DPDPA gap assessment for KaizenMotors
Scenario
KaizenMotors currently has no DPDPA programme. They collect employee data, customer contact info, vendor KYC, and use a US-based CRM (HubSpot). They have an Indian entity (Kaizen Motors India Pvt Ltd) and Malaysian + Thai subsidiaries. DPDPA enforcement is now mandatory (Aug 2026). Board wants a 3-month path to compliance.
Your role
You are the newly-appointed Data Protection Officer (DPO).
Your task
Produce a DPDPA gap-assessment report: 1. Personal data inventory (categories + volumes + flows) 2. Legal basis mapping per data flow (consent / contract / legal obligation / legitimate use) 3. 10 highest-risk gaps (with severity) 4. 3-month remediation roadmap (Month 1 / 2 / 3) 5. Cost estimate for gap closure
Deliverable format: Report ~1000-1500 words + gap register + roadmap
Toolkit
- DPDPA legal bases: consent, employment, function of the State, medical emergency, disaster response, court-ordered
- Cross-border transfer: DPDPA is silent on adequacy — assume all transfers need explicit consent
- HubSpot in US: transfer to US requires consent + optional SCC-equivalent
- Standard high-risk gaps: consent notices, RoPA (Record of Processing), DPO appointment, breach response, DSR fulfilment
Success criteria (what the AI grades against)
- Data inventory is asset-specific (not 'employee data')
- Legal basis mapped per flow (some will need consent, some don't)
- HubSpot cross-border transfer explicitly addressed
- Roadmap is realistic (not 'implement everything Month 1')
- Cost estimate has line items (tools + external help + internal effort)
Log in to submit your deliverable for AI review.
Log in / Register