Compliance overview

Live standing across every mapped department. Last synced from department interviews and survey responses 2 days ago.

Free quarterly refresh keeps this register current — next one in 88 days. See refresh cycle →
Activities mapped
40 across 5 depts
Retention undefined
18 of 40 activities
Processors unconfirmed
8 of 11 — no DPA on record
Evidence on file
27 source documents

Needs your attention

FindingDepartmentStatus
Lead-gen partners undocumented as processorsMarketingOpen
WhatsApp used for KYC document intakeHROpen
Retention listed as "Permanent" with no legal basis checkInternal AuditUnder review

Department coverage

AllNeeds review
DepartmentActivitiesRetentionStatus
HR106 undefinedIn review
IT10DefinedMapped
Marketing119 undefinedNeeds interview
Grievance3All undefinedUndersampled
Internal Audit6Conflict foundVerify

Action items

Every open finding, auto-raised from the register and cross-checked against interview evidence. Nothing here was typed in by hand.

FindingBasisDepartmentSourceStatus
Lead-gen partners undocumented as processorsSec 8(2)MarketingTable 2 vs Table 3 sweepOpen
WhatsApp used for KYC document intakeSec 8(5)HRInterview narrativeOpen
Retention listed as "Permanent" with no legal basis checkSec 8(7)Internal AuditRoPA tableUnder review
Retention/interview conflict on audit trailSec 8(7)Internal AuditTable 2 vs Table 3 sweepUnder review
BGV vendor identified, DPA requestedSec 8(2)HRProcessor registryRemediation sent

Records

What's mapped, who else touches it, and the source it's traced back to.

Processing activities

All deptsMarketingHR
IDData categoryDepartmentLegal basisRetention
PA-025Lead Generation DataMarketingConsentNot defined
PA-014Loan DetailsITLegal · ContractualRegulatory
PA-001Employee Personal DataHRLegal obligationAs required by law
PA-032Customer QueriesGrievanceConsentNot defined
PA-020Financial Records (Audit)Internal AuditLegitimate interestPermanent — flagged
◆ Gap: 2 open

PA-025 · Lead Generation Data

Marketing · sourced from interview, 24 Apr 2024
Description
Information on potential leads and prospects surfaced through digital partner channels.
Purpose
Identify and nurture potential customers
Storage
Salesforce
Processors linked
Meta AdsLeadSpring PartnersQuickFin ConnectFinLead Direct
Retention
Not defined — no policy on record
Evidence
MKT-INT-2024-04-24.docx · Table 2
ProcessorDepartmentRoleDPA statusCross-border
Meta AdsMarketingLead-gen / ad platformUnconfirmedYes
Vendor A (MSP)ITMSP — loan management DB accessUnconfirmedNo
BGV VendorHRBackground verificationNo retention clauseNo
LeadSpring PartnersMarketingLead-gen partnerUnconfirmedUnknown
CPGRAMSGrievanceGovt. grievance portalN/A — governmentNo
Outsourced developersITApp developmentUnconfirmedUnknown
DocumentLinked toHashUploaded
Grievance Department v1.1.docxPA-032, PA-033, PA-034a1f9…3c0228 May 2024
Marketing Department.docxPA-021 – PA-0317e0d…88b126 Apr 2024
HR Department v1.2.docxPA-001 – PA-010c44a…f01226 Apr 2024

Consequences of non-compliance

What the Act actually provides for, in plain terms — not a prediction of what would happen to you.

Reference only, not legal advice. Penalties under the DPDP Act are set by the Data Protection Board case by case — considering severity, repetition, and remediation — not calculated automatically per finding. Figures below are drawn from the Act's penalty schedule (Sec 33); verify against the current official text before relying on them, and consult counsel for anything specific to your organisation.

Penalty categories

Violation categoryStatutory basisPenalty rangeRelevant to
Failure to implement reasonable security safeguardsSec 8(5), ScheduleUp to ₹250 crore2 open findings
Failure to notify a personal data breachSec 8(6), ScheduleUp to ₹200 crore0 open findings
Non-compliance with obligations re: children's dataSec 9, ScheduleUp to ₹200 crore0 open findings
Non-compliance with other fiduciary obligationsSec 8, ScheduleUp to ₹50 crore3 open findings
Breach of duties by a Data PrincipalSec 15, ScheduleUp to ₹10,000Not applicable — fiduciary side only

How this connects to your register

Every finding in Action Items carries a "Basis" tag citing the specific Act section it relates to — that's the link back to this page, not a computed exposure number attached to the row itself.

Roadmap

What's coming next, and what it's built on. Nothing below is live yet.

Phase 2

Data Principal Rights

Access, correction, and erasure requests — each one queries the register directly instead of a manual search.

Depends on: Processing Activities ↔ Systems link (already built)
Phase 2

Breach Management

Incident logging with Board and Data Principal notification tracking.

Depends on: Risk / Control / Evidence (already built)
Phase 2

Cross-Border Transfers

Where data leaves India, checked against restricted-country status.

Depends on: a maintained restricted-country list (not yet built)
Phase 3

Consent Management

Notice and purpose configuration, plus per-person consent records in their own dedicated store.

Depends on: a separate high-volume consent store (not yet built)
Phase 3

SDF Compliance

DPO records, DPIA register, and independent-audit tracking for Significant Data Fiduciaries.

Thresholds pending final DPDP Rules — not yet confirmed

Reports

The document you actually hand to an auditor, a customer's procurement team, or the Board — not the working register, a finished record.

Available reports

ReportCoversLast generated
Full RoPA — all departments40 activities, 5 depts2 days ago
Processor & DPA status summary11 processors2 days ago
Open findings — board briefing18 action items2 days ago
Evidence index27 source documents2 days ago

Refresh cycle

Included in plan
Every quarter, Pramaan re-sends the survey to flag stale answers and re-checks the register against the latest regulatory catalog — included at no extra cost, so the RoPA never goes stale between engagements.
Last refresh: 2 days ago · Next scheduled: in 88 days

Survey & data collection

Track who's responded, and review anything that came in by voice before it enters the register.

Departments surveyed
5 of 5
Responses pending review
4 voice notes
Avg. completion
81%
"Other"/skip rate
6% — options fit well

Send survey

GrievanceMarketingAll not-yet-sent
Sent toDepartmentChannelSentStatus
R. SinghGrievanceWhatsAppToday, 9:02 AMCompleted
A. KapoorGrievanceWhatsAppToday, 9:02 AMOpened, not finished
N. IyerMarketingEmail2 days agoNot opened

Voice response review queue

RespondentQuestionTranscribed answer
Marketing teamWhich outside vendor?"QuickFin... Connect I think"
IT teamAnything informal or undocumented?"we send FinnOne access logs to..."

Department completion

DepartmentSent toRespondedCompletion
HR44100%
IT33100%
Marketing4375%
Grievance2150%
Internal Audit3267%

What the employee sees

WhatsApp · Pramaan Compliance
Sent to R. Singh, Grievance Hi Rohit — Acme Finance is mapping how each team handles customer data, no jargon, just how you actually work. Takes ~4 minutes, talk or tap.

pramaan.app/s/8f2k1
Taps the link — no login, no app install
Marketing team check-inQ5 of 8
Third-party check

Does this information ever go to anyone outside your team — another company, or a government body?

Which one? Type a name, or use the mic below.
Or just talk — tap to record a 30-second voice note instead of typing.