Gap Assessment + Penalty Calculator

DPDP Gap Assessment, Know Your Penalty Exposure Before the DPA Does

9 assessment sections. 250+ checkpoints. A ₹250 Crore penalty estimator that maps every gap directly to the DPDP Schedule. Most organizations discover they're exposed to 4–6x more penalty risk than they estimated. Find out where you actually stand, before the Data Protection Authority does.

Try the live product
250+ DPDP checkpoints Penalty mapped to each section PDF report for auditors
DPDP Penalty Exposure Summary
Sec 10. Security Safeguards ₹250 Cr
Sec 9. Children's Data ₹200 Cr
Sec 12-14. Principal Rights ₹50 Cr
Your Total Exposure ₹. Cr
Run the assessment to calculate
Regulatory Context

Why Gap Assessment Is Not Optional Under DPDP

The DPA has broad audit and investigation powers. Organizations that cannot demonstrate active compliance face penalties, not just warnings.

Section 28. DPA Audit Powers

The Data Protection Authority can direct any Data Fiduciary to provide information, conduct inquiries, and call for explanations. Organizations without documented gap assessments have no evidence of due diligence, the DPA's starting presumption becomes non-compliance. A formal gap assessment with timestamped results is your primary evidence of good-faith effort.

Schedule. Penalty Tiers Up to ₹250 Crore

The DPDP Act Schedule sets penalties per-violation: ₹250 Crore for security safeguard failures and unreported breaches; ₹200 Crore for children's data violations; ₹150 Crore for SDF-specific obligations; ₹50 Crore for data principal rights failures. Penalties are not merely symbolic, each is per-violation and can accumulate across multiple incidents or affected individuals.

Section 10. SDF Self-Compliance Obligation

Significant Data Fiduciaries face additional obligations including appointing a DPO, conducting Data Protection Impact Assessments, and undergoing periodic audits. But Section 10 also implies a general duty of proactive compliance for all Data Fiduciaries, waiting for a DPA complaint to discover gaps is not an acceptable strategy. A documented gap assessment demonstrates the proactive posture regulators expect.

Core Capabilities

9 Assessment Sections, 250+ Checkpoints, Zero Guesswork

9-Section Structured Assessment

Covers every major DPDP domain: Consent & Notice (Sec 5-6), Data Quality (Sec 8), Security Safeguards (Sec 10), Breach Notification (Sec 8(6)), Data Principal Rights (Sec 12-14), Children's Data (Sec 9), Cross-Border Transfers (Sec 16), SDF Obligations (Sec 10), and Grievance Mechanism (Sec 13). Each section drills into 20–35 specific checkpoints, surfacing gaps that high-level audits routinely miss.

₹250 Crore Penalty Estimator

Every identified gap is automatically mapped to its corresponding DPDP Schedule penalty tier. The estimator aggregates your total maximum financial exposure across all open gaps, producing a single ₹ figure you can present to your board and CFO. This transforms a compliance exercise into a business risk conversation, which is what actually drives remediation budgets.

Section-Level Compliance Score

A percentage compliance score for each of the 9 sections, plus an overall score. Scores are calculated based on the weighted severity of each checkpoint, a missing consent notice (₹250 Cr exposure) weighs more heavily than a missing acknowledgment receipt. The drill-down lets you prioritize high-risk sections for immediate remediation while tracking low-risk sections over time.

AI Remediation Recommendations

For each identified gap, the AI generates specific, actionable remediation steps, not generic advice. "Implement a consent notice" becomes "Add a DPDP-compliant consent notice to your onboarding flow covering data categories X, Y, Z and purposes A, B, referencing Rule 3 format requirements." Recommendations are ranked by penalty exposure so your team addresses the highest-risk gaps first.

Board-Ready PDF Report

One-click PDF export of the complete gap assessment, formatted for professional sharing with board directors, internal audit committees, external CA firms, legal counsel, and investment due diligence teams. The report includes an executive summary, section scores, gap list with penalty mapping, and a prioritized 90-day remediation roadmap generated by the AI.

Quarterly Progress Tracking

Run assessments quarterly and track your compliance score trend over time. dcomply stores your assessment history so you can show the DPA, or an auditor, a documented improvement trajectory. The comparison view highlights which gaps were closed since the last assessment, and which new obligations emerged from regulatory updates that require attention.

How It Works

From First Question to Board-Ready Report in Under 45 Minutes

The gap assessment is structured to be completed by your compliance, legal, and IT teams together. No external consultants required for the first pass.

Step 1. Configure your organization profile

Set your industry sector, approximate size, whether you process children's data, whether you transfer data cross-border, and whether you believe you qualify as an SDF. This profile customizes which checkpoints are mandatory versus advisory, a school has different requirements than a payment aggregator.

Step 2. Complete 250+ checkpoints across 9 sections

Each checkpoint is a specific yes/no/partial question tied to a DPDP obligation. Questions include contextual explanations of what the obligation requires, so non-legal team members can answer accurately. You can save progress and return, the assessment does not need to be completed in a single session.

Step 3. Review your gap analysis and penalty exposure

The system instantly calculates your compliance score per section and your aggregate penalty exposure in ₹ Crore. The gap list is sorted by penalty size, so the ₹250 Crore gaps appear at the top. Each gap includes the specific DPDP section violated, the maximum penalty, and the number of individuals potentially affected if the DPA investigates.

Step 4. Get AI remediation plan and export PDF

The AI generates a prioritized remediation plan for your specific gap profile, not a generic checklist. The plan includes estimated effort (hours/days) for each fix, ownership suggestions (IT/Legal/Operations), and references to the specific DPDP section each fix addresses. Download the full PDF report and share it with stakeholders. Schedule a re-assessment in 90 days to measure progress.

Use Cases by Industry

Who Runs a DPDP Gap Assessment, and Why

Startups. Investment Due Diligence

Series A and B investors now routinely include DPDP compliance in due diligence, especially for FinTech, HealthTech, and D2C companies.

  • Produce a PDF compliance report for investor data room
  • Identify and remediate gaps before investor review
  • Demonstrate proactive compliance culture to board
  • Calculate residual penalty exposure post-remediation
Enterprises. Pre-DPA Enforcement Readiness

Large organizations processing millions of data principals have the highest penalty exposure, and the most complex compliance programs to document.

  • Run assessments across multiple business units
  • Present aggregate penalty exposure to Risk Committee
  • Track remediation progress quarter-over-quarter
  • Generate DPA-ready evidence of compliance efforts
CA & Law Firms. Client Portfolio Audits

Chartered accountants and law firms advising on DPDP compliance use dcomply to conduct structured client assessments at scale.

  • Manage multiple client assessments in one workspace
  • White-label PDF reports for client delivery
  • Consistent methodology across all client engagements
  • Bill for assessment, remediation planning, and review cycles
What's Included

Complete Gap Assessment Feature List

9-section DPDP assessment framework (Act + Rules 2025)
250+ structured checkpoints mapped to DPDP sections
Per-gap penalty mapping to DPDP Schedule amounts
Total maximum penalty exposure calculator (₹ Crore)
Section-level and overall compliance percentage scores
Industry-specific checkpoint customization (13 sectors)
AI-generated remediation plan prioritized by penalty exposure
Board-ready PDF report with executive summary
Quarterly trend tracking and score comparison
Multi-client workspace for CA/law firm use
Save progress and resume multi-session assessments
SDF-specific additional checkpoints (Sec 10 obligations)
Rules 2025 coverage including Rule 3 consent notice format
Auto-updated assessment when DPDP Rules are amended
Integration & Technical Details

How Gap Assessment Connects to the Rest of dcomply

Connects to All dcomply Modules

When a gap assessment identifies a missing DSR portal, consent management system, or breach notification workflow, dcomply links directly to the relevant module to begin remediation. Closing a gap in the assessment updates your compliance score in real time. The assessment is the hub, every other module feeds back into it.

Export & API Capabilities

Export assessment results as PDF, CSV, or JSON for integration with your GRC platform, internal audit tools, or board reporting templates. The JSON export includes all gap IDs, section codes, penalty amounts, and remediation status, suitable for programmatic ingestion into risk management systems. API access available on Enterprise plans.

Data Security & Confidentiality

Assessment responses are stored encrypted at rest (AES-256) and in transit (TLS 1.3). dcomply does not share your gap assessment data with third parties. Each organization's assessment is logically isolated, multi-client workspaces maintain strict tenant separation. Assessment history is retained for 5 years to support regulatory evidence requirements.

FAQ

Frequently Asked Questions

A DPDP gap assessment is a structured evaluation that measures how closely your organization's current data protection practices align with the Digital Personal Data Protection Act 2023 and DPDP Rules 2025. dcomply's assessment covers 9 sections and 250+ checkpoints, each mapped to a specific DPDP obligation. The output is a compliance score, a list of identified gaps with associated penalty exposure under the DPDP Schedule, and a prioritized remediation plan. Unlike generic audits, this assessment calculates your exact maximum financial exposure, giving your board and legal team a clear ₹ figure to act on.

We recommend running a full gap assessment at least quarterly. The DPDP Rules 2025 are still evolving, and new obligations are regularly clarified by DPA guidance. Running a quarterly assessment lets you track your compliance score over time, demonstrate remediation progress to management, and catch any new gaps introduced by operational changes. Significant events, launching a new product, onboarding a major vendor, or beginning cross-border data transfers, should trigger an immediate re-assessment rather than waiting for the next scheduled cycle.

The penalty estimator maps each identified gap to the corresponding penalty in the DPDP Act Schedule. For example, a failure to implement adequate security safeguards under Section 10 carries a maximum penalty of ₹250 Crore. Failure to notify the DPA of a breach is also ₹250 Crore. Failure to protect children's data under Section 9 is ₹200 Crore. Non-compliance with data principal rights obligations under Sections 12-14 is ₹50 Crore. The estimator sums all exposed penalties to show your maximum total financial risk. Note that the DPA has discretion over actual penalty amounts, this figure represents your maximum theoretical exposure, which is the number your board needs to see to approve remediation investment.

Yes. The PDF report generated by dcomply's gap assessment is formatted for professional sharing with internal audit teams, external auditors, CA firms, legal counsel, and investors conducting due diligence. The report includes your compliance score, section-by-section breakdown, identified gaps, associated penalty exposure, and AI-generated remediation recommendations with priority rankings. For investment due diligence, the report demonstrates proactive DPDP compliance, increasingly a requirement at Series A and beyond as institutional investors build privacy risk into their ESG scoring.

The compliance score is based on your answers to 250+ structured checkpoints, each mapped directly to DPDP Act sections and Rules 2025. The scoring is deterministic, the same answers produce the same score every time. The accuracy depends entirely on the honesty and completeness of your inputs. dcomply recommends involving your legal team, CISO, and DPO (if appointed) in completing the assessment together. The AI recommendations for each gap are generated by Claude AI trained on DPDP Act 2023, Rules 2025, and implementation best practices, they are guidance, not legal advice, and should be reviewed by qualified counsel before implementation.

Both. The assessment covers all 44 sections of the DPDP Act 2023 and the complete DPDP Rules 2025 (Rules 3 through 22). Key Rule-level obligations tested include the prescribed format for consent notices (Rule 3), the grievance redressal mechanism requirements (Rule 13), DPO appointment conditions for SDFs (Rule 12), verifiable parental consent procedures for children's data (Rule 10), and data localisation requirements under Rule 17. Many organizations are exposed to penalties specifically because they addressed the Act but ignored the Rules, this assessment is designed to catch both layers of obligation.

Find Out What the DPA Would Find First

Run India's most comprehensive DPDP gap assessment. 9 sections, 250+ checkpoints, penalty exposure calculated in real time. Free on Solo plan.

Try the live product