Privacy education, consultancy & implementation, in 50+ jurisdictions.contact@vedhacon.com
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
Tools & templates

Working templates you can fill in and export

Practical, interactive toolkits — including a contract-analysis demo, readiness checker, DPIA and RoPA templates. The templates stay on your device; the contract demo uses anonymised sample data to show how a secure SharePoint or cloud-connected deployment can work.

Contract intelligence demo

Analyse contracts and surface obligations instantly

See how Vedhacon can deploy a customised Contract Control Tower for Data Processing Agreements, mutual MSAs and SOE/SOW documents covering data processors and principals.

Launch demo

Upload up to 10 contracts

Run a one-off review or group documents account-wise. The demo simulates PDF and DOCX ingestion without transmitting real contracts.

Instant structured analysis

Extract roles, processing terms, security duties, liability, indemnity, termination, evidence gaps and operational obligations.

SharePoint or cloud deployment

Connect a document library or approved cloud repository, update portfolio data in real time, and send an analysis summary by email.

Demonstration environment. It uses anonymised sample data. A production deployment can be configured to your contract types, clause library, approval workflow, security model, retention rules and reporting requirements.
Free diagnostic · No sign-up

Check your readiness in 10 minutes

An 18-question self-assessment across eight privacy domains. Every answer maps to a control, a risk rating and a suggested remediation order — so you leave with a plan, not just a score.

~10 minutes Runs in your browser
18Questions
8Domains covered
5Maturity levels
0Data leaves device

18-question diagnostic

Scope, lawful basis, notice, consent, rights, retention, transfers and breach in one pass.

Prioritised roadmap

Every answer maps to a control, with a risk rating and a suggested order of remediation.

No sign-up, nothing stored

Runs entirely in your browser, in line with our own privacy notice.

What the diagnostic covers

The eight domains assessed, the questions in each, and the maturity signal they produce.

1

Governance & accountability

3 questions

Ownership, DPO/Data Protection Officer role, policy set and board reporting

Reference: DPDP s.8 · GDPR Art.5(2), 24
Typical gap: No named accountable owner
2

Records & data mapping

2 questions

Whether processing is inventoried, classified and kept current

Reference: GDPR Art.30
Typical gap: RoPA missing or stale
3

Notice & transparency

2 questions

Clarity, completeness and accessibility of privacy notices

Reference: DPDP s.5 · GDPR Art.12-14
Typical gap: Notices not layered or outdated
4

Lawful basis & consent

3 questions

Basis selection, consent capture, proof and withdrawal

Reference: DPDP s.6 · GDPR Art.6-7
Typical gap: Consent not independently evidenced
5

Data subject rights

2 questions

Intake, identity checks, turnaround and audit trail

Reference: DPDP s.11-13 · GDPR Art.15-22
Typical gap: No logged SLA or workflow
6

Retention & minimisation

2 questions

Schedules, defensible periods and actual deletion

Reference: GDPR Art.5(1)(c),(e)
Typical gap: Schedule exists but is not enforced
7

Security & breach

2 questions

Controls, detection, and statutory notification readiness

Reference: DPDP s.8(5-6) · GDPR Art.32-34
Typical gap: No rehearsed 72-hour drill
8

Third parties & transfers

2 questions

Due diligence, contracts and cross-border mechanisms

Reference: GDPR Art.28, 44-49
Typical gap: Sub-processors untracked
8 domains18 questions5 maturity levelsDPDP Act 2023 & EU/UK GDPRRuns entirely in your browser
Maturity signal — every answer returns one of five levels
0Not startedNo control in place
1Ad hocInformal, undocumented
2DefinedDocumented and agreed
3ManagedMonitored with evidence
4OptimisedReviewed and improving

Domain scores roll up to an overall readiness band: Critical (0-24%), Developing (25-49%), Adequate (50-74%) or Strong (75-100%).

Critical0-24%
Developing25-49%
Adequate50-74%
Strong75-100%
Data Protection Impact Assessment

Data Protection Impact Assessment (DPIA)

A structured, regulator-ready assessment of high-risk processing — from necessity and proportionality through to residual risk sign-off.

DPDP Act 2023 GDPR Art. 35-36

Aligned to the Digital Personal Data Protection Act 2023 & DPDP Rules 2025 (India) and EU/UK GDPR Articles 35-36.

Complete every field. Grey cells are auto-calculated. Your entries auto-save in this browser.

DPIA worksheet

Sections 1-18 cover screening, necessity, risk analysis and sign-off. Complete top to bottom.

1. Document control
2. Project overview
FieldResponseGuidance
Project / System NameFull name of the initiative, product or system under assessment
Business OwnerAccountable business leader who owns the processing
Processor / Vendor(s)All third parties processing data on your behalf; list each separately
Go-Live DatePlanned production date; DPIA must complete before this
Project Description2-4 sentences: what the project does and why it is needed
Scope & BoundariesWhat is in scope and explicitly out of scope for this DPIA
Is this a new or changed processing activity?New system, new purpose, new data type, or material change
Estimated volume of data subjectsApproximate number of individuals affected
3. DPIA necessity / threshold assessment
#Trigger QuestionResponseNotes / Justification
1Does the processing involve large-scale processing of personal data?
2Does it involve sensitive personal data, financial, health, genetic or biometric data?
3Does it involve systematic monitoring, tracking or profiling of individuals?
4Does it involve automated decision-making with legal or similarly significant effects?
5Does it involve children's data or data of persons with disability?
6Does it involve cross-border transfer of personal data outside India?
7Does it use new or innovative technology (AI/ML, facial recognition, IoT)?
8Does it involve matching, combining or enriching datasets from multiple sources?
9Could it prevent data subjects from exercising a right or accessing a service?
10Is the organisation a Significant Data Fiduciary under DPDP Sec 10?
DPIA REQUIRED?
4. Processing activity details
FieldResponseGuidance
Processing PurposeState the specific, lawful purpose. Vague purposes fail DPDP Sec 5 notice tests
Consent (Sec 6) or a Certain Legitimate Use (Sec 7)
GDPR Lawful Basis (if EU/UK subjects)Select Art 6 basis; Art 9 condition also needed for special category
Processing Categories / OperationsCollection, storage, use, sharing, analysis, erasure etc.
How consent is captured, itemised, logged and withdrawn
Retention Period & JustificationDuration and the legal/business reason. DPDP requires erasure on purpose completion
Data Minimisation MeasuresHow you ensure only necessary data is collected
Notice / Privacy Policy ReferenceLink or document reference to the notice given to data principals
5. Personal data inventory
Data CategoryCollected?Specific Data ElementsSourceStorage LocationRetention PeriodEncryption at Rest / TransitAccess Restricted To
Basic Identifiers (name, DOB, gender)
Contact Details (email, phone, address)
Government IDs (Aadhaar, PAN, Passport)
Financial Data (bank, card, salary)
Health Data
Biometric Data
Genetic Data
Location Data
Online Identifiers / Cookies
Behavioural / Profiling Data
Employee / HR Data
Children's Data (under 18)
Criminal Convictions
Other (specify)
6. Data subjects
Data Subject CategoryIn Scope?Estimated VolumeVulnerable Group?Notice Provided?Consent Obtained?Special Considerations
Customers
Employees
Job Applicants
Contractors
Vendors / Suppliers
Minors (under 18)
Persons with Disability
Website Visitors
Prospects
General Public
7. Cross border transfers
Destination CountryRecipient EntityData Categories TransferredPurpose of TransferTransfer MechanismDPDP Sec 16 Permitted?Safeguards AppliedTransfer Risk
8. Technology landscape
System / ApplicationRole (Fiduciary/Processor)Hosting ModelData ResidencyVendor NameDPA / Contract in Place?Security CertificationNotes
9. Data flow mapping
StepStageDescription of FlowData CategoriesFrom (Source)To (Destination)Transfer MethodControls Applied
1Collection
2Transmission
3Storage
4Processing / Use
5Sharing / Disclosure
6Archival
7Deletion / Erasure
10. Privacy principles assessment
PrincipleRequirementCompliance StatusEvidence / JustificationGap IdentifiedAction Required
LawfulnessValid legal basis exists under DPDP Sec 6/7 and GDPR Art 6
FairnessProcessing does not cause unjustified detriment to data principals
TransparencyClear, itemised notice given in plain language and 22 scheduled languages
Purpose LimitationData used only for the specified purpose notified to the data principal
Data MinimisationOnly data necessary for the purpose is collected and retained
AccuracyData is correct, complete and kept up to date; correction process exists
Storage Limitation / RetentionData erased once purpose is served, unless law requires retention
Security (Integrity & Confidentiality)Reasonable security safeguards per DPDP Sec 8(5) and Rule 6
AccountabilityDocumented evidence of compliance; DPO appointed where required
11. Risk assessment matrix

The full risk register is maintained in the Privacy Risk Register below. Summary counts update automatically.

Total RisksCriticalHighMediumLowHighest Residual RiskRisks Requiring Treatment
000000
12. Data subject / data principal rights review
RightStatutory ReferenceSupported?How It Is Fulfilled (Process/System)Response SLAOwnerEvidenceGap / Action
Right to Access InformationDPDP Sec 11 / GDPR Art 15
Right to Correction & UpdatingDPDP Sec 12 / GDPR Art 16
Right to ErasureDPDP Sec 12 / GDPR Art 17
Right to Grievance RedressalDPDP Sec 13 / GDPR Art 77
Right to NominateDPDP Sec 14
DPDP Sec 6(4) / GDPR Art 7(3)
Right to Data PortabilityGDPR Art 20
Right to Object / Restrict ProcessingGDPR Art 18 & 21
Rights re Automated Decision-MakingGDPR Art 22
13. Security controls assessment
Control DomainControl RequirementStatusDescription of Control ImplementedOwnerLast TestedEvidenceGap / Action
Access ControlRole-based access, least privilege, periodic access reviews
EncryptionEncryption at rest and in transit (TLS 1.2+, AES-256)
Pseudonymisation / MaskingObfuscation or tokenisation of identifiers where feasible
Logging & MonitoringAccess logs retained minimum 1 year per DPDP Rule 6
Backup & RecoveryTested backups, defined RTO/RPO
Vulnerability ManagementPatching cadence, VAPT frequency
Breach Detection & ResponseDetection tooling and documented incident response plan
Breach Notification ReadinessNotify principals without delay; Board within 72 hours (Rule 7)
Secure DevelopmentSecure SDLC, code review, privacy by design
Physical SecurityData centre and office physical access controls
Data DisposalSecure erasure and certificate of destruction
Business ContinuityBCP/DR plan covering personal data systems
14. Third party / processor risk assessment
Vendor / ProcessorService ProvidedData SharedLocationValid Contract / DPA?Due Diligence CompletedSub-processors Approved?Residual Vendor Risk
15. AI / automated decision-making review
#QuestionResponseDetails / Mitigation
1Is automated decision-making or profiling used in this processing?
2
3Is meaningful information about the logic involved disclosed to data subjects?
4Is there a human-in-the-loop review or appeal mechanism?
5Has the model been tested for bias, fairness and discriminatory outcomes?
6Is training data lawfully sourced with an appropriate legal basis?
7Is model accuracy monitored and are outcomes auditable?
8Are AI-specific risks recorded in the Risk Register?
16. Residual risk acceptance
FieldEntryGuidance
Overall Residual Risk Rating
Auto-derived from the highest residual risk in the Risk Register
Is residual risk acceptable to the business?If No, processing must not proceed until mitigated
Justification for AcceptanceBusiness rationale for accepting the residual risk
Conditions / Compensating ControlsAny conditions attached to the acceptance
Accepted By (Name & Role)Must be the accountable risk owner
Acceptance DateDate of formal risk acceptance
Prior Consultation with Board/Regulator Required?Required where high risk cannot be mitigated (GDPR Art 36)
17. DPO sign-off
FieldEntryGuidance
DPO NameData Protection Officer resident in India (DPDP Sec 10 for SDF)
DPO RecommendationApprove / Approve with Conditions / Reject / Defer
DPO CommentsSubstantive commentary on residual risk and conditions
Conditions ImposedAny mandatory conditions before go-live
Sign-Off DateDate of DPO decision
18. Executive approval
FieldEntryGuidance
Approver NameSenior executive accountable for the processing
DesignationJob title of the approving executive
Approval DecisionFinal go / no-go decision
Approval CommentsAny executive-level caveats
Approval DateDate of final approval
Scheduled Review DateDPIA must be reviewed on material change or annually

Saved to this browser.

Privacy risk register

Inherent and Residual Risk = Impact x Likelihood, rated Low (1-4), Medium (5-9), High (10-16), Critical (17-25). The starter risks below are editable — amend or delete as needed.

Risk IDPrivacy Risk DescriptionRisk CategoryAffected PrincipleImpactLikelihoodInherent ScoreInherent RiskMitigation / Treatment PlanControl OwnerTarget DateResidual ImpactResidual LikelihoodResidual ScoreResidual Risk

Saved to this browser.

GDPR Article 30 · DPDP Act 2023 · Global privacy compliance

Interactive RoPA compliance dashboard

A live management view calculated from the Processing Register, organisation settings and subprocessor controls.

COMPLIANCE DASHBOARD

Record of Processing Activities

Live from register · Generated

0%overall
compliance
Total activities0
Compliance score0%
Open gaps0
Critical + high risk0

Key metrics

GDPR Article 30 / multi-law checklist

RequirementStatusReference
Checklist items passed0 of 13
Compliance percentage0%

Processing register

Complete one row per processing activity. Dashboard results update instantly as fields change.

0 activities
Process IDStatusIndustry SectorBusiness FunctionProcessing Activity NamePurpose of ProcessingDetailed DescriptionProcessing RoleData Subject CategoriesPersonal Data CategoriesSpecial Category DataVolume of RecordsData ClassificationCollection MethodData SourceLegal Basis (GDPR)Legal Basis (DPDP 2023)Legal Basis (Other Laws)Legitimate Interest Assessment RefConsent MechanismConsent Withdrawal MethodInternal RecipientsExternal RecipientsProcessor / Vendor NameSub-Processors UsedJoint ControllerCross-Border TransferTransfer Destination CountryTransfer MechanismSCC / TIA ReferenceRetention PeriodRetention JustificationDisposal MethodSecurity ControlsAutomated Decision MakingProfilingDPIA StatusDPIA ReferenceData Subject Rights SupportedBreach Notification ContactReview FrequencyLast ReviewedNext Review DueProcess OwnerRisk LevelCompleteness %Action

Saved to this browser.

This dashboard calculates live from the Processing Register, subprocessor controls and organisation settings. Compliance tool only — not legal advice.

Third-party privacy due diligence

Global Vendor Privacy Assessment

Deployment dashboard • live from assessment, evidence, action, and jurisdiction registers. Every figure below is calculated from your responses — nothing is pre-scored.

Ready-to-deploy template available on request

A configured, ready-to-deploy version of this Global Vendor Privacy Assessment — including the 66-control register, evidence tracker, action log and jurisdiction matrix — can be requested from enquiry@vedhacon.com. Mention your industry and the jurisdictions in scope and the pack will be tailored before despatch.

Deployment dashboard

Live from assessment, evidence, action, and jurisdiction registers

Saved
Assessment completion0%0 of 0 applicable controls answered
Weighted compliance0%Criticality-weighted control score
Open control gaps0Answered “No” or “Partial”
Evidence ready0%0 of 0 artifacts current
Applicable laws0Confirmed in scope
Overdue actions0Past target remediation date
Assessment decisionPendingDerived from score, gaps and evidence
High-risk unassessed0High-criticality controls with no response

Domain performance

Control coverage and compliance by assessment domain

DomainControlsAssessedCompliance

Global deployment coverage

Jurisdiction register status

Universal themes0
Registered laws0
Validated laws0
Legal review pending0

Use Legal Overlay for every newly introduced national, state, provincial, sectoral, employment, health, financial, children’s, biometric, cybersecurity, or AI requirement before deployment.

Attention queue

Items blocking a deployment decision

ItemCountRequired response

Vendor snapshot

Identity and current standing

Vendor
Service
RiskMedium
DecisionPending

Readiness note: This dashboard is decision support. Final legal applicability and approval remain with the accountable Privacy / Legal owner.

1. Vendor profile

Identifies the assessed party and the processing in scope

2. Control register — 66 controls across 9 domains

Mark each control Yes / Partial / No / Not applicable. The dashboard recalculates instantly.

IDControl requirementCriticalityResponseEvidence referenceNotes

3. Evidence register

Artifacts must be current and reviewable before closure

RefArtifactDomainStatusValid untilOwner

4. Action log

Remediation tracked to a named owner and target date

ActionSeverityOwnerTarget dateStatus

5. Jurisdiction register

Applicability must be confirmed by Privacy / Legal — laws left as TBD are counted as review pending

CodeLaw / frameworkJurisdictionTypeApplicability

This dashboard calculates live from the control, evidence, action and jurisdiction registers. Compliance tool only — not legal advice.

Assurance & internal audit

PRIVACY COMPLIANCE AUDIT DASHBOARD

A 107-control audit programme across 11 domains with live maturity scoring, compliance status breakdown, findings management and audit readiness indicators.

Request the ready-to-deploy template

This dashboard is interactive and runs entirely in your browser. For the full working Excel and Power BI audit template — including the scoping sheet, evidence index and CAPA tracker — email enquiry@vedhacon.com and our team will share a version configured to your audit universe.

Complete the Scoping section to populate engagement details

Audit scope, entity, period and lead auditor drive the header, the readiness indicators and every export produced from this page.

Overall maturity0.00Weighted mean across 11 domains
Compliance score0.0%Weighted score against maximum
Controls in scope107Applicable audit controls
Assessed0Controls with a recorded result
Open findings0Findings not yet closed
Critical gaps0Critical-risk open findings

1. Audit scoping

Domain maturity scorecard

Weighted score against maximum attainable, per audit domain

11 domains
DomainControlsAssessedWeightedMaxMaturityCompliance %

Compliance status breakdown

Distribution of results across the audit scope

0.0%Overall compliance score
StatusCount% of scope

Findings by risk rating

Open versus closed audit findings

0 findings
Risk ratingOpenClosedTotal

Audit readiness indicators

Programme health signals derived from the register

IndicatorValueRating

Critical control gaps (top 10)

Highest-weighted controls failing or unassessed

Ctrl IDControlStatus

Domain maturity heatmap

Weighted maturity 0–5 for each of the 11 domains, with assessment coverage and open findings

11 domains
<1.5 Initial1.5–2.4 Developing2.5–3.4 Defined3.5–4.4 Managed4.5+ Optimised

2. Control assessment register

107 controls
IDControl requirementCrit.StatusMaturityEvidence refOwnerFinding riskFinding stateNotes
Scores update live as results are recorded. Weighted score = Σ(criticality weight × maturity 0–5); Max score = Σ(weight × 5). Controls marked Not Applicable are removed from both the score and the denominator. Maturity is the weighted score expressed back on the 0–5 scale.
Horizon scanning

Regulatory tracker

Amendments, commencements and enforcement trends across the jurisdictions you operate in — with the status, effective date and the action each change demands of you.

10 jurisdictions Reviewed quarterly
10Jurisdictions tracked
12Instruments monitored
4Status categories
QReview cadence

Horizon scan — key instruments

Status as at Q3 2026. Filter by status to focus your remediation planning.

JurisdictionInstrumentStatusEffective / expectedWhat it changesAction required

Horizon-scanning summary for planning purposes and not legal advice. Confirm obligations against the official text before acting.

Speak up — stay safe

Whistleblower & fraud reporting

Report suspected fraud, misconduct or a policy violation — confidentially, anonymously if you prefer, and without fear of retaliation. Every report receives a tracking reference so you can follow progress.

Anonymous option Confidential
24hAcknowledgement target
8Report categories
0Retaliation tolerated
IDTracking reference issued

Fill in the online form

Complete a structured intake form. Choose an anonymous or a named submission and attach supporting evidence.

Track an existing report

Already submitted? Enter your tracking reference to check the current status and any response.

Scan & report

Scan the Vedhacon QR with any phone camera to open this secure intake channel — useful for posters, notice boards and shop floors.

Fraud & misconduct report

Nothing leaves your browser until you press submit. Fields marked * are required.

Your details
About the concern
Supporting files

Click to choose files or drag them here — up to 5 files, 10 MB each.

    Vedhacon prohibits retaliation against anyone who raises a concern in good faith. Reports are handled by the ethics team on a strict need-to-know basis and retained in line with our retention schedule.

    Track a report

    Enter the reference issued when you submitted your report.

    Status lookups run against the ethics case management system once the reporting endpoint is configured for your tenant.

    Scan & report

    Point any phone camera at the code — no app and no login required.

    QR code linking to the Vedhacon confidential fraud reporting channel Scan to report
    1. Open your phone camera and hold it over the code. Tap the link that appears — nothing needs to be installed.
    2. Choose named or anonymous. If you pick anonymous, no name, email, phone or device identifier is recorded with your report.
    3. Describe the concern and attach any supporting evidence, up to 5 files of 10 MB each.
    4. Save the reference you are given. It is the only way to follow up on an anonymous report.
    Direct link

    The QR resolves to the same confidential intake channel as the form above. Scans are not logged against individuals and the code carries no reporter identifier — it is safe to print on posters and share openly.

    Report received

    Keep the reference below — it is the only way to follow up on an anonymous report.

    VED-000000

    Acknowledgement target: 24 hours.

    More toolkits

    The rest of the library

    Six further registers, playbooks and evidence packs that plug into the same control set — available on request as editable workbooks.

    Request the full pack

    Regulatory tracker

    Horizon scanning of amendments and commencements across the jurisdictions you operate in.

    Vendor questionnaire

    Due-diligence set for processors, sub-processors and cross-border recipients.

    Breach register & playbook

    Log, assess and notify within statutory windows, with role assignments.

    Transfer route finder

    Mechanisms and assessments for cross-border transfers.

    Audit evidence pack

    Checklist mapping controls to ISO/IEC 27001, 27701 and 42001 evidence.

    Put the tools to work

    Want these tailored to your stack?

    We can adapt every template to your systems, vendors and jurisdictions, and train your team to maintain them.

    Talk to a consultant