DPDP Gap Assessment
Where you stand under the DPDP Act, and what to fix first.
An independent, evidence-based assessment of every obligation in the Act and the Rules, tested on your own systems, contracts and people and reconciled with your sector regulator. It ends with a prioritised roadmap and registers that stay live on DataSurity.
- 40 years with India's regulated enterprises
Trusted by leading enterprises
When enterprises commission a gap assessment
The Board asks where you stand
Leadership wants an independent baseline before May 2027, with the exposure stated plainly and a plan it can fund.
You may be a Significant Data Fiduciary
SDF candidates face a DPIA, an independent audit and algorithmic checks. The assessment shows how ready you are for each.
Your regulator is asking about privacy
RBI, SEBI and IRDAI reviews now touch personal data. One assessment answers both the Act and your sector rules.
You're about to implement
Before investing in consent, rights handling or new systems, a baseline shows where the real gaps are, so spend goes where the risk is.
Every artefact handed over, and kept live on the platform
Each deliverable is generated from the same record, so they agree with each other and stay current after the assessment ends.
Posture report
Scored across 12 domains, with every finding stated in plain words, its section of the Act, its risk and its fix.
Board and Audit Committee deck
Exposure, priorities and the business case for each step, in the form a Board reads.
Lawful-basis register
One ground from the Act for every processing activity, with activities that have none flagged.
Processing record and data-flow map
What you process, why, for whom, where and with whom, confirmed with process owners.
Third-party register
Every processor and partner, their role, their contract status and their questionnaire responses.
Retention reconciliation
Each record class set against the Act and your sector's retention rules, with conflicts resolved.
Findings register
Owners, management responses and evidence grades for every gap.
Prioritised roadmap
Quick wins, 90-day fixes and strategic work, each with an owner and a cost band.
Five phases, from scoping to the Board
Twelve domains, tested against the Act and the Rules
Each domain carries its DPDP citation and, where one applies, your sector regulator's rule beside it.
- Governance and accountability
Accountable processing and appropriate measures (s.8(1), s.8(4))
Roles, policies, Board oversight and DPO or contact arrangements
- Notice and transparency
Itemised notices in a language people choose (s.5)
Notice content, languages, placement and version control
- Consent
Free, specific and withdrawable consent (s.6)
Consent capture, records, withdrawal and legacy customers
- Legitimate uses
Processing without consent only for listed uses (s.7)
Each claimed use against its clause and guardrails
- Inventory and purpose
A known purpose for every processing (s.4)
The processing record, data categories and populations
- Processors and third parties
Processing by processors only under contract (s.8(2))
Vendor register, contracts and questionnaires
- Security safeguards
Reasonable safeguards (s.8(5), Rule 6)
Encryption, masking, access, logging and backups per system
- Data Principal rights
Access, correction, erasure, grievance, nomination (s.11 to s.14)
Channels, identity checks, timelines and evidence of closure
- Children's data
Verifiable parental consent, no tracking or targeted ads (s.9)
Age signals, parental consent journeys and blocked purposes
- Cross-border transfers
Transfers except to restricted countries (s.16)
Destinations per flow, plus sector localisation rules
- Breach management
Intimation to the Board and affected people (s.8(6), Rule 7)
Detection, playbooks and the DPDP and CERT-In clocks
- Sector overlay
Your regulator's rules alongside the Act
RBI, SEBI, IRDAI and CERT-In citations, conflicts reconciled
Assessed against your regulator as well as the Act
- KYC records reconciled with PMLA and RBI retention rules before any erasure is promised.
- Co-borrowers, guarantors and nominees treated as Data Principals in their own right.
- Lending partners and collection agencies assessed as processors under the RBI outsourcing and digital lending rules.
Delivered on DataSurity
The assessment runs on the same platform your teams keep using afterwards.
- Data Journey MappingThe processing record and registers built during the assessment become your live registers.
- Data Discovery & ClassificationRead-only scans provide safeguard evidence and show where personal data actually sits.
- Assessment & Compliance ReportingControls, findings, evidence grades and the report are produced and tracked here.
The registers, findings and roadmap stay live on DataSurity after the assessment, so next year's review starts where this one ends.
Trusted by leaders across industries
“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”
Rakesh G
Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

Frequently asked questions
Who needs a DPDP gap assessment?
Every Data Fiduciary, meaning every organisation that decides why and how personal data of people in India is processed. The more data you hold and the more regulated your sector, the more your Board will expect a documented baseline before May 2027. Likely Significant Data Fiduciaries need one to plan the DPIA and audit Section 10 requires.
How is this different from a self-assessment or a policy review?
A self-assessment scores answers to a questionnaire, and a policy review reads documents. This assessment tests whether the organisation does what its documents say, on its own systems and contracts, and grades every result by the evidence behind it. A partner approves each finding.
What do you need from our team?
A sponsor and a coordinator, an hour or so with each process owner, documents from a prioritised request list, and read-only access to key systems where discovery is in scope. The platform tracks every request, so nothing depends on email threads.
Does it cover our sector regulator?
Yes. Each control carries its DPDP citation and, where a sector overlay applies, the RBI, SEBI, IRDAI or CERT-In rule beside it. Where the two conflict, on retention for example, the report reconciles them. One assessment covers both.
Does our data leave our environment?
Discovery scans read-only and copies nothing out. Evidence is held on DataSurity, hosted in India, and access is limited to the assessment team. AI assists with drafting only on anonymised evidence, and no client data is sent to any external AI.
What happens after the assessment?
The roadmap becomes the implementation plan. SARC can lead it, co-deliver it with your teams, or advise while you execute. The registers stay live on DataSurity, and the consent, rights and discovery modules put the fixes into operation. A yearly reassessment measures progress against this baseline.




