Free tool · DPDP Act 2023
Is your business DPDP-ready?
India’s Digital Personal Data Protection Act is in force, with penalties up to ₹250 crore. Answer 12 questions, about 3 minutes, and get a readiness score with a prioritised fix list. No signup, nothing leaves your browser.
New to the law? Read our plain-English DPDP guide first.
01 / 12 · Consent & Notice
Before collecting any personal data, do you show a clear notice stating what you collect and why, in plain language?
02 / 12 · Consent & Notice
Is consent a genuine opt-in, unticked boxes, no pre-checked defaults, no bundled "agree to everything"?
03 / 12 · Consent & Notice
Can a user withdraw consent as easily as they gave it?
04 / 12 · Data Governance
Do you maintain an inventory of what personal data you hold, where it lives, and which vendors can access it?
05 / 12 · Data Governance
Do you use personal data only for the purpose stated at collection, no silent reuse for marketing or analytics?
06 / 12 · Data Governance
Do you delete personal data once its purpose is served, rather than keeping it indefinitely?
07 / 12 · Security
Do you have reasonable security safeguards, encryption in transit and at rest, access controls, no shared admin logins?
08 / 12 · Security
If personal data leaked tomorrow, do you have a written process to notify the Data Protection Board and affected users?
09 / 12 · User Rights
Do you publish a grievance contact and respond to data-related complaints within a defined time?
10 / 12 · User Rights
Can users request a copy of their data, corrections, or deletion, and do you actually fulfil these?
11 / 12 · Special Cases
If your service can be used by under-18s, do you obtain verifiable parental consent and avoid tracking or targeted ads at children?
12 / 12 · Special Cases
Do your contracts with vendors that process personal data (CRM, analytics, hosting) cover DPDP obligations?
0 / 12 answered