Compliance Assessment Report

DPDP Readiness Assessment

Digital Personal Data Protection Act 2023 — Compliance Gap Analysis for Company C

Company
Company C (company-c.example.com)
Assessment Date
2026-03-22
Assessor
Company A via Claude Code
Regulation
DPDPA 2023 + DPDP Rules 2025
Full Enforcement
May 13, 2027 — NO grace period
Maximum Penalty
₹ 250 Crore per violation

Overall DPDP Readiness Score

2%
0.5 / 25 checkpoints
CRITICAL — Not Ready

Company C scores 2 out of 25 DPDP checkpoints. The company is in the earliest stages of building a payment platform and has near-zero DPDP compliance infrastructure.

DPDP Compliance Timeline

What's coming — and Company C isn't ready for any of it

Nov 13, 2025
Phase 1
Core definitions, Data Protection Board constitution, basic duties, grievance redress, transparency
NOT READY
Nov 13, 2026
Phase 2
Consent Manager registration opens, Board oversight
NOT READY
May 13, 2027
Phase 3 — FULL ENFORCEMENT
Standalone privacy notices, security safeguards, 72-hour breach reporting, data retention/erasure, cross-border, Data Principal rights, PENALTIES LIVE
NOT READY
Days remaining until full enforcement: ~418 days. Every day without action increases regulatory risk.

Detailed Gap Analysis — All 25 DPDP Checkpoints

Complete checkpoint-by-checkpoint assessment across 9 compliance categories

A. Governance & Leadership 0 / 4
#RequirementDPDPA SectionStatusGap
1Designate a Grievance Redressal Officer with published contactSection 13, Rule 6FAILNo grievance officer designated; no contact published
2Establish privacy governance framework with board accountabilitySection 8FAILNo evidence of privacy governance structure
3Create and maintain data protection policySection 8, Rule 8FAILNo data protection policy exists
4DPO appointment (if SDF)Section 10N/ANot yet SDF — but must plan for growth
B. Data Inventory & Mapping 0 / 4
#RequirementDPDPA SectionStatusGap
5Comprehensive personal data inventorySection 8FAILNo data inventory; PII found hardcoded in API responses (F18)
6Map all data flows: collection, processing, storage, sharingSection 8FAILNo data flow mapping; data flows through Vercel, Fastly, Linode, Razorpay — undocumented
7Classify data by purpose, sensitivity, retentionSection 8(7)FAILNo classification; founder PII treated same as public content
8Document all Data Processor relationshipsSection 8(2)FAILMultiple processors (Vercel, Fastly, Linode, Razorpay, Google Fonts, GitHub) — no documented contracts
C. Consent Management 0 / 4
#RequirementDPDPA SectionStatusGap
9Implement lawful basis for each processing activitySection 4, 5, 7FAILNo consent mechanism on any property
10Notice-and-consent mechanism (itemized, clear, plain language)Section 5, Rule 3FAILNo privacy notice anywhere
11Consent withdrawal mechanism (as easy as giving consent)Section 6(4), Rule 3(c)(i)FAILNo consent collection = no withdrawal possible
12Maintain auditable consent recordsRule 3FAILNo consent records exist
D. Privacy Notices 0 / 3
#RequirementDPDPA SectionStatusGap
13Standalone privacy notice (independently understandable)Section 5, Rule 3FAILPrivacy Policy link on site is non-functional (href="#") — identified in VAPT (F16)
14Itemized description of data collected, purposes, servicesSection 5FAILNo privacy notice content exists
15Notice in scheduled languagesRule 3FAILNo notice in any language
E. Security Safeguards 0.5 / 3
#RequirementDPDPA SectionStatusGap
16Reasonable technical & organizational security measuresSection 8(5), Rule 8FAILVAPT found 25 vulnerabilities including 4 CRITICAL; PII exposed in API; no auth on payment endpoints
17Encryption at rest and in transitRule 8PARTIALHTTPS/TLS in transit (PASS), but no evidence of at-rest encryption
18Access controls, logging, and monitoringRule 8FAILNo authentication on API endpoints (F21); no evidence of logging/monitoring
F. Data Retention & Erasure 0 / 2
#RequirementDPDPA SectionStatusGap
19Defined retention periods per data categorySection 8(7)FAILNo retention policy; PII hardcoded permanently in code
20Automated erasure when purpose fulfilled or consent withdrawnSection 8(7)FAILNo erasure mechanisms; data in static API responses
G. Breach Notification 0 / 2
#RequirementDPDPA SectionStatusGap
21Breach detection and response planSection 8(6), Rule 7FAILNo incident response plan; no security.txt (F17)
2272-hour notification to Board + Data Principal notificationRule 7FAILNo breach notification infrastructure
H. Cross-Border & Data Localization 0 / 2
#RequirementDPDPA SectionStatusGap
23Document cross-border transfersSection 16FAILData flows to Vercel (US), Fastly (global CDN), GitHub (US) — not documented
24RBI data localization (payment data in India)RBI PA GuidelinesFAILPayment API on Vercel (servers in US/India mixed); Linode servers may be outside India
I. Data Principal Rights 0 / 1
#RequirementDPDPA SectionStatusGap
25Mechanisms for Data Principals to exercise rights (access, correction, erasure)Sections 11-14FAILNo rights infrastructure; no user accounts; no self-service portal

DPDP Readiness Scorecard Summary

Category-by-category compliance scores

Governance & Leadership
0%
0 / 4 checkpoints
Data Inventory & Mapping
0%
0 / 4 checkpoints
Consent Management
0%
0 / 4 checkpoints
Privacy Notices
0%
0 / 3 checkpoints
Security Safeguards
17%
0.5 / 3 (partial TLS)
Data Retention & Erasure
0%
0 / 2 checkpoints
Breach Notification
0%
0 / 2 checkpoints
Cross-Border & Localization
0%
0 / 2 checkpoints
Data Principal Rights
0%
0 / 1 checkpoints
Total Score
0.5 / 25
Overall: 2%

VAPT Findings That Are DPDP Violations

Security vulnerabilities that directly constitute DPDPA violations

VAPT FindingDPDPA ViolationSectionExploitabilityPotential Penalty
F18 — PII hardcoded in API (name, phone, email, address) Failure to implement reasonable security safeguards Section 8(5)
Critical
Up to ₹250 crore
F19 — Wildcard CORS on API Failure to protect data from unauthorized access Section 8(5)
Critical
Up to ₹250 crore
F21 — Unauthenticated payment API Failure to implement security safeguards Section 8(5)
Critical
Up to ₹250 crore
F16 — No Privacy Policy Failure to provide privacy notice Section 5
High
Up to ₹50 crore
F17 — No security.txt No breach reporting mechanism Section 8(6)
High
Up to ₹200 crore
F02 — Wildcard subdomain Inadequate organizational security measures Section 8(5)
High
Up to ₹250 crore
F23 — Public GitHub repo Failure to protect against unauthorized data access Section 8(5)
Critical
Up to ₹250 crore
Combined maximum penalty exposure: ₹250 crore (penalties are per violation, capped at the schedule maximum).

DPDP Penalties Company C Faces

Potential financial exposure under the DPDPA penalty schedule

₹250 Crore
Failure to implement reasonable security safeguards resulting in breach
PII exposure (F18), no auth (F21), CORS wildcard (F19)
₹200 Crore
Failure to notify Board & Data Principals of breach
No breach notification plan, no security.txt
₹200 Crore
Breach of children's data obligations
No age verification if any user is under 18
₹50 Crore
Non-compliance with any other DPDPA provision
No privacy notice, no consent, no erasure, no rights mechanism

What Needs To Be Done — DPDP Compliance Roadmap

Phased action plan to reach compliance before May 2027 enforcement

P0 Phase 1: IMMEDIATE (0-30 days) — Stop the Bleeding 7 actions
#ActionPriorityEffort
1Remove PII from API responses immediatelyP01 hour
2Add authentication to all API endpointsP01 day
3Fix CORS configuration (restrict to specific origins)P01 hour
4Draft and publish Privacy PolicyP03-5 days
5Draft and publish Terms of ServiceP03-5 days
6Designate a Grievance Redressal OfficerP01 day
7Make GitHub repo privateP05 minutes
P1 Phase 2: SHORT-TERM (30-90 days) — Build Foundation 8 actions
#ActionPriorityEffort
8Conduct personal data inventory — map all data across all systemsP11-2 weeks
9Document all Data Processor relationships (Vercel, Fastly, Linode, Razorpay)P11 week
10Execute Data Processing Agreements (DPAs) with all processorsP12-3 weeks
11Implement consent management — collection, withdrawal, record-keepingP12-4 weeks
12Implement security headers (CSP, X-Frame-Options, etc.)P11 day
13Add rate limiting on all endpointsP11 day
14Set up security monitoring and loggingP11 week
15Create breach notification procedureP11 week
P2 Phase 3: MEDIUM-TERM (90-180 days) — Full Compliance Build 8 actions
#ActionPriorityEffort
16Build Data Principal rights portal (access, correction, erasure requests)P22-4 weeks
17Implement data retention policies with automated erasureP22 weeks
18Set up cookie consent banner (when cookies are used)P21 week
19Implement age verification (if platform could have users under 18)P22 weeks
20Conduct Data Protection Impact AssessmentP22-4 weeks
21Ensure RBI data localization — payment data stored only in IndiaP22 weeks
22Regular VAPT scans — ongoing vulnerability assessmentP2Ongoing
23Staff training on data protectionP21 week
P3 Phase 4: PRE-ENFORCEMENT (180-418 days) — Audit & Certify 5 actions
#ActionPriorityEffort
24Independent DPDP compliance auditP32-4 weeks
25PCI-DSS certification (for payment processing)P33-6 months
26Apply for RBI PA/PG licenseP3Ongoing
27SOC 2 Type II preparation (if targeting enterprise clients)P36-12 months
28Continuous compliance monitoringP3Ongoing

How Company A Helps Company C Achieve DPDP Compliance

Product mapping to Company C's specific DPDP gaps

Company A Product Mapping to Company C's DPDP Gaps
Company C DPDP GapCompany A SolutionHow It Helps
No security safeguards assessmentAutomated VAPT (45 min)AI-powered security scan identifies all vulnerabilities; maps each to DPDP Section 8(5) obligations
No DPDP compliance mappingDPDP Compliance ModuleAuto-maps every security finding to specific DPDPA sections and rules; generates compliance readiness score
No breach notification planBreach Detection AlertsContinuous monitoring alerts when new vulnerabilities appear; helps meet 72-hour notification requirement
Unknown attack surfaceSubdomain ReconnaissanceDiscovers all 12+ domains, exposed APIs, and shadow IT — exactly what our VAPT found
No security trainingHindi Phishing SimulationAI-generated phishing campaigns test team readiness in Hindi/Hinglish/English
No ongoing compliance monitoringMonthly Plan (3 reports/mo)Continuous reassessment ensures compliance doesn't degrade over time
No data processor oversightCloud Security ScanningAWS/GCP/Azure config scanning ensures processor environments are secure
No compliance documentationPDF Reports with DPDP MappingCourt-ready, auditor-friendly reports documenting security posture and compliance status
No dark web exposure checkDark Web MonitoringChecks if company-c.example.com data or credentials are exposed on dark web forums
Why Company A Over Alternatives
FactorCompany AEnterprise Tools (HackerOne, Qualys)Free Tools (Nmap, ZAP)
Price₹2,000 first report₹15K-50K/month₹0
DPDP MappingBuilt-in, automatedNot India-specificNone
Time to Report45 minutes2-4 weeksManual analysis
Target AudienceIndian SMBs, startups, fintechsFortune 500, regulated banksSecurity engineers only
LanguageEnglish + Hindi remediationEnglish onlyEnglish only
Compliance CoverageDPDPA + CERT-In + RBIGlobal frameworks (SOC2, ISO)None
Action RequiredDNS verification onlyAgent installation, credentialsManual setup
Recommended Company A Plan for Company C
PhaseCompany A ProductCostWhat You Get
NowFree DPDP Check + Free Scan₹0Baseline DPDP readiness score + top 5 findings
Week 1Full Report (one-time)₹2,000Complete VAPT with DPDP mapping, remediation steps, fix quotes
Month 1-3Starter Plan₹4,999/mo3 rescans/month to track remediation progress
Month 4+Growth Plan₹9,999/mo10 reports/month, API access, continuous monitoring, trend analysis
Total Year 1~₹1.1 lakhsComplete DPDP security compliance coverage
Compare: A single manual VAPT engagement costs ₹40K-8.5L and takes 2-4 weeks. Company A covers the full year for less than one manual assessment.

Start Your DPDP Compliance Journey

Get your free DPDP readiness check and security scan today. See exactly where you stand before enforcement begins.

Competitor Comparison: DPDP Compliance Products in India

14 products analyzed — full competitive landscape

Full Competitive Landscape — 14 Products 14 analyzed
#ProductCompanyTypeIndia-Built?Free TierStarting PriceBest For
1Company ACompany A, BengaluruVAPT + DPDP ComplianceYesFree scan₹2,000/report; ₹4,999/moSMB fintechs, startups
2ConcurConcur, IndiaPrivacy & Consent PlatformYes20K data principals free₹84,000/yr (~₹7K/mo)Startups to enterprise
3ConsentinLeegality, IndiaConsent ManagementYes3,000 consents/mo freeCustom SaaS/on-premBFSI, e-commerce, lending
4PrivyIDfy, IndiaConsent + Data GovernanceYesNoCustom (on AWS Marketplace)Enterprise, regulated
5ConsentlyConsently, IndiaConsent HandlingYes1-month free trialPay-per-consentAny Indian business
6DPDPA ShieldDPDPA Shield Pvt Ltd, DelhiFull DPDP ComplianceYesStarter tierContact salesIndian startups by stage
7QverLabsQverLabs, IndiaAI Compliance PlatformYesNoCustomBFSI, healthcare, SaaS
8SeqriteQuick Heal (listed), IndiaPrivacy + SecurityYesNoCustom enterpriseEnterprises with Seqrite stack
9Ardent PrivacyArdent Privacy, IndiaData Discovery + PrivacyYesNoCustomEnterprise (HDFC, HPCL, Zee)
10CookieYesCookieYes (India-origin)Cookie ConsentYes5K pageviews/mo free$10/mo (~₹850) per domainAny website
11OneTrustOneTrust, USA ($5.1B)Full Privacy PlatformNo (adapted)No~$50K+/yr (~₹42L+)Multinational enterprise
12Securiti.aiSecuriti, USAData IntelligenceNo (adapted)No~$30K+/yr (~₹25L+)Complex data environments
13PrivacyEnginePrivacyEngine, IrelandPrivacy OperationsNo (adapted)NoCustomSDFs, DPOs, CISOs
14TsaaroTsaaro Consulting, IndiaConsulting + DPO-as-a-ServiceYesNo₹1-5L/engagementMid-market (Adani, NPCI, CRED)
Detailed Feature Comparison — 17 Features x 7 Products Feature Matrix
FeatureCompany AConcurConsentinDPDPA ShieldQverLabsOneTrustSecuriti
VAPT Security Scanning Yes No No No No No No
DPDP Compliance Mapping Yes Yes Yes Yes Yes Yes Yes
Consent Management Roadmap Yes Yes Yes Yes Yes Yes
Data Discovery Partial Yes Yes (Lens) No Yes (AI) Yes Yes
DSAR/Rights Portal Roadmap Yes Yes Yes Yes Yes Yes
Breach Notification Yes Yes Yes Yes (72hr) Yes Yes Yes
Cookie Consent No No Yes No No Yes Yes
22 Indian Languages No No Yes Yes Yes No No
Children's Data Module No Yes No Yes Yes Yes Yes
DPIA Automation No Yes Yes Yes Yes Yes Yes
Phishing Simulation Yes (Hindi) No No No No No No
Dark Web Monitoring Yes No No No No No No
RBI/SEBI Alignment Yes No No No No No Partial
On-Premises Option No No Yes No No Yes Yes
API Access Yes Yes Yes Yes Yes Yes Yes
Report in 45 min Yes N/A N/A N/A N/A N/A N/A
Free Tier Yes Yes (best) Yes Starter No No No
Price Comparison — Annual Cost for a Startup like Company C Cost Analysis
ProductAnnual Cost (INR)What You GetValue Rating
CookieYes~₹10K-50KCookie consent banners onlyLow (narrow scope)
Company A (Starter)~₹60K3 VAPT/mo + DPDP mapping + remediationBest for security-first
Concur (Growth)~₹84KConsent + data discovery + DSAR (50K principals)Best for consent-first
Company A (Growth)~₹1.2L10 VAPT/mo + API + monitoring + trendsBest comprehensive
Tsaaro~₹1-5L/engagementOne-time consulting assessmentModerate (not continuous)
Consentin (Leegality)~₹1-3LConsent lifecycle + data discoveryGood for BFSI
DPDPA ShieldCustomFull DPDP compliance suiteGood for startups
Sprinto~₹8-15LSOC2/ISO + DPDP add-onExpensive for DPDP-only
OneTrust~₹42L+Everything (100+ regulations)Overkill for startups
Securiti.ai~₹25L+Enterprise data intelligenceOverkill for startups
Manual VAPT~₹40K-8.5L per testSingle point-in-time assessmentPoor (not continuous)

Annual Cost Comparison (Visual)

CookieYes
₹10K-50K
Company A Starter
₹60K
Concur (Growth)
₹84K
Company A Growth
₹1.2L
Tsaaro
₹1-5L
Consentin
₹1-3L
Sprinto
₹8-15L
Manual VAPT
₹40K-8.5L / test
Securiti.ai
₹25L+
OneTrust
₹42L+
Value Matrix — Cost vs. Coverage Strategic View
Coverage Depth →
Low Cost ←——————————————→ High Cost
Security + Compliance (VAPT + DPDP + Continuous)
Company A Growth (₹1.2L)
Only product with VAPT + DPDP
High Cost Enterprise
OneTrust (₹42L+)
Securiti.ai (₹25L+)
PrivacyEngine (Custom)
Partial / Some Coverage
Company A Starter (₹60K)
Concur (₹84K)
Consentin (₹1-3L)
DPDPA Shield (Custom)
QverLabs (Custom)
Consently (Pay-per-consent)
High Cost / Partial
Sprinto (₹8-15L)
Seqrite (Custom)
Ardent Privacy (Custom)
CookieYes (₹10-50K)
Tsaaro (₹1-5L)
What Makes Company A Unique in This Market 7 Differentiators
Only Company A

VAPT + DPDP in One Platform

No other product combines security scanning with DPDP compliance mapping. Every competitor is either security-only or compliance-only.

Only Company A

45-Minute Report Delivery

All competitors are manual (weeks) or consent-only (no scanning). Company A delivers a full VAPT + DPDP report in 45 minutes.

Only Company A

Hindi Phishing Simulation

No other platform offers Indian-language phishing tests. AI-generated campaigns in Hindi/Hinglish/English.

Lowest Entry Price

₹2,000 Entry Price

Concur is ₹84K/yr; most others are custom/enterprise pricing. Company A starts at ₹2,000 for a full report.

Unique at This Price

Dark Web Monitoring

Enterprise-only feature at SMB pricing. Checks if your data or credentials are exposed on dark web forums.

Only Company A

RBI + SEBI + CERT-In Alignment

Consent platforms don't cover regulatory security mandates. Company A maps to RBI, SEBI, and CERT-In requirements.

Only Company A

No Credentials Needed

DNS-only verification; competitors often need agent installation, credentials, or complex onboarding.

For Company C specifically: Company A is the only product that addresses both the security vulnerabilities (25 findings from VAPT) AND the DPDP compliance gaps (25 checkpoints) in a single platform at startup pricing. A consent-only tool like Concur or Consentin won't fix the CRITICAL security issues. An enterprise tool like OneTrust costs 35x more.

See How Company A Stacks Up — Free

Run your free DPDP check now and compare the results with any competitor. No credit card, no agent installation, just DNS verification.

Key DPDPA Reference

Penalty schedule, Data Principal rights, and fintech-specific dual compliance requirements

Penalty Schedule
ViolationMax Penalty
Failure to implement security safeguards (breach)₹250 crore
Failure to notify Board & Data Principals of breach₹200 crore
Breach of children's data obligations₹200 crore
Breach of SDF obligations₹150 crore
Any other DPDPA non-compliance₹50 crore
Data Principal Rights (What Users Can Demand)
RightSectionWhat Company C Must Provide
Right to AccessSection 11Summary of all data processed, who it's shared with
Right to CorrectionSection 12Fix inaccurate/incomplete data
Right to ErasureSection 12Delete data when purpose served or consent withdrawn
Right to Grievance RedressalSection 13Accessible complaint mechanism
Right to NominateSection 14Designate someone for post-death data rights
Right to Withdraw ConsentSection 6(4)As easy as giving consent
Fintech-Specific Dual Compliance (DPDPA + RBI)
RequirementDPDPARBI
Data localizationNegative list (no restricted countries yet)Mandatory — all payment data in India
ConsentDPDPA consent frameworkKYC consent per RBI norms
RetentionErase when purpose served10-year retention for payment records
Breach notification72 hours to BoardRBI incident reporting requirements
Security standards"Reasonable safeguards"IS audit, VAPT mandatory for PA/PG
Net worthN/A₹15 crore (application), ₹25 crore (3rd year)

Don't Wait for Enforcement — Act Now

Company C has 418 days to go from 2% to full DPDP compliance. The penalty for inaction is up to ₹250 crore. Start with a free scan today.