Upcoming · AI Suite

Policy Gap Detector

Your privacy policy says one thing. Your systems do another. This finds every place those two disagree.

Join the waitlist See what it compares Or score your readiness today — free, five minutes, no account.
The real test

Three documents that have to agree

Each was written by different people at different times, and nobody has ever read them side by side.

01

The policy you publish

Usually written years ago, adapted from a template, and edited by whoever last had time. It is the only one of the three a customer or a regulator can actually read.

02

The notices you serve

Written later, by someone else, purpose by purpose. Where these promise something the policy does not mention, one of the two is wrong.

03

The processing you actually do

Your registry: every system, category, recipient and transfer. This is the ground truth, and it is the one nobody compares the policy against.

A tool that only reads your policy can tell you whether it is well written. It cannot tell you the policy is silent about the analytics vendor you added in March, or that it describes a retention period your own schedule contradicts. That comparison is only possible if the same system holds all three — which is the argument for doing this here rather than buying a scanner.

The usual findings

Almost every Indian policy has these four

Because almost every Indian policy began as a GDPR template, and the two laws differ in exactly the places a template cannot see.

1

It promises data portability

The DPDP Act grants no portability right. Your policy offers one anyway, because the template it came from was written for a law that does. You have published a promise nobody asked you for and no process to honour.

2

It omits nomination

§14 lets a person nominate someone to exercise their rights if they die or become incapable. No other major regime has it, so no template carries it, so almost no Indian policy mentions it.

3

It never mentions the Board

A person who is unsatisfied with your grievance handling may complain to the Data Protection Board, and Rule 3 expects them to be told how. Policies inherited from elsewhere point at a supervisory authority that has no jurisdiction here.

4

It quotes the wrong clock

“We respond within 30 days” is GDPR language. Rule 14(3) sets ninety days for grievance redressal, and the Act sets no fixed period for the rights themselves. A published promise of thirty days is a promise you can breach.

None of these is fatal on its own. All four are wrong on a document you have published as a statement of how you handle personal data — which is the document a regulator reads first and a claimant quotes back to you.

Being built to

Read the page, not a copy of it

You give it the URL your policy actually lives at. No export, no upload, no pasting a version that may already be out of date.

01

Against the Act, clause by clause

Each requirement of §5 and Rule 3 tested separately with the provision named, rather than a score out of a hundred that tells you nothing about what to change.

02

Against your notices

Where a consent notice describes a purpose your policy never mentions, or the two give different retention periods for the same data, that contradiction is the finding.

03

Against your registry

A processor in your vendor list and nowhere in your policy. A system hosted abroad with no transfer disclosed. The gap between what you do and what you say you do.

04

The contact actually works

§8(9) requires a published, reachable contact. A grievance address that bounces is a failed obligation, not an IT issue, and it is trivially checkable.

05

With the correction drafted

A gap you cannot act on is just a nag. Each finding arrives with the paragraph that would close it, for a person to weigh, edit and accept.

Watch it work

Findings a keyword search never returns

Your policy is prose. Your obligations are structured. Reading one against the other is the whole job, and it is the part a scanner cannot do.

Your policy says

“On request, we will provide your information in a commonly used electronic format so you can transfer it to another provider.”

It flags

A data portability commitment. The DPDP Act grants no such right, so this is a promise you made voluntarily and can be held to.

The word “portability” never appears. A keyword scan finds nothing here.
Your policy says

“We retain your records for as long as necessary to provide our services.”

It flags

Your retention schedule sets seven years for clinical records and ninety days for marketing. The policy describes neither and implies a single open-ended period.

Found by comparing the sentence against your own schedule, not against a rulebook.
Your policy says

“We may share your information with trusted partners who help us operate our business.”

It flags

Your registry lists eleven processors, two of them hosted outside India. The policy names none of them and does not disclose a transfer abroad at all.

Three documents compared at once: the sentence, the vendor list and the hosting locations.
What a gap costs

The numbers, from the Schedule itself

Every gap is priced against the Act’s own Schedule — and most published guidance, ours included until recently, has these wrong.

§8(5)₹250 Cr

Failure to take reasonable security safeguards. The heaviest penalty in the Act.

§8(6)₹200 Cr

Failure to notify a personal data breach to the Board or to affected people.

§9₹200 Cr

Failure in the additional obligations owed in relation to children’s data.

§10₹150 Cr

Failure in the extra duties of a Significant Data Fiduciary, if you are named one.

§5 §6 §8(2) §11–14₹50 Cr

Notice, consent, processor accountability and rights all sit here — the Schedule’s residual entry for any other contravention.

That last row is the one worth reading twice, because it is where most policy gaps land and it is routinely quoted at three to five times its real figure. A vendor telling you a consent defect carries ₹250 Cr is either not reading the Schedule or is counting on you not to. These are also maxima, set by the Board per contravention, not predictions — and §33(2) makes what you did about a gap an express factor in what any of them becomes.

Not a one-off

A policy goes stale the week after you fix it

The problem is not that your policy was wrong once. It is that nothing tells you when it becomes wrong again.

01

Re-read when the page changes

Marketing edits the policy without telling compliance. The next read happens because the document moved, not because somebody remembered to look.

02

Re-check when your processing changes

A new vendor or a new category in your registry is a change to what your policy should say. That is the trigger nobody currently has.

03

Closed gaps stay closed

Fix a finding and it is verified on the next read rather than taken on trust, so you can see the direction of travel over a year instead of one snapshot.

You do not have to wait to find out.

The free Scorecard already covers notice and rights handling across ten weighted dimensions, and our privacy lawyers review published policies against the Act today.

Your control

Findings for you, decisions by you

A published policy is a statement your organisation makes. Changing it is not something software should do quietly.

01

Corrections arrive as drafts

An accepted finding produces revised wording for review. Putting it in front of the public stays a decision a named person makes and the record shows who.

02

A clean report is not a clean bill

It tests your policy against what your registry says. Where your registry is incomplete so is the finding — which is why the mapping comes first.

03

Counsel where it counts

It flags where wording does not meet a provision. Whether your position is defensible is a judgement, and our empanelled privacy lawyers make that call today.

Questions

About the Policy Gap Detector

Is our GDPR-based privacy policy actually a problem?

Usually, and in both directions at once. It tends to promise data portability, which the DPDP Act does not grant, while omitting nomination under §14 and the right to complain to the Data Protection Board, which it does. It often quotes a thirty-day response window borrowed from a different regime when Rule 14(3) sets ninety days for grievance redressal. None of that is fatal. All of it is wrong on a document you have published as a statement of how you handle personal data.

What does a policy gap actually cost?

For most policy defects, up to ₹50 Cr — the Schedule's residual entry, which covers notice under §5, consent under §6, processor accountability under §8(2) and the rights under §11 to §14. The larger figures attach elsewhere: ₹250 Cr for a security failure, ₹200 Cr for breach notification or children's data, ₹150 Cr for a Significant Data Fiduciary's extra duties. Be careful of anyone pricing a consent defect at ₹250 Cr — that number belongs to a different obligation.

How do we check our policy before this exists?

Two ways today. The free Scorecard covers notice and rights handling among its ten dimensions and gives you a position in five minutes. For the document itself, our empanelled privacy lawyers review policies against the Act as a service — and for a policy that has been public for two years and inherited from a GDPR template, a person reading it closely is the right answer anyway.

Do you need access to our website?

Only the public URL of your policy — the same page any visitor can read. Nothing is uploaded, no credentials are needed, and the version examined is the one actually published rather than whatever was pasted into a form. The sharper comparisons — against your notices and your registry — use records that already sit in your own tenant.

Will it rewrite our policy for us?

It drafts the paragraph that closes a gap. It does not republish anything: an accepted correction becomes a draft that a named person approves, which is the same rule every other module here follows. For a policy carrying real exposure, have counsel read the revision — that service is available now and does not wait on this module.

When does it ship?

No date, deliberately. Join the waitlist and we will tell you when its findings are ones we would act on ourselves. The Scorecard and the lawyer review are available today and do not depend on it.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Find the gaps before an audit.

Ten dimensions scored against the Act, your exposure in rupees, and the three that cost you most — free, and no account.