How DPDP readiness scoring works

DPDP compliance
How DPDP readiness scoring works
Shortlist Stage · Assessment Methodology

How DPDP readiness scoring works

The methodology behind DPDP readiness scores — 8 control domains, weighting rationale, how each domain is assessed, and what your score means for enterprise client scrutiny and regulatory risk.

Quick Answer: DPDP readiness scoring assesses 8 control domains using document review, stakeholder interviews, and technical checks. The domains are weighted by regulatory exposure and enforcement likelihood. A score of 60 means you can pass basic vendor screening. A score of 80 means you can pass enterprise due diligence. A score of 95 means you are defensible against a Data Protection Board inquiry.

When a compliance firm tells you that your DPDP readiness score is 67, what does that number actually mean? If you've received a score — or are considering commissioning an assessment — you should be able to answer three questions: what went into the score, how each domain was assessed, and what the score implies for your actual risk exposure.

Scepticism about scores is healthy. A score produced by a tool that only reads your privacy policy URL is very different from a score produced by a 3-week assessment involving document review, interviews, and technical checks. This post explains what a rigorous methodology looks like and what each score band implies operationally.

If you're deciding between running an assessment in-house versus engaging a consultant, see our post on in-house versus consultant for DPDP compliance. To understand the full output of an assessment engagement, see our post on what a DPDP gap analysis report looks like.

The 8 control domains

DPDP readiness is assessed across eight domains, each mapped to specific provisions of the DPDP Act 2023 and DPDP Rules 2025. The domains and their weightings reflect the relative penalty exposure and enforcement likelihood associated with each area.

20%

1. Consent Management

How consent is obtained, recorded, and withdrawn. Includes consent notice format, purpose specificity, withdrawal mechanism, and consent record-keeping. High weight because consent is the primary legal basis under DPDP and the most visible surface for data principal complaints.

15%

2. Privacy Notice & Transparency

The quality and completeness of your privacy notice against the 10 DPDP requirements. Includes data categories, purposes, retention periods, Grievance Officer contact, and rights explanation. High visibility to regulators and enterprise clients.

15%

3. Data Principal Rights

Operational capability to respond to access, correction, erasure, and nomination requests. Includes request intake mechanism, internal fulfilment process, SLA adherence, and documentation. Weight reflects frequency of complaints in enforcement actions globally.

15%

4. Data Processor Agreements

Coverage and quality of DPAs with all third-party processors. Includes DPA existence, clause completeness, sub-processor management, and breach notification obligations. For most B2B SaaS vendors, this is the biggest gap.

15%

5. Security Controls

Technical and organisational measures protecting personal data. Includes encryption (in transit and at rest), access controls, MFA, breach detection, and penetration testing cadence. Weight reflects the direct link between security failures and regulatory penalties.

10%

6. Data Inventory & Minimisation

Whether the organisation maintains a current record of processing activities (ROPA) and actively practices data minimisation. Includes inventory completeness, minimisation controls, and purpose binding. Foundational for all other domains but lower enforcement priority in early years.

5%

7. Breach Response

Capability to detect, triage, notify, and document a personal data breach within the 6-hour regulatory window. Includes incident response plan, detection tooling, notification templates, and DPB communication protocol.

5%

8. Governance & Accountability

Internal ownership, policy framework, training, and board-level visibility of data protection. Includes Grievance Officer designation, DPO equivalent (if applicable), training records, and policy review cadence. Lower weight because it is an enabler rather than a direct compliance requirement.

How each domain is scored

Each domain uses a combination of three evidence sources, with different sources weighted by reliability:

Evidence Source Weight in Domain Score What it covers
Document review 50% Privacy notice, DPAs, consent flow screenshots, data inventory, incident response plan, board minutes, training records
Stakeholder interview 30% Engineering, legal, HR, and marketing leads; confirms whether documented processes are actually followed
Technical check 20% Database encryption config, access control logs, consent withdrawal mechanism test, rights request response test

The technical check is the component most self-assessment tools omit. Without it, a score can be inflated by good documentation of processes that are not actually implemented. For example, a company may have a documented access review process (document review: pass) but their last actual access review was 18 months ago (technical check: fail).

What each score band means

0–50
Material risk. Will fail enterprise due diligence. Active legal exposure.
51–70
Basic screen. May pass informal vendor checks. Will fail rigorous enterprise review.
71–85
Enterprise-ready. Passes most due diligence. Some residual gaps remain.
86–100
Defensible. Can withstand DPB inquiry. Strong position in enterprise contracts.

Score of 60: what it implies

A score of 60 means you have addressed the basics — you have a privacy notice, some consent mechanism, and a named Grievance Officer — but material gaps exist in at least three domains. You will pass a basic vendor screening questionnaire from a small or mid-market client. You will fail any formal due diligence from an enterprise client with an active legal team. Your exposure in the event of a data principal complaint is significant.

Score of 80: what it implies

A score of 80 means your documentation is substantially complete and your key processes are operational. You can pass most enterprise due diligence reviews. You have a remediation plan for your remaining gaps. In the event of a complaint or inquiry, you can demonstrate good faith effort. This is the target for most mid-market SaaS vendors seeking to win enterprise clients.

Score of 95: what it implies

A score of 95 means all eight domains are substantially compliant with documented evidence. Your consent management is purpose-specific and technically enforced. Your DPAs cover all processors including sub-processors. Your rights fulfilment process is tested and within SLA. Your breach detection and response is documented and rehearsed. You are genuinely defensible against a Data Protection Board inquiry — not just against a client questionnaire.

Why your score should change over time

A readiness score is a snapshot, not a certificate. Scores typically decline by 5–10 points per year if no maintenance effort is applied, because new vendors are onboarded without DPAs, new data categories are collected without notice updates, and old employees leave without access revocation. A quarterly review cadence is the minimum needed to maintain a score above 80.

See our privacy policy grading rubric for the documentation layer of scoring. For a real-world example of how a score improvement translated to a commercial outcome, see our case study of a SaaS vendor that passed a client DPDP review.

Get your DPDP Readiness Score

Our Readiness Score covers all 8 control domains with a weighted assessment methodology — not just a document scan. Delivered with domain-level findings and a prioritised remediation roadmap.

Get Your Readiness Score — ₹999 →

Frequently Asked Questions

Is a DPDP readiness score recognised by regulators or courts?

No government or regulatory body has established an official scoring framework under the DPDP Act. A readiness score is a professional assessment tool, not a certification. However, a documented score with an underlying methodology provides evidence of good faith compliance effort, which is relevant in enforcement proceedings. It is comparable to an ISO audit — it does not guarantee you won't be penalised, but it demonstrates you took compliance seriously.

How is a DPDP readiness score different from a SOC 2 or ISO 27001 assessment?

SOC 2 and ISO 27001 are security-focused frameworks that assess information security controls broadly. They overlap with DPDP on security controls (approximately 15% of the DPDP score) but do not assess consent management, data principal rights, data processor agreements, or breach notification in a DPDP-specific way. A company can be ISO 27001 certified and still score 40/100 on a DPDP readiness assessment. The two are complementary, not substitutes.

Can we use a DPDP readiness score in our RFP responses?

Yes, and increasingly enterprise clients are asking for exactly this. A third-party-assessed DPDP readiness score with a methodology summary is a stronger response than a self-declaration of compliance. Include the score, the assessment date, the scope (which entities and systems were assessed), and the assessor's letterhead. Most enterprise procurement teams at technology companies and financial services firms now have a standardised set of privacy questions in vendor RFPs — a scored assessment covers the majority of them.

Previous Post Next Post

Get Free DPDP Checklist