We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

DPDP Act 2023 · Privacy practice

DPDP gap assessment

A DPDP gap assessment is the fastest way to know where you stand against the Digital Personal Data Protection Act 2023 and its Rules before you invest in a full programme. CyberSigma’s privacy practice reviews how you actually process personal data — consent and notice, data-principal rights, data inventory, breach and grievance workflows, processor contracts and (if applicable) Significant Data Fiduciary duties — and returns a prioritised, obligation-by-obligation gap report with a costed remediation roadmap.

Get a free DPDP readiness review →Book a 20-minute call
What it covers

What the gap assessment reviews

  • Lawful processing, notice and consent lifecycle
  • Data-principal rights and grievance-redressal readiness
  • Data inventory / RoPA and data-flow coverage
  • Breach response and reporting workflow
  • Processor contracts, cross-border transfers and security safeguards
  • Significant Data Fiduciary duties (DPO, DPIA, audit) where applicable
Timeline & cost

Timeline and cost

Timeline
Typically 1–3 weeks depending on data estate and number of systems/vendors.
Cost factors
Number of systems and data stores, vendor count, and SDF status.
Deliverables

What you receive

Obligation-by-obligation gap report
Each DPDP obligation rated with the specific gap and its risk.
Costed remediation roadmap
A prioritised, sequenced plan to reach a working DPDP programme.
Why start here

Why a gap assessment first

It turns “are we DPDP-ready?” into a concrete, budgeted plan — and prevents buying policies or tooling before you know your actual gaps.

Proof

See how we’ve done it before

Relevant case study
How a gap assessment turned DPDP uncertainty into a costed, prioritised plan. Read case studies →
Redacted sample deliverable
Inspect a redacted data-inventory sample first. Request a redacted sample →

Where does your business stand on the DPDP Act 2023?

Get a free DPDP readiness review — share your work email and we map your obligations, gaps and next steps.

Verified facts

Drawn from the CyberSigma Compliance Registry (updated 11 August 2026). Every statement below is checked against the issuing body’s own publication, with the date it was last verified.

  • EnactmentEffective 11 August 2023

    Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.

    Official Gazette text (MeitY PDF) · verified 31 July 2026
  • DPDP Rules 2025 notificationEffective 13 November 2025

    Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).

    Gazette date corroborated across multiple law-firm analyses; the PIB document filename carries the press-release date (17 Nov), not the notification date.

    MeitY / PIB — DPDP Rules 2025 · verified 1 August 2026
  • Phase I — in force on notificationEffective 13 November 2025

    Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.

    DPDP Rules 2025 (phased commencement) · verified 1 August 2026
  • Phase II — one year from notificationEffective 13 November 2026

    Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.

    DPDP Rules 2025 (phased commencement) · verified 1 August 2026
  • Phase III — substantive frameworkEffective May 2027

    Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.

    DPDP Rules 2025 (phased commencement) · verified 1 August 2026
  • Penalty ceilingEffective May 2027

    The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.

    Amount verified directly against the Gazette PDF text ('may extend to two hundred and fifty crore rupees'). Enforcement follows the phased commencement (see dpdp-phase-3).

  • Breach notification timeline (Rule 7)Effective May 2027

    Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.

    Timelines corroborated across multiple legal publishers. Enforcement follows the phased commencement (see dpdp-phase-3). Runs in parallel with CERT-In’s 6-hour incident reporting — the same incident triggers both.

    DPDP Rules 2025, Rule 7 · verified 1 August 2026
  • Notice contents (section 5)Effective May 2027

    Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.

    Contents verified directly against the Gazette PDF text. Notice must be available in English or any Eighth Schedule language.

  • Consent Manager registration - Rule 4 in force 13 November 2026Effective 13 November 2026

    Rule 4 of the Digital Personal Data Protection Rules, 2025 establishes the registration and oversight framework for Consent Managers and comes into force on 13 November 2026. A Consent Manager is registered with the Data Protection Board of India and acts as a single point of contact through which a Data Principal can give, manage, review and withdraw consent via an accessible, transparent and interoperable platform.

    MeitY returns HTTP 403 to automated retrieval for both the Rules page and its own FAQ PDF, so this is corroborated across independent legal analyses rather than read from the primary text. Verify against the notified Rules before relying on it in a deliverable.

  • Consent Manager eligibility - First Schedule, Part AEffective 13 November 2026

    Part A of the First Schedule sets the conditions the Board must be satisfied of before registering a Consent Manager. They include incorporation in India, a minimum net worth of INR 2 crore (adjusted for inflation), sound financial condition and general character of management, and sufficient technical, operational and financial capacity to discharge the role. Directors, key managerial personnel and senior management must be persons of general reputation and record of fairness and integrity.

    MeitY returns HTTP 403 to automated retrieval for both the Rules page and its own FAQ PDF, so this is corroborated across independent legal analyses rather than read from the primary text. Verify against the notified Rules before relying on it in a deliverable.

  • Consent Manager obligations - First Schedule, Part BEffective 13 November 2026

    A Consent Manager acts in a fiduciary capacity toward the Data Principal. It must not act as Data Fiduciary or Data Processor for the same Data Principal whose consent it manages, must route personal data in a form it cannot itself read, must treat all Data Fiduciaries neutrally without preferential access, and must retain consent records for at least seven years.

    MeitY returns HTTP 403 to automated retrieval for both the Rules page and its own FAQ PDF, so this is corroborated across independent legal analyses rather than read from the primary text. Verify against the notified Rules before relying on it in a deliverable. The conflict rule is the commercially significant one: an organisation cannot register as a Consent Manager for data subjects it also serves as a Data Fiduciary.

Related in this cluster

DPDP gap assessment — FAQs

What does a DPDP gap assessment produce?

An obligation-by-obligation gap report against the DPDP Act 2023 and Rules, plus a prioritised, costed remediation roadmap — so you can budget and sequence the work.

How long does it take?

Typically 1–3 weeks depending on the size of your data estate and the number of systems and vendors in scope.

Find out where you stand on DPDP

A focused gap assessment gives you an obligation-by-obligation report and a costed roadmap. Reply within four business hours.

Book a 20-minute call →

Ready to discuss your DPDP gap assessment requirement?

CERT-In empanelled · PCI QSA authorised — a senior consultant responds within 4 business hours. Free, no obligation.