Applicability & Gap Assessment
Every DPDP program that succeeds begins with an unglamorous inventory: what personal data the organisation actually holds, where it flows, why each processing activity happens, and which of the Act's obligations attach to each. Companies that skip this step build compliance on assumption — policies covering data they do not have, gaps around data they forgot they collected, and a consent architecture designed for the business they imagine rather than the one they run. The Act's penalties are calculated per breach category; assumptions are how categories multiply.
Our assessment produces the map the program needs. Data inventories are built through structured discovery across products, HR systems, marketing stacks, and vendor flows — including the shadow processing that formal documentation never captures; applicability is analysed against the Act's territorial and material scope, honestly, including for foreign entities with no Indian presence but Indian users; and each processing activity is scored against the Act's requirements, producing a gap register ranked by risk. The output is a costed, sequenced roadmap — what must change, in what order, at what effort — that converts an unfamiliar statute into an approvable program.
What this covers
- Data inventory across products, HR, marketing, and vendor flows — including undocumented processing.
- Applicability analysis against territorial and material scope, including extraterritorial reach.
- Control-by-control gap assessment scored by risk and effort.
- Children's-data and sensitive-context review, where the Act's strictest rules live.
- Costed remediation roadmap sequenced for leadership approval.
Who needs this
Companies at the start of their DPDP journey; foreign entities uncertain whether the Act reaches them; and privacy teams that need Indian obligations translated into a program their board can fund.
How we deliver
- Structured discovery across products, HR, marketing, and vendor flows.
- Gap register scored by risk against the Act and its rules.
- Costed, sequenced roadmap delivered for leadership approval.
Why A2 Consultants
Our assessments convert an unfamiliar statute into an approvable program — two to four weeks of disciplined discovery, priced remediation, and a sequence your board can fund with confidence.
Engagement & what to expect
Assessments run two to four weeks for focused scopes and six to eight for complex, multi-product organisations: discovery interviews and system reviews first, data inventory and applicability analysis through the middle, and the scored gap register with costed roadmap concluding the exercise. Leadership receives a presentation-grade summary; implementation teams receive the working register. Most clients proceed directly into remediation with the roadmap as the program plan — and the assessment refreshes annually or on major product change, because data estates drift faster than policies admit.
You cannot protect data you have not mapped or comply with obligations you have not scoped — the assessment is where honest programs begin.