Discover
Map key processes, data sources, systems, repositories, vendors, AI tools and informal working channels.
DPDP readiness is difficult to build on assumptions. Organisations first need to understand how personal data actually moves through their business, across teams, systems, vendors, working copies, informal channels and AI tools.
NPV Group helps organisations convert that understanding into a practical readiness roadmap.
We begin with how work actually happens. Policies, notices and consent workflows should reflect real business processes. Our approach starts with process walkthroughs, data-flow mapping and evidence review before moving to gap assessment or implementation planning.
Instead of beginning with a legal checklist, we first help management answer three practical questions: what data do we hold? Where does it move? What needs to change first?
NPV’s initial DPDP readiness approach is built around three practical stages: Discover, Assess and Prioritise.
Map key processes, data sources, systems, repositories, vendors, AI tools and informal working channels.
Link discovered facts to DPDP readiness themes such as notice, consent, retention, vendor governance, breach response and rights handling.
Prepare a management-ready action roadmap covering gaps, owners, dependencies and next steps.
Data discovery, process mapping, data-flow mapping, evidence capture
Preliminary gap assessment, maturity view, risk prioritisation
Notices, consent architecture, governance model, SOPs, retention and rights workflows
Control implementation, training, PMO, tool-selection support
Privacy office support, Data Principal request support, vendor reviews, breach support
Internal audit support, control testing, management reporting, continuous improvement
Managed Privacy Office and Assurance support are positioned as planning and design services now, and as operating support from the substantive compliance phase around May 2027.
AI tools are now part of the data environment. Employees increasingly use tools such as ChatGPT, Claude, Gemini, Grok, Copilot and similar applications for drafting, summarising, analysing and preparing work outputs. NPV helps organisations identify whether AI tool usage is known, approved, account-controlled and covered by internal guidance.
Quick awareness tool for spreadsheets, email attachments, WhatsApp, local folders, shared drives, personal devices, paper scans, backups, vendor portals and AI tools.
Existing GDPR or group privacy work can help. Organisations that already have privacy policies, GDPR artefacts, group-level templates, vendor clauses or data inventories may not need to start from scratch. However, those artefacts should be mapped to Indian operations, Indian data principals, actual local data flows and DPDP-specific requirements.
Some matters require legal advice. NPV can work alongside legal advisers by providing process maps, data registers, vendor mapping, gap summaries and evidence files that make legal review more fact-based and implementation-ready.
| Area | NPV Group role | Lawyer / law firm role |
|---|---|---|
| DPDP applicability | Collect facts, map processing, identify issue areas | Provide legal interpretation where applicability is complex or disputed |
| Privacy notices | Map data categories, purposes, processes and user journeys | Draft or legally review notice wording |
| Consent design | Map consent touchpoints, withdrawal process and evidence needs | Advise on legal validity of consent basis and notice language |
| Certain legitimate uses | Identify operational scenarios and supporting facts | Advise whether reliance is legally supportable |
| Vendor / processor governance | Identify vendors, data flows, controls and gaps | Draft or negotiate contractual clauses, indemnities and liability terms |
| Cross-border access / transfer | Map data flows, access points, cloud and support locations | Advise on legal implications and contractual safeguards |
| Children’s data | Identify processes involving children or guardians | Advise on permissible processing and verifiable consent model |
| Breach response | Support fact gathering, affected data mapping and evidence documentation | Advise on notification obligations, liability and regulatory communications |
| Regulatory proceedings | Support evidence collation and management reporting | Representation before Data Protection Board or appellate forums |
| Legal opinions | Not part of readiness advisory | Formal legal opinion or privileged advice |
Most organisations do not need to begin with a full-scale implementation programme. A better starting point is a focused scoping conversation or discovery diagnostic. From there, NPV can help determine whether the next step should be a workshop, data discovery engagement, preliminary gap assessment or broader implementation roadmap.
Every organisation’s DPDP readiness journey depends on its data footprint, business model, systems, vendors, employee practices, AI tool usage and existing compliance baseline.
Legal boundary. NPV Group supports organisations with data discovery, process mapping, readiness assessment, control design, implementation support, evidence management and management reporting. Legal interpretation, legal drafting, privileged advice, regulatory representation and formal legal opinions should be handled by qualified lawyers or law firms.