DPDP Forum.
DPDP readiness check

India’s data protection law has moved. Has your business?

Ten minutes. A few honest answers about how your business actually handles customer data. A clearer picture of where you stand, before someone else asks you first.

A practical readiness check for the Digital Personal Data Protection Act, 2023, built for Indian business owners, not for lawyers reading it for fun.

Opens in a new tab. Free. No sign-up. About ten minutes.

Before you start

What to expect

  • Free, with no account or sign-up
  • Takes about ten minutes
  • Your answers stay in this browser tab
  • Guidance to work from, not legal advice
Built around the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, as notified on 13 November 2025.
No turnover threshold, no small-business exemption Score, gap report and roadmap in one pass Four starter documents, ready to adapt Reviewed by a lawyer, not written by one
01 Why this matters now

The law did not arrive on one day

It arrived in stages, and the stages are not over. The DPDP Act became law in 2023, but stayed dormant until the Rules were notified in November 2025. Two more milestones are still ahead, and this is the timeline the readiness check itself is built against.

11 August 2023
The DPDP Act, 2023 receives Presidential assent. The law is on the books, but without Rules to operate by, it stays largely dormant.
13 November 2025
The DPDP Rules, 2025 are notified. The Data Protection Board is constituted and a soft-enforcement period opens. This is when the law started to matter in practice.
Upcoming
November 2026
The Consent Manager framework becomes operational, and the obligations around consent and notice are expected to tighten as the phased schedule matures.
Upcoming
13 May 2027
End of the transition window. Full obligations become enforceable and the penalty Schedule applies with the Board fully in play.

This is not a countdown to a single deadline. It is the calendar the whole assessment is built against: understand it, and prepare sensibly.

Before you worry about compliance, answer a simpler question. Do you actually know what customer data your business holds, and who can see it?

02 What you get

Six things, at the end of ten minutes

Nothing here is invented for this page. This is exactly what the assessment produces once you finish.

01

Readiness score

A single score out of 100, worked out from how your answers weigh against the areas the Act treats as most serious.

02

Plain-language gap report

Every open item, explained in the same ordinary words the questions used, not legal phrasing you need translated.

03

Priority and severity

Gaps ordered by how seriously the Act treats them, so you know what to fix first and what can wait.

04

A practical roadmap

Your gaps sequenced against the real dates: now, before November 2026, and before 13 May 2027.

05

Starter documents

Four working drafts, your business name already filled in: a privacy notice, consent wording, a vendor checklist and a breach playbook.

06

Act & Rules reference library

A plain-language digest of the whole Act and the Rules, chapter by chapter, to come back to whenever you need it.

03 How it works

Five steps, nothing more

01

Tell us about the business and how it collects customer details.

02

Answer practical questions about how the business actually handles data.

03

See where the gaps are, in plain words, ordered by severity.

04

Get a roadmap for what to address, and by when.

05

Take the output to your lawyer or your internal team.

04 Who it is for

Built around how real Indian businesses collect data

The check is not written for one industry. These are the categories the assessment itself asks you to choose from.

Retail and jewellerySector 01
Clinic and healthcareSector 02
Education and coachingSector 03
E-commerce and D2CSector 04
HospitalitySector 05
Manufacturing and B2BSector 06
Services and otherSector 07

If your business collects a customer’s name, phone number or email through any digital channel, the Act applies regardless of sector, turnover or size. There is no small-business exemption.

05 What this tool does not claim

Worth saying plainly, so you can trust the rest

i

It is not a legal certificate. Nothing it produces is a certification, registration or approval of any kind.

ii

It does not certify compliance. A high score means fewer open gaps by your own answers, not a guarantee a regulator would agree.

iii

It does not replace a data-protection lawyer. The output is designed for a lawyer to review before you rely on it, not instead of one.

iv

It is a practical first assessment. A place to start with clear eyes, not the last word on where your business stands.

Up to ₹2,50,00,00,000

The highest statutory penalty ceiling under the Act, for a failure to take reasonable security safeguards that leads to a personal data breach. It is a maximum set by the Schedule to the Act, not a prediction, and it says more about how seriously the law treats security than about what is likely to happen to any one business. The sensible response to a law with real consequences is simply to know where you stand.

06 Latest updates

What has changed recently

Found gaps you are not sure how to fix?

A gap list tells you what to fix. It does not know which of those matters most for how your business actually runs. If that would help, talk it through with someone, free of charge, once you have your result.

Talk through your result
07 Need help

Leave your details and someone will call

This is the same enquiry desk the readiness check itself uses. No separate mailing list, no sales pitch, just a conversation about your result if you want one.

Most people who write in have already run the check and want to talk through what it found. You do not have to finish it first though; if you would rather understand the law before you start, that is a fair reason to write in too.

Tell us when it suits you to talk, and in which timezone. We default to Indian Standard Time, but you can pick another if that fits you better.

Everything here goes to the same place the check’s own “get help” button does. Nobody outside sees it.

Enter your name.
Enter a valid email address.
Enter a valid 10-digit Indian mobile number.
Enter your city.
Select your state.

When should we call? This part is optional.

Choose a date in the future, or leave both date and time blank.
Choose a time, or leave both date and time blank.
Choose a timezone.