DPDPA gap assessment

Assess how your current DPDPA process operates.

This assessment reviews nine practical areas that support DPDPA readiness.

Your result provides an initial view of existing controls and areas that may require further review. It is not legal advice, certification, or a formal compliance determination.

What the assessment reviews

  1. We maintain a current inventory of personal data, processing activities, systems, processors, and responsible owners.
  2. Each processing activity has a documented purpose, applicable processing ground, relevant personal data, and retention requirement.
  3. Our privacy notices clearly describe the personal data involved, the purpose of processing, the related service, available rights, and a contact channel.
  4. Where consent is used, the request is specific and clear, the decision is recorded, and withdrawal is accessible.
  5. We can identify the notice version and consent record that applied to a particular decision.
  6. Data Principals can submit requests relating to access information, correction, completion, updating, erasure, grievance redressal, and nomination.
  7. Requests are verified, assigned, tracked, responded to, and closed with supporting records.
  8. We have a documented personal data breach process for affected Data Principals, the Data Protection Board of India, remediation, and internal review.
  9. Retention and erasure requirements are defined, approved actions can be carried out across relevant systems, and completion can be evidenced.
What the assessment reviews

The questions cover personal data inventory, processing purposes, privacy notices, consent, Data Principal requests, grievance handling, personal data breach response, retention, erasure, and supporting evidence.

Answer each question based on the process and records that currently exist, not work that is only planned.

0 / 9 statements reviewed

Select each statement that is currently supported by an approved process and available evidence.