Back to The DPDP Act Section A

Readiness & Gap Assessment

Ten workstreams establishing compliance status ahead of 13 May 2027.

01  Applicability & Scoping Assessment

  • Determining Data Fiduciary or Data Processor status, and identifying processing activities that attract the Act.
  • Assessing extra-territorial applicability under Section 3.
  • Mapping interplay with RBI, SEBI, IRDAI and TRAI obligations, and the IT Act / SPDI Rules.
  • Assessing exposure to Significant Data Fiduciary designation under Section 10.

02  Data Discovery, Inventory & Mapping

  • Building a complete inventory of personal data across systems, applications and vendors.
  • Mapping data flows — collection, processing, storage, sharing, transfer and disposal.
  • Identifying children's data, data of persons with disabilities, and high-risk processing.

03  Gap Assessment & Compliance Diagnostic

  • Assessment against every operative obligation of the Act and Rules.
  • Review of existing privacy notices, consent flows, policies, contracts and security controls.
  • Risk-rated gap register with a prioritised remediation roadmap.

04  Notice & Consent Architecture

  • Standalone, plain-language privacy notices in English and the Eighth Schedule languages.
  • Consent that is free, specific, informed, unconditional and unambiguous, captured through clear affirmative action.
  • Withdrawal mechanisms as easy as giving consent, and a re-consent strategy for legacy data.
  • Legitimate-use grounds under Section 7, where consent is not the basis.

05  Data Principal Rights & Grievance Redressal

  • Workflows for access, correction, completion, updating, erasure and nomination requests.
  • A grievance process operating within statutory timelines.

06  Security Safeguards & Breach Readiness

  • Minimum safeguards under Rule 6: encryption, obfuscation, masking or tokenisation, access control, monitoring and continuity measures.
  • Breach-response playbook meeting the "without delay" intimation standard and the 72-hour Board report under Rule 7.
  • No materiality threshold applies — every breach is reportable.

07  Retention, Erasure & Logging

  • Retention schedules keyed to purpose, with automated erasure on withdrawal of consent or exhaustion of purpose (Rule 8, Third Schedule).

08  Children's & Disability Data

  • Verifiable parental consent and age-assurance mechanisms.
  • Prohibition on tracking, behavioural monitoring and targeted advertising directed at children.
  • Verifiable consent of a lawful guardian for persons with disabilities (Section 9, Fourth Schedule).

09  Processor & Vendor Contract Management

  • Review and redlining of processor agreements, cloud contracts and outsourcing arrangements.
  • DPDP-compliant data processing addenda covering safeguards, sub-processing, breach reporting, audit rights, and data return or erasure.
  • Vendor risk assessments and due-diligence questionnaires.

10  Cross-Border Transfer & Sectoral Overlay

  • Transfer restrictions under Section 16's negative-list model.
  • Localisation requirements under RBI, IRDAI and SEBI regulation, and Rule 13(4) for Significant Data Fiduciaries.
  • Transfer-impact assessments for offshore group entities and vendors.

Typical Outputs

  • DPDP Applicability & Scoping Note
  • Data Inventory
  • Risk-rated Gap Assessment Report
  • Remediation Roadmap

Speak With Our Data Protection & Privacy Team