DPDP
What Erasure does not solve
Explicit non-claims under DPDP-shaped evaluation — product limits, not legal advice.
What Erasure does not solve
Use this page when evaluating Erasure against DPDP-shaped obligations. It restates product scope so marketing and engineering stay aligned.
Never solved by software alone
These require legal judgment, contracts, or organizational process—no product can “check the box” for you:
- Lawful basis analysis for each processing purpose
- Privacy policy and notice wording that satisfies counsel
- Data processing agreements and vendor contracts
- Whether retention is required by other law (erasure may be limited)
- Appointing a DPO, board reporting, or enterprise GRC programs
- Regulatory filings and breach notification timelines
Out of Erasure product scope today
| Area | Status |
|---|---|
| ACCESS / CORRECT rights as first-class product types | Not shipped (DELETE is the fulfillment type) |
| Polished public subject intake UI portal | API intake exists; full portal productization incomplete |
| Automatic discovery of every SaaS/PII store without setup | You configure Systems and Data Maps |
| Cookie / tracker scanners | Not a scanner product |
| RoPA / DPIA document factories | Explicitly not the product |
| Cross-border transfer legal tools | Out of scope |
| Multi-device subject identity for consent | v1 is browser/installation-scoped |
| Multi-region active-active | Not a default product claim |
Partial coverage (be precise)
| Area | What exists | Gap |
|---|---|---|
| Notice completeness | Structured notice + publish | Legal surface (policy URLs, full counsel checklist) still productizing |
| Withdrawal | Optional purposes; prefs / SDK withdraw | Required purposes stay on; device-scoped |
| Connector estate | Postgres, MySQL, MongoDB, HTTP, Webhook (+ oauth sandbox for dev) | No full catalog of commercial SaaS “one-click” connectors claimed here |
| Evidence | Exportable operational packages | Not a sealed cryptographic legal archive |