Avoid penalties up to ₹250 crore
The Data Protection Board can impose penalties per violation. Know your exposure before a complaint or breach forces the question.
A rigorous 50-question self-assessment for any Indian organisation to gauge readiness for the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, with a plain-language report telling you where you stand, what's missing and what to do before enforcement lands.
Countdown to full-compliance deadline: 13 May 2027. No grace period.
Answer 50 quick Yes / No / Don't-know questions and instantly discover your organisation's compliance stage, weighted score and priority actions.
The DPDPA changes how every business in India collects, stores and uses personal data. This assessment turns a 44-section statute and detailed rules into a clear diagnostic, so leadership, legal, IT and operations teams can act with confidence.
The Data Protection Board can impose penalties per violation. Know your exposure before a complaint or breach forces the question.
Core operational obligations, notice, consent, security, breach reporting and data-principal rights, apply with no grace period.
A dated readiness score, domain scorecard and priority-action list you can put before boards, auditors and the Data Protection Board.
12-domain scorecard highlights the weakest links, from consent notices and DPIAs to breach response and cross-border transfers.
Enterprise buyers, investors and regulators increasingly ask for proof of privacy readiness. Answer with data, not adjectives.
No forms, no email harvesting, no software to install. Answer 50 questions and download a PDF report you can share instantly.
50 Yes / No / Don't-know questions, each with a plain explanation and a highlighted example.
For the most reliable picture answer all 50, but you may generate a report on what you've answered.
A weighted score, 12-domain scorecard, priority actions and deep-dive remediation. Download PDF or share on WhatsApp.
DPDP Rules, 2025 notified; Rules 1, 2 and 17-21 in force. Data Protection Board of India established and the Act's definitions operative. Focus: awareness and framework readiness.
Rule 4 in force: registration and obligations of Consent Managers. Enforcement machinery (penalties and appeals) moves into gear.
Core operational obligations in force - Rules 3 and 5-16 (and 22-23): notice, consent, security, breach notification, retention/erasure, data principal rights, cross-border, children's data and Significant Data Fiduciary duties. Hard full-compliance deadline, no grace period.
Answer 50 Yes / No / Don't-know questions and receive a weighted score, 12-domain scorecard, priority actions and a downloadable PDF report.
AI, Privacy & IP Counsel