ModulesGovernance

Governance

Manage your organisation's regulatory readiness and privacy governance framework, including accountability measures, oversight responsibilities, and compliance status.

Governance gives privacy leaders one place to measure how ready the organisation is for the Digital Personal Data Protection Act and to name the people accountable for privacy. Its centrepiece is the guided DPDP Readiness Assessment: you answer plain questions across six areas, Neostra scores the answers, flags critical gaps, tells you how to close them, and tracks the score over time. The module has three screens: Dashboard, Scanner, and Tenant Profile.

The DPDP Readiness Assessment

The assessment is a built-in, read-only template that Neostra maintains. It has 33 questions in six weighted sections. Each section is worth a fixed share of a 100 point total.

SectionQuestionsPointsWhat it evaluates
Governance520Data protection governance structure, leadership, and organisational accountability
Transparency520Public-facing privacy communications and contact accessibility
Security Safeguards825Technical and organisational security measures for protecting personal data
Data Mapping615Understanding and documentation of personal data flows
Incident Preparedness510Incident response and breach notification capabilities
Vendor Readiness410Vendor and processor management and contractual safeguards

Every question is a direct, practical check, for example "Have you assigned a Data Protection Lead or designated contact person for DPDP?" or "Is encryption at rest enabled for user data?". Each has the same four answers: Yes, No, In Progress, and N/A. Yes earns full points, In Progress earns half, No earns none, and N/A removes the question from scoring.

Questions carry a criticality of Low, Medium, High, or Critical, and the five Critical questions are marked with a Critical chip. Where a question has a hint, it appears under the title. For the answers that matter most, the template also defines:

  • Critical Gap. A named gap that appears when you choose the answer that triggers it, for example "No Data Protection Lead Assigned" when you answer No to the first question.
  • Remediation. Guidance shown for that answer, labelled Action Required, Recommendation, or Reminder depending on urgency, with a message, Steps to Remediate, and any Resources links.

You can review the whole template before you start, including its Score Interpretation Guide, each section's points, and every question's criticality, gaps, and remediation. From the Scanner, the template name links to this preview.

Running a scan

Initiate

Open Governance > Dashboard. If no scan exists yet, the page shows No Scan Created Yet. Click Initiate Scan, review the template preview, and click Run Scan. Neostra creates one assessment for your organisation and makes you its owner. Once a scan exists, the button reads View Assessment instead.

Answer

On Governance > Scanner, the left panel lists Sections & Questions with an answered count per section. Choose a section to see its progress, points, and Risk Assessment, then its questions. Select an answer, add Notes/Description if you want to record context, and click Save Answer. Answers are saved one at a time, so you can leave and return.

Filter

The status bar shows how many questions are answered. Use Filter to show All, Answered, or Not Answered questions.

Complete

When every question is answered, Mark Complete becomes available. Confirm in the Complete Assessment dialog. The status changes from In Progress to Completed, and answers can no longer be changed.

Relaunch

When your programme has moved on, the owner clicks Relaunch and confirms in the Relaunch Assessment dialog. The assessment returns to In Progress, picks up the latest template version, and keeps the answers that still apply so you can update the rest.

Ownership

An assessment has one owner. Only the owner can answer questions, edit the name, description, and tags, mark it complete, or relaunch it. Everyone else sees it read-only. If you are taking over the programme, click Become Owner and confirm. Ownership transfers to you and the previous owner loses edit access.

Understanding the score

The percentage is points earned divided by points available, with N/A questions removed from both sides. Each section is scored the same way on its own, so you can see where the shortfall sits. The Scanner shows the overall score as points out of 100 and a percentage, with the template's risk band:

ScoreRisk band
85 to 100Excellent - Fully Compliant
70 to 84Satisfactory
50 to 69Needs Improvement
0 to 49Critical - Immediate Action Required

The template's passing score is 70. Sections carry the same banding, so one section can read "Needs Improvement" while the overall assessment is "Satisfactory".

The Dashboard

Governance > Dashboard summarises the assessment for everyone in the tenant.

  • Overall Readiness Score. The percentage in a progress ring, with a Compliance Status of Ready (100%), Partial (70% or more), Weak (40% or more), or Non-compliant (below 40%).
  • Critical Gaps. The number of Critical questions, split into Open (not yet answered) and Closed (answered).
  • Last Scan. The date and time the assessment was last updated, how long ago that was, and its status.
  • Score Breakdown. Each section's percentage, coloured green above 70%, amber between 40% and 70%, and red below 40%.
  • Readiness Trend. How the score has built up since the assessment was created, as a line, area, or bar chart.
  • Critical Gaps list. Questions you answered with a gap-triggering option, shown by question number, gap title, and section. Click one to jump to that question in the Scanner.
  • Recent Activity. The latest answer updates, with the question reference, who made the change, and when.
  • DPO Contact. The name, phone number, and email of the person assigned to the Data Protection Officer profile in Tenant Profile.

The Scanner shows the template's risk band and the Dashboard shows a four-step compliance status. Both come from the same percentage.

Exporting the assessment

On Governance > Scanner, click Export to download the assessment as a PDF. It has a cover page, an overview with the template, owner, dates, description, score, and risk level, and a part per section listing each question with its answer, notes, points, critical gap, and remediation.

Tenant Profile

Governance > Tenant Profile records who holds each privacy role in your organisation. Neostra creates a fixed set of Tenant Role Profiles: Data Protection Officer, Grievance Officer, Executive Sponsor (CXO), Security Lead, Legal Lead, and Engineering Lead. Each shows as Assigned or Not Assigned. Click the edit icon or Assign User, choose a Neostra user, confirm their first name, last name, and email, and optionally add a title, phone number, and department.

Below the roles, Compliance Team Members is a repeatable list. Click Add Member to create as many slots as you need, assign users to them, and delete a slot when someone leaves. Deleting a slot does not delete the user account.

The Data Protection Officer assignment feeds the DPO Contact card on the Dashboard, so keep it current. The Grievance Officer profile is where you record the contact your organisation names for data principal grievances under the DPDP Act.

The readiness score is a self-assessment based on your answers, not a certification or legal advice. Review results with your DPO or counsel.