Start here

Privacy Gap Assessment — Know Exactly Where You Stand

Before you spend a rupee on tools or policies, find out exactly where you stand. A structured gap assessment scores your current posture against the laws that apply to you — and hands you a prioritised roadmap instead of a vague to-do list.

DPDPA 2023GDPR / UK GDPRBoard-accountableVetted expert network
Start here

What is a privacy gap assessment?

A privacy gap assessment is a structured review that measures your current data-protection posture against the specific laws that apply to you — the DPDP Act, GDPR, PDPA or all three — and shows precisely where the gaps are. You come away with a clear picture of what you already do well, what’s missing, and which gaps carry the most legal and commercial risk.

The point isn’t a 200-page audit nobody reads. It’s a decision tool: a scored baseline and a prioritised, effort-ranked roadmap so your next few months of privacy work are spent on the things that actually move risk and unblock deals.

What’s included

What the assessment delivers

A tight, decision-ready output — not a document dump.

Scope

Applicability check

Which laws apply to you and at what tier — ordinary fiduciary vs SDF, GDPR reach, PDPA — so you’re measured against the right bar.

Baseline

Current-state score

A structured score across notice, consent, records, rights, security, transfers, vendors and breach readiness.

Gaps

Prioritised gap list

Each gap rated by risk and effort, so it’s obvious what to fix first and what can wait.

Roadmap

Costed remediation plan

A sequenced roadmap with owners and rough effort — the plan you execute or hand to us to run.

Evidence

Interview & artefact review

Findings grounded in short stakeholder interviews and a review of what you already have, not assumptions.

Readout

Board-ready summary

A one-page executive read of where you stand and what closing the gaps takes.

Do you need this?

When it’s required — and when it’s just smart

A quick way to place yourself, then confirm it with a readiness assessment.

Best first step

Anyone unsure where they stand

If you can’t confidently answer ‘are we DPDP-ready?’, the assessment turns that uncertainty into a scored baseline and a plan.

Before you buy

Teams about to spend on tools

A gap assessment stops you buying a consent tool or DPIA platform you don’t need yet — and points spend where it counts.

Deal-driven

Companies facing due diligence

When a customer or investor sends a security questionnaire, a recent gap assessment and roadmap is the fastest way to answer credibly.

How we deliver it

From unknown to a costed plan in weeks

Light on your team’s time, heavy on clarity.

Structured, not vibes

We assess against a defined control set mapped to DPDPA, GDPR and PDPA — so the score means something.

Risk- and effort-ranked

Every gap is rated both ways, so the roadmap sequences quick wins and big rocks sensibly.

Execution-ready

The output plugs straight into a retainer if you want us to close the gaps, or into your own backlog if you don’t.

The law behind it

Measured against DPDPA, GDPR and PDPA

The assessment maps your posture to the obligations that actually apply — Data Fiduciary duties and SDF triggers under the DPDP Act 2023, the GDPR’s records, DPIA, rights and transfer requirements, and Singapore’s PDPA where relevant. Because it’s scoped to your real footprint, you’re never held to obligations that don’t apply to you. This is decision-support, not legal advice.

Pricing

Transparent retainers, from ₹80,000 per quarter

Most engagements fold into a single accountable retainer — usually 40–60% below the cost of a full-time hire. See how the tiers map to your scope.

Answers

Questions, answered straight

How long does a gap assessment take?

For most SMEs, a first assessment runs a couple of weeks end to end — a few short interviews, a review of your existing artefacts, then the scored report and roadmap. Larger or multi-jurisdiction scopes take a little longer.

What do we get at the end?

A scored current-state baseline, a prioritised list of gaps rated by risk and effort, a sequenced remediation roadmap with rough costs and owners, and a one-page Board-ready summary.

Is this the same as an audit?

No. An audit tests compliance against a standard, often for certification. A gap assessment is a decision tool — it tells you where you stand and what to do next, and it’s the sensible step before any formal audit.

Which laws do you assess against?

Whichever apply to you — most commonly India’s DPDP Act 2023, the EU/UK GDPR, and Singapore’s PDPA. We confirm applicability first so you’re measured against the right requirements.

What happens after the assessment?

You can execute the roadmap yourself, or fold it into a DPO retainer where we close the gaps and run the programme. The assessment is built to hand off cleanly either way.

Talk it through

Twenty minutes on your situation, your options, and realistic costs

No pitch, no obligation — just a clear read on where you stand and what an engagement would cover.

Follow DPOIndia in Google SearchAdd as a preferred source on Google