DPDPA
DPDPA Compliance
The Digital Personal Data Protection Act puts consent and data principal rights at the centre, which makes it a governance problem before it is a technical one: who collected what, on what basis, whether that basis can be evidenced, and what happens when a data principal asks. The engagement works the obligations through to controls that can be demonstrated.
Methodology
- 01
Identify data
Establish what personal data the organisation holds.
- 02
Map flows
Map how it moves, inside the organisation and out of it.
- 03
Identify processing
Identify the processing activities those flows serve.
- 04
Determine obligations
Determine which DPDPA obligations attach to them.
- 05
Assess gaps
Assess the gap between those obligations and current practice.
- 06
Implement
Implement the governance and controls that close it.
- 07
Validate
Validate that they operate, not only that they exist.
- 08
Monitor
Keep them monitored, because consent and rights are continuous obligations.
Approach to testing
- Requirement — what does the applicable standard, regulation or framework require?
- Control — what control has the organisation established?
- Implementation — how is the control actually implemented?
- Evidence — what evidence demonstrates that the control operates?
- Risk — what happens if the control is ineffective or absent?
- Action — what needs to be changed?
- Validation — has the corrective action actually addressed the issue?
Types of assessment
Black-Box
Assessment begins with limited organisational information, to provide an independent perspective of the governance environment.
Grey-Box
Selected organisational documentation, process information and evidence are provided for structured assessment.
White-Box
Full documentation, evidence, stakeholder and process access is provided for detailed control validation.
Hybrid
Combines independent assessment techniques with detailed evidence and stakeholder validation.
Frameworks and standards
- Digital Personal Data Protection Act
- The regulation assessed against.
- Applicable Rules / regulatory requirements
- The rules made under the Act, as they apply to the organisation.
- ISO/IEC 27701
- Privacy information management alignment.
- ISO/IEC 29134
- Privacy impact assessment methodology.
- CSS DPDPA Toolkit
- The toolkit the engagement is run from.
Tools used
Tooling is where testing starts, not where it ends. Every automated result is reproduced by hand before it reaches a report.
CSS DPDPA Toolkit
Obligation mapping, consent governance review and gap assessment.
GRC Assessment Toolkit
Gap assessment, evidence assessment and remediation tracking.
PlyoGRC
Where appropriate, the toolkits are supported through PlyoGRC for control, evidence, risk and compliance management.
Checklist approach
The checklist is the floor, not the ceiling. It guarantees coverage so nothing standard is missed; the findings that matter usually come from what a tester does after it is complete.
Data governance
- Personal data inventory
- Data flow mapping
- Processing activity mapping
- Data classification
- Data lifecycle mapping
- Data retention and deletion
Consent governance
- Consent collection
- Consent records
- Consent management
- Consent withdrawal
- Consent evidence
- Consent notice review
- Consent manager governance
- Consent lifecycle management
Data principal rights
- Access / information requests
- Correction
- Erasure
- Grievance management
- Rights request workflows
Organisational governance
- Data fiduciary / processor governance
- Privacy roles and responsibilities
- Privacy policies and notices
- Vendor / processor governance
- Data processing agreements
- Cross-border data governance
- Personal data breach governance
- Privacy incident management
- Retention and deletion governance
Risk and assurance
- Privacy risk assessment
- DPIA / PIA
- Control gap assessment
- Evidence assessment
- Compliance readiness
How CSS tests
A unified swarm of agents, for blind spot detection
AI agents drive several testing tracks against the same target at once, then cross-check each other. A single tester works one hypothesis at a time; parallel agents cover the space a sequential pass leaves behind.
Framework Mapping Agent — maps requirements and controls across applicable frameworks.
Policy Analysis Agent — identifies potential missing, inconsistent or outdated requirements.
Evidence Analysis Agent — associates evidence with applicable controls and identifies evidence gaps.
Risk Analysis Agent — identifies recurring risk themes and potential control weaknesses.
Blind-Spot Detection Agent — looks for issues that may not be immediately visible through conventional checklist assessment.
Executive Reporting Agent — helps transform detailed assessment information into concise management reporting.
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
Why this differs
What CSS does that most vendors do not
Every one of these is checkable. Ask any vendor for the same and compare the answers.
Beyond the checklist
Structured checklists and framework mappings establish coverage, but the assessment continues through implementation, evidence, risk, action and validation.
Consent treated as evidence, not a banner
Consent collection, records, withdrawal, notices and the consent manager are governed as a lifecycle, because under the Act the burden is on demonstrating the basis, not on having asked.
Operating control, not documentation only
Evidence is validated across five stages: Designed — is it appropriately designed? Implemented — has it been implemented? Operating — is it actually performed? Evidenced — can operation be shown? Effective — is it achieving its goal?
Human-in-the-loop AI assistance
AI-assisted analysis supports the assessment team but does not replace professional judgement. Material findings, risk conclusions and recommendations are reviewed and validated by CyberSmithSECURE professionals.
What you receive
A working management system, not a folder of documents
The target state is that owners know what they must do, management knows what decisions are pending, and evidence exists to demonstrate that controls operate. Outputs are grouped by who uses them.
Executive layer
Scope, risk posture, roadmap, management decisions, KPI/KRI, readiness summary
GRC layer
Risk register, Statement of Applicability, policies, procedures, ownership, evidence map, action tracker
Assurance layer
Internal audit, findings, CAPA, management review, certification-readiness assessment
Operational layer
Control records, recurring reviews, awareness, supplier / access / incident / continuity evidence as applicable
Governance cadence established
- Monthly
- Risk / action review, evidence status, control exceptions, material incidents
- Quarterly
- Risk trend, supplier / control reviews, KPI/KRI, management action tracking
- Annual
- Internal audit programme, management review, ISMS objectives, risk refresh, improvement plan
For this engagement specifically
- Control owners
- IT teams
- Security teams
- Compliance teams
- Process owners
- Auditors
- Key risks
- Significant gaps
- Business impact
- Priority actions
- Ownership
- Target timelines
Case studies
What this finds in practice
Representative engagement patterns. Sector and scale only — no client is named, and no detail is included that could identify one.
An organisation handling the personal data of individuals in India, requiring a structured approach to DPDPA-aligned governance and controls.
- Finding
- The organisation needed to translate India's Digital Personal Data Protection Act, 2023 into practical governance, documentation and operational controls. Personal data handling was not consistently inventoried, rights-handling processes were informal, and there was no structured way to evidence compliance ahead of the applicable timelines.
- Recommendation
- Inventory personal data and map processing activities and flows; draft DPDPA-aligned privacy policies, notices and procedures; build workflows for access, correction, erasure and consent withdrawal; assess processing activities against DPDPA requirements; and review processor arrangements and safeguards against the obligations they carry.
- Outcome
- An operational DPDPA-aligned privacy framework, structured handling of data rights requests, and an evidence-ready posture ahead of the deadlines. Delivered as a DPDPA gap assessment, a data inventory and mapping, privacy policies and a rights-request workflow.
Next
Scope this assessment
Most scopes are settled in one call. Tell us what the application does and who uses it, and we will tell you what testing it properly involves.