DPDP Gap Analysis in India: Find Your Compliance Gaps Fast
DPDP gap analysis showing exactly where you fall short of the DPDP Act, 2023, with fixes prioritised by risk. A step-by-step readiness guide for Indian firms.
10 min readBy Sachin Shirish, Director
Reviewed by Pragya Dwivedi, Associate Director, CISM, eWPTX

Why Start With a Gap Analysis
Before you spend on tools or consultants, find out where you actually stand. A DPDP gap analysis in India measures your current controls against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and shows exactly what is missing.
It is the cheapest, fastest way to plan. Instead of guessing, you get a prioritised list of gaps ranked by risk and penalty exposure, so every rupee you spend next goes to the highest-impact fix.
Most teams treat it as step zero: the diagnosis that makes everything after it efficient.
The timing matters. The Rules were notified on 13 November 2025, and most duties for Data Fiduciaries, including notices, security safeguards, breach intimation and data principal rights, apply from 13 May 2027. A gap analysis now leaves time to fix what it finds.
In short: a gap analysis is a structured review that compares your data protection controls against the Act and Rules and produces a prioritised list of gaps. It covers data mapping, consent and notices, data principal rights, security safeguards, retention, processor controls and breach readiness, scoring each as present, partial or missing. The output is a gap register with owners, priorities and timelines, so you fix the highest-risk items first. A focused review takes one to three weeks depending on systems and vendors. It is a planning tool, not verification: the gap analysis tells you what to fix, and an audit later proves you fixed it.
What It Is
It is a structured review comparing how you collect, store and protect personal data against what the Act requires. The output is a clear gap register with owners and priorities.
Sometimes called a gap assessment, it covers consent, notices, security, data principal rights and breach readiness: the same areas an auditor checks, framed as a fix-it plan rather than a pass or fail verdict.
The register is the deliverable that matters. A good review hands you a ranked list you can act on immediately, not a long report that sits unread after the kickoff call.
At a glance
- Data mapping across systems, vendors and backups.
- Consent, notice and data principal rights review.
- Security controls, access and encryption checks.
- Breach detection and reporting readiness.
- A prioritised gap register with owners and timelines.
What It Covers
It covers every duty in the Act: lawful processing, consent and notice, data principal rights, security safeguards, retention, processor controls and breach response.
A thorough review also checks documentation (records of processing, policies and contracts) because missing evidence is itself a gap when an auditor or regulator asks.
It tests people and process, not just technology. Who approves new data collection, and how staff handle a deletion request, cause as many problems as missing software controls.
How to Run One
Start by mapping data, then test each area against the Act using a structured checklist. Score every control as present, partial or missing, and attach evidence where it exists.
Score honestly. A control that half-works is partial, not present; counting partial controls as done is the most common reason a later audit fails despite a confident self-assessment.
Finish by ranking gaps by risk and effort. The finished register becomes your roadmap: each gap carries an owner, a priority and a target date, so progress stays visible to leadership.
How Long It Takes
A focused review takes one to three weeks, depending on how many systems and vendors you run. Data mapping is the longest part because it always surfaces forgotten data.
Smaller teams can complete a first pass in days with a structured checklist; larger, multi-system firms need longer and usually involve several department owners.
Timeboxing helps. Agree a fixed window up front and assign each system to an owner, so the analysis does not stall on the one team that is hard to reach.
Gap Analysis or Full Audit?
A gap analysis is a planning tool; an audit is verification. The first tells you what to fix and in what order, while the audit later proves to a third party that you fixed it.
Run the gap analysis first. Booking an audit before closing known gaps wastes money proving things you already know are broken.
Used together they compound: the gap analysis sets the plan, implementation closes the gaps, and the audit verifies the result.
Think of the cost as insurance. The Act allows penalties of up to Rs 250 crore for failing to take reasonable security safeguards, and a DPDP gap analysis in India costs a small fraction of that exposure.
Overseas firms serving people in India fall under the same Act, and their review can map DPDP gaps alongside GDPR, UK GDPR or CCPA so one exercise covers several regimes.
How SecureRoot Helps
SecureRoot runs the DPDP gap analysis in India as the first step of its DPDP Act compliance services, and connects the work to your wider compliance programme so compliance runs as one system, not scattered projects. Ask us about a free initial gap review.
Our team has supported BFSI, fintech, healthcare and government clients across India and abroad. The official text of the law is published by MeitY, and every engagement maps directly to the Act and its Rules.
Frequently asked questions
Straight answers, no marketing speak. If you don’t see your question here, just ask at info@secureroot.co or call +91 73071 48874.
Is a DPDP gap analysis worth it?
Yes, for almost any business that handles the personal data of people in India, and the return comes from sequencing rather than from the report itself. Apply a simple test afterwards: can you name the three things you will fix this quarter, who owns each one, and what evidence will prove each is closed? If not, the review was written rather than run. Two things make it pay. It stops you buying consent tooling or booking an audit against a data map you do not yet have, which is how teams pay twice for the same problem. It also gives finance a defensible number, because gaps ranked by risk carry rough remediation effort, so the compliance budget becomes a phased ask a board can approve instead of one lump sum. The phased commencement of the Rules is the other argument. Long-lead items such as retention rework and processor contract renegotiation have to start early to land on time.
Is a gap analysis the same as a gap assessment?
Yes, the two terms are used interchangeably in India and nothing turns on the wording. Both measure your current controls against the DPDP Act, 2023 and the DPDP Rules, 2025 and produce a prioritised list of what to fix. What actually differs between providers is the output, not the label. Ask to see the deliverable before you sign anything. A useful review hands you a gap register: one row per control, scored present, partial or missing, with the evidence seen, the owner who will close it, a priority driven by risk, and a target date. A descriptive report that restates the law and leaves you to work out the next step is the same exercise done badly. The distinction that does matter is gap analysis against audit. One is a planning tool that tells you what to fix, the other is verification that you fixed it.
What does a DPDP gap analysis checklist include?
It starts with your role, because Data Fiduciary and Data Processor duties differ, and everything downstream follows from that. From there it covers a data map across systems, vendors and backups, lawful basis and consent capture, notice content and language, withdrawal and data principal rights handling, security safeguards including access control and encryption, retention and deletion, processor contracts, breach detection and intimation, children's data where relevant, and contact person or DPO arrangements. The part most checklists handle badly is evidence. A score of partial should never stand on its own: record the artefact you actually saw, its reference and date, and the one condition that is unmet, such as a retention policy that exists but is not enforced in the analytics warehouse. That single line is what lets someone reopen the item months later without re-interviewing the team, and it is what turns the register into a defensible record rather than a set of opinions.
Does a gap analysis cover documentation?
Yes, and it is usually where the first real gaps appear. Records of processing, privacy notices, internal policies, consent logs and processor contracts are all reviewed, because an auditor or the Data Protection Board will ask for evidence rather than assurances. A control that operates but leaves no record is treated as a gap, since nothing about it can be demonstrated at the moment it is questioned. In practice the documentation review is what turns a technical opinion into a defensible position. Consent logs matter most: capture alone proves little without a timestamp and the notice version the person actually saw. Processor contracts run a close second, because duties you owe do not disappear when the processing is outsourced. Expect the review to flag documents that exist but are stale, since a notice that no longer matches what your product collects is worse than no notice.
How long does a DPDP gap analysis take?
Usually one to three weeks, and the range is driven by how many systems and vendors you run rather than by headcount. A startup with a handful of systems can finish a first pass in days using a structured checklist. A larger organisation with several products, many vendors and separate department owners sits at the longer end, because each owner has to be interviewed and each claim evidenced. Data mapping is almost always the slowest part: it uncovers copies of personal data in exports, analytics tools, support tickets, test environments and backups that nobody listed at kickoff. Schedules slip on ownership, so settle that before kickoff. A named owner is one person, not a department, and they must be able to say what personal data their system holds, who it is shared with, how long it is kept, and who approved that. Four unanswered questions is a gap found before the review starts.
Do foreign companies need a DPDP gap analysis?
If they process the personal data of people in India in connection with offering them goods or services, the Act applies to them, so a gap analysis is the sensible first step. Being incorporated elsewhere changes nothing about the duties; it only changes how you evidence them, since the systems, processors and support teams that touch Indian data often sit outside India. Scope it alongside the work you already do. Overlapping controls such as notices, rights handling, retention and security can be assessed once and mapped to the DPDP Act, GDPR, UK GDPR or CCPA together, so one exercise covers several regimes instead of three parallel projects. The differences are what the review should isolate: notice language expectations, the route for complaints to the Data Protection Board, and contact person or DPO arrangements that a person in India can actually reach.
Related service pages
DPDP Act Compliance Services · Compliance Services · Virtual DPO
Ready to get DPDP-ready?
This guide was researched against the DPDP Act, 2023 and its Rules, and reviewed by SecureRoot’s compliance team for accuracy.
Have a Question About This?
If this raised something specific to your environment, a scoping call is the fastest way to get a direct answer.
We reply within one business day.

