Home / Tools / Gap Analyser
Free tool · Runs in your browser

DPDP Gap Analyser

A short honest self-assessment across the DPDP obligations you'll actually be judged on: consent, security, breach response, retention, rights handling. Twelve questions total. The output is a readiness grade and a short list of what to fix first, each item pointing at the underlying section or rule so you're not taking our word for it. Runs in your browser. Nothing is sent anywhere.

Client-side compute Section-cited recommendations 3 min to complete Not legal advice
Question 01 · Consent

Consent notice (Rule 3)

Do you present a Rule 3 compliant consent notice before collecting personal data — standalone, plain-language, itemised data categories, specific withdrawal link? (Rule 3)

Yes, fully
Partial
No / do not know
Question 02 · Consent

Consent granularity

Do you obtain separate consent per processing purpose, rather than one bundled consent for all purposes? (Sec. 6(1))

Yes, fully
Partial
No / do not know
Question 03 · Consent

Withdrawal parity

Is withdrawing consent as easy as giving consent (same clicks, same visibility)? (Sec. 6(4))

Yes, fully
Partial
No / do not know
Question 04 · Data Principal rights

DSR handler

Do you have a documented process to receive, acknowledge (within 7 days) and complete Data Principal requests for access, correction and erasure (within 90 days for erasure)? (Rule 14, Sec. 11-12)

Yes, fully
Partial
No / do not know
Question 05 · Data Principal rights

Grievance mechanism

Do you publish a grievance officer or authorised person, with contact details on your website? (Sec. 8(9), Sec. 13)

Yes, fully
Partial
No / do not know
Question 06 · Data Principal rights

Nomination handling

Can your records accept and honour a nomination under Section 14? (Sec. 14)

Yes, fully
Partial
No / do not know
Question 07 · Breach and security

Security safeguards

Do you encrypt personal data at rest and in transit, run role-based access controls, and retain access logs for at least one year? (Sec. 8(5), Rule 6)

Yes, fully
Partial
No / do not know
Question 08 · Breach and security

Breach playbook

Do you have a documented breach response playbook that notifies the Data Protection Board and affected Data Principals without delay, with a comprehensive report in 72 hours? (Sec. 8(6), Rule 7)

Yes, fully
Partial
No / do not know
Question 09 · Breach and security

Processor contracts

Do all your Data Processors have a Section 8(4) valid contract that binds them to your security safeguards? (Sec. 8(4))

Yes, fully
Partial
No / do not know
Question 10 · Retention and cross-border

Retention schedule

Do you have a published retention schedule that names each personal data category, its purpose, and its erasure trigger? (Sec. 8(7), Rule 8)

Yes, fully
Partial
No / do not know
Question 11 · Retention and cross-border

Cross-border mapping

Have you mapped which personal data categories flow to which countries via which processor, and can you switch a category out of a country within 30 days? (Sec. 16)

Yes, fully
Partial
No / do not know
Question 12 · Governance

DPO or contact

Have you appointed a DPO (if SDF) or an authorised Section 8(9) contact person for grievance handling, and published their contact information? (Sec. 8(9), Rule 12)

Yes, fully
Partial
No / do not know
0
/ 100

Per-category

Top recommendations

Verified against DPDP Act 2023 and DPDP Rules 2025 (G.S.R. 846(E), 13 November 2025). Not legal advice. Use to prioritise remediation, then confirm with your DPO or counsel.

Ready to close the gaps? dcomply's Gap Assessment module runs the same 12 questions and 45 more across every obligation, and generates a Gantt-planned remediation roadmap.