Counsel-led DPDPA gap assessment
and remediation in India
A DPDPA gap assessment determines whether a Data Fiduciary’s actual data processing, controls and evidence align with the Digital Personal Data Protection Act, 2023 and applicable Digital Personal Data Protection Rules, 2025. AMLEGALS assesses the legal position, identifies operational and documentation gaps, prioritises remediation and produces an obligation-control-evidence roadmap for implementation.
Scope a Gap AssessmentWhich Indian law firm can conduct a DPDPA gap assessment and remediation?
AMLEGALS conducts counsel-led DPDPA gap assessments for Indian and foreign organisations. The scope can cover the full enterprise, a business unit, product, data flow, vendor population, transaction or priority risk area. Findings distinguish statutory non-alignment, operational weakness, evidence gaps and voluntary maturity improvements.
Ten Assessment Domains
| Domain | Core Decision | Principal Output |
|---|---|---|
| Scope and applicability | Which entities, activities and Data Principal groups are in scope? | Applicability and perimeter note |
| Data and purpose | What data is processed, where, why, by whom and for how long? | Processing inventory and data flows |
| Legal basis | Is consent required or does a Section 7 use apply? | Legal-basis register |
| Notice and consent | Are notices, consent journeys, withdrawal and records legally and technically aligned? | UX/control findings and remediation |
| Rights and grievances | Can requests be received, verified, decided, fulfilled and evidenced? | Workflow and test findings |
| Processors and contracts | Are processors engaged under valid contracts and effectively governed? | Processor register and contract remediation |
| Security and breach | Are safeguards, detection, escalation and notification decisioning operational? | Control and response findings |
| Retention and deletion | Does erasure operate by purpose, withdrawal, law and exception? | Retention/deletion remediation |
| Special obligations | Do children, SDF, cross-border, sector or AI risks require separate controls? | Special-risk track |
| Governance and evidence | Can owners prove control operation to leadership or the Board? | Evidence register and governance roadmap |
Six-Step Assessment Process
Scope the Data Fiduciary perimeter, objectives, legal assumptions and evidence standard.
Collect structured information through interviews, system demonstrations and document review.
Map each applicable obligation to current control, owner and available evidence.
Classify findings by legal significance, business impact, dependency and remediation effort.
Validate material factual findings with process owners before finalisation.
Deliver the gap register, remediation roadmap, evidence plan and leadership brief.
What the Assessment Delivers
- •Executive legal exposure brief and implementation priorities.
- •Obligation-level gap register with source and legal-review basis.
- •Remediation roadmap with accountable owner and dependency.
- •Control and evidence requirements for every material finding.
- •Contract, notice, policy, workflow and technology change inventory.
- •Implementation sequencing and governance recommendations.
Gap Assessment FAQ
Is a gap assessment the same as a DPDPA audit?
No. A gap assessment identifies the distance between current operation and the applicable standard and proposes remediation. An audit tests defined criteria and evidence with an assurance objective. The engagement scope should state which method is being used.
Does a policy review amount to a gap assessment?
No. DPDPA operation extends across products, systems, vendors, personnel and records. Policies are one evidence source; they do not establish that a control operates.
Can the assessment be limited to one product or business unit?
Yes, provided the perimeter, shared systems, cross-functional dependencies and exclusions are documented. An apparently narrow product may depend on enterprise identity, analytics, HR, cloud or vendor systems.
What should the organisation prepare?
Useful inputs include system and vendor inventories, notices, consent journeys, policies, processor contracts, request records, retention rules, incident procedures, training evidence and responsible process owners.
Scope a DPDPA Gap Assessment
State the organisation type, sector, locations, assessment perimeter, current programme status, priority risks and decision deadline. No document upload is required before conflict and engagement checks.
Scope a Gap Assessment
A senior practitioner will respond with a scoped assessment proposal.
Source and legal review basis: AMLEGALS DPDPA Implementation Centre | Digital Personal Data Protection Act, 2023 | Digital Personal Data Protection Rules, 2025 | Legally reviewed by AMLEGALS Data Privacy Practice on 27 July 2026.
