Privacy Management & Compliance
PrivacyIQ
Data inventory, technical discovery, and DPDP readiness in one place
1 min readLast reviewed July 18, 2026
The Problem
Why PrivacyIQ exists
Privacy programs are usually built on spreadsheets and point-in-time audits — nobody can say, on any given day, what personal data exists, where it flows, or whether a website is quietly sending data to a third party before consent is captured.
Industry Pain Points
What most teams are stuck with today
- Data inventories are manually maintained and go stale immediately
- Privacy audits are a once-a-year snapshot, not a continuous state
- Technical privacy risk — trackers, third-party scripts, consent-gate behavior — is rarely observed directly
- Regulatory readiness is asserted rather than evidenced
How Threat ResQ Solves It
Inside PrivacyIQ
PrivacyIQ brings together data discovery, inventory, findings, readiness, evidence, vendor risk, and data subject rights into one connected privacy management experience — organized around a product model (Discover, Assess, Manage, Prove) built on a technical discovery flow (Observe, Detect, Map, Assess, and Act) that turns raw technical observation into a documented, evidence-backed readiness view rather than a stale, point-in-time audit.
PrivacyIQ — Live Overview
Readiness Trend
—
See It In Action
PrivacyIQ, up close
PrivacyIQ — Overview dashboard
Screenshot placeholder
PrivacyIQ — Detail / drill-down view
Screenshot placeholder
PrivacyIQ — Reporting & export
Screenshot placeholder
Placeholder mockups — to be replaced with real product screenshots.
Platform Connection
PrivacyIQ in the Threat ResQ Platform
No product here works in isolation — every signal it produces or consumes is shared with the rest of the ecosystem.
Feature Comparison
What changes, concretely
Traditional approach
PrivacyIQ
Data inventories are manually maintained and go stale immediately
Data Inventory — data assets, processing activities, and data flows
Privacy audits are a once-a-year snapshot, not a continuous state
Technical Discovery — HTTP-level technical scanning for third-party domains and tracker signals, SSRF-hardened, with confidence-scored observations (DETECTED, INFERRED, POTENTIAL, UNKNOWN, NOT_OBSERVED) and a review workflow to promote scan observations into confirmed metadata. Browser-level (JavaScript-executing) discovery — in-browser script execution, runtime network capture, and automated production-scale collection — is on the roadmap and not currently available; the current scanner observes what a website exposes over plain HTTP.
Technical privacy risk — trackers, third-party scripts, consent-gate behavior — is rarely observed directly
Findings — explainable, severity-rated privacy findings, each a traceable chain from observation to finding to evidence to a specific mapped DPDP obligation (never a generic label)
Regulatory readiness is asserted rather than evidenced
Readiness — technical DPDP readiness evaluated per obligation into one of four states: Ready, Partial, Gap, or Unknown — never silently defaulted. Structured remediation/assignment tracking for recommended actions (the 'Act' stage) is on the roadmap; manual actions are tracked today alongside technical findings.
Industries Served
Where PrivacyIQ fits
PrivacyIQ gives BFSI compliance teams a live data inventory and DPDP readiness view, rather than a once-a-year privacy audit for a sector handling some of the most sensitive personal data in the economy.
PrivacyIQ's continuous technical discovery flags trackers and data flows around patient-facing systems, backing privacy obligations with evidence instead of an annual snapshot.
PrivacyIQ tracks data inventory and third-party trackers continuously, giving SaaS companies a current-state privacy posture to show enterprise buyers and DPDP-scoped Indian customers alike.
PrivacyIQ gives IT/ITES firms a living record of data flows and processing activities across client engagements, turning DPDP readiness into evidence rather than an assertion in a due-diligence questionnaire.
Capabilities
What's included
- Data Inventory — data assets, processing activities, and data flows
- Technical Discovery — HTTP-level technical scanning for third-party domains and tracker signals, SSRF-hardened, with confidence-scored observations (DETECTED, INFERRED, POTENTIAL, UNKNOWN, NOT_OBSERVED) and a review workflow to promote scan observations into confirmed metadata. Browser-level (JavaScript-executing) discovery — in-browser script execution, runtime network capture, and automated production-scale collection — is on the roadmap and not currently available; the current scanner observes what a website exposes over plain HTTP.
- Findings — explainable, severity-rated privacy findings, each a traceable chain from observation to finding to evidence to a specific mapped DPDP obligation (never a generic label)
- Readiness — technical DPDP readiness evaluated per obligation into one of four states: Ready, Partial, Gap, or Unknown — never silently defaulted. Structured remediation/assignment tracking for recommended actions (the 'Act' stage) is on the roadmap; manual actions are tracked today alongside technical findings.
- Posture — a deterministic, non-AI Privacy Posture score computed from five equally weighted dimensions (Regulatory Readiness, Data Asset Completeness, Processing Activity Mapping, Discovery Review Coverage, and Security (Findings-Adjusted)), each shown with its own numerator, denominator, and explanation. A dimension with no data yet is shown as Unknown, never silently scored zero. This is a technical privacy posture assessment based on available metadata, observations, evidence, and findings — it does not determine legal compliance.
- Evidence — evidence artifacts (a scan result, a manual entry, a document) backing findings and governance actions, each with a linked record and an integrity status. A dedicated evidence-collection module is on the roadmap.
- Privacy Requests, Vendor governance, and Incident register
FAQ
Common questions
Is PrivacyIQ a DPDP-only tool?
PrivacyIQ is built as a privacy management platform, not a single-regulation tool. Its current regulatory readiness scope is DPDP (India); broader regulatory coverage is on the roadmap, not yet implemented.
Does PrivacyIQ use AI to score posture?
No — posture scoring is deterministic and rule-based, not AI- or LLM-derived.
Is PrivacyIQ a compliance certification?
No. PrivacyIQ is a privacy management and technical readiness platform, not a certifying authority. It does not grant, claim, or imply 'DPDP compliant' status or any other compliance certification. Its posture score and readiness views are technical indicators that support a privacy programme, not legal conclusions.
Does PrivacyIQ execute JavaScript when scanning a website?
Not currently. PrivacyIQ's scanner observes what a website exposes over plain HTTP. It does not render pages in a browser, so scripts or trackers that only load after client-side JavaScript execution are not currently visible to it. This is a documented limitation, not a claim of complete visibility. Browser-level (JavaScript-executing) discovery is on the roadmap.
What is the Privacy Posture score?
A deterministic score computed from five equally weighted dimensions — Regulatory Readiness, Data Asset Completeness, Processing Activity Mapping, Discovery Review Coverage, and Security (Findings-Adjusted). Every component shows its numerator, denominator, and explanation. A dimension with no data yet is shown as Unknown, never a fabricated number. This is a technical privacy posture assessment; it does not determine legal compliance.
How does PrivacyIQ differ from consent management or generic data discovery tools?
Consent tools manage consent capture. Generic data discovery platforms find where data is stored, without DPDP-specific context. PrivacyIQ connects technical discovery, findings, and evidence directly to India's DPDP Act obligations and a technical readiness view.
What DPDP obligations does PrivacyIQ track?
PrivacyIQ tracks the DPDP Act's provisions structurally, without inventing commencement dates — obligations are only treated as effective once government notification actually establishes them. Each obligation is evaluated to one of four states — Ready, Partial, Gap, or Unknown — as a traceable chain from obligation to evidence to action.
See PrivacyIQ on your own environment.
30 minutes, no scripted pitch.