Compliance overview
Live standing across every mapped department. Last synced from department interviews and survey responses 2 days ago.
Needs your attention
| Finding | Department | Status | |
|---|---|---|---|
| Lead-gen partners undocumented as processors | Marketing | Open | |
| WhatsApp used for KYC document intake | HR | Open | |
| Retention listed as "Permanent" with no legal basis check | Internal Audit | Under review |
Department coverage
| Department | Activities | Retention | Status |
|---|---|---|---|
| HR | 10 | 6 undefined | In review |
| IT | 10 | Defined | Mapped |
| Marketing | 11 | 9 undefined | Needs interview |
| Grievance | 3 | All undefined | Undersampled |
| Internal Audit | 6 | Conflict found | Verify |
Action items
Every open finding, auto-raised from the register and cross-checked against interview evidence. Nothing here was typed in by hand.
| Finding | Basis | Department | Source | Status | |
|---|---|---|---|---|---|
| Lead-gen partners undocumented as processors | Sec 8(2) | Marketing | Table 2 vs Table 3 sweep | Open | |
| WhatsApp used for KYC document intake | Sec 8(5) | HR | Interview narrative | Open | |
| Retention listed as "Permanent" with no legal basis check | Sec 8(7) | Internal Audit | RoPA table | Under review | |
| Retention/interview conflict on audit trail | Sec 8(7) | Internal Audit | Table 2 vs Table 3 sweep | Under review | |
| BGV vendor identified, DPA requested | Sec 8(2) | HR | Processor registry | Remediation sent |
Records
What's mapped, who else touches it, and the source it's traced back to.
Processing activities
| ID | Data category | Department | Legal basis | Retention |
|---|---|---|---|---|
| PA-025 | Lead Generation Data | Marketing | Consent | Not defined |
| PA-014 | Loan Details | IT | Legal · Contractual | Regulatory |
| PA-001 | Employee Personal Data | HR | Legal obligation | As required by law |
| PA-032 | Customer Queries | Grievance | Consent | Not defined |
| PA-020 | Financial Records (Audit) | Internal Audit | Legitimate interest | Permanent — flagged |
PA-025 · Lead Generation Data
| Processor | Department | Role | DPA status | Cross-border |
|---|---|---|---|---|
| Meta Ads | Marketing | Lead-gen / ad platform | Unconfirmed | Yes |
| Vendor A (MSP) | IT | MSP — loan management DB access | Unconfirmed | No |
| BGV Vendor | HR | Background verification | No retention clause | No |
| LeadSpring Partners | Marketing | Lead-gen partner | Unconfirmed | Unknown |
| CPGRAMS | Grievance | Govt. grievance portal | N/A — government | No |
| Outsourced developers | IT | App development | Unconfirmed | Unknown |
| Document | Linked to | Hash | Uploaded |
|---|---|---|---|
| Grievance Department v1.1.docx | PA-032, PA-033, PA-034 | a1f9…3c02 | 28 May 2024 |
| Marketing Department.docx | PA-021 – PA-031 | 7e0d…88b1 | 26 Apr 2024 |
| HR Department v1.2.docx | PA-001 – PA-010 | c44a…f012 | 26 Apr 2024 |
Consequences of non-compliance
What the Act actually provides for, in plain terms — not a prediction of what would happen to you.
Penalty categories
| Violation category | Statutory basis | Penalty range | Relevant to |
|---|---|---|---|
| Failure to implement reasonable security safeguards | Sec 8(5), Schedule | Up to ₹250 crore | 2 open findings |
| Failure to notify a personal data breach | Sec 8(6), Schedule | Up to ₹200 crore | 0 open findings |
| Non-compliance with obligations re: children's data | Sec 9, Schedule | Up to ₹200 crore | 0 open findings |
| Non-compliance with other fiduciary obligations | Sec 8, Schedule | Up to ₹50 crore | 3 open findings |
| Breach of duties by a Data Principal | Sec 15, Schedule | Up to ₹10,000 | Not applicable — fiduciary side only |
How this connects to your register
Roadmap
What's coming next, and what it's built on. Nothing below is live yet.
Data Principal Rights
Access, correction, and erasure requests — each one queries the register directly instead of a manual search.
Breach Management
Incident logging with Board and Data Principal notification tracking.
Cross-Border Transfers
Where data leaves India, checked against restricted-country status.
Consent Management
Notice and purpose configuration, plus per-person consent records in their own dedicated store.
SDF Compliance
DPO records, DPIA register, and independent-audit tracking for Significant Data Fiduciaries.
Reports
The document you actually hand to an auditor, a customer's procurement team, or the Board — not the working register, a finished record.
Available reports
| Report | Covers | Last generated | |
|---|---|---|---|
| Full RoPA — all departments | 40 activities, 5 depts | 2 days ago | |
| Processor & DPA status summary | 11 processors | 2 days ago | |
| Open findings — board briefing | 18 action items | 2 days ago | |
| Evidence index | 27 source documents | 2 days ago |
Refresh cycle
Included in planSurvey & data collection
Track who's responded, and review anything that came in by voice before it enters the register.
Send survey
| Sent to | Department | Channel | Sent | Status |
|---|---|---|---|---|
| R. Singh | Grievance | Today, 9:02 AM | Completed | |
| A. Kapoor | Grievance | Today, 9:02 AM | Opened, not finished | |
| N. Iyer | Marketing | 2 days ago | Not opened |
Voice response review queue
| Respondent | Question | Transcribed answer | |
|---|---|---|---|
| Marketing team | Which outside vendor? | "QuickFin... Connect I think" | |
| IT team | Anything informal or undocumented? | "we send FinnOne access logs to..." |
Department completion
| Department | Sent to | Responded | Completion |
|---|---|---|---|
| HR | 4 | 4 | 100% |
| IT | 3 | 3 | 100% |
| Marketing | 4 | 3 | 75% |
| Grievance | 2 | 1 | 50% |
| Internal Audit | 3 | 2 | 67% |
What the employee sees
pramaan.app/s/8f2k1