CapabilitiesDPDP Readiness Capability Areas
Capabilities are grouped around how personal data is governed, used, protected and evidenced across the organisation.
Processing inventory and obligation mapping
Covers business purposes, data categories, data principals, systems, locations, disclosures, processors, retention and organisational roles. Inputs include product documentation, process maps, architecture, contracts and interviews. Outputs can include a processing inventory, data-flow map, applicability assumptions and obligation matrix. The work may use catalogues, spreadsheets or privacy platforms; legal interpretations require authorised review.
Notice, consent and data-principal rights
Reviews notice content and placement, consent capture and withdrawal, preference records, request intake, identity verification, correction, erasure, grievance handling and nomination. Deliverables may include control requirements, workflow design, roles, records and technology specifications. Dependencies include channel coverage, system capability and confirmed legal positions.
Security safeguards, incidents and third parties
Assesses access governance, authentication, encryption, logging, vulnerability management interfaces, breach escalation, processor instructions, vendor evidence, deletion and exit controls. The engagement can align with security and privacy frameworks, but it is not a penetration test, certification audit or legal contract opinion unless separately commissioned.
Governance, remediation and operational transition
Defines accountability, committees, decision rights, policy hierarchy, issue management, metrics, reporting, training and assurance checkpoints. Outputs can include an operating model, RACI, roadmap, implementation backlog, acceptance criteria and transition plan. Success depends on management ownership, funding and integration with normal product and operational processes.