Skip to main content
India privacy readiness

DPDP readiness, translated into practical controls and actions

Assess your organisation’s data practices, evidence, ownership, and remediation priorities across key Digital Personal Data Protection themes.

General readiness aid—not legal advice.
Results are based on your inputs and should be validated with qualified legal, privacy, security, and sector specialists.

How it works

Complete the assessment, review the weighted result, and turn the highest-risk gaps into an owned remediation plan.

1. Assess

Select the operational status for each control and record the owner and available evidence.

2. Prioritise

Receive a deterministic 0–100 score, confidence notice, weighted gaps, and urgency bands.

3. Remediate

Export or print the action plan and validate legal interpretations before implementation.

DPDP readiness assessment

Use “Not applicable” only with a documented rationale. Use “Needs legal review” when the correct treatment depends on legal interpretation.

Completion0%
Important: This tool does not determine legal compliance. The DPDP framework and related notifications may have phased commencement, prescribed details, sector overlays, or fact-specific implications requiring professional review.
Rate each control area

1. Data inventory and processing map

Document personal-data categories, sources, systems, purposes, locations, recipients, retention, and accountable owners.

Weight 10
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

2. Purpose specification and privacy notices

Map each processing activity to a clear purpose and provide accessible, itemised notices in appropriate languages and formats.

Weight 9
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

Use consent only where appropriate; capture clear affirmative action, withdrawal, notice version, language, time, and proof.

Weight 8
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

4. Legitimate-use assessment

Identify processing that may rely on a statutory legitimate use and retain the legal analysis and operational safeguards.

Weight 7
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

5. Data-principal rights handling

Operate authenticated workflows for access information, correction, erasure, grievance escalation, and nomination requests.

Weight 9
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

6. Children’s data and parental consent

Identify age-related processing, verify parents or lawful guardians where required, and prevent prohibited tracking or harmful processing.

Weight 9
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

7. Processor and vendor controls

Use written processing terms, due diligence, instructions, security requirements, incident duties, deletion, audits, and sub-processor controls.

Weight 8
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

8. Cross-border data considerations

Know where data is accessed or stored and maintain a mechanism to respond to government restrictions or sector-specific localisation rules.

Weight 6
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

9. Reasonable security safeguards

Apply risk-based access control, encryption, logging, secure development, vulnerability management, backups, testing, and monitoring.

Weight 10
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

10. Personal-data breach response

Maintain detection, triage, containment, evidence, decision, notification, communications, and lessons-learned procedures.

Weight 10
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

11. Retention and deletion

Define purpose-linked retention, legal holds, deletion triggers, processor deletion, backup handling, and evidence of disposal.

Weight 8
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

12. Grievance handling

Publish a contact route, assign responsibility, track deadlines, document outcomes, and connect unresolved matters to escalation paths.

Weight 7
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

13. Significant Data Fiduciary preparedness

Assess possible designation exposure and prepare for enhanced governance such as a DPO, independent audit, and impact assessments where relevant.

Weight 6
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

14. Training and awareness

Provide role-based training for leadership, product, engineering, HR, marketing, support, procurement, and incident responders.

Weight 6
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

15. Evidence and assurance

Maintain policies, records, logs, approvals, contracts, test results, audit trails, metrics, reviews, and remediation evidence.

Weight 9
Choose the status that can be supported by current evidence.
Example: Privacy, Security, HR, Product.
Example: policy ID, contract clause, system report, test date, or missing evidence.

Methodology, limitations, and appropriate use

The checker converts self-reported control maturity into a weighted operational-readiness view. It is designed to support planning, not to replace legal analysis or assurance.

How the methodology works

  • Higher weights are assigned to security, breach response, data mapping, notices, rights, consent, processor controls, and evidence.
  • Partial implementation receives partial credit; implementation with evidence receives full credit.
  • “Needs legal review” remains a scored risk because unresolved interpretation can block operational decisions.
  • Not-applicable answers are excluded so they do not inflate or depress the score.

How to use the result

  • Review Critical and High gaps with executive, legal, privacy, security, product, HR, procurement, and operations owners.
  • Convert each action into a tracked work item with scope, owner, target date, dependency, budget, acceptance criteria, and evidence.
  • Reassess after material system, purpose, vendor, product, incident, or regulatory changes.
  • Validate the final programme through legal review, control testing, and independent assurance appropriate to risk.
Privacy note: No form data is sent to external APIs. Basic calculation is performed by this server on submission; browser exports are generated locally. Data is not intentionally stored by this page beyond the session CSRF token unless the existing site separately implements secure logging or storage.

Frequently asked questions

Practical guidance for interpreting and using the readiness check.

Does a high score mean we comply with the DPDP Act?

No. The score reflects self-reported operational readiness under this tool’s methodology. Compliance depends on legal applicability, facts, current notifications, prescribed requirements, sector rules, contracts, and actual control effectiveness.

Who should complete the assessment?

A cross-functional group is preferable: privacy or legal, security, product, engineering, data governance, HR, marketing, procurement, customer operations, records management, and internal audit.

What counts as evidence?

Examples include approved policies, data maps, notices, consent logs, rights tickets, contracts, deletion reports, security configurations, incident exercises, training records, audit results, metrics, and management-review minutes.

When should “Needs legal review” be selected?

Use it when the correct status depends on legal interpretation—for example applicability, legitimate uses, children’s processing, exemptions, cross-border restrictions, sector overlays, or possible Significant Data Fiduciary obligations.

How should “Not applicable” be used?

Use it only when a documented, approved rationale demonstrates that the control area genuinely does not apply. Review that rationale when processing purposes, data subjects, technology, vendors, or law change.

Why are security and breach response heavily weighted?

Security safeguards and breach preparedness materially affect harm, operational resilience, notification readiness, and regulatory exposure. Weaknesses in these areas can create immediate enterprise risk.

Can small businesses use this tool?

Yes. The control themes can be scaled to organisational size, processing volume, sensitivity, and risk. Smaller organisations should still establish clear ownership, proportionate controls, and usable evidence.

How often should we reassess?

Reassess at least periodically and after material changes such as new products, new purposes, acquisitions, major vendors, new geographies, security incidents, or regulatory updates.

Does the tool send data outside our organisation?

The page uses no external APIs. Submission is processed by the hosting server, and export files are created in the browser. Existing hosting, analytics, logging, or site infrastructure may still process technical data independently.

How should remediation actions be prioritised?

Start with Critical and High gaps, especially security, breach response, data mapping, notices, rights, processor controls, consent, and unresolved legal questions. Then address medium gaps and strengthen assurance.

What is Significant Data Fiduciary preparedness?

It is readiness for enhanced obligations that may apply if an organisation is designated under the legal framework. The assessment flags governance capabilities that may require legal confirmation and advance planning.

Can the exported plan be used as an audit report?

No. It is a planning output based on self-assessment, not independent assurance. An audit requires defined criteria, evidence sampling, testing, documented findings, and competent independent evaluation.