InfraVeritas 360 IGaaS engine for intelligent, controlled infrastructure DPDPiq DPDP Act, 2023 India Start Assessment

Assessment instrument — specification

Understand the processing reality behind your DPDP position.

Most DPDP readiness exercises measure whether an organisation can describe its controls. They do not establish where personal data actually sits, who touches it, on what lawful basis, and what happens to it at end of purpose. The first is a documentation exercise. The second is a processing reality. DPDPiq is built to establish the second.

DPDPiq — assessment console Click to enlarge
Data Landscape — Construct C1 — item-level position, owner and attention, with the question chain at right. Notice & Consent — Construct C2 — what people are told, and whether their agreement holds up. Evidence pending — Open items awaiting artefact. Counted and named, not smoothed into a score. Data flow — How personal data moves, and which team answers for each step. Remediation sequence — 120-day capability plan. Categories of tools only — never vendor names.
1/5
Assessment window
3–5 working days
Internal effort displaced
~20 person-days
External system access
None at any stage
Administration
Client-side, human-led
ResearchIndependent responses received on three separate research discussions.

Research insight

Three discussions. Three independent responses. One common thread.

Over recent weeks, three research discussions on distinct subjects each received an independent response from the IBM Institute for Business Value. Different subjects; one recurring question — before a decision is taken, how much of the underlying reality has been understood, questioned and validated?

01 · PROCESSING REALITY02 · INVESTMENT AVOIDANCE03 · AI READINESSRESPONSERESPONSERESPONSEONE COMMON THREAD
  1. 01Discussion
    Research discussion

    Beyond the data register — can the board trust the processing reality?

    The gap between documented processing and the processing that actually occurs, and who validates the complete journey end-to-end.

    Response received
    “Who validates the complete journey? That is a question more boards should be asking.”
    Response from IBM Institute for Business Value
  2. 02Discussion
    Research discussion

    Investment avoidance value — the technology value not measured.

    The value created by preventing a wrong investment upstream, which by design leaves no downstream footprint to count.

    Response received
    “Better decisions upstream can create meaningful value downstream, especially where organisations are under pressure to justify every technology investment.”
    Response from IBM Institute for Business Value
  3. 03Discussion
    Research discussion

    AI adoption is not AI readiness — twelve questions management should ask first.

    The distinction between deploying an AI capability and being ready for one, framed as questions taken before approval.

    Response received
    “A useful reminder that AI readiness and AI adoption are not the same thing. Those questions could save organisations from learning some hard lessons later.”
    Response from IBM Institute for Business Value
01Method Why item-count instruments produce unreliable position statements.

The measurement problem

A questionnaire of 120–150 items has a structural defect: it collects self-reported control descriptions and treats them as evidence of compliance state. Four failures follow, and they are predictable rather than accidental.

  1. i

    Respondent displacement

    The person who can answer whether retention is enforced on a given store is rarely the person the form was assigned to. Answers regress to the organisational average rather than to ground truth.

    Research note · The Governance Denominator Problem · Infrastructure Visibility Challenges
  2. ii

    Construct drift

    Do you have a retention policy and is personal data in this system deleted at end of purpose are different constructs. The first is almost always yes. The second is frequently no. Instruments written against clause language measure the first and report on the second.

    Research note · Beyond the DPDP Checklist · Beyond the Data Register
  3. iii

    Absent evidence linkage

    Responses are not bound to artefacts. A yes stands whether or not a processing agreement, a consent record, a deletion job or a transfer register exists behind it. The instrument cannot separate an implemented control from an intended one.

    Research note · Can You Trust the Clocks that Created the Evidence?
  4. iv

    Non-repeatability

    Two assessors, or one assessor at two points in time, produce materially different output from the same organisation. Without a fixed administration protocol there is no baseline, and without a baseline remediation cannot be measured.

    Research note · IT Documentation for Audits
Statutory obligationItem as writtenAssigned respondentResponseReported positioniiconstruct driftirespondent displacementiiiabsent evidence linkageivnon-repeatability
Each failure severs a different link between the obligation and the position finally reported. Select one to locate it in the text.
02Constructs DPDP Act, 2023 Each construct resolved against artefact rather than assertion.

What the instrument resolves

Each construct maps to enforceable obligation and is assessed against evidence held by the organisation, inside the organisation's own control boundary.

C1

Processing inventory

Which categories of personal data are processed, in which systems, for which stated purpose, at what volume, under which business owner. Everything downstream is unreliable without this layer.

C2

Lawful basis integrity

For each activity, whether the basis relied on is consent or a legitimate use, and whether the notice given corresponds to the purpose actually served. Divergence is recorded as a finding, not reconciled away.

ss. 5 · 6 · 7
C3

Principal rights operability

Whether access, correction, erasure and grievance redressal are executable within statutory timelines — established by tracing an actual request path across systems, not by confirming a policy exists.

ss. 11 · 12 · 13
C4

Retention and erasure

Whether erasure at end of purpose is enforced by mechanism or asserted by policy. Backups, analytics copies, warehouse replicas and processor-held copies are examined explicitly: that is where the obligation fails undetected.

s. 8(7)
C5

Processor and transfer chain

Contractual and technical position across the processor chain, including sub-processors, and the cross-border transfer position. Depth beyond the first processor is where undocumented exposure concentrates.

ss. 8(2) · 16
C6

Breach readiness

Whether a personal data breach would be detected, classified and intimated within the reporting obligation — established against a walked scenario rather than a plan document.

s. 8(6)
C7

Significant Data Fiduciary set

Where the entity is notified as an SDF: impact assessment, independent audit and Data Protection Officer appointment. Assessed separately, because both the obligation set and the exposure differ.

s. 10 — where applicable
SC

Scope declaration

Entities, business lines and systems excluded at commencement are recorded and carried into the final position, so coverage is explicit rather than assumed by the reader.

C1Processing inventoryC2Lawful basisC3rightsC4retentionC5chainC6breachC7SDF
C1 gates every construct below it — an inventory that is wrong makes each downstream position unreliable. C7 applies only where the entity is notified. Select a construct to locate it.
03Protocol A fixed sequence. The same sequence produces a comparable baseline.

Administration

The instrument is administered by the organisation. InfraVeritas holds no access to client systems at any stage of the assessment.

  1. Scoping

    The construct set is bounded to the entity, business lines and systems in scope. Out-of-scope declarations are recorded and carried forward.

  2. Distributed response

    Items are routed to the role that holds the answer. Where a respondent cannot answer within their own knowledge, the item is escalated to a named colleague inside the instrument rather than estimated, and the escalation is logged. This is the largest single source of accuracy gain over a form: unanswerable items become visible instead of becoming false positives.

  3. Evidence binding

    Responses that assert a control carry an artefact reference. Every upload and download is OTP-authenticated and logged. Artefacts remain within the client's control boundary.

  4. Reconciliation

    Where responses conflict across respondents — and on inventory and retention they routinely do — the conflict is surfaced and resolved by a named accountable owner. Unresolved conflicts are reported as unresolved. They are not averaged.

  5. Position

    Output is an evidenced position per construct, with the basis of each conclusion stated.

FORMItemRespondentEstimateFalsepositive INSTRUMENTItemCannotanswerNamed owner· loggedEvidencedanswer
The escalation path is the mechanism. An item nobody can answer becomes a visible open item instead of a false positive.
03·ACollaboration Room provenance Every contribution attributed, scoped and stamped. The audit record answers later questions on its own.

Invite the person who holds the answer. Not the one holding the form.

The largest single accuracy loss in a data protection assessment is the moment a respondent estimates at an item that belonged to another function. The instrument closes that gap by design. Where an item exceeds the assigned respondent's own knowledge, they invite a named colleague from the department that holds the answer — into that item alone, or into the group of items where their operational knowledge sits.

  1. Scoped invitation

    A colleague is invited into a single item, a group of items, or the full assessment workspace — never wider than the scope declared. Access ends when the assigned scope closes.

  2. Role-bound access

    An invitee joins as Contributor (may answer and attach evidence) or Compliance Observer (may view and comment). The role is recorded against every subsequent action.

  3. One-time verification, separate identity

    A single-use verification code is issued to the invitee's own work email. The inviting respondent's credentials are not shared, seen or reused. Each session is a distinct identified actor.

  4. Cryptographic time-stamping

    Every upload, every download and every recorded contribution carries an HMAC-SHA-256 signature bound to the actor, the time and the artefact hash. The resulting audit record is deterministic and non-repudiable.

  5. Contributions surface separately; nothing is silently merged

    Conflicting contributions from different respondents on the same item remain unresolved until an accountable owner resolves them under their own name. Reconciliation is a decision, and the record reflects that.

The audit record is retained as part of the assessment baseline. A future assessor, a regulator asking who answered what and when, or a board asking on what basis a position was taken, is answered from the same record — not from recollection.

CHAIN OF CUSTODY · ONE CONTRIBUTION ITEM Q-2.1 What notice is shown at the point of collection? ACTOR Priya S. · Legal ROLE Contributor SCOPE Item Q-2.1 only VERIFICATION OTP · single-use · expired EVIDENCE notice-en-v3.pdf sha-256: a1c4 7f92 … e8b3 TIMESTAMP 2026-08-23 14:07:31 IST SIGNATURE HMAC-SHA-256 bound to actor · artefact · time RETAINED AS PART OF THE BASELINE · NON-REPUDIABLE
The record is the answer to any later question of who answered what, when, on what evidence and under whose credentials.
04Scoring A methodological position, stated so that it can be argued with.

Why there is no percentage score

Human-powered at every level

A single compliance percentage is arithmetically indefensible.

It requires assigning weights across non-commensurable obligations, and any weighting is an unstated policy judgement presented as a measurement. An organisation reported at 82 per cent with an unenforced erasure obligation over a high-volume principal database is in materially worse statutory position than one reported at 61 per cent with that obligation met.

DPDPiq reports position per construct, concentration of exposure, and the accountable owner for each open item. Professional judgement stays in the decision layer.

Corporate

Human orientation

Board

Human challenge

Executive

Human reconciliation

No % score

Conservative intelligence
ORG A82%C4 erasure — not enforcedORG B61%C4 erasure — met
Illustrative. The percentage moves in the opposite direction to the exposure.
05Limits An instrument that does not declare its limits should not be trusted on what it does claim.

What the instrument does not establish

  • It is not a legal opinion on statutory interpretation.
  • It does not certify compliance. The Act provides for no such certification, and any offer of one misdescribes the statute.
  • It performs no technical control testing — no penetration testing, no configuration scanning, no code review.
  • It does not discover data. It relies on the organisation's disclosure; undisclosed processing remains undisclosed.
  • It does not substitute for the independent audit obligation where an entity is notified as a Significant Data Fiduciary.
  • Its conclusions are bounded to the scope declared at commencement and to the state of the environment during the assessment window.
CLIENT CONTROL BOUNDARYClient systemsArtefacts and evidenceRespondentsReconciliationInfraVeritas360position statementsystem access
Evidence never leaves the boundary. A position statement is the only thing that crosses it.
06Output Five artefacts, retained as the baseline for the next administration.

What is produced

Position statement

Conclusion, evidentiary basis and residual uncertainty, stated for each construct.

Exposure register

Open obligations mapped to section of the Act, with accountable owner and the specific artefact or mechanism found absent.

Remediation sequence

Ordered by statutory exposure and by dependency — inventory and lawful basis gate most downstream work. Not a prioritised list of suggestions.

Board instrument

The position rendered for a body that must record that it applied its mind to the obligation. Two pages. Defensible under question.

Baseline

The assessment state, retained so the next administration measures change rather than restarting from zero.

ConstructSectionArtefact absent / mechanism missingOwnerExposure
C4s. 8(7)Warehouse replica has no automated retention job. Personal data older than declared purpose persists.Data PlatformHigh
C2s. 5Notice at collection diverges from purpose actually served on marketing conversion pixel.GrowthMedium
C5s. 16Sub-processor operates in restricted jurisdiction. No standard contractual clauses currently in force.Vendor OpsHigh
Illustrative extract from an exposure register. In production, each row carries the specific artefact reference and the accountable owner named against the item.
BASELINE CARRIED FORWARD01baseline set02change measured03change measured
Re-administration measures movement. Without a retained baseline every assessment restarts from zero.
07Access Buyer type and deployment model determine the commercial path. The assessment methodology remains common.

DPDPiq access models

Choose Your DPDPiq Access Model

For professional assessors or for your own organization. Available as SaaS or hosted in your environment.

Buyer type
Deployment mode
B2B · SaaS

Professional assessment capacity without platform rental.

Built for GRC consultants, audit practices, and empanelled firms conducting multi-client assessments. Pay only for the assessment pack. Zero platform rental.

B2B · Assessment Pack

20 Assessments Pack

₹3,99,000
180 Days 1/2 Year
  • Multi-client workspace
  • StatementStore 3.0 SHA-256 evidence binding
  • 18-Volume Master Dossier generation
  • Zero cloud egress
Start with Assessment Pack
B2B · Assessment Pack

50 Assessments Pack

₹7,99,000
365 Days 1 Year
  • Multi-client workspace
  • StatementStore 3.0 SHA-256 evidence binding
  • 18-Volume Master Dossier generation
  • Zero cloud egress
  • Priority support
  • Practice management features
Start with Assessment Pack
B2B · Assessment Pack

100 Assessments Pack

₹12,99,000
365 Days 1 Year
  • Multi-client workspace
  • StatementStore 3.0 SHA-256 evidence binding
  • 18-Volume Master Dossier generation
  • Zero cloud egress
  • Priority support
  • Practice management features
  • Dedicated solutions architect
Start with Assessment Pack
Pack validity

Validity starts from activation of the selected assessment capacity.

Hosted deployment

Final hosted deployment scope is confirmed after environment review.

Platform AMC

Hosted AMC is billed annually against the applicable monthly commercial range.

Ready to begin Start with the DPDP Foundation assessment.
Start Assessment
08Provenance IGaaS — Infrastructure Governance as a Service.

Where the instrument comes from

DPDPiq is an instrument of the IGaaS practice at InfraVeritas 360. IGaaS is a pre-compliance discipline: it establishes whether foundational governance holds before an entity enters a formal audit, across a control model of twelve governance domains and more than fifty frameworks including ISO 27001, SOC 2, GDPR, NIST CSF, CERT-In and DPDP.

We don't do compliance. We make you ready for it. DPDPiq applies that discipline to a single statute, at the depth the statute requires.

IGAAS CONTROL MODEL — TWELVE GOVERNANCE DOMAINSMORE THAN FIFTY FRAMEWORKSISO 27001SOC 2GDPRNIST CSFCERT-InDPDPDPDPiq
One statute, taken to the depth the statute requires, from a control model built for fifty.
09CorpusSelected posts from the InfraVeritas 360 research blog underlying this instrument.

Research the instrument is drawn from.

DPDPiq operationalises a set of arguments developed in the InfraVeritas 360 research blog. Each construct and each declared failure of item-count assessment corresponds to a published research note. The full corpus — approximately fifty posts — is on the blog; a mapped selection below.

Thesis and framing· The processing-reality thesis

  1. Beyond the DPDP Checklist: can management trust the personal data processing reality?Shaurya J. Das · Governance Research Expert · InfraVeritas 360
  2. Beyond the Data Register: can the board trust the processing reality?Shaurya J. Das · Governance Research Expert · InfraVeritas 360
  3. Infrastructure Governance & Operations IntelligenceShaurya J. Das · Governance Research Expert · InfraVeritas 360

Failure modes· Why item-count instruments fail

  1. The Governance Denominator Problem: what if your green dashboard is measuring an incomplete reality?Shaurya J. Das · Governance Research Expert · InfraVeritas 360
  2. Can You Trust the Clocks that Created the Evidence?Shaurya J. Das · Governance Research Expert · InfraVeritas 360
  3. IT Documentation for Audits: what Indian regulators actually expect to seeShaurya J. Das · Governance Research Expert · InfraVeritas 360
  4. Infrastructure Visibility Challenges: why you can't govern what you can't seeShaurya J. Das · Governance Research Expert · InfraVeritas 360

Constructs — inventory and identity· C1 and adjacent

  1. IT Asset Inventory: the first control every compliance audit checksShaurya J. Das · Governance Research Expert · InfraVeritas 360
  2. What is a CMDB and why every regulated Indian enterprise needs oneShaurya J. Das · Governance Research Expert · InfraVeritas 360

Constructs — retention and erasure· C4 and adjacent

  1. Data Backup Strategy for Indian Enterprises: RTO, RPO, and what CERT-In actually requiresShaurya J. Das · Governance Research Expert · InfraVeritas 360

Constructs — rights operability· C3

  1. Least Privilege Access Control: the identity foundation every compliance framework demandsShaurya J. Das · Governance Research Expert · InfraVeritas 360

Constructs — processor and transfer chain· C5

  1. The Authority Population Problem: what actually has power inside your technology environment?Shaurya J. Das · Governance Research Expert · InfraVeritas 360
  2. Third-Party Processing may be contractually complete — but is the dependency really visible?Shaurya J. Das · Governance Research Expert · InfraVeritas 360
  3. Third-Party Vendor Risk Management: the supply chain gap in Indian enterprise complianceShaurya J. Das · Governance Research Expert · InfraVeritas 360

Constructs — breach and evidence· C6 and evidence integrity

  1. Log Management and SIEM: the 180-day CERT-In requirement most enterprises are violatingShaurya J. Das · Governance Research Expert · InfraVeritas 360
  2. Network Segmentation: why flat networks fail CERT-In and ISO 27001 auditsShaurya J. Das · Governance Research Expert · InfraVeritas 360

Adjacent research· Investment avoidance & AI readiness

  1. Investment Avoidance Value: the technology value we rarely measure before procurementShaurya J. Das · Governance Research Expert · InfraVeritas 360
  2. Before You Approve an AI Investment: answer these 12 questionsShaurya J. Das · Governance Research Expert · InfraVeritas 360

Foundation· Foundation-layer thesis

  1. What is the Foundation Layer of IT Infrastructure?Shaurya J. Das · Governance Research Expert · InfraVeritas 360

An assessment is worth conducting only if its conclusions survive being questioned.

InfraVeritas 360 · IGaaS Instrument — DPDPiq Statute — DPDP Act, 2023 (India) Administration — client-side
A DEFENSIBLE POSITION SURVIVESScope declaredEvidence boundConflicts reconciledLimits statedPosition holdsUNDER QUESTION
Each input feeds the same test. Remove one and the position stops surviving it.