A 20-point checklist to score any monitoring vendor on DPDP readiness - plus the terms explained
No vendor is DPDP-certified in 2026, Custelis included - the Rules are still phasing in and there's no certification body yet. What you can do is score any vendor, including us, against specific, checkable points instead of taking "DPDP-ready" on faith. Score honestly - a vendor that fails a few of these but is upfront about it is a better sign than one that claims a clean sweep.
The checklist
Score each point against the vendor you're evaluating - not against Custelis specifically. Where relevant, we've noted how Custelis handles it, but use these as questions for any vendor's sales team to answer directly.
Consent & legal basis
- Legal basisDoes the vendor rely on Section 7 "legitimate use" for employment purposes, or does it bolt on a generic consent banner that doesn't match how employment data actually works?
- NecessityCan you configure monitoring scope per role, or is it all-or-nothing across every employee regardless of job function?
- ProportionalityDoes the vendor's default configuration start conservative (logging-only) and require deliberate opt-in for more intrusive capture, or does it ship maximal capture on by default?
Transparency
- DisclosureDoes every monitored device show a persistent notice that it's monitored, or can the agent run silently with no on-device indicator?
- Self-service accessCan an employee see what's actually been collected about them without filing a request and waiting?
- Covert capabilityDoes the vendor's own marketing or documentation offer a "stealth" or "invisible" mode? If yes, that's a direct transparency-requirement conflict, not a feature.
Data-principal rights
- AccessIs there a real, working self-service flow for an employee to request what's held about them, or is it "email our support team and wait"?
- Correction & erasureCan a data-principal request for correction or erasure actually be actioned in the product, not just acknowledged?
- Response draftingDoes the vendor help you respond accurately and quickly, or does your compliance team have to manually reconstruct what data exists on a given employee from scratch each time?
Breach response
- 72-hour trackingDoes the product track the Section 6 72-hour Board-notification deadline as a visible, running clock, or is that entirely a manual process on your side?
- Awareness timestampCan the detection/awareness timestamp be set to when you actually became aware, matching the "awareness, not confirmation" standard - or does the vendor's tooling only support "now"?
- Board-report contentDoes the vendor generate the specific fields a Board report needs (nature, affected categories, count, consequences, mitigation), or do you have to assemble that from raw logs under time pressure?
What's captured, and what isn't
- Keystrokes & credentialsIs keystroke logging or password/credential capture technically impossible in the product, or just "off by policy" (meaning a misconfiguration or a support override could turn it on)?
- ScreenshotsIf screenshots exist as a feature, are they off by default, rate-limited, and gated behind a documented risk assessment - or just a checkbox an admin can flip with no review step at all?
- Personal devicesDoes the agent install only on company-owned, IT-managed hardware, or can it be pushed to a personal or BYOD device without a separate consent flow?
- Content vs. metadataDoes DLP enforcement work from classification/metadata (who, what, where, when), or does the vendor claim to scan inside file content - and if the latter, where does that content go, and who can see it?
Governance
- DPIA gateIs there a real, enforced gate requiring a recorded impact assessment before intrusive features activate, or is "we recommend a DPIA" just a line in the docs nobody checks?
- Audit trailIs every access to sensitive collected data (a screenshot, a client record) itself logged and reviewable, or only the employee-facing activity, not admin/support access to it?
- Data residencyWhere is the data actually stored, and does that matter for your specific regulatory obligations beyond DPDP (e.g., client engagement terms, sector-specific rules)?
- Vendor lock-in on priceAre DLP, the data-principal-rights workflow, and the breach clock included from the base plan, or gated behind an "enterprise" tier you have to negotiate up to?
How Custelis scores on this list: Section 7 legitimate-use basis, per-role scope, conservative defaults, persistent monitoring notice, self-service data-principal portal, drafted (not automatic) response generation, a running 72-hour clock with editable awareness timestamp and a generated Board-report payload, hard-coded rejection of keystroke/credential capture (not just a policy toggle), screenshots off by default and DPIA-gated, IT-managed-device-only installation, classification-driven (not content-scanning) DLP, and DLP/data-rights/breach-tooling included from the Starter plan. See the full DPDP-readiness guide for the detail behind each of these.
Glossary
- Data Principal
- The individual the personal data is about. In an employee-monitoring context, this is your employee.
- Data Fiduciary
- The entity that decides why and how personal data is processed. Your organization is the Data Fiduciary for the monitoring data collected on your employees - the employer, not the vendor.
- Data Processor
- An entity processing personal data on a Data Fiduciary's behalf, under contract. A monitoring vendor typically acts as a processor for the data it stores on your behalf.
- Consent Manager
- A registered intermediary through which a data principal can give, manage, and withdraw consent across multiple fiduciaries. Not typically part of an internal employee-monitoring flow, which usually relies on the employment relationship's legitimate-use basis instead of individual consent collection.
- Significant Data Fiduciary (SDF)
- A Data Fiduciary the government designates for extra obligations - appointing a Data Protection Officer, running periodic DPIAs and audits - based on the volume and sensitivity of data processed. The threshold is set by government notification, not something you self-assess; most employers running monitoring software are not SDFs.
- Legitimate Use (Section 7)
- A basis for processing personal data without collecting individual consent, for specified purposes including employment. It is not a blanket exemption - processing still has to be necessary and proportionate to the purpose.
- DPIA (Data Protection Impact Assessment)
- A documented assessment of privacy risk carried out before starting a higher-risk processing activity. Intrusive capture - screenshots, for example - should be gated behind a completed and approved DPIA, not switched on by default.
- Rule 6 (security safeguards)
- The DPDP Rules provision requiring reasonable security safeguards - encryption, access controls, logging, backups - appropriate to the nature of the personal data being processed.
This page explains our understanding of the DPDP Act, 2023 and the DPDP Rules, 2025, and is not legal advice. Confirm applicability and compliance obligations for your organization with your own counsel.
Related reading
- DPDP-ready employee monitoring: a 2026 framework
- The 72-hour breach clock, explained
- Aadhaar, PAN & GST data protection
See how Custelis scores, live
No credit card to start. Intrusive features stay off until your own DPIA is recorded.
Try for free