Assess · DPDP Gap Assessment

DPDP Gap Assessment

Twelve obligation areas, each read against the provision that creates it, and a register of everywhere personal data actually sits.

Scope an assessment See what gets examined You keep the register, the findings and the roadmap regardless.
What we actually do

The engagement, in four steps

Two of these happen without you. Your team’s share is the visit and a handful of conversations.

1

We read what you already have

Privacy notice, policies, employment contracts, vendor agreements, consent forms. Most of this arrives by email and needs nothing from you but the files.

2

We come and see how it works

The reception desk, the forms people actually fill in, the systems in daily use, the spreadsheet somebody keeps. What happens rarely matches what is written down.

3

We score it, area by area

Twelve obligation areas, each read against the provision that creates it, with your exposure priced from the Act’s own Schedule rather than guessed at.

4

You keep the findings

A register of where personal data sits, a score you can re-run later, and a phased roadmap — in a tenant you own, whether or not you work with us again.

Elapsed time depends on the size of your operation and how quickly documents arrive, so we scope it rather than quote a package. What we will commit to is the shape above, and that the reading and the scoring are our time and not yours.

Coverage

Twelve areas, and the provision behind each

A gap is only a gap against something. Every finding names the clause it fails, which is also what makes it fixable.

§5 · Rule 3₹50 Cr

Every notice you serve — standalone, itemised, plain language, the languages you owe, and the three links Rule 3 requires including the route to complain to the Board.

Notice
§6₹50 Cr

How consent is actually taken. Free, specific, informed, unconditional and unambiguous; optional purposes not pre-ticked; withdrawal as easy as giving under §6(4).

Consent
§7₹50 Cr

What you run on a legitimate use rather than consent, and whether that holds. Treating everything as consent is as wrong as treating nothing as consent.

Legitimate use
§8(2)₹50 Cr

Every processor acting for you, whether a contract exists, and whether it covers what they actually do. Usually the longest list of findings.

Processors
§8(5) · Rule 6₹250 Cr

The prescribed safeguards: encryption or masking, access control, logs and monitoring able to detect an incident, backups, and logs retained a year.

Security
§8(6) · Rule 7₹200 Cr

Who is entitled to declare a breach, and whether anything exists that meets the three duties — two of which fall due the moment you become aware.

Breach
§8(7) · Rule 8₹50 Cr

Whether anything is ever deleted, on what schedule, against which class — and whether the 48-hour pre-erasure notice would ever be sent.

Retention
§8(9)₹50 Cr

The contactable person. Published where a customer can find them, and reachable — we test the address rather than take its existence on trust.

Contact
§9 · Rule 10₹200 Cr

Whether you hold children’s data at all, whether verifiable parental consent applies, and whether a Fourth Schedule exemption covers you.

Children
§10 · Rule 13₹150 Cr

Whether you are likely to be designated a Significant Data Fiduciary, and what the impact assessment, annual audit and algorithmic diligence would mean.

SDF
§11–14 · Rule 14₹50 Cr

How a rights request would arrive and what would happen to it. Identity checks, the ninety-day grievance period, and whether nomination exists anywhere.

Rights
§16 · Rule 15₹50 Cr

What leaves India, whether the notice covering it says so, and whether any sector regulator of yours restricts it further.

Cross-border

Penalties shown are the Act’s Schedule maxima, assessed per contravention by the Board rather than predicted. They are here because they order the roadmap: a security gap and a notice gap are not the same size of problem, and a report that treats them alike is not much of a report.

How it runs

Four parts, and the visit is only one

Most of this is reading. The walk-through is what people picture, and it is where the surprises are, but it is not the assessment.

1

The documents you already have

Privacy policy, every notice you serve, vendor contracts and any processing agreements, retention schedule, security policy, breach plan, training records. Read against the provisions above rather than skimmed for tone.

2

The people who run the processes

Reception, IT, HR, marketing, whoever answers the phone when a customer is upset. The documented process and the real one differ everywhere, and only the real one is what a regulator will be looking at.

3

The walk-through

On site, following personal data from wherever it arrives until it stops moving. This is where the paper register, the local spreadsheet and the tool one team bought on a card turn up, and none of them was ever on a list.

4

The Rule 6 safeguards

A technical review against what Rule 6 actually prescribes — encryption or masking, access control, logs and monitoring capable of detecting an incident, backups, and log retention. §8(5) is the Act’s heaviest penalty and this is what it turns on.

Time and effort

What it costs you in hours

The honest answer, because a scope that sounds small and then is not is worse than a scope that sounds fair.

01

Two to three weeks, elapsed

For a single-location business. Longer where there are several sites, several entities or a genuinely complicated estate, and we say which before quoting rather than after.

02

About a day of your team’s time

Spread across the interviews and the visit. Most of the elapsed time is us reading, not you preparing — and we work from the documents you already have.

03

No questionnaire to complete

If a form could find these gaps you would have found them. Send us what exists, let us talk to your people, and we do the assembling.

The honest distinction

Our Scorecard is free. This is not the same thing.

Both measure DPDP readiness. They answer different questions, and only one of them can find something you had forgotten.

01

The Scorecard asks you

Ten weighted dimensions, five minutes, no account, no cost. An excellent instrument with one limit: it can only score what you tell it.

02

This reads and verifies

Your actual notices against Rule 3. Your actual contracts against §8(2). Your actual safeguards against Rule 6. Documents, not recollections.

03

The gap between them is the point

Every business we have assessed scored itself higher than the evidence supported. Not from dishonesty — you cannot report a system you have stopped noticing.

So take the free one first. It costs five minutes and tells you whether this conversation is urgent. If it comes back healthy and nobody has ever read your contracts against §8(2), treat that as a reason to be curious rather than reassured.

What you keep

Five things, and they are yours

Records in a working system, plus one document for the people who will never open it.

01

The register

Every place personal data sits — system, owner, category, hosting location, whether it leaves India. Loaded into the platform, not a spreadsheet that ages.

02

Findings against provisions

Each gap named with the clause it fails, so your team can act on it without needing us to interpret our own report back to them.

03

Your readiness score

The same ten dimensions as the free Scorecard, answered from evidence rather than recollection. Usually a different number.

04

Your exposure, ordered

Priced against the Schedule so the roadmap runs by what costs you most rather than by what is quickest to close.

05

A board-ready summary

One document for directors and insurers. Findings, exposure and what to do first, in language that needs no glossary.

Everything we produce is yours, whether or not anything follows.

The register stays in your tenant, exportable. Nothing about walking away from us after this is designed to be difficult.

Questions

About the DPDP gap assessment

How long does a DPDP gap assessment take?

Two to three weeks elapsed for a single-location business, and about a day of your team's time inside that. Most of the period is us reading — your policies, your notices, your vendor contracts, your retention schedule — rather than you preparing. Several sites, several entities or a complicated estate takes longer, and we tell you which before quoting. Be wary of anyone offering a meaningful assessment in an afternoon: the walk-through can be done in a day, but the document review and the Rule 6 technical review cannot.

Why pay for this when your Scorecard is free?

Because a self-assessment can only report what you already know about, and the expensive gaps are the ones nobody has looked at in two years. The Scorecard asks you questions. This reads your actual notices against Rule 3, your actual contracts against §8(2) and your actual safeguards against Rule 6. Take the free one first — it is genuinely useful and it tells you how urgent this is.

Does the DPDP Act require a gap assessment?

Not in those words, and no provision uses the phrase. What the Act does is impose duties you cannot discharge without a data inventory — securing personal data under §8(5), reporting a breach within Rule 7's windows, answering rights requests, erasing when a purpose ends under §8(7). A Significant Data Fiduciary has the sharper version: Rule 13 requires an independent audit every twelve months, and an auditor asks for the inventory first. DPDP readiness begins here whether or not the statute names it.

What do you need from us?

The documents that already exist — privacy policy, notices, vendor contracts and any processing agreements, retention schedule, security policy, breach plan, training records — plus time with the people who run the processes, and access to walk the premises. There is no questionnaire to complete. If a form could find these gaps you would already have found them.

Will you need access to our systems or data?

Not to your data. The Rule 6 review looks at how safeguards are configured — whether access is controlled, whether logs exist and are retained, whether backups are real — and that is a conversation with your IT provider plus evidence, not a login to your database. We record metadata: system names, what category each holds, who owns it. A consultant holding copies of your personal data has made your problem larger.

What does it cost?

It depends on the size and spread of your estate, and we would rather scope it than quote a number that turns out wrong in either direction. For context, gap assessments are quoted across this market from around a lakh and a half upwards, and we have seen quotes at many multiples of that for work that was over-scoped. Ask what you hold at the end: if the answer is a report rather than a working register, compare carefully.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Find out what you are carrying.

Twelve obligation areas read against the provisions that create them, and a register you keep whichever way you go next.