DPDP NavigatorAct 2023 · Rules 2025
All templates
Board & Governance

Board Reporting Template for Privacy Metrics

A recurring report format for briefing the Board or leadership on the organization's DPDP compliance posture and metrics.

Template
PRIVACY METRICS - BOARD REPORT

Organization: [Organization Name]
Reporting Period: [Q_ FYXX / Month-Year]
Prepared By: [DPO Name]
Presented To: [Board of Directors / Data Protection Committee]
Date: [DD-MM-YYYY]

1. EXECUTIVE SUMMARY

[2-3 sentence summary of the overall privacy posture this period - e.g. "No high-severity breaches were recorded. Rights request volume grew 12 percent, all closed within SLA. One vendor contract gap identified and remediated."]

2. RIGHTS REQUESTS

Total Requests Received: [_]
By Type: Access [_] | Correction [_] | Erasure [_] | Nomination [_] | Grievance [_]
Closed Within SLA: [_%]
Overdue / Escalated: [_]
Escalated to Data Protection Board: [_]
Notable Trend: [e.g. "Erasure requests increased following the app update in [Month]"]

3. BREACH AND INCIDENT SUMMARY

Total Incidents Logged: [_]
By Severity: Low [_] | Medium [_] | High [_]
Board Intimations Filed (Section 8(6)): [_]
Data Principal Notifications Sent: [_]
Average Time to Containment: [_ hours/days]
Open Incidents: [_], with target closure dates

4. VENDOR AND PROCESSOR RISK

Total Active Vendors Processing Personal Data: [_]
Vendors Rated High Risk: [_], with remediation status
Contracts Renewed / Amended for Section 8(2) Alignment This Period: [_]

5. DPIA AND HIGH-RISK PROCESSING

DPIAs Completed This Period: [_]
Activities Flagged High Residual Risk: [_], with mitigation status
[If Significant Data Fiduciary:] Status of Annual DPIA: [On track / Completed on DD-MM-YYYY]
[If Significant Data Fiduciary:] Status of Independent Audit: [Scheduled / Completed, findings summary]

6. COMPLIANCE GAPS AND REMEDIATION

Column headers: Gap Identified | Source (Audit/Incident/Self-Assessment) | Risk Level | Remediation Owner | Target Date | Status

Example Row:
Gap Identified: Access logs retained for only 6 months against the recommended 1-year baseline
Source: Internal security review
Risk Level: Medium
Remediation Owner: [Security Lead]
Target Date: [DD-MM-YYYY]
Status: In progress

7. TRAINING AND AWARENESS

Employees Trained This Period: [_ / _ total, _%]
Topics Covered: [e.g. consent handling, breach escalation procedure]

8. UPCOMING PRIORITIES

- [Priority 1, e.g. "Complete DPIA for new recommendation engine before launch"]
- [Priority 2, e.g. "Close vendor contract gap with Customer Support Chat Platform"]
- [Priority 3]

Prepared and submitted by:
[DPO Name]
[Designation]

This template is a starting point, not legal advice. Have it reviewed by qualified counsel before use, and adapt bracketed placeholders to your organization's facts.