YOUR EVIDENCE notice-v1.0.pdf sha256 d1912fe5… consent-log.csv row 2 · withdrawn 2026-03-01 crm-retention.csv email · 540 days UNTRUSTED_DATA · hashed DETERMINISTIC CONTROLS 23 controls · 8 domains notice vs collection withdrawal vs processing policy vs actual retention erasure vs deletion proof processor vs contract same evidence → same answer, every time FINDINGS 11 exceptions each citing an evidence id 2 partial 2 effective 7 NOT TESTED awaiting a verified legal source THE RULE An untested control is not a pass. Coverage is stated as a fraction of every control in scope — not of the ones that concluded. EVIDENCE → ASSESSMENT → FINDINGS → GAPS → ACTION

DPDP Assessment: Evidence First, Conclusions Second

Most privacy tooling asks a model whether you comply. DPDP Assessment does the opposite: it reads your evidence, runs twenty-three controls written as ordinary code, and tells you what it could not test.

It runs inside the AI Assistant, on your device by default.

The DPDP Problem

A privacy assessment fails in two directions. Ask a model and you get fluent conclusions that change between runs. Build a spreadsheet and you get consistency with no reading of the evidence.

The harder problem is that India's DPDP regime commences in phases. A rule that exists is not necessarily a rule that binds you today — and a tool that cannot tell the difference will produce findings against provisions nobody has to follow yet.

What It Actually Does

You supply evidence. It produces findings, each citing the evidence behind it.

  • Twenty-three controls across notice and consent, inventory and purpose, rights, retention and erasure, processors, children, significant data fiduciary, and breach readiness.
  • Nine contradiction detectors that compare one piece of evidence against another.
  • A twenty-column workpaper and an Evidence Passport a third party can re-verify.

Conclusions come from predicates, not prompts. Every control is a function over normalised evidence. Given the same files it returns the same answer today, next quarter, and in front of a regulator. A model may extract and explain; it cannot conclude, and an interpretation that contradicts the predicate is discarded and recorded as an override attempt.

Run the Assessment

Open /ai-assistant.html and select DPDP Assessment from the mode list.

  1. Run the worked example (synthetic) — a complete assessment with no real personal data, to see the output shape before using your own.
  2. Load assessment JSON — your own inventory, consent records, retention rules and incidents.
  3. Read the banner first. It says whether statutory testing is active.
  4. Work down: blockers, contradictions, then the eight control domains.
  5. Download workpaper (CSV) or Evidence Passport (JSON).

There is an Ask about this assessment box. It routes questions to deterministic queries — "why is DPDP-RET-01 an exception?" is answered from the result, not from a model. Ask it something it cannot check and it refuses, listing what it can answer instead.

Evidence, Not Recollection

Every uploaded file is classified UNTRUSTED_DATA before anything reads it, and hashed with SHA-256. Eight injection patterns are neutralised in place and recorded — a privacy notice that tries to instruct the assistant is itself a finding, not an instruction.

The rule that shapes the whole evidence layer is this: a fact nobody can go and check is indistinguishable from one the model imagined.

FOUR KINDS OF STATEMENT EVIDENCE Located in a file. Page, row, quote, artefact hash. Can close a control INFERENCE Reasoned, not observed. Marked INFERRED with a basis. Never reads as fact UNVERIFIABLE Model-extracted with no location, or OCR read too poorly. Refused at creation GAP The evidence is simply absent. EVIDENCE_REQUIRED. Named, never a pass

A model-extracted fact without a page or row reference is refused at the point of creation, not filtered later. So is one that does not name the model that produced it. Low-confidence OCR cannot close a control; it asks for the page to be re-read.

Read the Findings

Each control returns one of eight results, and the distinction that matters most is between a conclusion and an absence of one.

  • Exception — the evidence contradicts the organisation's own position.
  • Partially effective — no breach found, but something was not assessed.
  • Effective — no exception found, with evidence cited.
  • NOT TESTED — evidence required, legal source unverified, or not testable as specified.

An untested control is not a pass. The chip count, the cover note and the workpaper all say so in those words, and coverage is reported as conclusive results over every control in scope. A dashboard that counts "we could not test it" as green is the most common way compliance tooling lies without stating a single falsehood.

Contradictions

Nine detectors compare evidence against evidence, with both sides and their evidence ids. On the worked example they find nine, including:

  • The notice omits three categories the product collects.
  • A principal withdrew consent in March; a processor record shows activity in August.
  • Policy says 90 days; the database holds 540.
  • A consent record cites a notice version that does not exist.
  • The inventory says no children's data, and the product collects date of birth.

Every one is deterministic. A contradiction a model found is one that changes between runs.

Two Separate Questions

This is the part most tools collapse, and it is where statutory findings go wrong.

SOURCE AUTHORITY “Is this the real document?” Hashed on import. A named person attests they opened the official source and compared it. OBLIGATION INTERPRETATION “What does it require?” The AI proposes, quoting the text verbatim. A named person accepts it, provision by provision. ≠ Passing the first grants nothing towards the second

A verified PDF does not make a model's reading of it correct. In the Obligation review bench, the AI reads a verified instrument and proposes obligations — source on the left with the quotation highlighted, proposal on the right. Each proposal must quote the instrument verbatim; a paraphrase, however accurate, is rejected automatically because it cannot be located in the text.

Nothing becomes testable until a named person accepts it. system, admin and AI are refused as verifiers — the tool cannot verify its own legal sources, because everything it could compare a document against is that same document.

Statutory Testing Is Off

The assistant ships in a state it states plainly at the top of every assessment:

STATUTORY TESTING NOT ACTIVE. DPDP statutory obligation testing is currently unavailable because an authoritative legal pack has not been activated. Internal privacy-control consistency testing remains available.

The reason is specific. The DPDP Rules text could not be retrieved from an official source: MeitY's document paths return 403 to non-interactive clients, and India Code did not respond. What was retrieved — a Press Information Bureau note, hashed and dated — is recorded as a tier-2 press source, not as the Gazette. It supports three instrument-level facts and zero obligations.

So seven of the twenty-three controls report LEGAL_REVIEW_REQUIRED, each naming the document that would unblock it. Their predicates are already written and tested; they are waiting on a source, not on code.

The other sixteen work today, because their standard is your own stated position compared against your own evidence. They need no statute — and they are reported as internal control consistency, never as statutory breach. The engine enforces that in code: a non-statutory finding using words like "violation" or "unlawful" is flagged as a wording defect.

From Finding to Action

Result What it means Next step
ExceptionYour evidence contradicts your own positionFix the process, or correct the record
PartialSomething could not be measuredSupply the missing measurement
Evidence requiredThe input is absent, and it is namedGather and re-run
Legal review requiredNo verified obligation to test againstImport and verify the instrument

The blockers panel groups untested controls by the document that would unblock them — "retrieve this one source and four controls become testable" is a more useful backlog than four separate blockers.

What It Does Not Mean

Taken verbatim from the workpaper the tool produces:

  • No statutory conclusion is expressed while the legal pack is empty.
  • Internal-consistency exceptions are findings about internal consistency, not determinations of statutory breach.
  • The workpaper has not been reviewed by a qualified person. It is a machine-prepared working paper, not legal advice.
  • The Evidence Passport establishes that files hash to the listed values. It is not a signature and does not establish that the evidence is complete or genuine.

Running an assessment does not make an organisation DPDP compliant. It tells you what your evidence says, what it contradicts, and what you have not yet shown.

Try It

Open the AI Assistant, choose DPDP Assessment, and run the worked example. It contains no real personal data and takes a few seconds — enough to see whether the output is the kind your team would defend in a review.

FAQ

What is DPDP Assessment?

A mode in the NextGen GRC AI Assistant that runs twenty-three privacy controls over your evidence and produces findings, contradictions, a workpaper and an evidence passport.

What do I need to provide?

An assessment JSON describing collection, notices, consents, retention, processors, rights requests and incidents. The worked example shows the shape and requires nothing of your own.

Does it decide whether I comply with the DPDP Act?

No. Statutory testing is inactive until an authoritative legal pack is imported and verified. What runs today compares your statements against your evidence.

Can it find gaps?

Yes, and it names them. A control with missing input returns EVIDENCE_REQUIRED listing exactly what is absent, and a conclusion citing no evidence is downgraded automatically.

Does my evidence leave the device?

Not on the default engine. The assistant runs on-device unless you explicitly select cloud inference, and no DPDP module makes a network call of its own.

How do I turn on statutory testing?

Import the official instrument under Legal pack, complete the verification attestation, then accept obligations one at a time in the review bench. Testing then covers only the obligations you accepted.

Run it yourself

Open the AI Assistant, choose DPDP Assessment in the mode list, and run the worked example. It uses synthetic data, needs no setup, and shows the output before you point it at anything of your own.

Open DPDP Assessment →