The most frequent compliance gaps we find during readiness assessments — and how to close them before they cost you.
Penalties under the DPDP Act can reach up to ₹250 Crore per instance, and the gaps that trigger them are rarely exotic. In readiness assessments across enterprises of varying size, the same handful of issues come up again and again.
1. No real data inventory
Many organizations can describe their data practices in a policy document but can't actually point to where every category of personal data lives across systems, spreadsheets, and vendor platforms.
2. Consent that doesn't hold up
Pre-Act consent flows often bundle multiple purposes into a single checkbox, which no longer satisfies the requirement for specific, purpose-limited consent.
3. Weak breach response timelines
The Act expects prompt notification to the Data Protection Board and affected individuals. Organizations without a tested incident response plan routinely miss this window simply due to unclear internal ownership.
4. Unvetted vendors and processors
A compliance program is only as strong as its weakest data processor. Vendor contracts that don't include DPDP-aligned data handling clauses are a recurring finding.
5. Security safeguards that exist on paper only
Reasonable security safeguards must be implemented and demonstrable — not just referenced in a policy. Gaps between documented controls and actual technical implementation are one of the most cited issues in assessments.