Table of contents
By-Research Team
September 29, 2026 | 15 min read | DPDP
What Should a DPDP Gap Assessment Include?
A DPDP gap assessment should examine whether an organisation’s personal data practices, policies, processes, controls, and evidence align with the applicable requirements of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. It should identify gaps, assess their priority, assign ownership, and translate findings into a practical remediation roadmap.
But there is a problem.
Many organisations start with a checklist: Do we have a privacy policy? Do we have a consent mechanism? Do we have a data breach policy?
The answers may all be “yes” while the underlying controls remain incomplete, inconsistently implemented, or impossible to demonstrate with evidence.
That is where a structured DPDP Assessment becomes valuable.
What is a DPDP Gap Assessment?
A DPDP gap assessment is a structured review that compares an organisation’s current data-processing practices and privacy controls against the requirements that apply to it under the DPDP framework. The assessment should examine both documented controls and how those controls operate in practice, supported by appropriate evidence.
The DPDP Act establishes obligations relating to areas including processing of personal data, consent, obligations of Data Fiduciaries, Data Principal rights, security safeguards, breach-related responsibilities, and additional requirements for certain organisations.
The notified DPDP Rules, 2025 provide further operational requirements in areas such as notices, security safeguards, breach notification, retention, children’s data, and Significant Data Fiduciary obligations.
A practical gap analysis therefore follows a simple logic:
Requirement → Current State → Evidence → Gap → Priority → Remediation
Essentials of an Effective DPDP Gap Assessment
A comprehensive DPDP gap assessment should cover the organisation’s data lifecycle, privacy governance, Data Principal-facing processes, security safeguards, third-party relationships, and applicable regulatory obligations. It should also test whether controls are implemented effectively and supported by evidence, rather than relying only on policy documents or questionnaire responses.
The following areas form the core of the assessment.
- Scope and DPDP Applicability
Start by determining what is actually being assessed and which requirements apply. Without a defined scope, even a detailed gap assessment can miss important processing activities or examine controls that are irrelevant to the organisation.
Assess:
- Business units and functions in scope
- Personal data processing activities
- Data Fiduciary and Data Processor relationships
- Products, services, applications, and platforms
- Relevant categories of Data Principals
- Applicable DPDP Act requirements
- Applicable DPDP Rules requirements
- Whether additional obligations apply, including those relevant to Significant Data Fiduciaries
Practical check: If a business cannot clearly identify which teams, systems, and processing activities fall within the assessment scope, the gap assessment itself has a scope gap.
- Personal Data Inventory and Data Mapping
Build a reliable picture of where personal data enters, moves, resides, and leaves the organisation. A DPDP assessment should test whether the documented inventory and data flows accurately represent actual processing across applications, databases, business processes, employees, processors, and third parties.
Review:
- Types of personal data collected
- Sources of personal data
- Processing purposes
- Collection channels
- Applications and databases
- Storage locations
- Internal data transfers
- Third-party sharing
- Data processors
- Cross-border data flows
- Data retention locations
- Processing records and inventories
Why does this matter? You cannot protect, retain, delete, or provide access to data that the organisation cannot reliably locate.
- Privacy Notice and Consent Management
Assess whether people are given the information required to make informed decisions and whether consent mechanisms operate as documented. The DPDP Rules, 2025 specify that notices should be standalone, understandable, and written in clear language, including details about the personal data and purposes involved.
Review:
- Privacy notices
- Data categories disclosed
- Processing purposes
- Notice delivery points
- Consent collection mechanisms
- Consent records
- Consent withdrawal
- Consent management workflows
- Links or mechanisms for exercising rights and making complaints
- Alignment between stated purposes and actual processing
The Rules also state that withdrawal of consent should be as easy as giving consent.
Do not stop at the policy. Test the journey.
If a user can provide consent in one click but needs to email three departments to withdraw it, the control deserves closer examination.
- Data Principal Rights Management
A DPDP Assessment should verify whether the organisation can operationally support applicable Data Principal rights, not merely state those rights in a privacy policy. The assessment should examine the complete workflow from request intake and verification through fulfilment, communication, escalation, and evidence of completion.
Assess:
- Rights-request channels
- Identity verification
- Request classification
- Internal ownership
- Search and retrieval processes
- Correction workflows
- Erasure workflows
- Nomination-related processes
- Grievance handling
- Response tracking
- Escalation
- Records of completed requests
- Data Retention, Deletion and Erasure
Review whether the organisation knows why personal data is retained, how long it should remain available, and how deletion or erasure is operationally executed. A retention policy is only the blueprint; the assessment must determine whether systems and processors actually follow it.
Review:
- Retention schedules
- Purpose-based retention
- Deletion triggers
- Automated deletion
- Manual deletion procedures
- Database and application controls
- Backup considerations
- Processor deletion
- Deletion evidence
- Exceptions required by applicable law
The key question is simple: Can the organisation prove that data is deleted when it should be?
- Security Safeguards
A DPDP gap assessment should examine whether appropriate technical and organisational safeguards protect personal data against risks such as unauthorised access, compromise, loss, or other security incidents. The notified Rules specify measures including encryption or other protection measures, access controls, logging and monitoring, backups, contractual safeguards, and technical and organisational measures.
Assess:
- Access controls
- Authentication mechanisms
- Encryption or equivalent safeguards
- Logging and monitoring
- Security incident detection
- Vulnerability management
- Backup and recovery
- Data protection controls
- Processor security obligations
- Technical and organisational measures
- Evidence that safeguards operate effectively
- Data Breach and Incident Response
Assess whether the organisation can detect, contain, investigate, document, and report a personal data breach through a defined and tested process. The DPDP Rules, 2025 prescribe notification requirements to affected Data Principals and the Board, including initial information without delay and additional information to the Board within the specified period.
Review:
- Incident detection
- Escalation procedures
- Breach classification
- Roles and responsibilities
- Internal communication
- Regulatory notification process
- Data Principal notification process
- Incident documentation
- Root-cause analysis
- Corrective actions
- Breach-response testing
- Processor and Third-Party Management
A DPDP gap assessment should examine how personal data is shared with processors and other third parties and whether contractual, operational, and security controls remain aligned throughout the relationship. The Rules specifically contemplate appropriate security provisions in contracts between Data Fiduciaries and Data Processors.
Review:
- Processor inventory
- Vendor due diligence
- Data-processing agreements
- Contractual privacy obligations
- Security clauses
- Sub-processors
- Data-sharing arrangements
- Retention requirements
- Deletion obligations
- Incident escalation
- Ongoing vendor monitoring
Your organisation may have a strong privacy programme. Your processor may have a completely different one.
- Children's Data and Other Applicable Requirements
Where an organisation processes children’s personal data, the assessment should test the additional controls required for that processing. The DPDP Rules, 2025 address verifiable parental consent and require appropriate technical and organisational measures before processing a child’s personal data.
Review, where applicable:
- Identification of children
- Age-verification mechanisms
- Parental consent
- Verification of the consenting parent
- Technical controls
- Organisational procedures
- Product or service-specific safeguards
The Rules define an adult for this purpose as a person who has completed 18 years of age.
Do not assume that a generic consent mechanism is enough. Children's data requires the organisation to examine the specific controls applicable to the processing.
- Privacy Governance and Accountability
Assess whether privacy responsibilities are clearly assigned, documented, and supported by governance processes. A privacy programme cannot operate as a one-person project; accountability should connect business, legal, privacy, security, technology, procurement, and relevant operational teams.
Review:
- Privacy roles and responsibilities
- DPO requirements, where applicable
- Governance committees
- Policies and procedures
- Employee training
- Privacy awareness
- Escalation mechanisms
- Record keeping
- Management oversight
- Compliance reporting
For organisations subject to additional Significant Data Fiduciary obligations, the assessment should separately test the controls and governance mechanisms relevant to those obligations. The DPDP Act provides for additional obligations for Significant Data Fiduciaries.
- Privacy Risk and DPIA Processes
The assessment should determine whether the organisation has a functioning process for identifying and addressing privacy risks associated with relevant processing activities. Where DPIAs or related assessments are applicable, review whether they are documented, linked to actual processing, and followed by appropriate mitigation.
Assess:
- Privacy risk identification
- High-risk processing
- DPIA methodology, where applicable
- Risk mitigation
- Approval and review
- Link between risk findings and controls
- Monitoring of residual risk
- Cross-Border Data Transfers
Review where personal data moves outside the organisation and across jurisdictions, including transfers involving cloud providers, processors, platforms, and other third parties. The assessment should identify the relevant data flows and evaluate them against the requirements and restrictions applicable to the organisation.
Review:
- Countries receiving data
- Cloud infrastructure
- Overseas processors
- International vendors
- Data-transfer arrangements
- Contractual controls
- Applicable government restrictions
- Monitoring mechanisms
- Documentation
The DPDP framework contains provisions concerning restrictions that may apply to transfers of personal data outside India, making cross-border flows an important part of the assessment scope.
- Significant Data Fiduciary Requirements
Where an organisation is a Significant Data Fiduciary, the DPDP gap assessment should include the additional obligations applicable to that designation rather than treating the organisation like any other Data Fiduciary. The assessment should separately evaluate governance, privacy impact assessment, audit, DPO, and other applicable requirements.
Review:
- Applicability
- DPO arrangements
- DPIA processes
- Independent audit requirements
- Periodic assessment
- Additional governance controls
- Compliance reporting
- Risk management
Applicability comes first. Do not build an expensive control framework for an obligation that does not apply; equally, do not miss an obligation because nobody checked applicability.
What Evidence Should Be Reviewed During a DPDP Gap Assessment?
A credible DPDP Assessment should be evidence-led. Policies and questionnaire responses can establish that a control has been documented, but supporting records, configurations, contracts, workflows, logs, and test results provide stronger evidence of how the control operates in practice.

-
Policies and Governance Documents
Review privacy policies, internal procedures, governance charters, roles and responsibilities, training materials, and accountability documentation.
The question is not simply whether a policy exists. Check whether it is current, approved, communicated, assigned to an owner, and reflected in operational processes.
-
Data Inventory and Mapping Evidence
Review data inventories, data-flow diagrams, RoPA or equivalent records, system inventories, application documentation, and processor records.
Compare documentation with reality.
-
Consent and Notice Evidence
Review privacy notices, consent screens, consent logs, timestamps, consent records, withdrawal records, and relevant configuration or workflow evidence.
The strongest evidence often comes from seeing the control operate rather than reading a description of how it should operate.
-
Data Principal Rights Evidence
Review request logs, tickets, identity-verification procedures, fulfilment records, response communications, escalation records, and grievance records.
Sample completed requests where appropriate.
A functioning rights process should leave an auditable trail from request to resolution.
-
Retention and Deletion Evidence
Review retention schedules, deletion workflows, system configurations, deletion logs, processor instructions, and evidence of completed deletion.
Check whether retention rules are translated into operational controls.
-
Vendor and Processor Evidence
Review executed contracts, DPAs, vendor assessments, security questionnaires, processor inventories, sub-processor information, and monitoring records.
Do not rely only on a standard contract template.
The assessment should determine whether the actual third-party relationship reflects the organisation's documented privacy requirements.
-
Security and Incident Evidence
Review access-control records, security configurations, logs, monitoring evidence, backup procedures, incident records, breach-response tests, and corrective-action records.
The DPDP Rules expressly identify security measures such as encryption or equivalent safeguards, access controls, logging and monitoring, backups, contractual safeguards, and technical and organisational measures.
Evidence turns a compliance statement into something that can actually be examined.
Want to know your DPDP readiness position?
Explore our DPDP Compliance Services to strengthen your privacy programme.
How Should DPDP Compliance Gaps Be Evaluated?
A useful gap analysis should evaluate more than whether a control exists. Each finding should be assessed against the applicable requirement, current implementation, supporting evidence, business impact, priority, ownership, and remediation path.

A practical assessment can follow this sequence:
-
Identify the Applicable Requirement
Map the processing activity or control to the relevant DPDP Act provision, DPDP Rule, or other applicable requirement.
Start with the requirement, not the solution. Otherwise organisations can end up buying technology before understanding the actual compliance problem.
-
Assess the Current State
Determine how the organisation currently performs the relevant activity.
Document the actual process—not the process everyone wishes existed.
-
Review Supporting Evidence
Validate the current-state assessment against appropriate evidence.
Evidence should confirm the control, not merely decorate the assessment report.
-
Determine the Gap
Classify what is missing, incomplete, ineffective, inconsistent, outdated, or insufficiently evidenced.
A useful status model can include:
- Compliant: Requirement is addressed and sufficient evidence exists.
- Partially Compliant: Control exists but has material limitations.
- Non-Compliant: Applicable requirement is not adequately addressed.
- Not Evidenced: A control may exist, but sufficient evidence was not available.
- Not Applicable: The requirement does not apply to the assessed activity or organisation.
-
Assess Risk and Priority
Not every finding deserves the same remediation sequence.
Consider:
- Regulatory exposure
- Data volume
- Nature of processing
- Number and type of Data Principals affected
- Security implications
- Operational impact
- Dependency on third parties
- Effort required to remediate
-
Assign Ownership
Every material gap should have a responsible owner. Depending on the finding, ownership may sit with privacy, legal, security, IT, HR, procurement, product, operations, or another business function.
-
Define Remediation and Timeline
Document what needs to change, who will make the change, what resources are required, and what evidence will demonstrate closure.
A remediation action should be specific enough that someone can actually execute it.
What Should a DPDP Gap Assessment Report Include?
A DPDP gap assessment report should convert assessment findings into an evidence-backed management document. It should clearly show the applicable requirement, current state, evidence reviewed, identified gap, priority, accountable owner, recommended remediation, timeline, and criteria for closure.
A practical report should contain:
-
Executive Summary
Highlight the most significant findings, major risk areas, and overall remediation priorities.
-
Assessment Scope
Document the business units, processing activities, systems, vendors, and requirements covered.
-
Assessment Methodology
Explain how requirements were mapped, evidence was reviewed, and findings were evaluated.
-
Applicable Requirements
Identify the relevant DPDP Act and Rules provisions considered during the assessment.
-
Current-State Findings
Explain what the organisation currently does.
-
Evidence Reviewed
Record the documents, records, systems, interviews, configurations, or other evidence considered.
-
Gap Register
Document each identified gap and its associated requirement.
-
Risk/Priority Rating
Indicate which gaps require immediate, near-term, or longer-term attention.
-
Ownership Matrix
Assign accountable teams or individuals.
-
Remediation Recommendations
Explain what should change and how.
-
Remediation Timeline
Establish target dates and dependencies.
-
Closure Criteria
Define what evidence will demonstrate that a gap has actually been addressed.
-
DPDP Compliance Roadmap
Translate individual findings into a coordinated programme of work.
The report should be usable by both privacy professionals and business leaders. A board or executive should be able to understand the exposure and priorities, while the implementation team should know exactly what needs to happen next.
Conclusion
A strong DPDP gap assessment is a diagnostic exercise, not a paperwork exercise. It should trace the organisation's privacy architecture from data collection and mapping through consent, rights, retention, security, processors, incidents, governance, and applicable regulatory obligations.
The real test is straightforward: Can the organisation demonstrate that its privacy controls exist, operate as intended, and are supported by evidence?
If the answer is unclear, that uncertainty belongs in the assessment.
Key Takeaways
- A DPDP gap assessment helps find where an organisation’s privacy practices do not meet DPDP requirements.
- It checks data, consent, user rights, security, retention, vendors, breaches, and governance.
- The assessment should review real evidence, not just policies and documents.
- Each gap should be identified, evaluated, and prioritised based on its risk and impact.
- Every important gap should have an owner and a clear action plan.
- The final report should show what is working, what is missing, and what needs to be fixed.
- A good assessment checks whether privacy controls actually work in practice.
- The goal is to turn identified gaps into a clear DPDP compliance roadmap.
Related Blog






