Start with a practical DPDP readiness check.
Use NPV Group’s diagnostic tools to understand where your organisation may need data discovery, preliminary gap assessment or a structured DPDP readiness roadmap.
The five diagnostic tools
DPDP Applicability Checker
Initial screening tool: an indicative readiness relevance check, not a legal opinion or confirmation of applicability.
Data Discovery Readiness Diagnostic
Flagship diagnostic for visibility over data flows, systems, vendors, AI tools, informal channels and evidence gaps.
Employee Data Risk Checker
Focused review of employee, HR, payroll, attendance, biometric, contractor, nominee, family, health and insurance-related data.
Personal Data Blind-Spot Checker
Quick awareness tool for spreadsheets, email attachments, WhatsApp, local folders, shared drives, personal devices, paper scans, backups, vendor portals and AI tools.
Vendor / Processor Risk Snapshot
Vendor governance and processor mapping: where third parties, outsourced teams and platforms may access or process personal data.
Most organisations do not need to begin with a full-scale implementation programme. A better starting point is a focused scoping conversation or discovery diagnostic.
Before you begin: what personal data should you think about?
Personal data is not limited to Aadhaar, PAN, mobile number or email ID. It can include any information that identifies, or can reasonably relate to, an individual, whether the person is a customer, employee, applicant, vendor contact, visitor, consultant, student, patient, investor, website user or nominee.
While answering the tools, think about formal systems as well as spreadsheets, email attachments, shared drives, messaging apps, local files, paper scans, vendor portals and AI prompts.
- Identity data
- Name, photograph, signature, date of birth, employee ID, customer ID
- Contact data
- Mobile number, email ID, residential address, emergency contact
- Government identifier data
- PAN, Aadhaar, passport, driving licence, voter ID
- Employment / HR data
- Resume, appointment letter, salary, attendance, appraisal, disciplinary records
- Financial data
- Bank account, UPI, reimbursements, payment records, salary account
- Health / insurance data
- Medical certificates, insurance details, claims, disability information
- Education / qualification data
- Degrees, marksheets, certifications, background verification
- Customer / transaction data
- Orders, invoices, service history, complaints, support tickets
- Vendor / consultant data
- Vendor contact persons, KYC, bank details, agreements
- Digital identifiers
- IP address, login ID, cookies, device ID, access logs
- Location / attendance data
- GPS, branch attendance, biometric attendance, access-control logs
- Communication data
- Emails, call recordings, chats, WhatsApp messages, meeting recordings
- Visual / audio data
- CCTV, photographs, video, voice samples
- Biometric data
- Fingerprints, facial recognition templates, biometric attendance
- Children’s data
- Student, child customer, dependent or minor-related records
- Family / nominee data
- Nominee, dependent, family and emergency-contact information
- AI-input data
- Prompts, uploaded files, pasted records, AI conversation history
AI tool usage
If employees use ChatGPT, Claude, Gemini, Grok, Copilot or similar applications for official work, the organisation should understand what data is being entered into those tools, whether accounts are personal or organisation-provided, and whether accounts are free or enterprise-controlled.
What you receive. For selected tools, users will receive an indicative PDF report. The report may include a readiness snapshot, key observations, personal-data categories, AI usage indicators, vendor exposure, legal-review flags and suggested next steps. The report is designed as a discussion aid and is not a legal opinion, audit assurance, statutory certification or confirmation of DPDP compliance.