DataSurity

DPDP Gap Assessment

Where you stand under the DPDP Act, and what to fix first.

An independent, evidence-based assessment of every obligation in the Act and the Rules, tested on your own systems, contracts and people and reconciled with your sector regulator. It ends with a prioritised roadmap and registers that stay live on DataSurity.

  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION
  • 40 years with India's regulated enterprises

Trusted by leading enterprises

  • Indiabulls Securities
  • KDSG Super-Speciality Hospital
  • Modicare
  • Express Inn Hotels & Resorts
  • Econo Broking
  • DAMS
  • Freesia by Express Inn
  • MBL
  • Trident Group
  • Dhani
  • Indiabulls Asset Reconstruction
Use cases

When enterprises commission a gap assessment

  • The Board asks where you stand

    Leadership wants an independent baseline before May 2027, with the exposure stated plainly and a plan it can fund.

  • You may be a Significant Data Fiduciary

    SDF candidates face a DPIA, an independent audit and algorithmic checks. The assessment shows how ready you are for each.

  • Your regulator is asking about privacy

    RBI, SEBI and IRDAI reviews now touch personal data. One assessment answers both the Act and your sector rules.

  • You're about to implement

    Before investing in consent, rights handling or new systems, a baseline shows where the real gaps are, so spend goes where the risk is.

Deliverables

Every artefact handed over, and kept live on the platform

Each deliverable is generated from the same record, so they agree with each other and stay current after the assessment ends.

  • Posture report

    Scored across 12 domains, with every finding stated in plain words, its section of the Act, its risk and its fix.

  • Board and Audit Committee deck

    Exposure, priorities and the business case for each step, in the form a Board reads.

  • Lawful-basis register

    One ground from the Act for every processing activity, with activities that have none flagged.

  • Processing record and data-flow map

    What you process, why, for whom, where and with whom, confirmed with process owners.

  • Third-party register

    Every processor and partner, their role, their contract status and their questionnaire responses.

  • Retention reconciliation

    Each record class set against the Act and your sector's retention rules, with conflicts resolved.

  • Findings register

    Owners, management responses and evidence grades for every gap.

  • Prioritised roadmap

    Quick wins, 90-day fixes and strategic work, each with an owner and a cost band.

Methodology

Five phases, from scoping to the Board

Scope

Twelve domains, tested against the Act and the Rules

Each domain carries its DPDP citation and, where one applies, your sector regulator's rule beside it.

DomainWhat the Act asksWhat we test
  • Governance and accountability

    Accountable processing and appropriate measures (s.8(1), s.8(4))

    Roles, policies, Board oversight and DPO or contact arrangements

  • Notice and transparency

    Itemised notices in a language people choose (s.5)

    Notice content, languages, placement and version control

  • Consent

    Free, specific and withdrawable consent (s.6)

    Consent capture, records, withdrawal and legacy customers

  • Legitimate uses

    Processing without consent only for listed uses (s.7)

    Each claimed use against its clause and guardrails

  • Inventory and purpose

    A known purpose for every processing (s.4)

    The processing record, data categories and populations

  • Processors and third parties

    Processing by processors only under contract (s.8(2))

    Vendor register, contracts and questionnaires

  • Security safeguards

    Reasonable safeguards (s.8(5), Rule 6)

    Encryption, masking, access, logging and backups per system

  • Data Principal rights

    Access, correction, erasure, grievance, nomination (s.11 to s.14)

    Channels, identity checks, timelines and evidence of closure

  • Children's data

    Verifiable parental consent, no tracking or targeted ads (s.9)

    Age signals, parental consent journeys and blocked purposes

  • Cross-border transfers

    Transfers except to restricted countries (s.16)

    Destinations per flow, plus sector localisation rules

  • Breach management

    Intimation to the Board and affected people (s.8(6), Rule 7)

    Detection, playbooks and the DPDP and CERT-In clocks

  • Sector overlay

    Your regulator's rules alongside the Act

    RBI, SEBI, IRDAI and CERT-In citations, conflicts reconciled

Sector expertise

Assessed against your regulator as well as the Act

  • KYC records reconciled with PMLA and RBI retention rules before any erasure is promised.
  • Co-borrowers, guarantors and nominees treated as Data Principals in their own right.
  • Lending partners and collection agencies assessed as processors under the RBI outsourcing and digital lending rules.
Platform

Delivered on DataSurity

The assessment runs on the same platform your teams keep using afterwards.

Client perspectives

Trusted by leaders across industries

“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”

Rakesh G

Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

FAQs

Frequently asked questions

Who needs a DPDP gap assessment?

Every Data Fiduciary, meaning every organisation that decides why and how personal data of people in India is processed. The more data you hold and the more regulated your sector, the more your Board will expect a documented baseline before May 2027. Likely Significant Data Fiduciaries need one to plan the DPIA and audit Section 10 requires.

How is this different from a self-assessment or a policy review?

A self-assessment scores answers to a questionnaire, and a policy review reads documents. This assessment tests whether the organisation does what its documents say, on its own systems and contracts, and grades every result by the evidence behind it. A partner approves each finding.

What do you need from our team?

A sponsor and a coordinator, an hour or so with each process owner, documents from a prioritised request list, and read-only access to key systems where discovery is in scope. The platform tracks every request, so nothing depends on email threads.

Does it cover our sector regulator?

Yes. Each control carries its DPDP citation and, where a sector overlay applies, the RBI, SEBI, IRDAI or CERT-In rule beside it. Where the two conflict, on retention for example, the report reconciles them. One assessment covers both.

Does our data leave our environment?

Discovery scans read-only and copies nothing out. Evidence is held on DataSurity, hosted in India, and access is limited to the assessment team. AI assists with drafting only on anonymised evidence, and no client data is sent to any external AI.

What happens after the assessment?

The roadmap becomes the implementation plan. SARC can lead it, co-deliver it with your teams, or advise while you execute. The registers stay live on DataSurity, and the consent, rights and discovery modules put the fixes into operation. A yearly reassessment measures progress against this baseline.

Knowledge resources

Start with where you stand.

Tell us about your organisation, and we'll scope the assessment with you.

  • DPDP Act
  • DPDP Rules
  • RBI
  • SEBI
  • IRDAI
  • CERT-In
  • PMLA
  • NIST CSF 2.0
  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION

We use these details to respond to your request and send what you asked for. See our privacy notice.