Data Niyam

Data Niyam · DPDP ReadyCheck

Know exactly where you stand on the DPDP Act, 2023.

A structured readiness assessment that scores your organisation across ten compliance domains, quantifies your risk, and hands you a prioritised roadmap — delivered on the DICE Framework, from a first look to a board-ready programme.

10 assessment domains4 engagement tiersDICE methodologyBFSI · Healthcare · NBFC · GCC · SME
D

Discover

Scope the estate, map obligations, and discover what personal data you hold and where it lives.
I

Inspect

Evidence current controls, interview owners, and see how data actually flows and is protected today.
C

Control

Score gaps, rank risk, and put the notices, records and policies in place that close them.
E

Evolve

Stand up the operating model, embed controls, and stay audit-ready as the DPDP Rules land.

Choose your starting point

Four ReadyCheck plans, one framework

Each tier goes further along the DICE lifecycle. Start where you are today — a lighter tier can always graduate into a fuller programme without losing the work already done.

RC-01

Essentials

Micro & small businesses taking their first structured look at DPDP.

499/ assessment
DICE
  • Guided maturity self-assessmentStructured questionnaire across all 10 domains
  • Readiness scorecardSingle maturity score with a domain-level gap heatmap
  • Top-10 priority actionsThe highest-impact fixes, plainly ranked

Mode: Remote, self-guided
Timeline: 1–2 weeks
Effort on you: Light

Start Essentials
Most popularRC-02

Pro

Growing single-entity firms that need evidence, not just a self-rating.

Bespoke
DICE
  • Everything in Essentials
  • Evidence-based control reviewDocuments and artefacts assessed against each domain
  • Stakeholder interviewsStructured sessions with key function owners
  • Risk register & scoringLikelihood-impact scoring with exposure view
  • Executive dashboardOne-page posture for leadership
  • 90-day remediation roadmapSequenced, owner-tagged actions

Mode: Facilitated, remote + interviews
Timeline: 3–4 weeks
Effort on you: Moderate

Start Pro
RC-03

Pro Plus

Regulated & multi-department orgs — NBFCs, healthcare, mid-market.

Bespoke
DICE
  • Everything in Pro
  • Data flow mappingHow personal data moves across systems and parties
  • Records of processing (RoPA)Built and populated for your estate
  • Notice & consent artefact reviewAgainst DPDP notice and consent standards
  • Policy gap analysisExisting policies mapped to obligations
  • DPIA template + one worked sample
  • Vendor / processor risk matrixDPA and third-party exposure
  • Board-ready report

Mode: On-site option + workshops
Timeline: 6–8 weeks
Effort on you: Structured

Discuss Pro Plus
RC-04

Enterprise

Enterprise Data Governance & Privacy

Large & multi-entity organisations, BFSI, GCCs and Significant Data Fiduciaries.

Powered by the DICE Model™ — DEFINE → INGEST → CURATE → EVOLVE

Bespoke
DICE
  • Everything in Pro Plus
  • Enterprise Data GovernanceData discovery, inventory, ownership, classification & lifecycle governance
  • Multi-entity & multi-location governanceUnified governance across subsidiaries, business units & geographies
  • Data Quality, Metadata & LineageCritical data elements, quality governance, business glossary & lineage
  • DPDP, Privacy & Regulatory GovernanceDPDP, GDPR, RBI & sector-specific obligations mapped to controls
  • Full DICE implementation roadmapPrioritised roadmap with target governance operating model
  • Risk, Vendor & Third-Party GovernanceData-sharing, processors, vendors & third-party controls
  • Control framework & capability buildingPolicies, standards, roles, controls & organisation-wide training
  • Audit & certification readinessEvidence-ready governance aligned to ISO 27701 / ISO 42001
  • Ongoing advisoryOptional retainer for continuous Data Governance, Privacy & Regulatory advisory

Mode: Programme, on-site + retainer
Timeline: 6 to 8 months, then ongoing
Effort on you: Programme-led

Talk to usDownload Enterprise PDF

What each tier covers

The ten domains, tier by tier

Every ReadyCheck touches all ten DPDP domains — the depth is what changes. A full mark is hands-on assessment and deliverables; a half mark is a lighter, high-level review.

Assessment domainEssentialsRC-01ProRC-02Pro PlusRC-03EnterpriseRC-04
01Notice & Consent
02Lawful Processing & Purpose Limitation
03Data Principal Rights & Grievance
04Data Inventory & Flow Mapping
05Data Minimisation & Retention
06Security Safeguards
07Personal Data Breach Management
08Processor & Third-Party Management
09Children's & Special-Category Data
10Governance & Accountability (DPO, DPIA, audit)
Hands-on assessment & deliverables High-level review Not in scope for this tier

The engagement

How a ReadyCheck runs

The same disciplined path every time — the DICE Framework — scaled to the tier you choose.

01

Discover & scope

Agree the estate, entities and obligations in play, and discover what personal data exists across them.

02

Inspect & evidence

Gather artefacts and interview owners to see how controls actually work today, domain by domain.

03

Control & report

Score gaps into a ranked risk view, and set the controls in motion in an executive-ready report.

04

Evolve & sustain

Hand over a sequenced remediation plan — and, at higher tiers, help you stand the programme up.

Not sure which tier fits?

Tell us your sector, size and where you are on DPDP today. We'll point you to the right ReadyCheck — no pressure to go bigger than you need.

Book a readiness conversation

Data Niyam · Powered by the DICE Framework · Discover · Inspect · Control · Evolve

Pricing shown is indicative and confirmed at engagement scoping. Enterprise is quoted per organisation.