DPDP Assessment: Evidence First, Conclusions Second
Most privacy tooling asks a model whether you comply. DPDP Assessment does the opposite: it reads your evidence, runs twenty-three controls written as ordinary code, and tells you what it could not test.
It runs inside the AI Assistant, on your device by default.
The DPDP Problem
A privacy assessment fails in two directions. Ask a model and you get fluent conclusions that change between runs. Build a spreadsheet and you get consistency with no reading of the evidence.
The harder problem is that India's DPDP regime commences in phases. A rule that exists is not necessarily a rule that binds you today — and a tool that cannot tell the difference will produce findings against provisions nobody has to follow yet.
What It Actually Does
You supply evidence. It produces findings, each citing the evidence behind it.
- Twenty-three controls across notice and consent, inventory and purpose, rights, retention and erasure, processors, children, significant data fiduciary, and breach readiness.
- Nine contradiction detectors that compare one piece of evidence against another.
- A twenty-column workpaper and an Evidence Passport a third party can re-verify.
Conclusions come from predicates, not prompts. Every control is a function over normalised evidence. Given the same files it returns the same answer today, next quarter, and in front of a regulator. A model may extract and explain; it cannot conclude, and an interpretation that contradicts the predicate is discarded and recorded as an override attempt.
Run the Assessment
Open /ai-assistant.html and select DPDP Assessment from the mode list.
- Run the worked example (synthetic) — a complete assessment with no real personal data, to see the output shape before using your own.
- Load assessment JSON — your own inventory, consent records, retention rules and incidents.
- Read the banner first. It says whether statutory testing is active.
- Work down: blockers, contradictions, then the eight control domains.
- Download workpaper (CSV) or Evidence Passport (JSON).
There is an Ask about this assessment box. It routes questions to deterministic queries — "why is DPDP-RET-01 an exception?" is answered from the result, not from a model. Ask it something it cannot check and it refuses, listing what it can answer instead.
Evidence, Not Recollection
Every uploaded file is classified UNTRUSTED_DATA before anything reads it, and hashed with SHA-256. Eight injection patterns are neutralised in place and recorded — a privacy notice that tries to instruct the assistant is itself a finding, not an instruction.
The rule that shapes the whole evidence layer is this: a fact nobody can go and check is indistinguishable from one the model imagined.
A model-extracted fact without a page or row reference is refused at the point of creation, not filtered later. So is one that does not name the model that produced it. Low-confidence OCR cannot close a control; it asks for the page to be re-read.
Read the Findings
Each control returns one of eight results, and the distinction that matters most is between a conclusion and an absence of one.
- Exception — the evidence contradicts the organisation's own position.
- Partially effective — no breach found, but something was not assessed.
- Effective — no exception found, with evidence cited.
- NOT TESTED — evidence required, legal source unverified, or not testable as specified.
An untested control is not a pass. The chip count, the cover note and the workpaper all say so in those words, and coverage is reported as conclusive results over every control in scope. A dashboard that counts "we could not test it" as green is the most common way compliance tooling lies without stating a single falsehood.
Contradictions
Nine detectors compare evidence against evidence, with both sides and their evidence ids. On the worked example they find nine, including:
- The notice omits three categories the product collects.
- A principal withdrew consent in March; a processor record shows activity in August.
- Policy says 90 days; the database holds 540.
- A consent record cites a notice version that does not exist.
- The inventory says no children's data, and the product collects date of birth.
Every one is deterministic. A contradiction a model found is one that changes between runs.
Two Separate Questions
This is the part most tools collapse, and it is where statutory findings go wrong.
A verified PDF does not make a model's reading of it correct. In the Obligation review bench, the AI reads a verified instrument and proposes obligations — source on the left with the quotation highlighted, proposal on the right. Each proposal must quote the instrument verbatim; a paraphrase, however accurate, is rejected automatically because it cannot be located in the text.
Nothing becomes testable until a named person accepts it. system, admin and AI are refused as verifiers — the tool cannot verify its own legal sources, because everything it could compare a document against is that same document.
Statutory Testing Is Off
The assistant ships in a state it states plainly at the top of every assessment:
STATUTORY TESTING NOT ACTIVE. DPDP statutory obligation testing is currently unavailable because an authoritative legal pack has not been activated. Internal privacy-control consistency testing remains available.
The reason is specific. The DPDP Rules text could not be retrieved from an official source: MeitY's document paths return 403 to non-interactive clients, and India Code did not respond. What was retrieved — a Press Information Bureau note, hashed and dated — is recorded as a tier-2 press source, not as the Gazette. It supports three instrument-level facts and zero obligations.
So seven of the twenty-three controls report LEGAL_REVIEW_REQUIRED, each naming the document that would unblock it. Their predicates are already written and tested; they are waiting on a source, not on code.
The other sixteen work today, because their standard is your own stated position compared against your own evidence. They need no statute — and they are reported as internal control consistency, never as statutory breach. The engine enforces that in code: a non-statutory finding using words like "violation" or "unlawful" is flagged as a wording defect.
From Finding to Action
| Result | What it means | Next step |
|---|---|---|
| Exception | Your evidence contradicts your own position | Fix the process, or correct the record |
| Partial | Something could not be measured | Supply the missing measurement |
| Evidence required | The input is absent, and it is named | Gather and re-run |
| Legal review required | No verified obligation to test against | Import and verify the instrument |
The blockers panel groups untested controls by the document that would unblock them — "retrieve this one source and four controls become testable" is a more useful backlog than four separate blockers.
What It Does Not Mean
Taken verbatim from the workpaper the tool produces:
- No statutory conclusion is expressed while the legal pack is empty.
- Internal-consistency exceptions are findings about internal consistency, not determinations of statutory breach.
- The workpaper has not been reviewed by a qualified person. It is a machine-prepared working paper, not legal advice.
- The Evidence Passport establishes that files hash to the listed values. It is not a signature and does not establish that the evidence is complete or genuine.
Running an assessment does not make an organisation DPDP compliant. It tells you what your evidence says, what it contradicts, and what you have not yet shown.
Try It
Open the AI Assistant, choose DPDP Assessment, and run the worked example. It contains no real personal data and takes a few seconds — enough to see whether the output is the kind your team would defend in a review.
FAQ
What is DPDP Assessment?
A mode in the NextGen GRC AI Assistant that runs twenty-three privacy controls over your evidence and produces findings, contradictions, a workpaper and an evidence passport.
What do I need to provide?
An assessment JSON describing collection, notices, consents, retention, processors, rights requests and incidents. The worked example shows the shape and requires nothing of your own.
Does it decide whether I comply with the DPDP Act?
No. Statutory testing is inactive until an authoritative legal pack is imported and verified. What runs today compares your statements against your evidence.
Can it find gaps?
Yes, and it names them. A control with missing input returns EVIDENCE_REQUIRED listing exactly what is absent, and a conclusion citing no evidence is downgraded automatically.
Does my evidence leave the device?
Not on the default engine. The assistant runs on-device unless you explicitly select cloud inference, and no DPDP module makes a network call of its own.
How do I turn on statutory testing?
Import the official instrument under Legal pack, complete the verification attestation, then accept obligations one at a time in the review bench. Testing then covers only the obligations you accepted.
Open the AI Assistant, choose DPDP Assessment in the mode list, and run the worked example. It uses synthetic data, needs no setup, and shows the output before you point it at anything of your own.
Open DPDP Assessment →