DPDP Gap Assessment Vendor — What You Actually Get
A buyer's guide to vendor DPDP gap assessments: methodology, eight control domains, scoring approach, and what the output report looks like.
Before commissioning any professional service, the sensible buyer asks: what will I actually receive for my money, and how will I know it was worth it? This is especially reasonable when buying something as intangible as a "gap assessment." The word "assessment" can mean anything from a one-hour call and a generic PDF to a multi-week structured review that produces actionable findings.
This post walks through what a credible DPDP gap assessment for an IT or SaaS vendor should cover — the methodology, the eight control domains, how findings are scored, and what the output looks like. If you are evaluating vendors or considering commissioning an assessment, this is the benchmark to use.
Phase 1: Scope Definition (Week 1)
No two vendors are the same, and a gap assessment that ignores this produces useless results. The first task is defining what is in scope. This involves understanding: what products or services the vendor offers, which of those products process personal data and for whom, the categories and approximate volume of personal data involved, which geographies are served (India-only vs. cross-border), whether the vendor is acting as a Data Fiduciary (determining the purpose of processing) or a Data Processor (processing on client instructions), or both in different parts of the business, and whether any processing qualifies as involving sensitive personal data under the DPDP Act.
This scoping conversation also identifies which existing documentation is available — information security policies, existing DPA templates, privacy notices, previous audit reports — so the assessment team is not re-discovering things the vendor has already documented.
A well-scoped assessment takes 3–4 hours of discovery calls with the right people (typically: a legal or compliance lead, a CTO or senior engineer, and an HR or operations lead), plus a document review period.
Phase 2: The Eight Control Domains
A comprehensive DPDP gap assessment evaluates the vendor across eight control domains. Each domain has a set of control questions with defined "evidence of compliance" criteria.
Domain 1: Data Mapping and Inventory
Does the vendor know what personal data it holds, where it is stored, how it flows between systems, who has access, and on what legal basis? Evidence includes a maintained Record of Processing Activities (RoPA), data flow diagrams, and an asset register that includes data stores. Key questions: Is the inventory complete? Current? Is there an owner? Can the vendor locate any individual's data on request?
Domain 2: Consent and Legal Basis
For each processing activity, is there a documented legal basis? For activities relying on consent, is that consent freely given, specific, informed, and capable of withdrawal? Does the vendor have a technical mechanism to record and honour consent withdrawal? This domain often reveals surprises: vendors who assume "we have a privacy policy" equals "we have valid consent" — they do not.
Domain 3: Retention and Deletion
Are there documented retention periods for each data category, aligned to business need and legal requirement? Is there a technical mechanism to actually delete data when the period expires — including backups, archives, and data held by sub-processors? Is there a process for contractual data return or deletion at the end of client engagements?
Domain 4: Security Controls
This domain evaluates the technical and organisational measures protecting personal data: encryption at rest and in transit, access controls (RBAC, MFA, privileged access management), vulnerability management, penetration testing frequency, backup and recovery procedures, and security awareness training. The DPDP Act requires "reasonable security safeguards" — this domain assesses what "reasonable" looks like for the vendor's risk profile.
Domain 5: Breach Response
Does the vendor have a documented personal data breach response plan? Does it cover detection, internal escalation, containment, assessment, notification to the Data Fiduciary (and where required, the Data Protection Board and data principals), and post-incident review? Has the plan been tested through a tabletop exercise? Are breach notification timelines defined and achievable?
Domain 6: Vendor and Sub-processor Management
Does the vendor have a register of its own sub-processors? Are appropriate Data Processing Agreements in place with each sub-processor? Is there a process for assessing new sub-processors before engagement? Does the vendor flow down contractual obligations to its supply chain? Many IT vendors are meticulous about their client-facing DPAs but have done nothing about their own third-party tools that process client data.
Domain 7: Data Subject Rights
Does the vendor have a process to receive, verify, and respond to data subject rights requests? This includes access requests, correction requests, erasure requests, and grievance complaints. Is the process documented? Is there a designated owner? Is the response timeline defined? Does the technical infrastructure support data lookup and deletion per individual?
Domain 8: Documentation and Governance
Is there a privacy policy? A data protection policy? A DPA template? A Grievance Officer appointment with published contact details? Are employees trained on data protection obligations? Is there a documented privacy governance structure — even a lightweight one? Documentation is often the fastest domain to remediate but is frequently the most neglected.
Phase 3: Gap Scoring — Red, Amber, Green
Each control within the eight domains is scored on a three-point scale:
RED — Critical Gap: The control is absent or fundamentally non-functional. This represents regulatory exposure and/or a deal-blocking risk with enterprise clients. Remediation is required before the vendor can credibly respond to enterprise questionnaires on this domain.
AMBER — Partial Gap: The control exists but is incomplete, inconsistent, or not documented. It may satisfy low-stakes clients but will not withstand scrutiny from enterprise procurement or regulatory audit. Remediation improves posture and reduces risk.
GREEN — Compliant: The control is in place, documented, and demonstrable. A third party could verify this control is functioning through an audit.
A typical 50–100 person SaaS vendor with no existing privacy programme will find 40–60% of controls red, 20–30% amber, and 10–20% green on first assessment. This is not unusual — it is the starting point, not a verdict.
Phase 4: The Output Report
The output of a credible gap assessment is not a compliance score out of 100. It is a structured report with four components:
Executive Summary — A 2-page plain-language summary of the overall posture, the three most critical gaps, and the recommended prioritisation. This is the document that goes to the founder or board.
Domain-by-Domain Gap Register — A detailed register listing every control evaluated, its RAG status, the evidence reviewed, the identified gap, and the recommended remediation action. This is the working document for the implementation team.
Prioritised Remediation Roadmap — A phased plan (typically 30/60/90 days) that sequences remediation based on risk severity and implementation effort. High-impact, low-effort fixes (like appointing a Grievance Officer and publishing their contact details) go first. Complex multi-team initiatives (like implementing a technical consent management system) go later.
Evidence Baseline — A record of all documents reviewed and interviews conducted, so subsequent assessments can track delta rather than starting from scratch.
What a Gap Assessment Is Not
A gap assessment is not a certification. It does not give you a DPDP "certificate" — no such certification exists under the Act as of now. It does not replace a DPA. It does not guarantee you will pass your client's questionnaire — but it gives you the factual basis to answer every question honestly and specifically. And it is not a one-time event: a reassessment every 12–18 months, or after any significant product or infrastructure change, is the recommended cadence.
For context on where a gap assessment fits in your broader compliance journey, see our posts on DPA vs full DPDP readiness and who should own privacy in a SaaS company. A self-scoring checklist across these eight domains is available at the DPDP readiness checklist for IT vendors. For background on DPDP requirements for IT companies specifically, see our earlier post on DPDP compliance for IT companies.
Frequently Asked Questions
How long does a vendor DPDP gap assessment typically take?
For a 50–200 person IT or SaaS vendor, a comprehensive gap assessment across all eight domains typically takes 3–5 weeks: 1 week for scoping and document collection, 2–3 weeks for domain-by-domain evaluation and evidence review, and 1 week for report preparation and prioritised roadmap. Lighter assessments covering only the highest-risk domains can be completed in 2 weeks.
What documents should we prepare before a gap assessment?
Gather: your privacy policy, any existing DPA templates, information security policy, organisational chart showing data access roles, a list of all third-party tools that process personal data, any previous audit reports (ISO 27001, SOC 2, etc.), and your incident response or business continuity plan. Even if these documents are incomplete or informal, sharing them saves assessment time and demonstrates seriousness.
Can a gap assessment be used as evidence in a client audit?
A gap assessment report from a credible third party demonstrates that you have taken a systematic approach to identifying and remediating compliance gaps. Many enterprise clients accept this as part of vendor due diligence, especially when accompanied by a remediation roadmap with clear timelines. It is not a substitute for an ISO 27001 or SOC 2 certificate, but it meaningfully strengthens your compliance posture for DPDP-specific questions.
See How Your Vendors Stack Up
Our Vendor Risk Scorecard evaluates a third-party vendor's DPDP posture across all eight control domains — giving you a structured risk rating before you sign the contract.
Get the Vendor Risk Scorecard — ₹1,499