DPDP gap analysis: sample report + what to expect
A complete walkthrough of what a rigorous gap analysis delivers — so you can tell a thorough assessment from a checkbox exercise before you sign a contract.
You've decided you need a DPDP gap analysis. You've spoken to two or three vendors. Each one has sent you a proposal that looks roughly similar on paper. How do you know which one will actually deliver a useful output — and what should that output contain?
This post walks through the anatomy of a thorough DPDP gap analysis report. You'll see sample findings across four control domains, understand what a risk heatmap communicates, and learn how a well-structured remediation roadmap differs from a list of generic recommendations. By the end, you'll be able to evaluate any proposal or sample report against a concrete benchmark.
If you're still deciding whether to hire a consultant at all, see our post on how to choose a DPDP compliance consultant. Once you've run your assessment, you'll likely need to review your vendor DPA templates as a next step.
Section 1: Executive Summary
The executive summary is written for the CEO and board, not for the compliance team. It should fit on one page and answer four questions without jargon:
- Overall readiness score — a single number on a defined scale (e.g., 47/100)
- Top three risks — the findings that create the greatest legal exposure
- Estimated cost to remediate — a ballpark figure so leadership can budget
- Recommended timeline — when the organisation could reasonably reach a defensible compliance posture
A red flag: if the executive summary references findings by control number without explaining what they mean in plain language, the report was written for the consultant's benefit, not yours.
Section 2: Control-by-Control Findings
The DPDP Act and Rules 2025 map onto eight control domains. A thorough report assesses each domain separately. Here are sample findings across four of them.
Domain 1: Consent Management
| Control | Finding | Severity |
|---|---|---|
| Consent notice format | Website consent notice combines marketing consent with terms acceptance in a single checkbox. DPDP Rules require separate, purpose-specific consent. All marketing consent collected to date is legally invalid. | HIGH |
| Consent withdrawal mechanism | No withdrawal mechanism exists on the web portal. Users cannot withdraw consent without emailing support, which is non-compliant with Rule 3(4). | HIGH |
| Record of consent | Consent timestamps are logged in the CRM but not linked to the specific notice version presented. Cannot prove which notice version a user saw. | MEDIUM |
Domain 2: Data Principal Rights
| Control | Finding | Severity |
|---|---|---|
| Right to access | No self-service access mechanism. Users must email grievance@company.com but SLA is not defined and no tracking system exists. Target: 48-hour response. Current: no SLA. | HIGH |
| Right to correction | Self-service profile editing available for basic fields. No process for correcting data held in analytics systems or third-party integrations. | MEDIUM |
| Right to erasure | No erasure workflow. Deletion requests are handled ad hoc by the engineering team. No evidence of deletion from backup systems. | HIGH |
Domain 3: Data Processor Agreements
This is the domain most organisations fail silently. The finding structure here looks different because the assessment involves reviewing actual contracts:
| Processor | DPA Status | Gap | Severity |
|---|---|---|---|
| Cloud hosting provider | Standard online DPA accepted | No audit rights clause. No data deletion SLA on contract termination. | MEDIUM |
| Marketing automation platform | No DPA in place | Processes 80,000+ email addresses with no contractual obligation on the processor. Critical gap. | HIGH |
| HR payroll software | MSA signed 2022 | MSA predates DPDP Rules. No data processing schedule, no breach notification timeline, sub-processor list not disclosed. | HIGH |
For a deeper look at what a compliant DPA must contain, see our post on vendor DPA templates for India.
Domain 4: Security Controls
| Control | Finding | Severity |
|---|---|---|
| Encryption at rest | Production database encrypted. Development database is not — contains real customer data copied for testing. | HIGH |
| Access control review | 12 former employees still have active database credentials. Last access review was 18 months ago. | HIGH |
| Breach detection | No automated anomaly detection. Breach detection relies on manual monitoring. Average detection time unknown. | MEDIUM |
Section 3: Risk Severity Heatmap
A heatmap plots every finding on two axes: likelihood of regulator scrutiny and potential penalty impact. This is not decorative — it tells you where to spend remediation budget first.
A well-constructed heatmap will show, for example, that "no DPA with marketing automation platform" sits in the top-right quadrant (high likelihood, high impact) because it involves large volumes of personal data and is easy for a regulator to identify through a data principal complaint. Meanwhile, "development database not encrypted" may sit high on impact but lower on likelihood because it requires a breach to surface.
The heatmap directly informs which items belong in Sprint 1 of your remediation roadmap versus Sprint 3.
Section 4: Prioritised Remediation Roadmap
The remediation roadmap is where most generic reports fail. A checklist of actions ("implement consent withdrawal mechanism, execute DPAs with all processors") is not a roadmap. A real roadmap assigns:
- Owner — which function (legal, engineering, HR, finance) is accountable
- Effort estimate — person-days or story points, not vague "medium effort"
- Dependencies — which items must be completed before others can begin
- Target date — mapped to a realistic sprint or milestone
- Validation criteria — how you'll know the item is actually done
A 45-day sprint structure typically covers HIGH severity items. MEDIUM items follow in a 90-day window. LOW items can be addressed as part of normal business processes over 6 months.
Section 5: Accountability Matrix
The final section maps every control domain to a named internal owner, an external advisor contact, and a board-level sponsor. This is the document your legal team will reference during any regulatory inquiry. It also clarifies who is responsible for maintaining compliance after the initial remediation sprint — which is where many organisations fall apart.
Once your gap analysis is complete, use the DPDP readiness scoring methodology to understand how your starting score was calculated and what your post-remediation target should be. See also our case study of a SaaS vendor that passed a client DPDP review for a real-world sequence of events.
What separates thorough from checkbox
A checkbox gap analysis delivers a list of controls mapped to "compliant / non-compliant" without evidence, without severity context, and without a workable remediation plan. It typically takes 2–3 days and produces a 10-page PDF that looks impressive but gives you no actionable next step.
A thorough gap analysis involves document review (privacy notices, existing DPAs, consent flows, data inventory), technical checks (database access logs, encryption configuration), and stakeholder interviews across legal, engineering, HR, and marketing. It takes 2–3 weeks and produces a 30–50 page report with an accompanying remediation tracker in a shareable format.
The difference in price is typically ₹50K–₹1.5L. The difference in outcome is whether you actually reach compliance — or just have a document that says you tried.
Get a rigorous DPDP Rules Gap Analysis
Our Rules Gap Analysis covers all 8 control domains with severity-rated findings, a risk heatmap, and a 45-day remediation roadmap — delivered in 14 business days.
Start Rules Gap Analysis — ₹2,999 →Frequently Asked Questions
How long does a DPDP gap analysis take?
A thorough gap analysis takes 2–3 weeks. The first week covers document review and data inventory. The second week involves stakeholder interviews and technical checks. The third week is report drafting and review. Compressed timelines (7–10 days) are possible for smaller organisations with fewer systems and a dedicated internal point of contact.
What inputs do I need to provide for the assessment?
You'll need to share your current privacy notice, a list of all data processors and their contracts, your consent collection flows (screenshots or recordings are fine), your data retention policy (even if informal), and access to your Grievance Officer process documentation. If you have an existing data inventory or ROPA, share that too — it significantly reduces assessment time.
Can we use the gap analysis report with enterprise clients as compliance evidence?
Yes, and this is one of the most common use cases. An independently-conducted gap analysis with a signed cover letter from the assessor is accepted as compliance evidence by most enterprise procurement teams. It demonstrates that you have identified your gaps and have a remediation plan in place — which is the standard most enterprise clients apply at the shortlisting stage.