Before you spend a rupee on tools or policies, find out exactly where you stand. A structured gap assessment scores your current posture against the laws that apply to you — and hands you a prioritised roadmap instead of a vague to-do list.
A privacy gap assessment is a structured review that measures your current data-protection posture against the specific laws that apply to you — the DPDP Act, GDPR, PDPA or all three — and shows precisely where the gaps are. You come away with a clear picture of what you already do well, what’s missing, and which gaps carry the most legal and commercial risk.
The point isn’t a 200-page audit nobody reads. It’s a decision tool: a scored baseline and a prioritised, effort-ranked roadmap so your next few months of privacy work are spent on the things that actually move risk and unblock deals.
A tight, decision-ready output — not a document dump.
Which laws apply to you and at what tier — ordinary fiduciary vs SDF, GDPR reach, PDPA — so you’re measured against the right bar.
A structured score across notice, consent, records, rights, security, transfers, vendors and breach readiness.
Each gap rated by risk and effort, so it’s obvious what to fix first and what can wait.
A sequenced roadmap with owners and rough effort — the plan you execute or hand to us to run.
Findings grounded in short stakeholder interviews and a review of what you already have, not assumptions.
A one-page executive read of where you stand and what closing the gaps takes.
A quick way to place yourself, then confirm it with a readiness assessment.
If you can’t confidently answer ‘are we DPDP-ready?’, the assessment turns that uncertainty into a scored baseline and a plan.
A gap assessment stops you buying a consent tool or DPIA platform you don’t need yet — and points spend where it counts.
When a customer or investor sends a security questionnaire, a recent gap assessment and roadmap is the fastest way to answer credibly.
Light on your team’s time, heavy on clarity.
We assess against a defined control set mapped to DPDPA, GDPR and PDPA — so the score means something.
Every gap is rated both ways, so the roadmap sequences quick wins and big rocks sensibly.
The output plugs straight into a retainer if you want us to close the gaps, or into your own backlog if you don’t.
The assessment maps your posture to the obligations that actually apply — Data Fiduciary duties and SDF triggers under the DPDP Act 2023, the GDPR’s records, DPIA, rights and transfer requirements, and Singapore’s PDPA where relevant. Because it’s scoped to your real footprint, you’re never held to obligations that don’t apply to you. This is decision-support, not legal advice.
Most engagements fold into a single accountable retainer — usually 40–60% below the cost of a full-time hire. See how the tiers map to your scope.
For most SMEs, a first assessment runs a couple of weeks end to end — a few short interviews, a review of your existing artefacts, then the scored report and roadmap. Larger or multi-jurisdiction scopes take a little longer.
A scored current-state baseline, a prioritised list of gaps rated by risk and effort, a sequenced remediation roadmap with rough costs and owners, and a one-page Board-ready summary.
No. An audit tests compliance against a standard, often for certification. A gap assessment is a decision tool — it tells you where you stand and what to do next, and it’s the sensible step before any formal audit.
Whichever apply to you — most commonly India’s DPDP Act 2023, the EU/UK GDPR, and Singapore’s PDPA. We confirm applicability first so you’re measured against the right requirements.
You can execute the roadmap yourself, or fold it into a DPO retainer where we close the gaps and run the programme. The assessment is built to hand off cleanly either way.
No pitch, no obligation — just a clear read on where you stand and what an engagement would cover.