DPDP Assessment: While We Check Privacy, Who Is Checking the Assessment Mechanism?

By Shaurya J. Das Governance Research Associate · 26 August 2026

GOVERNANCE RESEARCH NOTE

A DPDP Foundation Layer research note on what an organisation may reveal while explaining its privacy position, and whether the mechanism receiving that information should also come within the governance view.

EXECUTIVE RESEARCH SUMMARY

When an organisation starts a DPDP assessment, it is not only answering questions about privacy. As the assessment goes deeper, it may disclose where personal data is stored, which applications are involved, which processors are used, who has access, how retention works, where deletion is difficult, what evidence exists and which team actually owns a particular processing activity.

This information normally comes from different parts of the organisation. HR may know one part, IT another, Finance another, Sales another and Procurement yet another. The assessment mechanism may eventually receive all these parts together and create a connected view which no single department had in the first place.

This creates a simple research question for us. While we are asking the organisation to explain how it handles personal data, are we applying enough of the same governance thinking to the mechanism which is receiving, connecting and retaining the organisation's answers and evidence?

A privacy assessment can know more about the organisation than we initially realise

A privacy assessment normally starts in a harmless way. The organisation is asked what personal data it collects, why it collects it, where it stores the information, who has access and whether any external processor is involved. At this level, it still feels like a questionnaire and the information being entered may not appear particularly sensitive.

The situation changes when the assessment becomes useful. A serious answer normally requires context. HR may have to explain employee data, HRMS, payroll processing, recruitment records, biometric attendance and employee-document retention. Sales may explain CRM, prospect information, customer records and marketing platforms. Finance may explain payment records and statutory retention, while IT may need to explain applications, hosting, administrator access, backup, logs, archives and deletion capability.

Procurement may then identify the processor and the contract. Legal may explain the purpose, notice and contractual position. IT may identify a technical dependency which was not known to HR. A business team may disclose that an old application still has records which were assumed to have been removed. The privacy team is gradually connecting pieces which were previously sitting with different people.

By the time this process is completed, the assessment mechanism may not be holding only thirty, forty or one hundred answers. It may be holding a structured picture of the organisation's operating environment. That picture can include systems, vendors, access paths, ownership, retention weaknesses, evidence and unresolved gaps.

This is where the thought started for us.

A privacy assessment may itself become one of the few places where many disconnected parts of an organisation's processing reality are brought together. If that happens, should the assessment record itself be treated as something which deserves a clear governance boundary?

Individual information may look harmless. The connected picture may not.

There is another reason this question needs a deeper look. Governance risk does not always sit inside one individual field of information. Sometimes the value, and the sensitivity, appears only after multiple pieces are connected. An application name by itself may not say much. A vendor name by itself may not say much. A retention answer by itself may also look ordinary.

But if one environment contains the application name, processor, administrator access, location, retention weakness, supporting screenshot and internal owner, it tells a very different story. The sensitivity can come from the relationship between the information, not necessarily from any one answer.

This is particularly relevant during DPDP work because the assessment is trying to discover exactly those relationships. We want to know how the person, purpose, system, processor, location, retention, access, evidence and owner connect. That connectivity improves the assessment, but it may also increase the importance of the assessment record itself.

So the uncomfortable question is not only whether personal data is being entered into the assessment. There is a second category which deserves attention: internal enterprise information which may not itself be personal data, but which can reveal how the organisation processes personal data and where its weaknesses or dependencies currently sit.

PUBLIC RESEARCH · IBM INSTITUTE FOR BUSINESS VALUE

IBM Institute for Business Value has discussed governance through accountability, transparency and provenance. One important part of that thinking is that trust improves when an organisation can understand where information came from, how it moved and what happened to it through its lifecycle.

For this research, provenance creates an interesting parallel. During a privacy assessment we often ask the organisation to prove the origin and reliability of an answer. But once that answer enters the assessment mechanism, should the organisation also be able to understand the history and handling of the assessment information itself?

The real question may start only after the organisation presses Submit

Most organisations understandably focus on the output of an assessment. Management wants to know what the gaps are, what has to be corrected, where risk is visible and what should happen next. The privacy team wants a usable report. The business wants clarity rather than another long exercise.

But before the report is generated, the organisation has already provided something valuable. It has explained its operating reality. This creates another set of questions which are normally less visible in the assessment discussion. Where did the submitted information go? Where was it processed? Where is it stored? Who can access it? What is recorded in logs? How long does it remain there?

The same question becomes more important for evidence. An answer may be general, but supporting evidence can be much more revealing. A screenshot may show an application name, user information or configuration. A vendor document may show another dependency. A process document may identify internal owners. A contract may contain information which the organisation would normally control carefully.

There may also be information created by the assessment itself. The original answer, subsequent clarification, internal comment, evidence review, identified contradiction and final finding can together show not only the current position but also where the organisation originally misunderstood its own environment.

None of this means an online assessment platform is wrong. It does not mean external hosting is wrong. It does not mean one technology model is better than another. The research question is much simpler: does the organisation know what it has agreed to, and can it explain the information path if someone asks later?

The question is not whether information can leave the organisation.

The question is whether the organisation understands what left, why it left, where it went, who could see it, what remained and what dependency was created.

A simple retention example shows why this becomes difficult

Consider an organisation where HR initially confirms that employee information is deleted after the required retention period. This may be an honest answer based on the process HR follows. From HR's point of view, the employee record is closed and the information is no longer visible in day-to-day operations.

During a deeper discussion, IT explains that the primary application may delete the operational record, but a backup copy remains for another period. Finance then explains that some supporting records must remain because another statutory requirement applies. The payroll processor may have a separate retention arrangement.

The first answer was therefore not necessarily false. It was incomplete. No single team had the complete picture. The value of the assessment came from connecting several reasonable departmental answers and discovering that the organisational position was different from the first declaration.

Now look at the other side of the same exercise. The assessment mechanism may know the HRMS application, payroll processor, backup arrangement, internal ownership, statutory exception, deletion limitation and the supporting evidence which proved the gap. It may also contain the original answer and the later corrected understanding.

That is a very useful governance record. But because it is useful, it also deserves to be governed properly.

Information disclosed What it may reveal when connected
HRMS application Technology used for employee processing
Payroll processor External processing dependency
Access model Internal or external privilege structure
Backup retention Known limitation in deletion capability
Evidence Proof of configuration or operating practice
Original and revised answers How the organisation's understanding changed

What exactly are we trying to govern?

At first, this question may appear to be only about where assessment data is stored. But storage is only one part of the problem. Even if the organisation knows that an assessment platform is hosted in a particular location, that does not automatically explain everything that happens to the information once it enters that environment.

There can be several separate stages. Information is entered. It may be stored in one database. Evidence may be stored somewhere else. Logs may record certain activity. Reports may create another copy of the information. Backups may follow their own lifecycle. Support users may have different access from the people actually performing the assessment.

The organisation may therefore know the hosting location but still not completely understand the processing path. This is similar to what we often see inside the organisation itself. Knowing the name of an application does not mean we know every place where the information travels after entering the application.

So merely asking, “Where is our assessment hosted?” may not be enough. The better question may be: “What is the complete handling path from the point an organisation provides an answer to the point management receives and relies on the final report?”

What is Assessment Mechanism Governance?

INFRAVERITAS360 RESEARCH PROPOSITION

Assessment Mechanism Governance is a working research proposition that says an organisation should have reasonable visibility of how information disclosed during a privacy assessment is received, processed, connected, accessed, stored, retained and evidenced before management relies on the final assessment position.

We are deliberately calling this a research proposition and not a control requirement. The DPDP Act does not use this term. It is not an established industry definition and it should not be presented as one.

The purpose of giving the issue a working name is simply to make it easier to discuss. In many governance problems, something remains invisible because it sits between recognised categories. We understand privacy assessment. We understand platform security. We understand third-party risk. But the governance of the assessment information itself can sit somewhere between all three.

Naming the question does not prove the proposition. It only gives practitioners something specific to challenge. If the issue is already sufficiently covered through existing privacy, security and vendor-governance controls, that is also an important research outcome.

PUBLIC RESEARCH · McKINSEY & COMPANY

McKinsey's research on enterprise data readiness makes a useful point for this discussion. Modern information governance cannot always stop at the place where the original document or record is stored. Information may be retrieved, transformed, combined, passed through another layer and then surfaced again in an output.

This is relevant to assessment design because knowing where an uploaded document sits may not explain the complete handling path. The governance question may have to look at storage, retrieval, processing and output together rather than assuming that storage location alone explains the full information journey.

Assessment Mechanism Governance is not the same as platform security

It would be easy to reduce this research question to cybersecurity and ask whether the assessment platform is encrypted, patched, monitored and access controlled. Those controls matter, but they answer a different question. A technically secure platform can still create a governance dependency which the organisation has not fully understood.

Security asks whether the environment is protected. Privacy asks whether personal data is handled according to the applicable purpose and obligation. Assessment Mechanism Governance asks whether the organisation can explain what happened to the information it disclosed during the assessment and what dependencies were created by doing so.

This distinction matters because management may receive a satisfactory security assurance and still have a separate question about operating visibility. A system can be secure and externally hosted. It can be secure and internally hosted. Either model may be acceptable. The governance question is whether the organisation understands which model it has selected and what that choice means for the assessment information.

Area Primary management question
Security Is the assessment environment appropriately protected?
Privacy Is personal data being handled according to applicable requirements?
Assessment Mechanism Governance Can the organisation explain the complete handling path of the information disclosed during the assessment?

One more issue: the assessment may create information which did not exist before

There is another layer which is easy to miss. An assessment does not only receive existing information. It can also create new governance information by connecting answers, evidence and contradictions. Before the assessment, HR may have one view, IT another and Finance another. After the assessment, the organisation may know that those views do not completely agree.

That contradiction itself is new information. A finding which says that retention is inconsistent across systems is new information. A report which connects one vendor dependency with an access weakness and missing evidence is also new information. The mechanism is therefore not merely storing what the organisation already knew. It can become the place where previously disconnected facts become a new management picture.

This is important because the final connected picture may be more sensitive than any single original answer. An HR user may know the employee process but not the backup architecture. IT may know the backup architecture but not the contractual processor position. Procurement may know the contract but not the technical access path. The assessment may know all three.

This may increase the value of the assessment significantly. It may also increase the importance of understanding who can access that connected picture and how long it remains available.

Another practical problem: an answer may change after internal discussion

There is also a practical behaviour we see during assessments. A team gives an answer based on its present understanding. The report is generated. Management or another department reviews the output and notices that one answer does not completely reflect the operating reality. A clarification then changes the answer.

This is not necessarily a failure of the person who gave the first answer. Privacy processing often crosses functions. HR may know the front-end process but not the backup. Sales may know customer collection but not the retention configured inside the CRM. Procurement may know the contracted processor while IT knows an additional technical sub-dependency.

If the answer changes, the report may also change. A retention answer can affect a gap, a finding, a risk position, an evidence requirement and a remediation recommendation. This makes the history of the assessment important. The organisation should ideally be able to understand what was originally declared, what changed, why it changed and what part of the final position was affected.

This creates another governance principle worth testing: answers may change as understanding improves, but the earlier assessment history should not simply disappear.

A practical way to look at the assessment path

ILLUSTRATIVE GOVERNANCE SEQUENCE
Assessment Information Visibility = What Was Disclosed + Where It Went + Who Could Access It + What Was Created From It + What Was Retained + Which Dependencies Were Created + What Evidence Exists

This is not a risk formula and it should not be used as a mathematical compliance score. It is only a way to make the assessment path visible on one page. The purpose is to identify the questions management may need to ask before assuming that the assessment mechanism itself sits outside the governance discussion.

The important addition here is “what was created from it”. An organisation may upload a number of separate answers which individually reveal very little. The assessment may connect those answers and produce a finding, dependency map or management conclusion which is materially more useful, and sometimes materially more sensitive, than the original inputs.

If all these areas are understood, management has a stronger view of the assessment mechanism. If one or two remain unknown, that does not automatically make the assessment unsuitable. It simply means the unknown should remain visible as an unknown rather than quietly becoming an assumption.

From questionnaire to evidence-based assessment

This thought also changes how we look at the assessment itself. A normal questionnaire can stop once the user has selected Yes, No or Not Applicable. A stronger assessment asks why the answer is true, who owns it and what evidence supports it. A still stronger assessment connects that answer with other departments and asks whether the organisation's overall position remains the same.

Question → Declaration → Evidence → Connection → Contradiction Check → Validation → Management Position

Once an assessment works at this level, the mechanism starts carrying more governance value. It contains not only the final answer, but the journey between what was initially declared and what could eventually be substantiated. That difference can matter later if management wants to understand how a conclusion was reached.

This is where our Foundation Layer thinking becomes relevant. We should not confuse a declared position with an evidenced position. We should also not confuse a report being generated with the assessment process being fully understood.

A good assessment should allow the organisation's understanding to improve. But improvement should add to the history, not erase it. If a declaration changes because another team has produced better evidence, that change itself may be an important governance record.

Five questions before a digital DPDP assessment

I do not think management needs another fifty-question due-diligence exercise before it can even begin a privacy assessment. That would defeat the purpose. But five basic questions may help identify whether the assessment mechanism is sufficiently understood before meaningful information starts moving into it.

Question Why it matters
1. What information are we actually going to disclose? A serious assessment may contain systems, processors, internal gaps and evidence, not only compliance answers.
2. Where will that information be processed and stored? Makes the location and technology dependency visible before the exercise begins.
3. Who can see the answers, evidence and resulting findings? The final connected assessment may reveal more than the original individual answers.
4. What remains after the assessment is completed? Answers, evidence, logs, backups, revisions and generated reports may have different retention paths.
5. Can we explain the assessment path later? A management position becomes stronger when the organisation can reconstruct what happened rather than relying only on memory or assumption.

This belongs on the management table, not only with IT or the privacy team

Privacy assessment is cross-functional by nature. HR owns part of the processing reality. IT owns another part. Sales and Finance may own other parts. Procurement may know the vendor arrangement. Legal may know the contractual requirement. The privacy or GRC team is often the one trying to bring these pieces into one reliable position.

This means the assessment mechanism can sit at a unique point in the organisation. It can receive information from many functions which do not normally share the complete picture with each other. That can make the mechanism very useful because it helps management see connections that were previously invisible.

But the same reason that makes it useful is also the reason why governance becomes relevant. Management should know not only whether the platform produces a professional report, but also whether the information needed to produce that report has been handled in a way which the organisation understands and can defend.

A faster assessment is useful. A more detailed assessment is useful. Better automation can be useful. But none of these should make the underlying information path disappear from management's view.

GOVERNANCE CAUTION

This research should not be read as an argument against cloud, SaaS, automation, external platforms or intelligent systems. Different organisations will make different architecture choices depending on their operating model, risk position and practical requirements.

The governance question is only whether the choice was made after understanding what information would be disclosed, what would be created from that information, where it would go, what would remain and which new dependencies would become part of the assessment process.

From privacy assessment to better management reliance

The purpose of a privacy assessment is not simply to produce a report. The report is only useful if management can rely on the position underneath it. That means understanding what was declared, what evidence existed, what contradictions were found, what dependencies remained and what could finally be substantiated.

Our research question adds one more layer to that chain. If the assessment mechanism is itself receiving important organisational information, management may also need enough visibility to understand the mechanism through which the position was created.

This does not require management to understand every technical detail. It requires something more practical: an ability to explain the broad information path and the important dependencies if the assessment is questioned later.

While we are asking the organisation to explain what happens to personal data, can the organisation also explain what happened to the information it disclosed during the assessment?
FOUNDATION LAYER CONCLUSION

The purpose of a DPDP assessment is not only to understand the organisation's personal-data processing reality. As assessments become more digital, connected and evidence-heavy, there may also be value in understanding the processing reality of the assessment itself.

FOUNDATION LAYER CHECK

Before the next digital privacy assessment, ask one simple question:

If we are about to disclose our applications, processors, access paths, evidence, retention limitations and unresolved gaps, how clearly can we explain what will happen to this information after we submit it?

Thank You

We sincerely thank privacy professionals, DPOs, GRC practitioners, CIOs, CISOs, technology teams, legal professionals, auditors and industry practitioners whose published work, online discussions, personal meetings and practical experience continue to challenge the way we are looking at this subject.

Many of the questions in this note came from normal operational discussions rather than from trying to create a new definition. The more we looked at what organisations may disclose during a detailed privacy assessment, the more the assessment mechanism itself started appearing as a reasonable subject for governance discussion.

We also thank IBM Institute for Business Value and McKinsey & Company for making their research publicly available. Their work has been used here only as independent research context to test whether our question has a wider governance basis. No endorsement, validation or review of InfraVeritas360, this research proposition or DPDPiq by either organisation is implied.

If you believe the assessment mechanism should remain completely outside the privacy-governance boundary, we would particularly value that view. If you have seen an operating model which handles this issue differently, that is equally useful to the research.

Research becomes stronger when someone finds the assumption we have missed.

Primary Research Sources

IBM Institute for Business Value
Research on enterprise governance, accountability, transparency, provenance and the governance of information through its lifecycle. Used as independent research context for the discussion around whether assessment information should remain traceable and understandable after submission.

McKinsey & Company
Research on enterprise data readiness and governance beyond traditional storage, including retrieval, processing and output layers. Used as independent context for the question of whether storage location alone is sufficient to understand an information path.

Government of India
Digital Personal Data Protection Act, 2023 and applicable notified Rules. These remain the statutory context for the privacy discussion. Nothing in this research note should be treated as a replacement for legal interpretation of the Act, Rules or the specific facts of an organisation.

RESEARCH NOTE

“Assessment Mechanism Governance” is presented in this article as an InfraVeritas360 working research proposition. It is not a statutory term, legal test, certification requirement, audit standard or established industry theorem. External research is used only to test the relevance of the underlying question. The external organisations referenced in this note have not reviewed, validated or endorsed this proposition.

SUGGESTED CITATION

InfraVeritas360 Research (2026), “DPDP Assessment: While We Check Privacy, Who Is Checking the Assessment Mechanism?”, Governance Research Notes.

GOVERNANCE RESEARCH NOTES (GRN)

InfraVeritas360 publishes independent research observations on infrastructure governance, privacy, operational assurance and management reliance. The purpose of these notes is to question the layer below the visible position and understand what evidence, ownership and operating reality actually support it.

Related Research

Beyond the DPDP Checklist: Can Management Trust the Personal Data Processing Reality?

A Foundation Layer research note on whether visible DPDP compliance can be relied upon without a reliable understanding of the processing reality underneath it.

Third-Party Processing May Be Contractually Complete. But Is the Dependency Really Visible?

Research on the gap between contractual completeness and practical visibility of an operating dependency.

Investment Avoidance Value: The Technology Value We Rarely Measure Before Procurement

Research on whether better validation before commitment can itself create measurable technology value.

InfraVeritas360 Research

Independent research on Infrastructure Governance, Foundation Layer, Privacy and Management Reliance.

Human Intelligence First. Executive Validated.

FROM RESEARCH QUESTION TO PROCESSING REALITY

If your organisation wants to look beyond a basic DPDP checklist and understand the processing reality, ownership, evidence and dependencies underneath its current position, continue the discussion through DPDPiq.

Explore DPDPiq
Governance Research Notes (GRN)
Independent research observations on infrastructure governance, operational assurance and enterprise risk. Published by InfraVeritas 360 for practitioner and institutional reference.