Personal-data inventory is fragmented
Business, HR, marketing, product, support, analytics and cloud teams hold different views of what personal data exists and where it moves.
Understand how your current personal-data practices, controls, technology and evidence align with India’s Digital Personal Data Protection Act, 2023 and the notified DPDP Rules, 2025. DataConsultant converts the review into a defensible gap register and prioritised remediation roadmap—without presenting readiness as legal advice, certification or a statutory audit opinion.
Regulatory applicability, commencement status and legal interpretations should be validated with qualified counsel. Assessment scope, evidence depth, timeline and commercial terms are confirmed before mobilisation.
Separate documented controls from assumptions, missing artefacts and untested practices.
Connect relevant requirements with current processes, technology, owners and evidence.
Focus leadership attention on material gaps, dependencies and time-sensitive decisions.
Convert findings into owned actions, sequencing, evidence requirements and decision gates.
The assessment establishes an agreed DPDP control perimeter, identifies the evidence that should demonstrate current practice, reviews how personal data moves through priority business processes and systems, and records gaps that need remediation. The work is designed to give executives, privacy leaders, security teams, technology owners, risk functions and business stakeholders a shared view of what is known, what is missing and what should happen next.
Readiness is not the same as a legal opinion, certification or statutory assurance.
The assessment records which requirements are already in force, future-dated, dependent on designation or notification, or require legal interpretation. That keeps the roadmap anchored to the actual regulatory status rather than a generic checklist.
The final Rules notification was published on 13 November 2025 with different commencement dates for different rules.
The final Rules notification states these rules commenced on publication. Relevant organisational assumptions and governance dependencies should therefore be identified now.
The notification gives Rule 4 a one-year commencement period. Readiness planning should treat that date separately from the broader eighteen-month group.
These rules have a longer commencement period. The assessment can identify lead-time work without incorrectly stating that every future requirement is already in force.
The most useful trigger is not “we need a policy”. It is a gap between what the organisation believes it does and what it can evidence across real systems, journeys, contracts and operations.
Business, HR, marketing, product, support, analytics and cloud teams hold different views of what personal data exists and where it moves.
Published notices may not map cleanly to actual collection points, downstream uses, retention, sharing or user journeys.
Consent capture, withdrawal, correction, erasure, grievance and identity-verification processes may vary across channels and systems.
IAM, encryption, backups, logging, monitoring and incident practices may exist without an integrated personal-data control view.
Third-party inventories, contracts, access routes, sub-processors, retention obligations and incident responsibilities may not be centrally visible.
Retention statements may not be translated into operational triggers, deletion workflows, backup handling and accountable exceptions.
Start with a scoped baseline across the personal-data processes, systems, stakeholders and control domains that matter most.
The final scope is tailored to the organisation, processing activities and verified applicability. These domains provide a practical assessment perimeter rather than a universal pass/fail checklist.
Personal-data categories, processing purposes, business journeys, systems, data flows, parties, roles and applicability assumptions.
Collection-point notices, purpose clarity, user-facing language, contact information, channel consistency and evidence of notice delivery.
Consent journeys, withdrawal paths, consent records, processing changes and documented treatment of relevant legitimate-use scenarios.
Access-related information, correction, erasure, nomination, grievance, identity verification, routing, ownership and response evidence.
Relevant collection journeys, age or guardian considerations, verifiable consent readiness and exceptions only where legally applicable.
Access, authentication, encryption, backups, monitoring, logs, detection, containment, evidence preservation and notification workflow readiness.
Processor inventory, contractual controls, approved access, sub-processing, due diligence, retention, return/deletion and incident dependencies.
Retention logic, deletion triggers, purpose completion, account lifecycle, exception handling, backup implications and data minimisation.
Named owners, policies, control monitoring, escalation, contact roles and additional Significant Data Fiduciary readiness where applicable.
Verified cross-border, localisation, contractual or sector requirements where applicable—without assuming restrictions that have not been notified.
Evidence requests are proportionate to the agreed scope. DataConsultant records what was reviewed, what could not be obtained and where conclusions rely on interview confirmation rather than documentary or technical evidence.
A structured sequence keeps regulatory interpretation, operational evidence, technical review and remediation planning connected without turning the engagement into an open-ended compliance programme.
Define entities, processes, systems, stakeholders, jurisdictions, evidence and decisions.
Map verified DPDP requirements and applicability assumptions to control domains.
Request documents, records, configurations, samples and accountable interviews.
Review control design, evidence quality, operating practice and material gaps.
Agree severity logic, dependencies, owners, legal questions and remediation sequence.
Validate findings, deliver the roadmap and align leadership on mobilisation actions.
Use the scoping discussion to define a proportionate evidence request instead of collecting every privacy and security artefact in the organisation.
The assessment does not need an invented 0–100 score to be decision-ready. Findings can be prioritised using agreed, transparent criteria tied to evidence and business context.
Actual severity criteria are agreed during scoping and documented in the assessment method.
Deliverables are designed to support remediation ownership and executive decisions, not merely to document that an assessment occurred.
Assessment perimeter, assumptions, exclusions, entities, processing areas and legal questions requiring confirmation.
Traceability between verified requirements, control objectives, processes, systems, owners and evidence.
Reviewed artefacts, samples, interview confirmations, missing evidence and validation limitations.
Evidence-backed observations across personal-data processing, privacy, security, vendors, lifecycle and governance.
Prioritised gaps with rationale, affected scope, dependencies, ownership and required validation.
Actionable tasks with intended outcome, accountable owner, evidence of closure and sequencing considerations.
Logical workstreams, dependencies, decision gates and mobilisation priorities aligned to commencement timing.
Leadership-level summary of exposure themes, unresolved decisions, priorities, ownership and next-step options.
Define owners, dependencies, evidence of closure and sequencing so findings can move into implementation rather than remain in a report.
A readiness assessment is most useful when leadership needs an independent baseline and practical action plan before committing to a broader privacy programme, technology implementation or formal assurance activity.
The assessment remains vendor-neutral. Tools are reviewed only where they form part of the actual personal-data processing, control evidence or remediation decision.
Websites, apps, CRM, marketing automation, forms, support platforms and preference experiences.
Warehouses, lakehouses, databases, ETL/ELT, analytics, BI, metadata, lineage and data-quality environments.
IAM, MFA, privileged access, encryption, key management, SIEM, monitoring, backup and incident systems.
Consent, rights workflows, processing inventories, GRC, privacy management, records and policy management.
Cloud providers, SaaS platforms, processors, sub-processors, managed services and cross-system data-sharing dependencies.
DataConsultant does not publish an approved fixed fee for this service. Public pricing can help buyers frame a budget, but it must not be presented as DataConsultant’s own commercial offer.
Current Indian public offers reviewed on 8 September 2026 include a DPDP readiness assessment starting at ₹45,000 and another at ₹1,49,999 + GST. Their scope, client size, evidence depth and delivery model are not identical, so this range is useful only for early budgeting. Regulated, multi-entity or enterprise assessments can require materially broader scope.
DataConsultant pricing is based on the evidence and decisions required—not a competitor package copied into a proposal.
The value of the engagement comes from connecting privacy requirements with the way data, systems, controls and ownership actually work across the enterprise.
Start with evidence, limitations and decisions rather than assuming the current policy set is complete.
Connect personal-data flows, architecture, ownership and lifecycle practices to privacy and security controls.
Produce traceable findings, evidence registers, owners and remediation actions that teams can implement.
Carry context into governance, privacy, security, data and implementation work when follow-on support is required.
Share your entities, major processing areas, current privacy programme, systems, vendor landscape and the decisions leadership needs from the assessment.
Answers to common buyer questions about assessment boundaries, evidence, phased commencement, scope, deliverables, pricing and remediation.
Share your contact details and requirement. DataConsultant can review likely scope, evidence needs, stakeholder involvement and the appropriate next step.