Applicability Profiling
Establish which DPDP obligations apply to the organization based on its actual processing, role and data subjects, and record the reasoning so the position is defensible.
Obligation Mapping
Map applicable obligations to the internal processes, systems and owners expected to satisfy them, exposing obligations with no owner at all.
Phased-Commencement Readiness
Assess readiness against applicable notified commencement timelines so remediation is sequenced to when obligations actually take effect.
Notice Sample Testing
Review notices as they are actually presented at collection points - in product, on web forms, in onboarding flows - for content, timing, clarity and consistency with real processing.
Consent Process Review
Test how consent is captured, stored, evidenced, withdrawn and propagated, including whether withdrawal reaches downstream systems and third parties.
Rights Workflow Walkthrough
Walk actual rights requests through the organization end to end and measure whether they were verified, fulfilled within timeline and recorded.
Grievance Readiness
Assess whether the grievance channel is published, reachable, staffed, triaged and resolved within expected timelines, and whether outcomes are recorded.
Security Safeguard Review
Review the safeguards protecting personal data for adequacy relative to the sensitivity and volume processed, and for evidence that they operate.
Processor Dependency Review
Identify third parties processing personal data, assess contractual coverage and sub-processor visibility, and flag dependencies with no oversight.
Breach Preparedness
Test the organization’s ability to detect, assess, decide on notification and record a personal data breach, including whether roles and timelines are understood.
Risk-Ranked Remediation Programme
Rank every gap by regulatory exposure, individual impact and commencement timing, and sequence remediation into a programme the business can actually resource.