DPDP Compliance Assessment · India
A structured review of your organisation against the applicable requirements of the DPDP Act, 2023 and the DPDP Rules, 2025. It identifies where evidence or controls are missing and turns the findings into prioritised implementation actions ahead of 13 May 2027.
Free self-assessment · No legal determination · Specialist assessment available
The problem
The DPDP Act spans notice, consent, security, breach response, retention, Data Principal rights, children's data, vendor contracts and — for some organisations — additional Significant Data Fiduciary duties. Most teams don't yet know which of these apply, how far off they are, or what to fix first. An assessment replaces that guesswork with a clear, prioritised starting point before 13 May 2027.
Definition
A DPDP compliance assessment is a structured review of how an organisation collects, uses, shares, retains, secures and governs digital personal data against the applicable requirements of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It identifies gaps in controls or evidence and converts them into prioritised remediation actions.
A general DPDP compliance or gap assessment is not itself a universal statutory requirement. It is an implementation mechanism used to evaluate readiness for the underlying obligations that apply to the organisation.
Choose your path
The free self-assessment is a low-friction entry point. A formal, evidence-based assessment is the specialist-led service. They are not equivalent.
Coverage
Each area is checked against the Act and Rules, with statutory obligations clearly separated from implementation good practice.
| Assessment area | What we assess | Legal basis / status |
|---|---|---|
| Scope & applicability | Whether the DPDP Act applies to your processing, and in what capacity | Statutory S.3 |
| Role: Fiduciary / Processor | Whether you determine purpose and means (Data Fiduciary) or process on instruction (Data Processor) | Statutory S.2 |
| Processing purposes & legal pathway | Whether each purpose has a valid basis — consent or a certain legitimate use | Statutory S.4–7 |
| Privacy notices | Whether notices meet the content and language requirements | Statutory S.5 |
| Consent & withdrawal | Whether consent is free, specific, informed, unambiguous and easy to withdraw | Statutory S.6 |
| Certain legitimate uses | Whether any processing relies on S.7 and meets its conditions | Statutory S.7 |
| Personal-data inventory / data flows | Whether you have a working view of what data you hold and where it flows | Implementation control |
| Data Principal rights | Whether access, correction, erasure and nomination can be honoured | Statutory S.11–14 |
| Grievance & published contact | Whether an effective grievance route and a published contact exist | Statutory S.8(9)–(10), S.13 |
| Retention & erasure | Whether data is erased on withdrawal or purpose-end and per prescribed periods | Statutory S.8(7) + Rules |
| Processor / vendor governance | Whether processors are engaged under a valid contract; wider tiering and monitoring | Statutory S.8(2) + implementation |
| Reasonable security safeguards | Whether safeguards meet the standard | Statutory S.8(5) + Rules |
| Personal-data breach readiness | Whether you can detect, respond to and notify a breach correctly | Statutory S.8(6) + Rules |
| Children's data | Whether verifiable parental consent and the S.9 restrictions on children's data are met | Statutory S.9 + Rules |
| Cross-border transfers | Whether transfers respect Section 16 and applicable Rules (no blanket localisation) | Statutory S.16 |
| SDF readiness (where relevant) | Exposure against the S.10(1) factors and readiness for S.10(2) obligations if designated | Regulatory trigger S.10 |
Evidence
Exact requirements depend on scope. A formal assessment typically draws on some of the following.
The objective is not to collect documents for their own sake. Evidence is used to determine whether a requirement is applicable, whether a control exists, and whether remediation is required.
When you usually need this
Deliverables
Depending on scope, outputs may include:
How it works
Understand the organisation, processing profile, systems and the applicable DPDP requirements.
Review responses, processes, controls and available evidence.
Connect findings to the relevant legal requirement or implementation control and prioritise remediation.
Turn the findings into a practical implementation roadmap and identify the expertise required.
Know the difference
Three distinct instruments. None is a universal statutory requirement; the SDF-specific obligations apply only once an organisation is designated by the Central Government.
| Compliance Assessment | Privacy Audit | DPIA | |
|---|---|---|---|
| Main question | Where are the gaps? | Are implemented controls working? | What privacy risks arise from processing? |
| Typical timing | Before / during implementation | After controls exist | Before / around relevant processing decisions |
| Universal statutory requirement? | No | No | No |
| SDF-specific requirement | The assessment itself: no | Independent auditor / periodic audit applies once designated | Periodic DPIA applies once designated |
| Output | Gap & remediation roadmap | Assurance / findings | Processing-risk assessment |
The Privacy Audit service is covered separately. A periodic independent audit is a Significant Data Fiduciary obligation under S.10(2)(b), not a requirement for every organisation.
Timing
Sections 18–26 commenced, establishing the Data Protection Board framework.
Consent Manager registration: S.6(9), S.27(1)(d) and Rule 4.
Main Data Fiduciary duties, Data Principal rights and most Board inquiry, adjudication and penalty provisions commence.
An assessment conducted during the implementation window can identify the work that needs to be completed before operational readiness becomes deadline-driven.
The specialist-partner model
We scope the requirement first, so any specialist introduced is the right one for that specific gap — not a one-size-fits-all consulting engagement.
A notice or contract problem is not a security problem. We identify which discipline the finding actually calls for.
Clearly-scoped work, transparent structure, and your choice of whether to proceed with any provider.
Questions
Request a formal assessment
A specialist-led, evidence-based assessment scoped to you. Share a few details and we'll route your request to the right specialist.
Ten minutes now saves months of guessing later. Map your obligations, see your gaps, and get a plan you can take to your leadership.
What's next
We will route your request to the right person