DPDP readiness scorecard
India's DPDP Act core obligations become enforceable 13 May 2027. Answer 12 quick questions to see where you stand, get a gap list with fixes, and a plan to close them. Free, no signup.
Do you give a clear notice (with itemised purposes) before or at the time you collect personal data?
Do you obtain free, specific, informed, unconditional consent — and can users withdraw it as easily as they gave it?
Do you process personal data only for the specific purpose consented to?
Have you implemented reasonable security safeguards (encryption, access control, logging)?
Do you have a documented personal-data-breach response process?
Can a person request access to, correction of, or erasure of their data through a published channel?
Have you published a grievance-redressal mechanism with a response timeline (≤90 days)?
Do you erase personal data once the purpose is served / consent is withdrawn?
For children's data, do you obtain verifiable parental consent and avoid tracking/targeted ads?
Do you have contracts (DPAs) binding every data processor / vendor you share data with?
Have you appointed a contactable grievance/Data Protection Officer and published their details?
Do you maintain records of consent and processing activities you can produce on demand?