Skip to main content

Free checker

DPDP readiness checker

Twenty questions that tell you how far you are from being able to defend your DPDP position.

Run it now

Answer the questions and you get the number, the working behind it and what we would do about it. The calculation itself runs in your browser, so your answers stay with you.

What you tell it

  • How you collect consent today, and whether you can prove it after the fact
  • Whether you have a current record of processing
  • How data principal requests reach you and what happens next
  • Processor contracts, retention rules and breach process

What you get back

  • A readiness score across consent, notice, rights, retention, vendors and breach
  • The gaps ranked by how exposed they leave you
  • A ninety day plan with an owner suggested against each item
  • The evidence a regulator would ask for first

How the score is worked out

  1. 1

    Questions map one to one onto obligations in the DPDP Act 2023 and the draft Rules.

  2. 2

    Scoring is weighted by enforcement likelihood rather than treating every clause as equal.

  3. 3

    Consent and breach response carry the heaviest weight, because they are the most visible failures.

  4. 4

    Anything you cannot evidence is scored as absent, which is how an audit will treat it.

Where this stops being useful

A good score means your paperwork is in order. It does not mean your engineering matches it. The two diverge more often than anyone likes.

What readiness means under this Act

The DPDP Act 2023 is short, which misleads people into thinking compliance is light. Most of its weight sits in four obligations: a lawful basis that for most Indian businesses means consent to a higher standard than currently used, data principal rights as workflows with clocks on them, breach notification to the Board and to affected individuals, and not retaining personal data past its purpose.

Readiness is not whether you have a privacy policy. It is whether you could, today, produce a consent record for a named user, honour an erasure request across every system including backups and processors, and identify who would decide a breach is notifiable at two in the morning.

This checker asks those questions rather than the documentation questions, because documentation is the part organisations have and capability is the part they do not.

The four gaps that appear in nearly every assessment

Inventory. You cannot honour erasure against data you have not mapped, and the map is almost never complete: the analytics warehouse, a CRM export on a shared drive, a vendor's copy, a backup that restores deleted records.

Consent architecture. Retrofitting granular, withdrawable consent onto a product built on implied consent is a product change with engineering lead time, not a legal exercise. Withdrawal also has to propagate to processors.

Processor contracts. The Act makes you accountable for what your processors do, and most vendor agreements predate it and say nothing useful about breach notification timelines, audit rights or deletion at termination.

Evidence. Being compliant and being able to demonstrate compliance are different problems, and only the second is testable. Every control needs an artefact.

Reading your score honestly

A high score with a weak inventory answer is not a high score. Inventory gates everything else, so treat it as a multiplier rather than as one section among several.

Sections where you answered partially deserve more attention than sections where you answered no. A partial control creates a documented commitment you are not fully keeping, which is worse in an enforcement conversation than an acknowledged gap with a plan against it.

If the tool tells you something you already knew, that is a result. Most privacy programmes stall not from ignorance but from the absence of a named owner for the uncomfortable parts.

What to fix first

Breach notification, immediately, because it is one page and a named decision maker and the cost of not having it is unbounded. Note that it is separate from the six hour CERT-In duty and triggered differently; build one detection process with two reporting paths off it.

Then inventory, because everything else depends on it. Then retention, because deleting data past its purpose is the largest single reduction in exposure available and it costs engineering time rather than licence spend.

Then consent, which is a product change with a long lead time and should be started early even though it will finish late. Then rights, then evidence, which accumulates rather than being built.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.