How DPDP readiness scoring works
The methodology behind DPDP readiness scores — 8 control domains, weighting rationale, how each domain is assessed, and what your score means for enterprise client scrutiny and regulatory risk.
When a compliance firm tells you that your DPDP readiness score is 67, what does that number actually mean? If you've received a score — or are considering commissioning an assessment — you should be able to answer three questions: what went into the score, how each domain was assessed, and what the score implies for your actual risk exposure.
Scepticism about scores is healthy. A score produced by a tool that only reads your privacy policy URL is very different from a score produced by a 3-week assessment involving document review, interviews, and technical checks. This post explains what a rigorous methodology looks like and what each score band implies operationally.
If you're deciding between running an assessment in-house versus engaging a consultant, see our post on in-house versus consultant for DPDP compliance. To understand the full output of an assessment engagement, see our post on what a DPDP gap analysis report looks like.
The 8 control domains
DPDP readiness is assessed across eight domains, each mapped to specific provisions of the DPDP Act 2023 and DPDP Rules 2025. The domains and their weightings reflect the relative penalty exposure and enforcement likelihood associated with each area.
1. Consent Management
How consent is obtained, recorded, and withdrawn. Includes consent notice format, purpose specificity, withdrawal mechanism, and consent record-keeping. High weight because consent is the primary legal basis under DPDP and the most visible surface for data principal complaints.
2. Privacy Notice & Transparency
The quality and completeness of your privacy notice against the 10 DPDP requirements. Includes data categories, purposes, retention periods, Grievance Officer contact, and rights explanation. High visibility to regulators and enterprise clients.
3. Data Principal Rights
Operational capability to respond to access, correction, erasure, and nomination requests. Includes request intake mechanism, internal fulfilment process, SLA adherence, and documentation. Weight reflects frequency of complaints in enforcement actions globally.
4. Data Processor Agreements
Coverage and quality of DPAs with all third-party processors. Includes DPA existence, clause completeness, sub-processor management, and breach notification obligations. For most B2B SaaS vendors, this is the biggest gap.
5. Security Controls
Technical and organisational measures protecting personal data. Includes encryption (in transit and at rest), access controls, MFA, breach detection, and penetration testing cadence. Weight reflects the direct link between security failures and regulatory penalties.
6. Data Inventory & Minimisation
Whether the organisation maintains a current record of processing activities (ROPA) and actively practices data minimisation. Includes inventory completeness, minimisation controls, and purpose binding. Foundational for all other domains but lower enforcement priority in early years.
7. Breach Response
Capability to detect, triage, notify, and document a personal data breach within the 6-hour regulatory window. Includes incident response plan, detection tooling, notification templates, and DPB communication protocol.
8. Governance & Accountability
Internal ownership, policy framework, training, and board-level visibility of data protection. Includes Grievance Officer designation, DPO equivalent (if applicable), training records, and policy review cadence. Lower weight because it is an enabler rather than a direct compliance requirement.
How each domain is scored
Each domain uses a combination of three evidence sources, with different sources weighted by reliability:
| Evidence Source | Weight in Domain Score | What it covers |
|---|---|---|
| Document review | 50% | Privacy notice, DPAs, consent flow screenshots, data inventory, incident response plan, board minutes, training records |
| Stakeholder interview | 30% | Engineering, legal, HR, and marketing leads; confirms whether documented processes are actually followed |
| Technical check | 20% | Database encryption config, access control logs, consent withdrawal mechanism test, rights request response test |
The technical check is the component most self-assessment tools omit. Without it, a score can be inflated by good documentation of processes that are not actually implemented. For example, a company may have a documented access review process (document review: pass) but their last actual access review was 18 months ago (technical check: fail).
What each score band means
Score of 60: what it implies
A score of 60 means you have addressed the basics — you have a privacy notice, some consent mechanism, and a named Grievance Officer — but material gaps exist in at least three domains. You will pass a basic vendor screening questionnaire from a small or mid-market client. You will fail any formal due diligence from an enterprise client with an active legal team. Your exposure in the event of a data principal complaint is significant.
Score of 80: what it implies
A score of 80 means your documentation is substantially complete and your key processes are operational. You can pass most enterprise due diligence reviews. You have a remediation plan for your remaining gaps. In the event of a complaint or inquiry, you can demonstrate good faith effort. This is the target for most mid-market SaaS vendors seeking to win enterprise clients.
Score of 95: what it implies
A score of 95 means all eight domains are substantially compliant with documented evidence. Your consent management is purpose-specific and technically enforced. Your DPAs cover all processors including sub-processors. Your rights fulfilment process is tested and within SLA. Your breach detection and response is documented and rehearsed. You are genuinely defensible against a Data Protection Board inquiry — not just against a client questionnaire.
Why your score should change over time
A readiness score is a snapshot, not a certificate. Scores typically decline by 5–10 points per year if no maintenance effort is applied, because new vendors are onboarded without DPAs, new data categories are collected without notice updates, and old employees leave without access revocation. A quarterly review cadence is the minimum needed to maintain a score above 80.
See our privacy policy grading rubric for the documentation layer of scoring. For a real-world example of how a score improvement translated to a commercial outcome, see our case study of a SaaS vendor that passed a client DPDP review.
Get your DPDP Readiness Score
Our Readiness Score covers all 8 control domains with a weighted assessment methodology — not just a document scan. Delivered with domain-level findings and a prioritised remediation roadmap.
Get Your Readiness Score — ₹999 →Frequently Asked Questions
Is a DPDP readiness score recognised by regulators or courts?
No government or regulatory body has established an official scoring framework under the DPDP Act. A readiness score is a professional assessment tool, not a certification. However, a documented score with an underlying methodology provides evidence of good faith compliance effort, which is relevant in enforcement proceedings. It is comparable to an ISO audit — it does not guarantee you won't be penalised, but it demonstrates you took compliance seriously.
How is a DPDP readiness score different from a SOC 2 or ISO 27001 assessment?
SOC 2 and ISO 27001 are security-focused frameworks that assess information security controls broadly. They overlap with DPDP on security controls (approximately 15% of the DPDP score) but do not assess consent management, data principal rights, data processor agreements, or breach notification in a DPDP-specific way. A company can be ISO 27001 certified and still score 40/100 on a DPDP readiness assessment. The two are complementary, not substitutes.
Can we use a DPDP readiness score in our RFP responses?
Yes, and increasingly enterprise clients are asking for exactly this. A third-party-assessed DPDP readiness score with a methodology summary is a stronger response than a self-declaration of compliance. Include the score, the assessment date, the scope (which entities and systems were assessed), and the assessor's letterhead. Most enterprise procurement teams at technology companies and financial services firms now have a standardised set of privacy questions in vendor RFPs — a scored assessment covers the majority of them.