Working templates you can fill in and export
Practical, interactive toolkits — including a contract-analysis demo, readiness checker, DPIA and RoPA templates. The templates stay on your device; the contract demo uses anonymised sample data to show how a secure SharePoint or cloud-connected deployment can work.
Analyse contracts and surface obligations instantly
See how Vedhacon can deploy a customised Contract Control Tower for Data Processing Agreements, mutual MSAs and SOE/SOW documents covering data processors and principals.
Upload up to 10 contracts
Run a one-off review or group documents account-wise. The demo simulates PDF and DOCX ingestion without transmitting real contracts.
Instant structured analysis
Extract roles, processing terms, security duties, liability, indemnity, termination, evidence gaps and operational obligations.
SharePoint or cloud deployment
Connect a document library or approved cloud repository, update portfolio data in real time, and send an analysis summary by email.
Check your readiness in 10 minutes
An 18-question self-assessment across eight privacy domains. Every answer maps to a control, a risk rating and a suggested remediation order — so you leave with a plan, not just a score.
18-question diagnostic
Scope, lawful basis, notice, consent, rights, retention, transfers and breach in one pass.
Prioritised roadmap
Every answer maps to a control, with a risk rating and a suggested order of remediation.
No sign-up, nothing stored
Runs entirely in your browser, in line with our own privacy notice.
What the diagnostic covers
The eight domains assessed, the questions in each, and the maturity signal they produce.
Governance & accountability
3 questionsOwnership, DPO/Data Protection Officer role, policy set and board reporting
Records & data mapping
2 questionsWhether processing is inventoried, classified and kept current
Notice & transparency
2 questionsClarity, completeness and accessibility of privacy notices
Lawful basis & consent
3 questionsBasis selection, consent capture, proof and withdrawal
Data subject rights
2 questionsIntake, identity checks, turnaround and audit trail
Retention & minimisation
2 questionsSchedules, defensible periods and actual deletion
Security & breach
2 questionsControls, detection, and statutory notification readiness
Third parties & transfers
2 questionsDue diligence, contracts and cross-border mechanisms
Domain scores roll up to an overall readiness band: Critical (0-24%), Developing (25-49%), Adequate (50-74%) or Strong (75-100%).
Data Protection Impact Assessment (DPIA)
A structured, regulator-ready assessment of high-risk processing — from necessity and proportionality through to residual risk sign-off.
Aligned to the Digital Personal Data Protection Act 2023 & DPDP Rules 2025 (India) and EU/UK GDPR Articles 35-36.
Complete every field. Grey cells are auto-calculated. Your entries auto-save in this browser.
DPIA worksheet
Sections 1-18 cover screening, necessity, risk analysis and sign-off. Complete top to bottom.
| Field | Response | Guidance |
|---|---|---|
| Project / System Name | Full name of the initiative, product or system under assessment | |
| Business Owner | Accountable business leader who owns the processing | |
| Processor / Vendor(s) | All third parties processing data on your behalf; list each separately | |
| Go-Live Date | Planned production date; DPIA must complete before this | |
| Project Description | 2-4 sentences: what the project does and why it is needed | |
| Scope & Boundaries | What is in scope and explicitly out of scope for this DPIA | |
| Is this a new or changed processing activity? | New system, new purpose, new data type, or material change | |
| Estimated volume of data subjects | Approximate number of individuals affected |
| # | Trigger Question | Response | Notes / Justification |
|---|---|---|---|
| 1 | Does the processing involve large-scale processing of personal data? | ||
| 2 | Does it involve sensitive personal data, financial, health, genetic or biometric data? | ||
| 3 | Does it involve systematic monitoring, tracking or profiling of individuals? | ||
| 4 | Does it involve automated decision-making with legal or similarly significant effects? | ||
| 5 | Does it involve children's data or data of persons with disability? | ||
| 6 | Does it involve cross-border transfer of personal data outside India? | ||
| 7 | Does it use new or innovative technology (AI/ML, facial recognition, IoT)? | ||
| 8 | Does it involve matching, combining or enriching datasets from multiple sources? | ||
| 9 | Could it prevent data subjects from exercising a right or accessing a service? | ||
| 10 | Is the organisation a Significant Data Fiduciary under DPDP Sec 10? |
| Field | Response | Guidance |
|---|---|---|
| Processing Purpose | State the specific, lawful purpose. Vague purposes fail DPDP Sec 5 notice tests | |
| DPDP Legal Basis (India) | Consent (Sec 6) or a Certain Legitimate Use (Sec 7) | |
| GDPR Lawful Basis (if EU/UK subjects) | Select Art 6 basis; Art 9 condition also needed for special category | |
| Processing Categories / Operations | Collection, storage, use, sharing, analysis, erasure etc. | |
| Consent Mechanism & Record | How consent is captured, itemised, logged and withdrawn | |
| Retention Period & Justification | Duration and the legal/business reason. DPDP requires erasure on purpose completion | |
| Data Minimisation Measures | How you ensure only necessary data is collected | |
| Notice / Privacy Policy Reference | Link or document reference to the notice given to data principals |
| Data Category | Collected? | Specific Data Elements | Source | Storage Location | Retention Period | Encryption at Rest / Transit | Access Restricted To |
|---|---|---|---|---|---|---|---|
| Basic Identifiers (name, DOB, gender) | |||||||
| Contact Details (email, phone, address) | |||||||
| Government IDs (Aadhaar, PAN, Passport) | |||||||
| Financial Data (bank, card, salary) | |||||||
| Health Data | |||||||
| Biometric Data | |||||||
| Genetic Data | |||||||
| Location Data | |||||||
| Online Identifiers / Cookies | |||||||
| Behavioural / Profiling Data | |||||||
| Employee / HR Data | |||||||
| Children's Data (under 18) | |||||||
| Criminal Convictions | |||||||
| Other (specify) |
| Data Subject Category | In Scope? | Estimated Volume | Vulnerable Group? | Notice Provided? | Consent Obtained? | Special Considerations |
|---|---|---|---|---|---|---|
| Customers | ||||||
| Employees | ||||||
| Job Applicants | ||||||
| Contractors | ||||||
| Vendors / Suppliers | ||||||
| Minors (under 18) | ||||||
| Persons with Disability | ||||||
| Website Visitors | ||||||
| Prospects | ||||||
| General Public |
| Destination Country | Recipient Entity | Data Categories Transferred | Purpose of Transfer | Transfer Mechanism | DPDP Sec 16 Permitted? | Safeguards Applied | Transfer Risk |
|---|
| System / Application | Role (Fiduciary/Processor) | Hosting Model | Data Residency | Vendor Name | DPA / Contract in Place? | Security Certification | Notes |
|---|
| Step | Stage | Description of Flow | Data Categories | From (Source) | To (Destination) | Transfer Method | Controls Applied |
|---|---|---|---|---|---|---|---|
| 1 | Collection | ||||||
| 2 | Transmission | ||||||
| 3 | Storage | ||||||
| 4 | Processing / Use | ||||||
| 5 | Sharing / Disclosure | ||||||
| 6 | Archival | ||||||
| 7 | Deletion / Erasure |
| Principle | Requirement | Compliance Status | Evidence / Justification | Gap Identified | Action Required |
|---|---|---|---|---|---|
| Lawfulness | Valid legal basis exists under DPDP Sec 6/7 and GDPR Art 6 | ||||
| Fairness | Processing does not cause unjustified detriment to data principals | ||||
| Transparency | Clear, itemised notice given in plain language and 22 scheduled languages | ||||
| Purpose Limitation | Data used only for the specified purpose notified to the data principal | ||||
| Data Minimisation | Only data necessary for the purpose is collected and retained | ||||
| Accuracy | Data is correct, complete and kept up to date; correction process exists | ||||
| Storage Limitation / Retention | Data erased once purpose is served, unless law requires retention | ||||
| Security (Integrity & Confidentiality) | Reasonable security safeguards per DPDP Sec 8(5) and Rule 6 | ||||
| Accountability | Documented evidence of compliance; DPO appointed where required |
The full risk register is maintained in the Privacy Risk Register below. Summary counts update automatically.
| Total Risks | Critical | High | Medium | Low | Highest Residual Risk | Risks Requiring Treatment |
|---|---|---|---|---|---|---|
| 0 | 0 | 0 | 0 | 0 | — | 0 |
| Right | Statutory Reference | Supported? | How It Is Fulfilled (Process/System) | Response SLA | Owner | Evidence | Gap / Action |
|---|---|---|---|---|---|---|---|
| Right to Access Information | DPDP Sec 11 / GDPR Art 15 | ||||||
| Right to Correction & Updating | DPDP Sec 12 / GDPR Art 16 | ||||||
| Right to Erasure | DPDP Sec 12 / GDPR Art 17 | ||||||
| Right to Grievance Redressal | DPDP Sec 13 / GDPR Art 77 | ||||||
| Right to Nominate | DPDP Sec 14 | ||||||
| Right to Withdraw Consent | DPDP Sec 6(4) / GDPR Art 7(3) | ||||||
| Right to Data Portability | GDPR Art 20 | ||||||
| Right to Object / Restrict Processing | GDPR Art 18 & 21 | ||||||
| Rights re Automated Decision-Making | GDPR Art 22 |
| Control Domain | Control Requirement | Status | Description of Control Implemented | Owner | Last Tested | Evidence | Gap / Action |
|---|---|---|---|---|---|---|---|
| Access Control | Role-based access, least privilege, periodic access reviews | ||||||
| Encryption | Encryption at rest and in transit (TLS 1.2+, AES-256) | ||||||
| Pseudonymisation / Masking | Obfuscation or tokenisation of identifiers where feasible | ||||||
| Logging & Monitoring | Access logs retained minimum 1 year per DPDP Rule 6 | ||||||
| Backup & Recovery | Tested backups, defined RTO/RPO | ||||||
| Vulnerability Management | Patching cadence, VAPT frequency | ||||||
| Breach Detection & Response | Detection tooling and documented incident response plan | ||||||
| Breach Notification Readiness | Notify principals without delay; Board within 72 hours (Rule 7) | ||||||
| Secure Development | Secure SDLC, code review, privacy by design | ||||||
| Physical Security | Data centre and office physical access controls | ||||||
| Data Disposal | Secure erasure and certificate of destruction | ||||||
| Business Continuity | BCP/DR plan covering personal data systems |
| Vendor / Processor | Service Provided | Data Shared | Location | Valid Contract / DPA? | Due Diligence Completed | Sub-processors Approved? | Residual Vendor Risk |
|---|
| # | Question | Response | Details / Mitigation |
|---|---|---|---|
| 1 | Is automated decision-making or profiling used in this processing? | ||
| 2 | Does the decision produce legal or similarly significant effects on individuals? | ||
| 3 | Is meaningful information about the logic involved disclosed to data subjects? | ||
| 4 | Is there a human-in-the-loop review or appeal mechanism? | ||
| 5 | Has the model been tested for bias, fairness and discriminatory outcomes? | ||
| 6 | Is training data lawfully sourced with an appropriate legal basis? | ||
| 7 | Is model accuracy monitored and are outcomes auditable? | ||
| 8 | Are AI-specific risks recorded in the Risk Register? |
| Field | Entry | Guidance |
|---|---|---|
| Overall Residual Risk Rating | — | Auto-derived from the highest residual risk in the Risk Register |
| Is residual risk acceptable to the business? | If No, processing must not proceed until mitigated | |
| Justification for Acceptance | Business rationale for accepting the residual risk | |
| Conditions / Compensating Controls | Any conditions attached to the acceptance | |
| Accepted By (Name & Role) | Must be the accountable risk owner | |
| Acceptance Date | Date of formal risk acceptance | |
| Prior Consultation with Board/Regulator Required? | Required where high risk cannot be mitigated (GDPR Art 36) |
| Field | Entry | Guidance |
|---|---|---|
| DPO Name | Data Protection Officer resident in India (DPDP Sec 10 for SDF) | |
| DPO Recommendation | Approve / Approve with Conditions / Reject / Defer | |
| DPO Comments | Substantive commentary on residual risk and conditions | |
| Conditions Imposed | Any mandatory conditions before go-live | |
| Sign-Off Date | Date of DPO decision |
| Field | Entry | Guidance |
|---|---|---|
| Approver Name | Senior executive accountable for the processing | |
| Designation | Job title of the approving executive | |
| Approval Decision | Final go / no-go decision | |
| Approval Comments | Any executive-level caveats | |
| Approval Date | Date of final approval | |
| Scheduled Review Date | DPIA must be reviewed on material change or annually |
Saved to this browser.
Privacy risk register
Inherent and Residual Risk = Impact x Likelihood, rated Low (1-4), Medium (5-9), High (10-16), Critical (17-25). The starter risks below are editable — amend or delete as needed.
| Risk ID | Privacy Risk Description | Risk Category | Affected Principle | Impact | Likelihood | Inherent Score | Inherent Risk | Mitigation / Treatment Plan | Control Owner | Target Date | Residual Impact | Residual Likelihood | Residual Score | Residual Risk |
|---|
Saved to this browser.
Interactive RoPA compliance dashboard
A live management view calculated from the Processing Register, organisation settings and subprocessor controls.
Record of Processing Activities
Live from register · Generated —
compliance
Key metrics
GDPR Article 30 / multi-law checklist
| Requirement | Status | Reference |
|---|
Processing register
Complete one row per processing activity. Dashboard results update instantly as fields change.
| Process ID | Status | Industry Sector | Business Function | Processing Activity Name | Purpose of Processing | Detailed Description | Processing Role | Data Subject Categories | Personal Data Categories | Special Category Data | Volume of Records | Data Classification | Collection Method | Data Source | Legal Basis (GDPR) | Legal Basis (DPDP 2023) | Legal Basis (Other Laws) | Legitimate Interest Assessment Ref | Consent Mechanism | Consent Withdrawal Method | Internal Recipients | External Recipients | Processor / Vendor Name | Sub-Processors Used | Joint Controller | Cross-Border Transfer | Transfer Destination Country | Transfer Mechanism | SCC / TIA Reference | Retention Period | Retention Justification | Disposal Method | Security Controls | Automated Decision Making | Profiling | DPIA Status | DPIA Reference | Data Subject Rights Supported | Breach Notification Contact | Review Frequency | Last Reviewed | Next Review Due | Process Owner | Risk Level | Completeness % | Action |
|---|
Saved to this browser.
This dashboard calculates live from the Processing Register, subprocessor controls and organisation settings. Compliance tool only — not legal advice.
Global Vendor Privacy Assessment
Deployment dashboard • live from assessment, evidence, action, and jurisdiction registers. Every figure below is calculated from your responses — nothing is pre-scored.
A configured, ready-to-deploy version of this Global Vendor Privacy Assessment — including the 66-control register, evidence tracker, action log and jurisdiction matrix — can be requested from enquiry@vedhacon.com. Mention your industry and the jurisdictions in scope and the pack will be tailored before despatch.
Deployment dashboard
Live from assessment, evidence, action, and jurisdiction registers
Domain performance
Control coverage and compliance by assessment domain
| Domain | Controls | Assessed | Compliance |
|---|
Global deployment coverage
Jurisdiction register status
Use Legal Overlay for every newly introduced national, state, provincial, sectoral, employment, health, financial, children’s, biometric, cybersecurity, or AI requirement before deployment.
Attention queue
Items blocking a deployment decision
| Item | Count | Required response |
|---|
Vendor snapshot
Identity and current standing
Readiness note: This dashboard is decision support. Final legal applicability and approval remain with the accountable Privacy / Legal owner.
1. Vendor profile
Identifies the assessed party and the processing in scope
2. Control register — 66 controls across 9 domains
Mark each control Yes / Partial / No / Not applicable. The dashboard recalculates instantly.
| ID | Control requirement | Criticality | Response | Evidence reference | Notes |
|---|
3. Evidence register
Artifacts must be current and reviewable before closure
| Ref | Artifact | Domain | Status | Valid until | Owner |
|---|
4. Action log
Remediation tracked to a named owner and target date
| Action | Severity | Owner | Target date | Status |
|---|
5. Jurisdiction register
Applicability must be confirmed by Privacy / Legal — laws left as TBD are counted as review pending
| Code | Law / framework | Jurisdiction | Type | Applicability |
|---|
This dashboard calculates live from the control, evidence, action and jurisdiction registers. Compliance tool only — not legal advice.
PRIVACY COMPLIANCE AUDIT DASHBOARD
A 107-control audit programme across 11 domains with live maturity scoring, compliance status breakdown, findings management and audit readiness indicators.
This dashboard is interactive and runs entirely in your browser. For the full working Excel and Power BI audit template — including the scoping sheet, evidence index and CAPA tracker — email enquiry@vedhacon.com and our team will share a version configured to your audit universe.
Audit scope, entity, period and lead auditor drive the header, the readiness indicators and every export produced from this page.
1. Audit scoping
Domain maturity scorecard
Weighted score against maximum attainable, per audit domain
| Domain | Controls | Assessed | Weighted | Max | Maturity | Compliance % |
|---|
Compliance status breakdown
Distribution of results across the audit scope
| Status | Count | % of scope |
|---|
Findings by risk rating
Open versus closed audit findings
| Risk rating | Open | Closed | Total |
|---|
Audit readiness indicators
Programme health signals derived from the register
| Indicator | Value | Rating |
|---|
Critical control gaps (top 10)
Highest-weighted controls failing or unassessed
| Ctrl ID | Control | Status |
|---|
Domain maturity heatmap
Weighted maturity 0–5 for each of the 11 domains, with assessment coverage and open findings
2. Control assessment register
| ID | Control requirement | Crit. | Status | Maturity | Evidence ref | Owner | Finding risk | Finding state | Notes |
|---|
Regulatory tracker
Amendments, commencements and enforcement trends across the jurisdictions you operate in — with the status, effective date and the action each change demands of you.
Horizon scan — key instruments
Status as at Q3 2026. Filter by status to focus your remediation planning.
| Jurisdiction | Instrument | Status | Effective / expected | What it changes | Action required |
|---|
Horizon-scanning summary for planning purposes and not legal advice. Confirm obligations against the official text before acting.
Whistleblower & fraud reporting
Report suspected fraud, misconduct or a policy violation — confidentially, anonymously if you prefer, and without fear of retaliation. Every report receives a tracking reference so you can follow progress.
Fill in the online form
Complete a structured intake form. Choose an anonymous or a named submission and attach supporting evidence.
Track an existing report
Already submitted? Enter your tracking reference to check the current status and any response.
Scan & report
Scan the Vedhacon QR with any phone camera to open this secure intake channel — useful for posters, notice boards and shop floors.
Fraud & misconduct report
Nothing leaves your browser until you press submit. Fields marked * are required.
Click to choose files or drag them here — up to 5 files, 10 MB each.
Vedhacon prohibits retaliation against anyone who raises a concern in good faith. Reports are handled by the ethics team on a strict need-to-know basis and retained in line with our retention schedule.
Track a report
Enter the reference issued when you submitted your report.
Status lookups run against the ethics case management system once the reporting endpoint is configured for your tenant.
Scan & report
Point any phone camera at the code — no app and no login required.
Scan to report
- Open your phone camera and hold it over the code. Tap the link that appears — nothing needs to be installed.
- Choose named or anonymous. If you pick anonymous, no name, email, phone or device identifier is recorded with your report.
- Describe the concern and attach any supporting evidence, up to 5 files of 10 MB each.
- Save the reference you are given. It is the only way to follow up on an anonymous report.
The QR resolves to the same confidential intake channel as the form above. Scans are not logged against individuals and the code carries no reporter identifier — it is safe to print on posters and share openly.
Report received
Keep the reference below — it is the only way to follow up on an anonymous report.
Acknowledgement target: 24 hours.
The rest of the library
Six further registers, playbooks and evidence packs that plug into the same control set — available on request as editable workbooks.
Consent register
Capture, evidence and withdraw consent with a defensible audit trail. CSV-ready columns: subject, purpose, timestamp, method, status, withdrawal.
Regulatory tracker
Horizon scanning of amendments and commencements across the jurisdictions you operate in.
Vendor questionnaire
Due-diligence set for processors, sub-processors and cross-border recipients.
Breach register & playbook
Log, assess and notify within statutory windows, with role assignments.
Transfer route finder
Mechanisms and assessments for cross-border transfers.
Audit evidence pack
Checklist mapping controls to ISO/IEC 27001, 27701 and 42001 evidence.
Want these tailored to your stack?
We can adapt every template to your systems, vendors and jurisdictions, and train your team to maintain them.
Talk to a consultant