How it works
A guided six-step workflow.
Client staff supply the inputs; the AI does the reading and mapping; the lawyer runs review and sign-off.
The pipeline
Five stages, end to end.
Every assessment moves through the same pipeline — from intake to a regulator-ready report.
- 01 Intake
- 02 Extract
- 03 Assess
- 04 Review
- 05 Report
Steps 1–2 · Intake & extract
Getting the facts in — accurately.
Questionnaire & intake
Client staff answer a questionnaire and upload documents themselves.
- How
- Formats auto-detected; every file virus-scanned, hashed and safely stored.
- Why better
- Weeks of lawyer email become safe, self-serve data collection.
Document intelligence
Radicept reads every document — even scanned, image-only PDFs.
- How
- Hybrid OCR + AI extraction turn files into evidence tagged to statute.
- Why better
- A junior's line-by-line reading, done in minutes and never skipped.
Compliance Questionnaire
Is personal data encrypted at rest across all production systems?
Risk-relevant questionDocuments
24 documents · 21 indexed · 3 processing
Privacy Policy v4.pdf
Customer-facing notice
Consent Form - Onboarding.pdf
Vendor DPA - Cloud Hosting.docx
Information Security Policy.pdf
Retention Schedule.csv
Recreated from the product interface
Steps 3–4 · Map & assess
Mapping practice to the statute.
Data map
An inventory of data categories, activities and flows — built for you.
- How
- AI extracts entities; a deterministic rule fixes sensitivity (Aadhaar, PAN).
- Why better
- The assessment's foundation is automatic, yet safety-critical calls stay rule-based.
AI assessment & findings
Each activity is mapped to the applicable provisions and graded; gaps become findings.
- How
- Retrieval + rerank + a grounded LLM, reconciled against deterministic rules.
- Why better
- Hundreds of checks, consistent and cited — not one lawyer's memory.
| Category | Sensitivity | Source |
|---|---|---|
| Aadhaar number | Special category | documents |
| Payment instrument | Sensitive | documents |
| Employee records | Sensitive | questionnaire |
| Marketing email | General | manual |
Sensitivity is set by deterministic rule — not model judgment.
-
§8(4) Reasonable security safeguards
Encryption at rest is documented for the primary database, but no control is evidenced for backups or the analytics replica.
Partial AI OnboardingConfidence 74% -
§5(1) Notice accompanying consent request
The published notice states the categories collected and the purpose of processing, and is served before consent is captured.
Compliant Human OnboardingConfidence 91% -
§8(6) Breach notification to the Board
No documented procedure for notifying the Data Protection Board within the prescribed period was found in the supplied policies.
Non-Compliant AI OnboardingConfidence 88%
Recreated from the product interface
Steps 5–6 · Review & report
Judgment where it counts — then proof.
Human review
The lawyer confirms, edits or overrides — only where it matters.
- How
- A confidence router auto-accepts the certain and escalates the doubtful.
- Why better
- Judgment spent on the 20% that needs it; every decision is auditable.
Report & evidence
A board-ready report and a dated evidence snapshot, in one click.
- How
- Deterministic score + a citation-checked AI narrative; posture captured and dated.
- Why better
- No writing from scratch — and you can prove your posture to a regulator.
Reviews
6 review(s)
Onboarding Data Map — Gap Analysis
Generated Sep 4, 2026 · Framework: DPDP Act 2023
Summary
34
Activities
18
Categories
12
Flows
612
Provisions
208
Mappings
47
Findings
Gap Analysis
28
Compliant
5
Non-Compliant
11
Partial
| Entity Type | Entity Name | Issue |
|---|---|---|
| Processing Activity | Marketing analytics | No legal basis recorded |
| Data Category | Employee records | Retention period not specified |
Recreated from the product interface
See Radicept on your own documents.
A guided demo on a real DPDP assessment — from intake to a regulator-ready report.