4

Assessment & Audit

SL-01

Map the data, test every processing activity against the Act, and produce a risk-rated gap register with a remediation roadmap. Closing a gap here moves the clauses it blocked, which is what makes the readiness score respond to real work.

Active assessments

Progress against scope, with the reviewer named. An assessment without a reviewer is a self-assessment.

All assessments
  • ASM-2026-0007Annual DPDP gap assessment — FY 2026-27
    All directorates and citizen-facing services · Priya Nair · reviewed by Meera Iyer
    DPDP gap assessmentin progress
    74%
    Due in 17 days23 gaps · 5 critical
  • ASM-2026-0005Children's data review — Education & Health
    Scholarship, school enrolment, nutrition and health card systems · Priya Nair · reviewed by Meera Iyer
    Children's data review (S.9 / Rule 10)in review
    92%
    Due in 5 days7 gaps · 3 critical
  • ASM-2026-0004Processor and third-party review
    All 26 empanelled processors and their sub-processors · Imran Sethi · no reviewer assigned
    Processor & third-party reviewin progress
    46%
    Due in 29 days4 gaps · 1 critical
Open gaps by severity

What the register actually holds.

16open
  • Critical6
  • High6
  • Medium3
  • Low1
Remediation by workstream

Grouped so the work can be assigned to a team rather than scattered across a backlog.

Roadmap
Rule 6 security controls

Control by control, weakest first. This is the section a regulator opens after a breach.

All controls
  • Contractual security obligations on Data ProcessorsRule 6(1)(f)Gap
  • Encryption, obfuscation, masking or virtual tokensRule 6(1)(a)Partially compliant
  • Control over access to computer resourcesRule 6(1)(b)Partially compliant
  • Backups for continued processing after compromiseRule 6(1)(e)Partially compliant
  • Technical and organisational measures to give effect to safeguardsRule 6(1)(h)Partially compliant
  • Visibility through logs, monitoring and reviewRule 6(1)(c)Compliant
Overall Rule 6
63%

Related