Buyer's tool

A 20-point checklist to score any monitoring vendor on DPDP readiness - plus the terms explained

No vendor is DPDP-certified in 2026, Custelis included - the Rules are still phasing in and there's no certification body yet. What you can do is score any vendor, including us, against specific, checkable points instead of taking "DPDP-ready" on faith. Score honestly - a vendor that fails a few of these but is upfront about it is a better sign than one that claims a clean sweep.

The checklist

Score each point against the vendor you're evaluating - not against Custelis specifically. Where relevant, we've noted how Custelis handles it, but use these as questions for any vendor's sales team to answer directly.

Consent & legal basis

Transparency

Data-principal rights

Breach response

What's captured, and what isn't

Governance

How Custelis scores on this list: Section 7 legitimate-use basis, per-role scope, conservative defaults, persistent monitoring notice, self-service data-principal portal, drafted (not automatic) response generation, a running 72-hour clock with editable awareness timestamp and a generated Board-report payload, hard-coded rejection of keystroke/credential capture (not just a policy toggle), screenshots off by default and DPIA-gated, IT-managed-device-only installation, classification-driven (not content-scanning) DLP, and DLP/data-rights/breach-tooling included from the Starter plan. See the full DPDP-readiness guide for the detail behind each of these.

Glossary

Data Principal
The individual the personal data is about. In an employee-monitoring context, this is your employee.
Data Fiduciary
The entity that decides why and how personal data is processed. Your organization is the Data Fiduciary for the monitoring data collected on your employees - the employer, not the vendor.
Data Processor
An entity processing personal data on a Data Fiduciary's behalf, under contract. A monitoring vendor typically acts as a processor for the data it stores on your behalf.
Consent Manager
A registered intermediary through which a data principal can give, manage, and withdraw consent across multiple fiduciaries. Not typically part of an internal employee-monitoring flow, which usually relies on the employment relationship's legitimate-use basis instead of individual consent collection.
Significant Data Fiduciary (SDF)
A Data Fiduciary the government designates for extra obligations - appointing a Data Protection Officer, running periodic DPIAs and audits - based on the volume and sensitivity of data processed. The threshold is set by government notification, not something you self-assess; most employers running monitoring software are not SDFs.
Legitimate Use (Section 7)
A basis for processing personal data without collecting individual consent, for specified purposes including employment. It is not a blanket exemption - processing still has to be necessary and proportionate to the purpose.
DPIA (Data Protection Impact Assessment)
A documented assessment of privacy risk carried out before starting a higher-risk processing activity. Intrusive capture - screenshots, for example - should be gated behind a completed and approved DPIA, not switched on by default.
Rule 6 (security safeguards)
The DPDP Rules provision requiring reasonable security safeguards - encryption, access controls, logging, backups - appropriate to the nature of the personal data being processed.

This page explains our understanding of the DPDP Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Confirm applicability and compliance obligations for your organization with your own counsel.

Related reading

See how Custelis scores, live

No credit card to start. Intrusive features stay off until your own DPIA is recorded.

Try for free