Author: Shweta Chaudhury
As India prepares for the DPDP roll-out, with full statutory compliance for all provisions required by May 2027, the development sector is also gearing up to protect the data of the people they serve.
At Project Tech4Dev, we built a self-serve platform where NGOs can access practical DPDP resources. On this platform, NGOs can also take a dipstick self-assessment, answering 25 questions across five DPDP compliance areas to receive an instant readiness score. Based on their responses, they also receive an AI-generated customised 30/90/365-day action plan to help them prioritise their next steps. This should allow for NGOs to align with their management and board on what’s needed for compliance at a high strategic level.
What are the initial assessments telling us?
38 organizations have used our self-assessment tool, so far, and some early patterns are beginning to emerge. A selection of the insights are available on our self-serve platform. But let’s dive deeper here on what we are seeing.

Across sectors, NGOs appear to have already started taking steps towards compliant data storage and usage practices. However, many organisations need to strengthen their data collection and consent processes. There is also an urgent need to build clear channels for beneficiaries to exercise their rights, including requesting corrections, seeking erasure of their data, or raising grievances.

Chart 1: Average scores achieved out of a maximum of 10, across compliance sections
The weakest area so far appears to be governance. Most organisations have not put in place any foundational processes such as having written privacy policies, arranging training for all their staff, building breach response plans, and conducting periodic reviews. This is a critical activity, as these processes will be paramount when organisations are audited and are required to show evidence of compliance.
Some other interesting insights emerged when we looked at the granular data:
- Larger orgs are no better prepared than smaller ones.
- Some areas where most orgs are doing poorly are Data retention, Grievance redressal mechanism, Withdrawal of consent, Staff Training, Identification of Data breaches.
- Some areas where most orgs have made a start or are doing quite well are Purpose Limitation, Data minimisation, protecting and restricting access to PII data, Vendor management

Chart 2: Average scores, out of a total of 50, by size of organization
There are marked sectoral differences as well, with some sectors already moving ahead of the pack. It’s encouraging to see that organisations working on sensitive topics such as Disability and Humanitarian areas, had made a head start, even before the enactment of DPDP, and have put safeguards in place for managing sensitive data.

Chart 3: Average scores achieved out of a maximum of 10, across compliance sections, for organisations working on Education vis-a-vis all organizations

Chart 4: Average scores achieved out of a maximum of 10, across compliance sections, for organisations working on Health & Nutrition vis-a-vis all organizations
The Way Forward
While we can make endless comparisons using data, what is important for social organizations to think of as they embark on their compliance journey, is to do an honest assessment of where they stand now. Then translate that into action from a tech and data perspective, and break things down into a simple but actionable roadmap. A crucial part of implementing DPDP successfully is to build the requisite people processes and new field SoPs.
As the development sector builds legal compliance, they will also implement good data practices, and build better cyber and data security protocols. All of this will strengthen institutional trust, improve accountability, and safeguard the rights of individuals, particularly vulnerable communities, while enabling more ethical and effective data-driven decision-making.