Readiness assessment

DPDP Compliance Assessment · India

DPDP Compliance Assessment: Find Out Exactly Where You Stand

A structured review of your organisation against the applicable requirements of the DPDP Act, 2023 and the DPDP Rules, 2025. It identifies where evidence or controls are missing and turns the findings into prioritised implementation actions ahead of 13 May 2027.

Free self-assessment · No legal determination · Specialist assessment available

ForData Fiduciaries assessing DPDP readiness
FormatFree self-assessment or specialist-led
OutputPrioritised remediation roadmap
Statutory statusImplementation mechanism, not a universal legal requirement
Prepare for13 May 2027

The problem

“My CEO told me to get DPDP compliant.” Now what?

The DPDP Act spans notice, consent, security, breach response, retention, Data Principal rights, children's data, vendor contracts and — for some organisations — additional Significant Data Fiduciary duties. Most teams don't yet know which of these apply, how far off they are, or what to fix first. An assessment replaces that guesswork with a clear, prioritised starting point before 13 May 2027.

Definition

What is a DPDP compliance assessment?

A DPDP compliance assessment is a structured review of how an organisation collects, uses, shares, retains, secures and governs digital personal data against the applicable requirements of the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It identifies gaps in controls or evidence and converts them into prioritised remediation actions.

Choose your path

Which type of DPDP assessment do you need?

The free self-assessment is a low-friction entry point. A formal, evidence-based assessment is the specialist-led service. They are not equivalent.

Free DPDP Readiness Assessment

Free
Best for
Initial orientation and identifying likely gaps
Inputs
Your answers to a guided questionnaire
Evidence reviewed
No formal evidence validation
Output
Indicative readiness picture and priorities
Specialist involvement
Not required initially
Cost
Free
Start Free Assessment

Formal DPDP Compliance Assessment

Specialist-led
Best for
Organisations preparing an implementation programme or needing defensible findings
Inputs
Stakeholder interviews, documents, systems and evidence
Evidence reviewed
Yes
Output
Documented findings, obligation/control/evidence mapping and a remediation roadmap
Specialist involvement
Yes
Commercial model
Scoped engagement
Request a Formal Assessment

Coverage

What does a DPDP compliance assessment cover?

Each area is checked against the Act and Rules, with statutory obligations clearly separated from implementation good practice.

Assessment areaWhat we assessLegal basis / status
Scope & applicabilityWhether the DPDP Act applies to your processing, and in what capacityStatutory S.3
Role: Fiduciary / ProcessorWhether you determine purpose and means (Data Fiduciary) or process on instruction (Data Processor)Statutory S.2
Processing purposes & legal pathwayWhether each purpose has a valid basis — consent or a certain legitimate useStatutory S.4–7
Privacy noticesWhether notices meet the content and language requirementsStatutory S.5
Consent & withdrawalWhether consent is free, specific, informed, unambiguous and easy to withdrawStatutory S.6
Certain legitimate usesWhether any processing relies on S.7 and meets its conditionsStatutory S.7
Personal-data inventory / data flowsWhether you have a working view of what data you hold and where it flowsImplementation control
Data Principal rightsWhether access, correction, erasure and nomination can be honouredStatutory S.11–14
Grievance & published contactWhether an effective grievance route and a published contact existStatutory S.8(9)–(10), S.13
Retention & erasureWhether data is erased on withdrawal or purpose-end and per prescribed periodsStatutory S.8(7) + Rules
Processor / vendor governanceWhether processors are engaged under a valid contract; wider tiering and monitoringStatutory S.8(2) + implementation
Reasonable security safeguardsWhether safeguards meet the standardStatutory S.8(5) + Rules
Personal-data breach readinessWhether you can detect, respond to and notify a breach correctlyStatutory S.8(6) + Rules
Children's dataWhether verifiable parental consent and the S.9 restrictions on children's data are metStatutory S.9 + Rules
Cross-border transfersWhether transfers respect Section 16 and applicable Rules (no blanket localisation)Statutory S.16
SDF readiness (where relevant)Exposure against the S.10(1) factors and readiness for S.10(2) obligations if designatedRegulatory trigger S.10

Evidence

What documents and evidence may be reviewed?

Exact requirements depend on scope. A formal assessment typically draws on some of the following.

  • Business/entity structure and processing use cases
  • Privacy notices, consent screens and forms
  • Consent records/logs and withdrawal journeys
  • Application/system inventory and data-flow diagrams
  • CRM / HRMS / marketing systems
  • Processor/vendor list and processor contracts
  • Rights and grievance workflows
  • Retention schedules and deletion processes
  • Security policies and access-control evidence
  • Encryption, logging and backup evidence
  • Incident-response and breach-notification processes
  • Children's-data / age-assurance controls, governance and prior assessments

When you usually need this

Start here if any of these sound familiar.

  • You're starting DPDP compliance from scratch.
  • Leadership has asked for a compliance position or plan.
  • You're not sure which obligations actually apply to you.
  • You process customer or employee data across several systems.
  • You're weighing whether you may have Significant Data Fiduciary exposure.
  • You want to prioritise spend before committing to implementation.

Deliverables

A plan you can act on — not a 60-page report.

Depending on scope, outputs may include:

  • Executive readiness summary
  • Applicability and obligation map
  • Requirement / control / evidence matrix
  • Risk-rated findings register
  • Missing-evidence register
  • Priority remediation actions with owners and workstreams
  • Dependencies and immediate / 30-day / 90-day actions
  • Longer-term implementation roadmap
  • Specialist workstreams where external expertise may be required

How it works

Four steps, and you're pointed in the right direction.

1

Scope

Understand the organisation, processing profile, systems and the applicable DPDP requirements.

2

Assess

Review responses, processes, controls and available evidence.

3

Map the gaps

Connect findings to the relevant legal requirement or implementation control and prioritise remediation.

4

Act

Turn the findings into a practical implementation roadmap and identify the expertise required.

Know the difference

DPDP assessment vs audit vs DPIA

Three distinct instruments. None is a universal statutory requirement; the SDF-specific obligations apply only once an organisation is designated by the Central Government.

Compliance AssessmentPrivacy AuditDPIA
Main questionWhere are the gaps?Are implemented controls working?What privacy risks arise from processing?
Typical timingBefore / during implementationAfter controls existBefore / around relevant processing decisions
Universal statutory requirement?NoNoNo
SDF-specific requirementThe assessment itself: noIndependent auditor / periodic audit applies once designatedPeriodic DPIA applies once designated
OutputGap & remediation roadmapAssurance / findingsProcessing-risk assessment

The Privacy Audit service is covered separately. A periodic independent audit is a Significant Data Fiduciary obligation under S.10(2)(b), not a requirement for every organisation.

Timing

Why assess DPDP readiness now?

13 Nov 2025

Board framework

Sections 18–26 commenced, establishing the Data Protection Board framework.

13 Nov 2026

Consent Manager milestone

Consent Manager registration: S.6(9), S.27(1)(d) and Rule 4.

13 May 2027

Substantive duties

Main Data Fiduciary duties, Data Principal rights and most Board inquiry, adjudication and penalty provisions commence.

The specialist-partner model

The right expertise for the actual problem.

We assess before we match

We scope the requirement first, so any specialist introduced is the right one for that specific gap — not a one-size-fits-all consulting engagement.

Discipline fits the gap

A notice or contract problem is not a security problem. We identify which discipline the finding actually calls for.

You stay in control

Clearly-scoped work, transparent structure, and your choice of whether to proceed with any provider.

  • Notice or contract problem → privacy / legal specialist
  • Consent architecture → privacy technology + product / engineering
  • Security safeguards → cybersecurity specialist
  • Data mapping or deletion → data engineering / governance
  • SDF DPO appointment → appropriate DPO specialist via DPOIndia
We may work with specialist service and technology providers depending on the requirement. Organisations remain free to decide whether to proceed with any provider introduced through the platform.

Questions

Frequently asked questions.

What is a DPDP compliance assessment?
A structured review of how you collect, use, share, retain, secure and govern digital personal data against the DPDP Act, 2023 and DPDP Rules, 2025. It identifies gaps in controls or evidence and turns them into prioritised remediation actions.
Is a DPDP compliance assessment mandatory?
No. There is no universal statutory duty to run an assessment. It is an implementation mechanism to evaluate readiness for the obligations that do apply — most of which commence on 13 May 2027.
Who should conduct a DPDP compliance assessment?
Any Data Fiduciary handling digital personal data — typically compliance, legal, security or product owners. The free self-assessment can be run in-house; a formal, evidence-based assessment is specialist-led.
What does a DPDP assessment cover?
Applicability and role, lawful basis and notices, consent, rights and grievance handling, retention, processors, security, breach readiness, children's data, cross-border transfers and SDF exposure — see the coverage table above.
What documents are needed for a DPDP assessment?
It depends on scope. Common inputs include privacy notices, consent screens and records, system and processor inventories, contracts, retention schedules, and security and breach documentation. Evidence is used to test whether a requirement applies and whether a control exists.
How long does a DPDP compliance assessment take?
The free self-assessment takes about 10 minutes. A formal assessment depends on scope — the number of entities, systems and processors, and the maturity of your existing documentation.
How much does a DPDP compliance assessment cost?
The self-assessment is free. A formal assessment is scoped to your organisation; cost depends on entities and business units, applications and data flows, processor count, processing complexity, children's or high-risk processing, technical validation needs, documentation maturity and any SDF-specific work. Request a scoped assessment for a quote.
What is the difference between a DPDP assessment and an audit?
An assessment asks where the gaps are, usually before or during implementation. An audit asks whether implemented controls are working, after they exist. Neither is a universal statutory requirement; a periodic independent audit applies to a Significant Data Fiduciary once designated.
Does a DPDP assessment provide certification?
No. This service should not be represented as a statutory or government-recognised DPDP certification — no such general scheme is established by the Act. It provides findings and a remediation roadmap.
What happens after gaps are identified?
Findings are prioritised into immediate, 30-day, 90-day and longer-term actions, mapped to owners and workstreams, and — where implementation needs a specialist — matched to the right expertise. You choose whether to proceed.
What changes if we are designated a Significant Data Fiduciary?
SDF status is decided by Central Government notification, not self-declared. If designated, additional obligations apply — an India-based Data Protection Officer, an independent data auditor and periodic DPIAs. The assessment flags SDF exposure and readiness; it does not predict designation.
Can we start with the free assessment?
Yes. The free self-assessment is the low-friction entry point for an indicative readiness picture. A formal, evidence-based assessment is available when you need defensible findings for an implementation programme.

Request a formal assessment

Tell us about your organisation.

A specialist-led, evidence-based assessment scoped to you. Share a few details and we'll route your request to the right specialist.

We'll only use these details to scope and route your request. No legal determination is made from this form.

Thanks — request received.
We'll review your details and get back to you to scope a formal, evidence-based assessment.

Start where you actually are.

Ten minutes now saves months of guessing later. Map your obligations, see your gaps, and get a plan you can take to your leadership.