Privacy education, consultancy & implementation, in 50+ jurisdictions.enquiry@vedhacon.com
Guidance and examples adapt to your selection.↑↓ to browse, ↵ to apply
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Who we are

Privacy is a discipline. We treat it like one.

Vedhacon is a practitioner-led privacy practice. We pair people who read the statute with people who build the systems, so guidance never stops at what the law says and always reaches what you do on Monday.

What drives us

Our mission and our vision

One describes the work we do every day. The other describes the world we are working towards.

Our mission

To make privacy law understandable, implementable and provable, for every organisation, not only those that can afford a legal department.

We translate obligations into controls a team can operate, records a regulator would accept, and knowledge that stays in the organisation after we leave. Where guidance can be published openly, we publish it, because a right that nobody understands is not yet a right in practice.

Our vision

A world in which protecting personal data is ordinary practice rather than a specialist project, and in which any organisation, anywhere, can find out what applies to it in plain language.

We want privacy to be designed in at the point a system is built, not retrofitted after an incident. And we want the people who do this work to come from every background, not only from law, because the discipline needs both the statute and the engineering.

What we stand for

Six values, and what each one costs us

A value is only real if it sometimes works against your own interest. Each of these carries a commitment we hold to even when it would be easier not to.

01

Independence

We sell no software, resell no platform and take no referral fees. The recommendation you receive is the one we would follow ourselves.

What it costs: we turn down commission, and we tell clients when they do not need us.
02

Evidence over assertion

A control counts only when it can be demonstrated. We test whether a control operated, not whether a document describing it exists.

What it costs: our reports are longer, and sometimes less comfortable to read.
03

Plain language

If a notice, a policy or a report needs a lawyer to decode it, it has failed the person it was written for. We write for the reader, not the file.

What it costs: plain drafting takes far longer than copying a precedent.
04

No dependency by design

We build capability inside your team and hand over documentation they can maintain. A good engagement makes the next one smaller.

What it costs: we deliberately design ourselves out of the retainer.
05

Confidentiality, practised

We are trusted with data maps, incidents and findings. We name no client without written permission, and we hold ourselves to the standards we assess others against.

What it costs: our best work is the work we can never show you.
06

Access for all

Anyone with no background in governance, risk and compliance can begin here and build a career. Our foundation material is free and stays free.

What it costs: we give away material others sell, on purpose.
The people behind it

A small founding team of practitioners

Vedhacon was founded by three practitioners working across law, security engineering and audit. Every engagement is delivered by the people who wrote the method.

Shambhu Kumar, founding member of Vedhacon

Shambhu KumarFounding Member

A governance, risk and compliance practitioner working across data privacy, information security and AI governance. Leads applicability analysis, certification readiness and the published guidance programme, and is the point of contact for most new engagements.

DPDP Act 2023GDPRISO/IEC 27001ISO/IEC 27701ISO/IEC 42001Internal audit

Security engineeringFounding Member

Leads the implementation side of the practice: data discovery and mapping, consent and notice architecture, retention enforcement, and the technical controls that sit behind a privacy obligation rather than beside it.

Data mappingConsent architectureRetentionTransfers

Audit & assuranceFounding Member

Leads internal and third-party audit, evidence packs and remediation tracking, and the breach response work, including tabletop exercises and post-incident review.

Internal auditVendor assessmentBreach responseEvidence
On naming our own people. Two of our founding members are described here by discipline rather than by name, at their request. We ask every client for written permission before naming them, and we hold ourselves to the same standard internally. It would be a poor privacy practice that published its own colleagues without asking first.
Our story

Built because compliance advice kept stopping short

Between us we had sat on both sides of the table: writing the obligation, and then being handed it. The pattern was always the same. A gap report arrives, everyone agrees it is accurate, and six months later almost nothing has moved, because nobody translated any of it into work a team could actually do.

So Vedhacon starts where most advice ends. We establish what genuinely applies, we build the control with the team who will own it, and we leave behind the evidence that proves it works. Then we publish as much of the underlying guidance as we can, openly, because the organisations that most need this are usually the ones least able to buy it.

Today that covers the DPDP Act, GDPR and UK GDPR, CCPA and the US state laws, PIPL, the ASEAN regimes and more than fifty jurisdictions in total, with ISO/IEC 27001, 27701 and 42001 readiness built in.

Law, read properly

Obligations traced to the statute and the rules, not to a template someone inherited.

Controls, built to hold

Notices, consent, DPIAs, records and playbooks your own team can maintain.

Evidence, audit-ready

Documentation that survives external assessment, not just internal review.

Knowledge, shared

Open education, so the first hire and the hundredth office can both start here.

How we work

A predictable path from question to certificate

Engagements are scoped in writing, delivered in defined phases, and handed over with documentation your own team can maintain. You always know what is being done, by whom, and what it will cost.

01 · UnderstandWhich laws apply, to which data

In which geographies, for which processing, and what the organisation actually does today.

02 · AssessA gap assessment, obligation by obligation

Risk-rated, with a prioritised remediation plan rather than an undifferentiated list.

03 · ImplementControls built with the owning teams

Notices, consent, DPIA, records and breach response, built alongside them, not handed over cold.

04 · ProveInternal audit and certification support

Evidence packs and attendance through the assessment, so the programme withstands scrutiny.

05 · SustainTraining and regulatory monitoring

As laws, products and vendors change, so the programme does not quietly drift out of date.

06 · HandoverDocumentation your team can maintain

No dependency by design. That is the point of the engagement, not a side effect of it.

50+Jurisdictions covered
3ISO standards supported
Legal + TechDual-discipline practice
End-to-endScope to certificate
Work with us, or join us

Technical and legal professionals are welcome here

Privacy lawyers, security engineers, auditors, DPOs and academics contribute as moderators, authors and webinar hosts. Credited, flexible, and open to every jurisdiction we cover.

Start a conversation Apply to contribute