Skip to content
Check Your SSE Readiness

Measure What Matters

From Sensitivity to Social Impact

Impact speaks when measured, and qualifies when assessed.

Evidence demonstrates impact. The Social Stock Exchange calls for independent assessments. Protecting beneficiary data is now mandatory. Three forces are reshaping how social impact must be proved in India.

  • The Companies (CSR Policy) Amendment Rules, 2021

    Rule 8(3) mandates impact assessment for ₹1-crore-plus CSR projects, completed at least one year earlier, by companies averaging ₹10-crore-plus CSR obligations over the preceding three years.

  • SEBI's Social Stock Exchange

    Calls for credible, SAS-aligned independent impact reports.

  • The DPDP Act, 2023

    Demands stricter security for beneficiary data, with substantive provisions commencing 13 May 2027.

Our Assessors are NISM-certified. We validate outcomes, strengthen evidence, and support SSE readiness.

Explore our solutions
S. 2(k), DPDPA, 2023

As a Data Processor

Along with intervention data, assessments contain beneficiaries’ personal data that requires secure handling. Our commitment to this principle is what sets us apart.

When Samvedana Analytics conducts an impact assessment, we process data on behalf of our clients, acting as a Data Processor under the Digital Personal Data Protection Act, 2023. We take that responsibility seriously.

Our data handling is powered by verifiable trust infrastructure for data authenticity, developed by Axiomaera Private Limited, a deep-tech, DPIIT-recognised company (DIPP248013). Axiomaera is solely a technology licensor and does not obtain, store or process any kind of beneficiary data.

From field data collection through to the final report, every stage of data processing is carried out as per a written agreement in accordance with the Section 8(2) of the DPDPA, 2023 and the security safeguards prescribed under Rule 6 of the DPDP Rules, 2025 — including access controls, encryption, and processing logs.

DPDPA has set the standard. The Social Impact Assessment agencies and assessors are yet to embrace the Data Processor obligations. We have adopted these standards. We explicitly state our obligations and also abide by them, because the organisations we assess deserve that rigour, and so do the communities whose data we handle.

Section 12, DPDPA, 2023

The obligations we hold

Four Data Processor obligations, met from field data collection to final reporting.

01

Consent management

Every processing activity rests on the data principal’s clear, informed, and revocable consent.

02

Specific-purpose processing

Beneficiary data is used only for the specific purpose it was collected for, and nothing beyond it.

03

Data necessity

We collect only the data an assessment genuinely needs, in keeping with data minimisation.

04

Right to erasure

Data principals may request deletion of their personal data under Section 12 of the DPDPA.

Measure your impact with confidence.