Assessment & Compliance Reporting
Every control, tested, evidenced and tracked to closure.
An assessment your Board and your auditor can rely on. Controls are tested on your real activities, systems and vendors, graded by the evidence behind them, reviewed by a partner and followed through to the fix.
Trusted by leading enterprises
Real evidence in. A report you can stand behind out.
The assessment reads your register, your records and your people, and gives leadership a clear view of where you stand.
- Processing register
- Discovery findings
- Consent and rights records
- Documents and policies
- Stakeholder interviews
- Sector regulator rules
- Scored posture across 12 domains
- Findings graded by evidence
- Owners and a roadmap
- Board report and deck
- Annexure registers
- A mitigation file
An assessment that holds up under scrutiny
181 controls
Across 12 domains, mapped to NIST CSF 2.0, ISO 27001 and ISO 27701, and calibrated to the Act and Rules
3 evidence grades
Evidence-verified, assertion-only or not tested, shown on every finding
2 citations
On every control: the DPDP section and your sector regulator's rule, side by side
Five steps from first look to steady improvement
What the assessment does for you
Tested where the data lives
Controls sit on the things they govern: each processing activity, system and third party. A control can't be scored without a source, and the unit tested and the sample drawn are recorded. The result reflects your operations, not a questionnaire.
Honest about evidence
Every finding says how it was established: verified from evidence, taken from what someone said, or not yet tested. The report shows the split, so leadership knows exactly how much of its posture rests on tested fact. AI helps extract evidence and draft working papers, with personal data anonymised first. Every finding still carries its evidence grade and a partner's approval.
Two regulators, one assessment
Each control carries its DPDP section and, where it applies, the RBI, SEBI, IRDAI or CERT-In rule beside it. Where the two disagree, on retention or incident reporting, the report gives the reconciled position instead of choosing one.
From findings to fixes, year on year
Findings go to named owners with management responses and a prioritised roadmap. Each result cites the version of the register it tested, so the next assessment measures real movement. The engagement's own record becomes the mitigation file Section 33(2) lets the Board consider.
What the Act asks, and how Assessment answers
The assessment tests the Data Fiduciary's general duties and shows the evidence behind each one.
- s.8(1), s.8(4)
Accountability and appropriate measures to observe the Act
Controls across 12 domains, tested and graded by evidence
- s.8(2)
Processors only under valid contracts
Vendor contracts tested as control units
- s.8(5), Rule 6
Reasonable security safeguards
Safeguard controls tested on each system, with Discovery evidence
- s.8(6), Rule 7
Breach intimation to the Board and affected people
Incident readiness tested against both the DPDP and CERT-In clocks
- s.10, Rule 12
SDF duties: DPIA, independent audit, algorithmic checks
SDF candidacy profiled per entity, with DPIA and audit readiness
- s.17
Exemptions
Applied per activity, with the duties that still apply kept in scope
- s.33(2)
Factors the Board weighs in setting a penalty
The assessment's record exported as a mitigation file
What Assessment draws on
- Data Journey MappingControls are tested against the register, and each result cites the version it tested.
- Data Discovery & ClassificationSafeguard evidence from scans feeds security controls, marked by how it was established.
- Consent ManagementConsent records and notice versions become evidence for Sections 5 and 6.
Deploy it your way
Built for regulated Indian enterprises: your data stays where your policies say it must.
- 01
SaaS, hosted in India
Managed by SARC AI on infrastructure in Indian data centres.
- 02
Private cloud
Runs in your own cloud account, under your keys and access policies.
- 03
On-premises
Installed in your data centre. Scanners read in place, and nothing leaves your network.
Connects to
PostgreSQL
MySQL
Oracle Database
Microsoft SQL Server
MongoDB
MariaDB
- IDIBM Db2
SAP HANA
Snowflake
Amazon Redshift
Google BigQuery
Databricks
Teradata
Amazon DynamoDB
Azure SQL
Apache Cassandra
Redis
Elasticsearch
Couchbase
ClickHouse
Apache Hive
Apache Kafka
SQLite
Neo4j
Connectors are enabled during onboarding. Logos belong to their owners and indicate compatibility, not endorsement.
Certified
Frequently asked questions
How is this different from a DPDP self-assessment?
A self-assessment scores your answers to a questionnaire. This assessment tests controls on your actual activities, systems and vendor contracts, records what was sampled, and grades every result by the evidence behind it. A partner reviews each finding before it reaches the report.
How is it different from an ISO 27001 audit?
ISO 27001 tests an information security management system. DPDP also asks about lawful grounds, notices, consent, rights, processors, children's data, cross-border transfers and breach reporting. Our framework sits above NIST CSF 2.0, ISO 27001 and ISO 27701, and shows where the Act asks for more.
What does "assertion-only" mean on a finding?
That the control was scored on what someone told us, without evidence we tested ourselves. The report marks these separately from evidence-verified findings, so leadership sees clearly how much of the posture rests on tested fact.
Does it cover our sector regulator?
Yes. Sector overlays add RBI, SEBI, IRDAI or CERT-In citations beside the DPDP ones on every relevant control. Where the two conflict, such as on retention, the report reconciles them. One assessment covers both regulators.
How often should we run it?
Most organisations run it once a year. Between assessments, the processing register stays live in Data Journey Mapping, and findings are tracked to closure by their owners. Each new assessment cites the register version it tested, so progress from one year to the next is measurable.
What is a mitigation file?
Section 33(2) lists what the Data Protection Board considers when setting a penalty, including steps taken to mitigate. The assessment's own record, with its timestamps, versions and evidence, exports as the starting point of that file. The work of being assessed becomes part of your defence.
Trusted by leaders across industries
“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”
Rakesh G
Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)





