy professionals are expected to understand a client's operations, identify applicable laws, document gaps, maintain registers, collect evidence, and track remediation. Much of that work still happens across spreadsheets, email threads, and disconnected files.
vDPO Encrypted Client Workspaces bring that work together in one software-as-a-service platform. Each real client receives a separate workspace for its privacy-compliance programme, with access to every country and law available on vDPO included in the subscription.
Who is it for?
- Lawyers advising clients on privacy and data-protection obligations.
- Internal and external DPOs managing ongoing compliance programmes.
- Privacy consultants working with several organisations.
- Auditors documenting findings, evidence, actions, and review outcomes.
A professional can manage multiple organisations on vDPO, while each client remains a separately scoped and separately encrypted workspace.
What does a client subscription include?
- One dedicated real-client compliance workspace.
- Access to all countries and laws available on vDPO, with no separate jurisdiction fee.
- Law-driven compliance checklists and progress tracking.
- Structured assessments, registers, risks, controls, gaps, actions, and evidence records.
- Client-specific reports and an ongoing record of the compliance programme.
- Encrypted storage for designated sensitive client content.
The annual fee is charged per client workspace. Not per country, law, assessment, or compliance module.
How does real-client encryption work?
The simplest way to think about it is that every real client gets a separate locked digital safe. The key for one client's safe cannot open another client's safe.
Technically, each client receives its own 256-bit data-encryption key. This is the secret key. vDPO then uses AES-256-GCM (the encryption method) to turn sensitive information into unreadable ciphertext before saving it in the database.
AES-256-GCM does two jobs. It prevents the information from being read without the correct client key, and it lets vDPO detect if the encrypted information has been altered or placed in the wrong record.
vDPO never stores the client key in readable form. Only an encrypted copy of the client key is stored in the database, while the separate platform key needed to unlock it is kept outside the database. When an authorised professional needs to view the information, vDPO first checks that the signed-in user owns that client workspace. It then temporarily unlocks the client key in server memory for that request. The readable client key is not stored in the browser or user session.
If encryption or verification fails, vDPO stops the save. It does not quietly store the sensitive information as readable text.
What information is protected?
This includes content such as company identification numbers, DSAR requester details, breach and assessment narratives, checklist notes, risk and control details, and saved tool inputs and outputs.
Some basic profile and workflow information remains readable so vDPO can identify the workspace, apply laws, calculate progress, and manage tasks. Personal data, confidential narratives, passwords, and secrets should therefore not be entered in client names, labels, or status fields.
What does the encryption protect against?
If somebody obtains only a copy of the database or a database backup, the protected information remains unreadable without the separate platform key. Because every client has a different key, obtaining one client's key would not unlock every other client's protected information.
This is encryption at rest. It is not zero-knowledge encryption: vDPO must be able to decrypt the information when an authorised professional needs to use it. Professionals must still use HTTPS, protect their accounts and devices, collect only necessary information, and apply suitable retention periods.
Important: Practice clients are for fictional learning data and do not receive real-client field encryption. Always choose Real client before entering live client information. The client type cannot be changed after creation.
Pricing
| Subscription | Applicability | Annual fee per client |
|---|---|---|
| Early-bird subscription | Available before the platform launch | Rs 12,000 + GST for the first subscription year |
| Standard subscription | From 1 September 2026 | Rs 18,000 + GST per client, per year |
During the early-bird period, users may purchase additional client packs at the early-bird price of ₹12,000 per client plus GST. These packs may be retained for future engagements and activated for any client on or before 1 September 2027. Each pack becomes linked to the selected client upon activation.
The early-bird price applies only to the client's first subscription year. Renewals will be charged at the prevailing subscription price. Every active client subscription includes the complete country and law library available on vDPO.