Twelve obligation areas, each read against the provision that creates it, and a register of everywhere personal data actually sits.
Two of these happen without you. Your team’s share is the visit and a handful of conversations.
Privacy notice, policies, employment contracts, vendor agreements, consent forms. Most of this arrives by email and needs nothing from you but the files.
The reception desk, the forms people actually fill in, the systems in daily use, the spreadsheet somebody keeps. What happens rarely matches what is written down.
Twelve obligation areas, each read against the provision that creates it, with your exposure priced from the Act’s own Schedule rather than guessed at.
A register of where personal data sits, a score you can re-run later, and a phased roadmap — in a tenant you own, whether or not you work with us again.
Elapsed time depends on the size of your operation and how quickly documents arrive, so we scope it rather than quote a package. What we will commit to is the shape above, and that the reading and the scoring are our time and not yours.
A gap is only a gap against something. Every finding names the clause it fails, which is also what makes it fixable.
Every notice you serve — standalone, itemised, plain language, the languages you owe, and the three links Rule 3 requires including the route to complain to the Board.
NoticeHow consent is actually taken. Free, specific, informed, unconditional and unambiguous; optional purposes not pre-ticked; withdrawal as easy as giving under §6(4).
ConsentWhat you run on a legitimate use rather than consent, and whether that holds. Treating everything as consent is as wrong as treating nothing as consent.
Legitimate useEvery processor acting for you, whether a contract exists, and whether it covers what they actually do. Usually the longest list of findings.
ProcessorsThe prescribed safeguards: encryption or masking, access control, logs and monitoring able to detect an incident, backups, and logs retained a year.
SecurityWho is entitled to declare a breach, and whether anything exists that meets the three duties — two of which fall due the moment you become aware.
BreachWhether anything is ever deleted, on what schedule, against which class — and whether the 48-hour pre-erasure notice would ever be sent.
RetentionThe contactable person. Published where a customer can find them, and reachable — we test the address rather than take its existence on trust.
ContactWhether you hold children’s data at all, whether verifiable parental consent applies, and whether a Fourth Schedule exemption covers you.
ChildrenWhether you are likely to be designated a Significant Data Fiduciary, and what the impact assessment, annual audit and algorithmic diligence would mean.
SDFHow a rights request would arrive and what would happen to it. Identity checks, the ninety-day grievance period, and whether nomination exists anywhere.
RightsWhat leaves India, whether the notice covering it says so, and whether any sector regulator of yours restricts it further.
Cross-borderPenalties shown are the Act’s Schedule maxima, assessed per contravention by the Board rather than predicted. They are here because they order the roadmap: a security gap and a notice gap are not the same size of problem, and a report that treats them alike is not much of a report.
Most of this is reading. The walk-through is what people picture, and it is where the surprises are, but it is not the assessment.
Privacy policy, every notice you serve, vendor contracts and any processing agreements, retention schedule, security policy, breach plan, training records. Read against the provisions above rather than skimmed for tone.
Reception, IT, HR, marketing, whoever answers the phone when a customer is upset. The documented process and the real one differ everywhere, and only the real one is what a regulator will be looking at.
On site, following personal data from wherever it arrives until it stops moving. This is where the paper register, the local spreadsheet and the tool one team bought on a card turn up, and none of them was ever on a list.
A technical review against what Rule 6 actually prescribes — encryption or masking, access control, logs and monitoring capable of detecting an incident, backups, and log retention. §8(5) is the Act’s heaviest penalty and this is what it turns on.
The honest answer, because a scope that sounds small and then is not is worse than a scope that sounds fair.
For a single-location business. Longer where there are several sites, several entities or a genuinely complicated estate, and we say which before quoting rather than after.
Spread across the interviews and the visit. Most of the elapsed time is us reading, not you preparing — and we work from the documents you already have.
If a form could find these gaps you would have found them. Send us what exists, let us talk to your people, and we do the assembling.
Both measure DPDP readiness. They answer different questions, and only one of them can find something you had forgotten.
Ten weighted dimensions, five minutes, no account, no cost. An excellent instrument with one limit: it can only score what you tell it.
Your actual notices against Rule 3. Your actual contracts against §8(2). Your actual safeguards against Rule 6. Documents, not recollections.
Every business we have assessed scored itself higher than the evidence supported. Not from dishonesty — you cannot report a system you have stopped noticing.
So take the free one first. It costs five minutes and tells you whether this conversation is urgent. If it comes back healthy and nobody has ever read your contracts against §8(2), treat that as a reason to be curious rather than reassured.
Records in a working system, plus one document for the people who will never open it.
Every place personal data sits — system, owner, category, hosting location, whether it leaves India. Loaded into the platform, not a spreadsheet that ages.
Each gap named with the clause it fails, so your team can act on it without needing us to interpret our own report back to them.
The same ten dimensions as the free Scorecard, answered from evidence rather than recollection. Usually a different number.
Priced against the Schedule so the roadmap runs by what costs you most rather than by what is quickest to close.
One document for directors and insurers. Findings, exposure and what to do first, in language that needs no glossary.
The register stays in your tenant, exportable. Nothing about walking away from us after this is designed to be difficult.
Two to three weeks elapsed for a single-location business, and about a day of your team's time inside that. Most of the period is us reading — your policies, your notices, your vendor contracts, your retention schedule — rather than you preparing. Several sites, several entities or a complicated estate takes longer, and we tell you which before quoting. Be wary of anyone offering a meaningful assessment in an afternoon: the walk-through can be done in a day, but the document review and the Rule 6 technical review cannot.
Because a self-assessment can only report what you already know about, and the expensive gaps are the ones nobody has looked at in two years. The Scorecard asks you questions. This reads your actual notices against Rule 3, your actual contracts against §8(2) and your actual safeguards against Rule 6. Take the free one first — it is genuinely useful and it tells you how urgent this is.
Not in those words, and no provision uses the phrase. What the Act does is impose duties you cannot discharge without a data inventory — securing personal data under §8(5), reporting a breach within Rule 7's windows, answering rights requests, erasing when a purpose ends under §8(7). A Significant Data Fiduciary has the sharper version: Rule 13 requires an independent audit every twelve months, and an auditor asks for the inventory first. DPDP readiness begins here whether or not the statute names it.
The documents that already exist — privacy policy, notices, vendor contracts and any processing agreements, retention schedule, security policy, breach plan, training records — plus time with the people who run the processes, and access to walk the premises. There is no questionnaire to complete. If a form could find these gaps you would already have found them.
Not to your data. The Rule 6 review looks at how safeguards are configured — whether access is controlled, whether logs exist and are retained, whether backups are real — and that is a conversation with your IT provider plus evidence, not a login to your database. We record metadata: system names, what category each holds, who owns it. A consultant holding copies of your personal data has made your problem larger.
It depends on the size and spread of your estate, and we would rather scope it than quote a number that turns out wrong in either direction. For context, gap assessments are quoted across this market from around a lakh and a half upwards, and we have seen quotes at many multiples of that for work that was over-scoped. Ask what you hold at the end: if the answer is a report rather than a working register, compare carefully.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Twelve obligation areas read against the provisions that create them, and a register you keep whichever way you go next.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.