Know where your business stands on India's DPDP law.
A structured self-assessment against the DPDP Act 2023 and DPDP Rules 2025, built for leadership, data protection officers and compliance teams. Get a readiness score, your priority gaps and a 90-day plan in minutes.
- 5 to 20 minutes
- No sign-up needed
- Report you can share
Readiness
58/100
Building
- Consent and lawful use72
- Security safeguards61
- Breach handling34
- Retention and erasure45
Until 13 May 2027238 days
- Requirements
- 73
- Areas
- 13
- Must-do items
- 43
- In the quick check
- 20
Built for the people accountable for DPDP
CXOs and boards
A clear score, the exposure in rupees and the few decisions that matter this quarter.
Data protection officers
Requirement-level status with evidence confidence, mapped to the Act and Rules.
Legal, risk and IT teams
Owners, first steps and a 30, 60 and 90 day plan to work from.
01
How it works
Three steps. Your answers save on your device as you go.
- Step 1
Profile your business
Eight questions decide which requirements apply to you, including children, cross-border and SDF duties.
- Step 2
Assess each requirement
Mark where you stand on each requirement and whether you can show proof.
- Step 3
Review your report
See your readiness score, priority gaps, penalty exposure and an action plan.
02
What we assess
Every requirement is written from the Act and Rules in plain business language.
01
Governance and accountability
9 requirements, 4 must-do
Up to ₹50 crore
02
Consent and lawful use
10 requirements, 5 must-do
Up to ₹50 crore
03
Notice
4 requirements, 2 must-do
Up to ₹50 crore
04
Rights of data principals
7 requirements, 4 must-do
Up to ₹50 crore
05
Children and guardians
5 requirements, 4 must-do
Up to ₹200 crore
06
Security safeguards
7 requirements, 6 must-do
Up to ₹250 crore
07
Breach handling
6 requirements, 4 must-do
Up to ₹200 crore
08
Retention and erasure
4 requirements, 3 must-do
Up to ₹50 crore
09
Vendors and processors
3 requirements, 1 must-do
Up to ₹50 crore
10
Data leaving India
3 requirements, 1 must-do
Up to ₹50 crore
11
Significant data fiduciary duties
6 requirements, 4 must-do
Up to ₹150 crore
12
Data discovery and scoping
7 requirements, 4 must-do
Up to ₹50 crore
13
Contact, grievance and the Board
2 requirements, 1 must-do
Up to ₹50 crore
Which of these apply to you?
Your profile decides. Most businesses see 50 to 70 requirements in the full assessment.
Check my business
03
Key dates
Obligations commence in phases. Plan backwards from these dates.
- In force
11 August 2023
DPDP Act receives assent
- In force
13 November 2025
DPDP Rules notified; Board provisions in force
- Upcoming
13 November 2026
Consent Manager provisions commence
57 days to go
- Upcoming
13 May 2027
Remaining obligations commence
238 days to go
Proposal: MeitY proposed in January 2026 to shorten the compliance window from 18 to 12 months. Confirm status before relying on it.
04
Penalty exposure
These are statutory maximums. The Board decides each case on its facts.
| Breach | Maximum |
|---|---|
| Failure to take reasonable security safeguards | Up to ₹250 crore |
| Failure to notify the Board or affected people of a breach | Up to ₹200 crore |
| Breach of additional obligations for children | Up to ₹200 crore |
| Breach of additional obligations of a significant data fiduciary | Up to ₹150 crore |
| Breach of any other provision | Up to ₹50 crore |
See your readiness in five minutes.
Start with the quick check. You can move to the full assessment at any time without losing your answers.
Your answers stay on your device until you share your details to open the report.