A customer fills out your website form with their name, phone number and email address. The information then moves to your CRM, reaches your sales team, perhaps gets followed up on WhatsApp, and may eventually sit across several cloud platforms.
The question is simple:
Do you actually know where that customer's personal data goes?
If the answer is unclear, it's time to look beyond the Privacy Policy and understand the organisation's actual data flow.
A Data Protection Impact Assessment (DPIA) is a structured way of identifying how personal data is collected, accessed, stored and shared, and assessing the privacy risks associated with those activities.
Under India's DPDP framework, Significant Data Fiduciaries have specific DPIA and audit obligations. However, a DPIA should not be assumed to be legally mandatory for every business. For other organisations, it can still be a useful risk-assessment and DPDP readiness exercise.
What questions should a business ask?
A practical DPIA should help you answer at least these 10 questions.
1. What personal data does the organisation collect?
Start by identifying the information you collect from customers, employees, users or other individuals.
This could include names, phone numbers, email addresses, location information, account details, enquiries and other information relating to identifiable individuals.
2. Who has access to this data?
Which departments, employees and roles can access personal information?
Sales, marketing, HR, customer support and management may have different access requirements. The important question is whether that access is necessary and appropriately controlled.
3. Which third parties receive the data?
Your organisation may not be the only party handling personal data.
Think about your:
CRM → cloud provider → email platform → analytics tools → WhatsApp provider → marketing platforms
Mapping these relationships helps identify where information leaves your direct control.
4. Where is the data stored?
Is customer information stored on company servers, cloud platforms, CRM systems, employee laptops, mobile devices or application databases?
You need visibility across the entire data environment.
5. Where are the relevant systems located?
Understanding where your servers, cloud infrastructure and data-processing systems are located can be important when assessing your data flows and regulatory obligations.
This becomes particularly relevant when businesses use international technology platforms.
6. Who controls the systems and data?
Who has administrative access to your CRM?
Who controls the cloud account?
Who can access or export the database?
These questions can uncover risks that aren't visible from the customer-facing website.
7. When and why can the data be accessed?
Access should have a legitimate business purpose.
A DPIA should examine the circumstances under which employees, vendors or systems can access personal data and whether that access is appropriate.
8. What controls prevent misuse?
Businesses should assess the safeguards around personal data, such as:
- Role-based access
- Authentication
- Password controls
- Access logging
- Device security
- Employee permissions
- Data encryption
- Vendor controls
Having access controls is one thing. Knowing whether they adequately address the actual risk is another.
9. Are the existing safeguards adequate?
This is where a DPIA moves beyond simply documenting systems.
The question becomes:
Are our current technical, organisational and operational safeguards appropriate for the risks we've identified?
The answer may reveal gaps requiring further action.
10. What needs to change?
A DPIA should ultimately lead to an action plan.
Depending on the organisation, this could involve changes to:
- Website forms
- Consent and notice mechanisms
- CRM workflows
- Access controls
- Data retention
- Data deletion
- Third-party integrations
- Mobile applications
- Cloud systems
- Internal processes
The objective isn't to create another document that sits in a folder. It is to turn identified risks into practical actions.
What happens after a DPIA?
A useful assessment should follow a simple cycle:
Identify → Assess → Prioritise → Remediate
First understand what personal data exists and where it moves.
Then assess the risks.
Next, prioritise the gaps based on their potential impact and business context.
Finally, create a realistic remediation roadmap.
This approach can help businesses move from “We think we're compliant” to “We understand our data environment and know what needs attention.”
Is a DPIA the same as DPDP compliance?
No.
A DPIA is an assessment tool, not a universal certificate of compliance.
The broader DPDP readiness journey can involve legal requirements, policies, processes, technology, security, vendor management and organisational controls.
For that reason, businesses should avoid treating a DPIA as a one-time checkbox exercise.
Where can Socialtitli help?
Many data-protection gaps eventually require changes to the technology through which personal data is collected or processed.
That could mean a website contact form, mobile application, CRM, cloud system, analytics setup or automated workflow.
Socialtitli is currently building its DPDP capability and can assist businesses with the technology and digital implementation side of their data-protection readiness journey—including reviewing digital data flows and identifying technology-related areas that may require attention.
Where legal interpretation or determination of specific statutory obligations is required, businesses should involve an appropriately qualified privacy or legal professional.
For businesses requiring changes to their digital touchpoints, Socialtitli can also assist with website development and implementation.
The best place to start
If your organisation cannot confidently answer all 10 questions, that's not necessarily a problem.
It's a reason to investigate.
A structured DPIA or data-protection readiness assessment can help answer:
What data do we collect?
Why do we collect it?
Where does it go?
Who can access it?
How is it protected?
What needs to change?
That understanding can become the foundation for a practical DPDP readiness roadmap.
At Socialtitli we can support the digital and technology side of that journey while businesses obtain appropriate legal/privacy guidance for their specific circumstances.
Need help understanding where your business stands?
If you're unsure about your website, CRM, applications, data flows or access controls, contact Socialtitli to discuss your requirement.
We can help you take the first step: understanding your current digital data environment, identifying technology-related gaps and working out what needs attention.