Assessment & Audit
SL-01Map the data, test every processing activity against the Act, and produce a risk-rated gap register with a remediation roadmap. Closing a gap here moves the clauses it blocked, which is what makes the readiness score respond to real work.
6 critical gaps are open
Combined statutory ceiling of ₹1550 Cr. The top three by exposure are unlawful AI processing, processor contracts without the prescribed security provisions, and unencrypted identifiers in legacy databases.
Active assessments
Progress against scope, with the reviewer named. An assessment without a reviewer is a self-assessment.
- ASM-2026-0007Annual DPDP gap assessment — FY 2026-27All directorates and citizen-facing services · Priya Nair · reviewed by Meera IyerDPDP gap assessmentin progress74%Due in 17 days23 gaps · 5 critical
- ASM-2026-0005Children's data review — Education & HealthScholarship, school enrolment, nutrition and health card systems · Priya Nair · reviewed by Meera IyerChildren's data review (S.9 / Rule 10)in review92%Due in 5 days7 gaps · 3 critical
- ASM-2026-0004Processor and third-party reviewAll 26 empanelled processors and their sub-processors · Imran Sethi · no reviewer assignedProcessor & third-party reviewin progress46%Due in 29 days4 gaps · 1 critical
Open gaps by severity
What the register actually holds.
16open
- Critical6
- High6
- Medium3
- Low1
Remediation by workstream
Grouped so the work can be assigned to a team rather than scattered across a backlog.
Rule 6 security controls
Control by control, weakest first. This is the section a regulator opens after a breach.
- Contractual security obligations on Data ProcessorsRule 6(1)(f)Gap
- Encryption, obfuscation, masking or virtual tokensRule 6(1)(a)Partially compliant
- Control over access to computer resourcesRule 6(1)(b)Partially compliant
- Backups for continued processing after compromiseRule 6(1)(e)Partially compliant
- Technical and organisational measures to give effect to safeguardsRule 6(1)(h)Partially compliant
- Visibility through logs, monitoring and reviewRule 6(1)(c)Compliant
Overall Rule 6
63%
Highest-exposure gaps
Ranked by the statutory ceiling attached to the obligation each one blocks.
- CriticalEight processor contracts lack the prescribed security provisionsGAP-2026-0211 · Vikram Saxena · Vendor Registry₹250 Cr
- CriticalUnencrypted personal data columns in three legacy databasesGAP-2026-0212 · Naveen Kulkarni · Data Discovery₹250 Cr
- HighShadow AI usage detected across 6 unsanctioned servicesGAP-2026-0231 · Vikram Saxena · AI Processing Guard₹250 Cr
- CriticalVerifiable parental consent not obtained for scholarship applicants under 18GAP-2026-0214 · Dr. Kavya Menon · Consent Management₹200 Cr
- CriticalDPIA not completed within the last twelve monthsGAP-2026-0226 · Sanjay Chauhan · DPIA₹150 Cr
- HighAlgorithmic due diligence not performed for eligibility scoringGAP-2026-0227 · Sunita Khanna · DPIA₹150 Cr
Related
Gap registerEvery gap, risk-rated and mapped to the clauses it blocks, with the business impact and recommendation.Remediation roadmapThe work itself — prioritised, owned, and grouped into workstreams that a delivery team can actually run.Security controlsRule 6 control by control, with implementation notes and the evidence behind each position.DPIAData Protection Impact Assessments and algorithmic due diligence, required annually for an SDF.